Overview
USD 94,000.00 - 157,000.00 per year
Full Time
Skills
Innovation
Payments
Partnership
Finance
Network Operations
Cloud Computing
Network
Lifecycle Management
Tier 1
Problem Management
Data Centers
Microsoft Visual SourceSafe
DHCP
Onboarding
Workflow
Licensing
Forecasting
Auditing
Payment Card Industry
Continuous Integration
Continuous Delivery
Collaboration
Storage
Migration
T1
Border Gateway Protocol
OSPF
VMware vSphere
VMware
VMware ESXi
Firewall
Use Cases
Data Link Layer
Routing
ACL
NAT
Management
PKI
Root Cause Analysis
PowerCLI
Python
Ansible
Code Review
Version Control
VMware Certified Professional
RHCSA
Linux+
ITIL
Load Balancing
Computer Networking
Arista
Cisco
IDS
IPS
Regulatory Compliance
PCI DSS
Law
Recruiting
Reporting
Information Security
Insurance
Life Insurance
SAFE
Microsoft Windows
Job Details
Our Purpose
Mastercard powers economies and empowers people in 200+ countries and territories worldwide. Together with our customers, we're helping build a sustainable economy where everyone can prosper. We support a wide range of digital payments choices, making transactions secure, simple, smart and accessible. Our technology and innovation, partnerships and networks combine to deliver a unique set of products and services that help people, businesses and governments realize their greatest potential.
Title and Summary
Senior Platform Engineer
Who is Mastercard?
Mastercard is a global technology company in the payments industry. Our mission is to connect and power an inclusive, digital economy that benefits everyone, everywhere by making transactions safe, simple, smart, and accessible. Using secure data and networks, partnerships and passion, our innovations and solutions help individuals, financial institutions, governments, and businesses realize their greatest potential.
Our decency quotient, or DQ, drives our culture and everything we do inside and outside of our company. With connections across more than 210 countries and territories, we are building a sustainable world that unlocks priceless possibilities for all.
Overview
The Micro-Segmentation Operations team within Global Network Operations is seeking an Engineer, NSX & Microsegmentation to ensure Mastercard's private cloud and data center network services are resilient, secure, and high-performing. This role focuses on VMware NSX-T lifecycle management and operational support, as well as Illumio-based microsegmentation for bare-metal firewalls and server workloads.
You will execute in-place NSX upgrades, perform configuration changes (e.g., segments/port groups, distributed firewall rules, Tier-0/Tier-1 gateways, load balancer objects), manage platform licensing and certificates, and drive incident/problem management across production environments. The ideal candidate thrives in high-stakes operational contexts, communicates crisply, and partners across infrastructure, security, and app teams to deliver change safely and on time.
Role
In this position, you will:
Operate and upgrade VMware NSX-T across multiple data centers: plan/execute lifecycle activities (NSX Managers/Edges/Transport Nodes), pre-checks, impact assessments, change/rollback plans, post-validation, and documented handoffs.
Administer NSX configurations: create/modify segments & port groups (VDS/VSS), transport zones, segment profiles, DHCP profiles, T0/T1 routing, NAT, BGP/OSPF adjacencies, NSX DFW sections/policies, Groups/Tags, and (as applicable) NSX Advanced Load Balancer objects.
Support Illumio microsegmentation (bare-metal firewalls): manage PCE objects & label schemas, author and validate segmentation policies, deploy/upgrade agents (VENs) where applicable, support enforcement modes, and partner on app onboarding/runbooks.
Manage certificates for NSX Managers/Edges and related appliances: track expirations, coordinate CSRs, perform installs/rotations, and maintain inventories & workflows to eliminate certificate-related outages.
Own licensing for NSX & Illumio: monitor entitlements, forecast needs, initiate purchase requests, and ensure timely renewals and compliant deployment.
Triage and resolve incidents/problems: perform root-cause analysis across virtual networking, routing, and segmentation; maintain SLAs; create follow-up problem records with corrective actions and knowledge articles.
Open and drive vendor cases (VMware, Illumio, and OEMs): provide diagnostics, packet captures/logs, reproduce issues in lower environments, and track to closure with clear stakeholder updates.
Harden and validate security posture: maintain least-privilege DFW/Illumio policies, coordinate change windows, and support audits (e.g., PCI) with evidence, diagrams, and rule reviews.
