> Markdown version of [/jobs/ext/203262-senior-network-security-engineer](https://www.wearedevelopers.com/jobs/ext/203262-senior-network-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Network Security Engineer - **Company:** Mastercard - **Location:** O'Fallon, MO, United States - **Experience:** Expert - **Salary:** $96,000.0 - $163,000.0 - **Contract:** Permanent contract - **Skills:** Border Gateway Protocol, Code Review, Cyber Security, Data Centers, Dynamic Host Configuration Protocol, Linux, Intrusion Detection Systems, Python (Programming Language), Network Security, Routing, Packet Analyzer, Open Shortest Path First (OSPF), PCI Data Security Standards, Public Key Infrastructure, PowerCLI, Ansible, SSL Certificate Management, Load Balancing, Bare Metal, Firewall Services Module, Restful APIs, Software Version Control, Cisco, Vmware - **Published:** May 19, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=af7c586b8a921d0d ## About the Role * Demonstrate hands-on expertise with VMware NSX-T Data Center: upgrades/migrations, Managers/Edges, T0/T1, EVPN/VXLAN fundamentals, DFW policy design, Groups/Tags, NAT, and BGP/OSPF peerings. * Have solid vSphere/vCenter/ESXi operational skills, including VDS networking, host transport configuration, and connectivity troubleshooting across virtual/physical boundaries. * Show practical experience with Illumio Core (PCE) or equivalent microsegmentation platforms for bare-metal firewall use cases: labels/policies, agent lifecycle, policy simulation/validation, and staged enforcement. * Possess strong troubleshooting skills spanning L2-L4 (and basic L7 where relevant): routing, neighbor states, MTU/ECMP asymmetry, ACL/DFW hits, NAT, and cert/trust failures. * Understand certificate management (PKI, CSRs, chains, renewal/rotation) and license administration (entitlements, consumption, renewal windows). * Communicate clearly with technical and non-technical audiences; produce crisp change plans, RCA documents, and executive-level summaries. * Embrace automation and IaC concepts (PowerCLI, Python, Ansible, REST APIs); familiarity with code review and version control is a plus. * Operate within ITIL frameworks (INC/PRB/CRQ) and change governance; comfortable running changes during maintenance windows and peak-season constraints. * (Preferred) Hold certifications such as VMware VCP-NV / VCIX-NV, Illumio certifications, RHCSA/Linux+, and/or ITIL v4; exposure to NSX Advanced Load Balancer (Avi) is beneficial. * (Nice to have) Familiarity with adjacent domains: physical networking (Arista/Cisco), firewalling, IDS/IPS/service insertion, and compliance (e.g., PCI DSS). ## Description The Micro-Segmentation Operations team within Global Network Operations is seeking an Engineer, NSX & Microsegmentation to ensure Mastercard's private cloud and data center network services are resilient, secure, and high-performing. This role focuses on VMware NSX-T lifecycle management and operational support, as well as Illumio-based microsegmentation for bare-metal firewalls and server workloads. You will execute in-place NSX upgrades, perform configuration changes (e.g., segments/port groups, distributed firewall rules, Tier-0/Tier-1 gateways, load balancer objects), manage platform licensing and certificates, and drive incident/problem management across production environments. The ideal candidate thrives in high-stakes operational contexts, communicates crisply, and partners across infrastructure, security, and app teams to deliver change safely and on time. Role In this position, you will: * Operate and upgrade VMware NSX-T across multiple data centers: plan/execute lifecycle activities (NSX Managers/Edges/Transport Nodes), pre-checks, impact assessments, change/rollback plans, post-validation, and documented handoffs. * Administer NSX configurations: create/modify segments & port groups (VDS/VSS), transport zones, segment profiles, DHCP profiles, T0/T1 routing, NAT, BGP/OSPF adjacencies, NSX DFW sections/policies, Groups/Tags, and (as applicable) NSX Advanced Load Balancer objects. * Support Illumio microsegmentation (bare-metal firewalls): manage PCE objects & label schemas, author and validate segmentation policies, deploy/upgrade agents (VENs) where applicable, support enforcement modes, and partner on app onboarding/runbooks. * Manage certificates for NSX Managers/Edges and related appliances: track expirations, coordinate CSRs, perform installs/rotations, and maintain inventories & workflows to eliminate certificate-related outages. * Own licensing for NSX & Illumio: monitor entitlements, forecast needs, initiate purchase requests, and ensure timely renewals and compliant deployment. * Triage and resolve incidents/problems: perform root-cause analysis across virtual networking, routing, and segmentation; maintain SLAs; create follow-up problem records with corrective actions and knowledge articles. * Open and drive vendor cases (VMware, Illumio, and OEMs): provide diagnostics, packet captures/logs, reproduce issues in lower environments, and track to closure with clear stakeholder updates. * Harden and validate security posture: maintain least-privilege DFW/Illumio policies, coordinate change windows, and support audits (e.g., PCI) with evidence, diagrams, and rule reviews. * Automate and document: use PowerCLI, Python, Ansible, or REST APIs to standardize changes and validations; write SOPs/runbooks, diagrams, and KBs; contribute to CI/CD pipelines where appropriate. * Partner cross-functionally: collaborate with platform, compute, storage, security, and application teams to plan maintenance, align dependencies, and minimize risk. * Participate in on-call rotation for NSX/segmentation services and support peak-season readiness and freeze-window protocols per Mastercard standards. * Comply with ITIL processes: create/execute CRQs with risk/impact/rollback details, update INC/PRB records, and communicate status through executive-ready channels., Every person working for, or on behalf of, Mastercard is responsible for information security. All activities involving access to Mastercard assets, information, and networks comes with an inherent risk to the organization and therefore, it is expected that the successful candidate for this position must: * Abide by Mastercard's security policies and practices; * Ensure the confidentiality and integrity of the information being accessed; * Report any suspected information security violation or breach; and Complete all periodic mandatory security trainings in accordance with Mastercard's guidelines., All activities involving access to Mastercard assets, information, and networks comes with an inherent risk to the organization and, therefore, it is expected that every person working for, or on behalf of, Mastercard is responsible for information security and must: * Abide by Mastercard's security policies and practices; * Ensure the confidentiality and integrity of the information being accessed; * Report any suspected information security violation or breach, and * Complete all periodic mandatory security trainings in accordance with Mastercard's guidelines. ## Related Videos - [How Cisco embraced a DevOps culture within its network engineering team](https://www.wearedevelopers.com/videos/99-how-cisco-embraced-a-devops-culture-within-its-network-engineering-team) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [WebAssembly: The Next Frontier of Cloud Computing](https://www.wearedevelopers.com/videos/972-webassembly-the-next-frontier-of-cloud-computing) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Generating code with Angular schematics](https://www.wearedevelopers.com/videos/129-generating-code-with-angular-schematics) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) ## Related Articles - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed)