Introduction
\n
The Department of Information Technology (DoIT) provides support to state agencies, the Executive Office of the Governor, the Governor’s coordinating offices, and a variety of independent agencies within the Executive Branch.
\n
\n
Striving to provide the highest level of customer service to its internal and external customers, DoIT supports Maryland’s agencies and commissions through its leadership and strategic direction for Information Technology and Telecommunications, establishing a long-range, target technology architecture, encouraging cross-agency collaboration, and advocating best practices for operations and project management.
\n
\n
***This is a contractual position, with limited benefits***
\n
***All hires need to be eligible to work in the U.S., either as a U.S. Citizen or those who have a Permanent Resident or green card, as the state of Maryland does not have the ability to sponsor employees***
\n
***Applicants are required to submit an up-to-date and accurate resume.
\n
\n
Main Purpose
\n
This position designs and implements edge protection solutions within the established Edge Defense architecture to secure the public-facing applications and networks of the more than 80 Maryland state agencies served by the Office of Security Management (OSM). Reporting to the Edge Defense manager within the Cybersecurity Engineering directorate, this position translates approved architecture and standards into working configurations: onboarding agency applications behind web application firewall and secure proxy services, designing rule sets and network segmentation configurations, and integrating edge telemetry into the State's centralized logging and SIEM pipelines.
\n
\n
This position is the primary engineering resource for bringing new agency workloads under edge protection and for resolving the complex technical problems that routine operations cannot. It designs configurations and leads implementations within the architecture defined by senior engineers and architects, troubleshoots difficult cross-platform issues, and supports firewall rule-based audits. By making protective controls fit each agency's applications correctly, this position ensures that centralized edge defense delivers real, tailored protection rather than generic coverage.
\n
\n
This work directly supports the State's IT Master Plan goals for secure, modernized digital services and advances Maryland's Zero Trust architecture alignment by implementing least-privilege segmentation and rigorous inspection at the network edge. The position recommends design refinements upward while operating within the boundaries set by the domain architecture.
\n
\n
Position Duties
\n
- \n
- Leads the onboarding of agency applications behind web application firewall, secure proxy, and DDoS protection services. Assesses each application's architecture, traffic patterns, and protection requirements, then designs and implements the appropriate edge configuration within established standards. Coordinates cutover with agency IT staff, validates that protections function correctly without breaking application behavior, and tunes initial rule sets to balance security and availability. Documents the resulting design and hands off operational procedures to the operations engineers. Recommends architectural adjustments to senior engineers when an application's needs fall outside existing patterns.
- \n
- Designs and implements web application firewall rule sets, network firewall policies, and network segmentation configurations within the approved architecture. Develops custom rules to address application-specific threats, reduce false positives, and enforce least-privilege access aligned with Zero Trust principles. Tests configurations in controlled fashion before deployment, validates protective effect, and iterates based on observed traffic. Documents design rationale and maintains configuration standards for consistency across agencies. Recommends changes to baseline rule templates and segmentation models to senior engineers and architects where broader improvement is warranted.
- \n
- Investigates and resolves complex technical issues across edge security platforms that exceed routine operational handling, including intermittent protection failures, performance degradation, false-positive storms, and multi-platform interaction problems. Analyzes telemetry, packet-level data, and configuration state to isolate root cause, and designs corrective configurations. Provides engineering support during security incidents affecting edge controls, working with the Security Operations Center to contain and remediate. Documents findings and feeds recurring problems back into design and runbook improvements, escalating architectural implications to senior engineers.
- \n
- Designs and implements the integration of edge security platform telemetry into the State's centralized logging and SIEM pipelines. Configures log sources, ensures completeness and correct formatting of security-relevant events, and validates that data lands reliably for detection and analysis. Works with the logging and detection engineering teams to confirm that edge telemetry supports required monitoring use cases and coverage. Troubleshoots data-flow gaps and onboarding issues, and recommends improvements to log enrichment and routing to senior engineers and the responsible platform teams.
- \n
- Supports periodic firewall and edge policy audits by analyzing rule bases for unused, overly permissive, conflicting, or outdated rules and preparing findings for review. Designs remediation configurations to tighten access toward least privilege while preserving required agency connectivity, and implements approved changes. Documents the rationale and disposition of audited rules to support compliance and continuity. Coordinates with agency IT staff to validate that proposed changes do not disrupt legitimate traffic, and recommends structural improvements to the rule base to senior engineers.
- \n
\n
\n
Minimum Qualifications
\n
Experience:
\n
Nine years of experience in network or application security engineering, including designing and implementing protections for public-facing applications and networks within an established architecture.
\n
Notes:
\n
- \n
- Candidates may substitute a bachelor's degree in computer science, cybersecurity, information technology, software engineering, information systems, computer engineering or a related field from an accredited college or university for up to four years of the required experience.
- \n
- Candidates may substitute up to two years of the required experience for a graduate-level degree in one of the fields listed above from an accredited college or university.
- \n
\n
\n
Preferred Qualifications:
\n
- \n
- Experience onboarding applications onto web application firewall or edge protection platforms
- \n
- Experience designing rule sets and network segmentation within an established security architecture
- \n
- Experience troubleshooting complex application-delivery and security issues and supporting incident response
- \n
- Experience integrating edge platform logging with security information and event management tooling
- \n
- Experience supporting firewall audits and rule-base reviews
- \n
\n