Introduction
\n
The Department of Information Technology (DoIT) provides support to state agencies, the Executive Office of the Governor, the Governor’s coordinating offices, and a variety of independent agencies within the Executive Branch.
\n
\n
Striving to provide the highest level of customer service to its internal and external customers, DoIT supports Maryland’s agencies and commissions through its leadership and strategic direction for Information Technology and Telecommunications, establishing a long-range, target technology architecture, encouraging cross-agency collaboration, and advocating best practices for operations and project management.
\n
\n
***This is a contractual position, with limited benefits***
\n
***All hires need to be eligible to work in the U.S., either as a U.S. Citizen or those who have a Permanent Resident or green card, as the state of Maryland does not have the ability to sponsor employees***
\n
***Applicants are required to submit an up-to-date and accurate resume.
\n
\n
Main Purpose
\n
This position performs the day-to-day operation of the enterprise edge security platforms that protect the public-facing applications and networks of more than 80 Maryland state agencies served by the Department of Information Technology's Office of Security Management (OSM). Working under the Edge Defense manager within the Cybersecurity Engineering directorate, this position monitors the health and performance of web application firewall platforms, network firewalls, secure proxy services, distributed denial-of-service protection, and TLS/certificate services, ensuring these controls remain continuously available and effective for the agencies that depend on them.
\n
\n
This position sustains the operational reliability of the State's edge defenses through disciplined monitoring, alert response, and execution of approved changes. It implements pre-approved policy and rule modifications, works assigned ticket queues, executes documented runbooks during maintenance windows, and escalates conditions that fall outside established procedures to senior engineers and the Edge Defense manager. In doing so, it directly advances OSM's mission of delivering centralized, consistent cybersecurity protection to state agencies.
\n
\n
The operational discipline of this position supports the State's IT Master Plan objectives for resilient, secure digital services and reinforces the perimeter and inspection controls that underpin Maryland's Zero Trust architecture alignment. Reliable execution at this level frees senior engineers to focus on design and architecture while ensuring that the controls already in production continue to defend agency workloads.
\n
\n
Position Duties
\n
- \n
- Continuously monitors the availability, performance, and health of edge security platforms including web application firewalls, network firewalls, secure proxies, DDoS protection, and TLS/certificate services. Reviews dashboards, telemetry, and system alerts to confirm controls are functioning as configured across agency environments. Performs scheduled health checks, verifies certificate validity and expiration timelines, and confirms policy enforcement is active. Documents observed conditions and identifies deviations from expected baselines. Escalates anomalies, degraded performance, or suspected control failures to senior engineers and the Edge Defense manager for disposition rather than making independent design decisions.
- \n
- Responds to alerts generated by edge security platforms and works assigned service and incident ticket queues within established service levels. Triages incoming requests from agencies and internal OSM teams, performs initial investigation, and resolves routine issues using documented procedures. Correlates edge platform events with monitoring data to characterize the nature of an alert, and hands off events requiring analysis to the Security Operations Center or senior engineers. Maintains accurate, timely ticket records and communicates status to requestors. Escalates complex or novel conditions promptly to the Edge Defense manager.
- \n
- Implements pre-approved changes to edge security policies and rule sets, including web application firewall signatures, firewall access rules, proxy configurations, and DDoS mitigation settings. Applies changes strictly in accordance with approved change tickets, documented runbooks, and the established architecture, verifying correct application and confirming that intended protections are in effect without disrupting agency services. Does not author new architectural approaches or approve changes; recommends refinements to senior engineers. Records all modifications in the change management system and confirms rollback readiness before implementation.
- \n
- Executes maintenance activities on edge security platforms during scheduled windows, following documented runbooks for updates, failovers, certificate renewals, and configuration deployments. Coordinates timing with affected agencies and internal teams, performs pre- and post-change validation, and confirms restoration of full service before closing the window. Follows established rollback procedures when validation fails and escalates unresolved conditions. Verifies that redundancy and failover mechanisms operate as designed during maintenance to preserve continuity of protection for agency workloads.
- \n
- Maintains operational documentation for the edge defense environment, including runbooks, health-check procedures, contact lists, and configuration records. Updates procedures to reflect implemented changes and captures lessons learned from incidents and maintenance activities. Ensures documentation remains accurate and accessible so that operational knowledge is preserved and repeatable across the team. Contributes observations from daily operations that inform runbook improvements, and flags gaps or outdated material to senior engineers and the Edge Defense manager for review.
- \n
\n
\n
Minimum Qualifications
\n
Experience:
\n
Nine years experience working on security/networks/systems operations, and directly involved with operations management, policy development, system procurement activities, leadership, and information assurance management.
\n
Notes:
\n
- \n
- Candidates may substitute a Bachelor's degree in information security, computer science, electrical systems, cybersecurity, or related field from an accredited university for up to four years of the required experience.
- \n
- Candidates may substitute the “Education” requirement listed above, for a High School Diploma or possession of a High School Equivalency certificate and two additional years of experience as described above.
- \n
- Candidates may substitute up to two years of the “Experience” requirement listed above for a graduate level degree in computer science, electrical systems, cybersecurity or related field from an accredited college or university.
- \n
\n
\n
Licenses, Registrations and Certifications:
\n
Must have an Information Assurance Management (IAM) level 2 or higher certification as described on the Maryland Department of Information Technology website.
\n
\n
Preferred Qualifications:
\n
- \n
- Experience operating and monitoring web application firewall, proxy, or related edge security platforms
- \n
- Experience triaging alerts and managing ticket queues within defined service levels
- \n
- Experience implementing approved policy and rule changes under formal change management
- \n
- Experience executing maintenance windows and operational runbooks
- \n
- Experience maintaining operational documentation and knowledge bases
- \n