Automate and document: use PowerCLI, Python, Ansible, or REST APIs to standardize changes and validations; write SOPs/runbooks, diagrams, and KBs; contribute to CI/CD pipelines where appropriate.
Partner cross-functionally: collaborate with platform, compute, storage, security, and application teams to plan maintenance, align dependencies, and minimize risk.
Participate in on-call rotation for NSX/segmentation services and support peak-season readiness and freeze-window protocols per Mastercard standards.
Comply with ITIL processes: create/execute CRQs with risk/impact/rollback details, update INC/PRB records, and communicate status through executive-ready channels.
All About You
The ideal candidate for this position should:
Demonstrate hands-on expertise with VMware NSX-T Data Center: upgrades/migrations, Managers/Edges, T0/T1, EVPN/VXLAN fundamentals, DFW policy design, Groups/Tags, NAT, and BGP/OSPF peerings.
Have solid vSphere/vCenter/ESXi operational skills, including VDS networking, host transport configuration, and connectivity troubleshooting across virtual/physical boundaries.
Show practical experience with Illumio Core (PCE) or equivalent microsegmentation platforms for bare-metal firewall use cases: labels/policies, agent lifecycle, policy simulation/validation, and staged enforcement.
Possess strong troubleshooting skills spanning L2-L4 (and basic L7 where relevant): routing, neighbor states, MTU/ECMP asymmetry, ACL/DFW hits, NAT, and cert/trust failures.
Understand certificate management (PKI, CSRs, chains, renewal/rotation) and license administration (entitlements, consumption, renewal windows).
Communicate clearly with technical and non-technical audiences; produce crisp change plans, RCA documents, and executive-level summaries.
Embrace automation and IaC concepts (PowerCLI, Python, Ansible, REST APIs); familiarity with code review and version control is a plus.
Operate within ITIL frameworks (INC/PRB/CRQ) and change governance; comfortable running changes during maintenance windows and peak-season constraints.
(Preferred) Hold certifications such as VMware VCP-NV / VCIX-NV, Illumio certifications, RHCSA/Linux+, and/or ITIL v4; exposure to NSX Advanced Load Balancer (Avi) is beneficial.
(Nice to have) Familiarity with adjacent domains: physical networking (Arista/Cisco), firewalling, IDS/IPS/service insertion, and compliance (e.g., PCI DSS).
Corporate Security Responsibility
Every person working for, or on behalf of, Mastercard is responsible for information security. All activities involving access to Mastercard assets, information, and networks comes with an inherent risk to the organization and therefore, it is expected that the successful candidate for this position must:
Abide by Mastercard's security policies and practices;
Ensure the confidentiality and integrity of the information being accessed;
Report any suspected information security violation or breach; and
Complete all periodic mandatory security trainings in accordance with Mastercard's guidelines.
Mastercard is a merit-based, inclusive, equal opportunity employer that considers applicants without regard to gender, gender identity, sexual orientation, race, ethnicity, disabled or veteran status, or any other characteristic protected by law. We hire the most qualified candidate for the role. In the US or Canada, if you require accommodations or assistance to complete the online application process or during the recruitment process, please contact and identify the type of accommodation or assistance you are requesting. Do not include any medical or health information in this email. The Reasonable Accommodations team will respond to your email promptly.
Corporate Security Responsibility
All activities involving access to Mastercard assets, information, and networks comes with an inherent risk to the organization and, therefore, it is expected that every person working for, or on behalf of, Mastercard is responsible for information security and must:
In line with Mastercard's total compensation philosophy and assuming that the job will be performed in the US, the successful candidate will be offered a competitive base salary and may be eligible for an annual bonus or commissions depending on the role. The base salary offered may vary depending on multiple factors, including but not limited to location, job-related knowledge, skills, and experience. Mastercard benefits for full time (and certain part time) employees generally include: insurance (including medical, prescription drug, dental, vision, disability, life insurance); flexible spending account and health savings account; paid leaves (including 16 weeks of new parent leave and up to 20 days of bereavement leave); 80 hours of Paid Sick and Safe Time, 25 days of vacation time and 5 personal days, pro-rated based on date of hire; 10 annual paid U.S. observed holidays; 401k with a best-in-class company match; deferred compensation for eligible roles; fitness reimbursement or on-site fitness facilities; eligibility for tuition reimbursement; and many more. Mastercard benefits for interns generally include: 56 hours of Paid Sick and Safe Time; jury duty leave; and on-site fitness facilities in some locations.
Pay Ranges
Remote - Arizona: $94,000 - $157,000 USD
Job Posting Window
Posting windows may change based on the volume of applications received and business necessity. Candidates are encouraged to apply expeditiously.
Mastercard powers economies and empowers people in 200+ countries and territories worldwide. Together with our customers, we're helping build a sustainable economy where everyone can prosper. We support a wide range of digital payments choices, making transactions secure, simple, smart and accessible. Our technology and innovation, partnerships and networks combine to deliver a unique set of products and services that help people, businesses and governments realize their greatest potential.
Title and Summary
Senior Platform Engineer
Who is Mastercard?
Mastercard is a global technology company in the payments industry. Our mission is to connect and power an inclusive, digital economy that benefits everyone, everywhere by making transactions safe, simple, smart, and accessible. Using secure data and networks, partnerships and passion, our innovations and solutions help individuals, financial institutions, governments, and businesses realize their greatest potential.
Our decency quotient, or DQ, drives our culture and everything we do inside and outside of our company. With connections across more than 210 countries and territories, we are building a sustainable world that unlocks priceless possibilities for all.
Overview
The Micro-Segmentation Operations team within Global Network Operations is seeking an Engineer, NSX & Microsegmentation to ensure Mastercard's private cloud and data center network services are resilient, secure, and high-performing. This role focuses on VMware NSX-T lifecycle management and operational support, as well as Illumio-based microsegmentation for bare-metal firewalls and server workloads.
You will execute in-place NSX upgrades, perform configuration changes (e.g., segments/port groups, distributed firewall rules, Tier-0/Tier-1 gateways, load balancer objects), manage platform licensing and certificates, and drive incident/problem management across production environments. The ideal candidate thrives in high-stakes operational contexts, communicates crisply, and partners across infrastructure, security, and app teams to deliver change safely and on time.
Role
In this position, you will:
Operate and upgrade VMware NSX-T across multiple data centers: plan/execute lifecycle activities (NSX Managers/Edges/Transport Nodes), pre-checks, impact assessments, change/rollback plans, post-validation, and documented handoffs.
Administer NSX configurations: create/modify segments & port groups (VDS/VSS), transport zones, segment profiles, DHCP profiles, T0/T1 routing, NAT, BGP/OSPF adjacencies, NSX DFW sections/policies, Groups/Tags, and (as applicable) NSX Advanced Load Balancer objects.
Support Illumio microsegmentation (bare-metal firewalls): manage PCE objects & label schemas, author and validate segmentation policies, deploy/upgrade agents (VENs) where applicable, support enforcement modes, and partner on app onboarding/runbooks.
Manage certificates for NSX Managers/Edges and related appliances: track expirations, coordinate CSRs, perform installs/rotations, and maintain inventories & workflows to eliminate certificate-related outages.
Own licensing for NSX & Illumio: monitor entitlements, forecast needs, initiate purchase requests, and ensure timely renewals and compliant deployment.
Triage and resolve incidents/problems: perform root-cause analysis across virtual networking, routing, and segmentation; maintain SLAs; create follow-up problem records with corrective actions and knowledge articles.
Open and drive vendor cases (VMware, Illumio, and OEMs): provide diagnostics, packet captures/logs, reproduce issues in lower environments, and track to closure with clear stakeholder updates.
Harden and validate security posture: maintain least-privilege DFW/Illumio policies, coordinate change windows, and support audits (e.g., PCI) with evidence, diagrams, and rule reviews.
Automate and document: use PowerCLI, Python, Ansible, or REST APIs to standardize changes and validations; write SOPs/runbooks, diagrams, and KBs; contribute to CI/CD pipelines where appropriate.
Partner cross-functionally: collaborate with platform, compute, storage, security, and application teams to plan maintenance, align dependencies, and minimize risk.
Participate in on-call rotation for NSX/segmentation services and support peak-season readiness and freeze-window protocols per Mastercard standards.
Comply with ITIL processes: create/execute CRQs with risk/impact/rollback details, update INC/PRB records, and communicate status through executive-ready channels.
All About You
The ideal candidate for this position should:
Demonstrate hands-on expertise with VMware NSX-T Data Center: upgrades/migrations, Managers/Edges, T0/T1, EVPN/VXLAN fundamentals, DFW policy design, Groups/Tags, NAT, and BGP/OSPF peerings.
Have solid vSphere/vCenter/ESXi operational skills, including VDS networking, host transport configuration, and connectivity troubleshooting across virtual/physical boundaries.
Show practical experience with Illumio Core (PCE) or equivalent microsegmentation platforms for bare-metal firewall use cases: labels/policies, agent lifecycle, policy simulation/validation, and staged enforcement.
Possess strong troubleshooting skills spanning L2-L4 (and basic L7 where relevant): routing, neighbor states, MTU/ECMP asymmetry, ACL/DFW hits, NAT, and cert/trust failures.
Understand certificate management (PKI, CSRs, chains, renewal/rotation) and license administration (entitlements, consumption, renewal windows).
Communicate clearly with technical and non-technical audiences; produce crisp change plans, RCA documents, and executive-level summaries.
Embrace automation and IaC concepts (PowerCLI, Python, Ansible, REST APIs); familiarity with code review and version control is a plus.
Operate within ITIL frameworks (INC/PRB/CRQ) and change governance; comfortable running changes during maintenance windows and peak-season constraints.
(Preferred) Hold certifications such as VMware VCP-NV / VCIX-NV, Illumio certifications, RHCSA/Linux+, and/or ITIL v4; exposure to NSX Advanced Load Balancer (Avi) is beneficial.
(Nice to have) Familiarity with adjacent domains: physical networking (Arista/Cisco), firewalling, IDS/IPS/service insertion, and compliance (e.g., PCI DSS).
Corporate Security Responsibility
Every person working for, or on behalf of, Mastercard is responsible for information security. All activities involving access to Mastercard assets, information, and networks comes with an inherent risk to the organization and therefore, it is expected that the successful candidate for this position must:
Abide by Mastercard's security policies and practices;
Ensure the confidentiality and integrity of the information being accessed;
Report any suspected information security violation or breach; and
Complete all periodic mandatory security trainings in accordance with Mastercard's guidelines.
Mastercard is a merit-based, inclusive, equal opportunity employer that considers applicants without regard to gender, gender identity, sexual orientation, race, ethnicity, disabled or veteran status, or any other characteristic protected by law. We hire the most qualified candidate for the role. In the US or Canada, if you require accommodations or assistance to complete the online application process or during the recruitment process, please contact and identify the type of accommodation or assistance you are requesting. Do not include any medical or health information in this email. The Reasonable Accommodations team will respond to your email promptly.
Corporate Security Responsibility
All activities involving access to Mastercard assets, information, and networks comes with an inherent risk to the organization and, therefore, it is expected that every person working for, or on behalf of, Mastercard is responsible for information security and must:
- Abide by Mastercard's security policies and practices;
- Ensure the confidentiality and integrity of the information being accessed;
- Report any suspected information security violation or breach, and
- Complete all periodic mandatory security trainings in accordance with Mastercard's guidelines.
In line with Mastercard's total compensation philosophy and assuming that the job will be performed in the US, the successful candidate will be offered a competitive base salary and may be eligible for an annual bonus or commissions depending on the role. The base salary offered may vary depending on multiple factors, including but not limited to location, job-related knowledge, skills, and experience. Mastercard benefits for full time (and certain part time) employees generally include: insurance (including medical, prescription drug, dental, vision, disability, life insurance); flexible spending account and health savings account; paid leaves (including 16 weeks of new parent leave and up to 20 days of bereavement leave); 80 hours of Paid Sick and Safe Time, 25 days of vacation time and 5 personal days, pro-rated based on date of hire; 10 annual paid U.S. observed holidays; 401k with a best-in-class company match; deferred compensation for eligible roles; fitness reimbursement or on-site fitness facilities; eligibility for tuition reimbursement; and many more. Mastercard benefits for interns generally include: 56 hours of Paid Sick and Safe Time; jury duty leave; and on-site fitness facilities in some locations.
Pay Ranges
Remote - Arizona: $94,000 - $157,000 USD
Job Posting Window
Posting windows may change based on the volume of applications received and business necessity. Candidates are encouraged to apply expeditiously.
Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.