Edge Defense Solutions Engineer

Maryland Department of Information Technology
Annapolis, MD, United States
5 days ago
Apply on www.disabledperson.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
9 years minimum
Working hours
Regular working hours

Tech stack

Application Firewall Cyber Security Information Systems Computer Engineering DDoS Mitigation Data Flow Control Network Segmentation Zero Trust Network Access Security Information and Event Management Software Engineering Systems Integration Data Logging
+4 more
Software Security Firewalls (Computer Science) Information Technology Multiplatform

Job description

The Department of Information Technology (DoIT) provides support to state agencies, the Executive Office of the Governor, the Governor’s coordinating offices, and a variety of independent agencies within the Executive Branch.

Striving to provide the highest level of customer service to its internal and external customers, DoIT supports Maryland’s agencies and commissions through its leadership and strategic direction for Information Technology and Telecommunications, establishing a long-range, target technology architecture, encouraging cross-agency collaboration, and advocating best practices for operations and project management., This position designs and implements edge protection solutions within the established Edge Defense architecture to secure the public-facing applications and networks of the more than 80 Maryland state agencies served by the Office of Security Management (OSM). Reporting to the Edge Defense manager within the Cybersecurity Engineering directorate, this position translates approved architecture and standards into working configurations: onboarding agency applications behind web application firewall and secure proxy services, designing rule sets and network segmentation configurations, and integrating edge telemetry into the State’s centralized logging and SIEM pipelines.

This position is the primary engineering resource for bringing new agency workloads under edge protection and for resolving the complex technical problems that routine operations cannot. It designs configurations and leads implementations within the architecture defined by senior engineers and architects, troubleshoots difficult cross-platform issues, and supports firewall rule-based audits. By making protective controls fit each agency’s applications correctly, this position ensures that centralized edge defense delivers real, tailored protection rather than generic coverage.

This work directly supports the State’s IT Master Plan goals for secure, modernized digital services and advances Maryland’s Zero Trust architecture alignment by implementing least-privilege segmentation and rigorous inspection at the network edge. The position recommends design refinements upward while operating within the boundaries set by the domain architecture., * Leads the onboarding of agency applications behind web application firewall, secure proxy, and DDoS protection services. Assesses each application’s architecture, traffic patterns, and protection requirements, then designs and implements the appropriate edge configuration within established standards. Coordinates cutover with agency IT staff, validates that protections function correctly without breaking application behavior, and tunes initial rule sets to balance security and availability. Documents the resulting design and hands off operational procedures to the operations engineers. Recommends architectural adjustments to senior engineers when an application’s needs fall outside existing patterns.

  • Designs and implements web application firewall rule sets, network firewall policies, and network segmentation configurations within the approved architecture. Develops custom rules to address application-specific threats, reduce false positives, and enforce least-privilege access aligned with Zero Trust principles. Tests configurations in controlled fashion before deployment, validates protective effect, and iterates based on observed traffic. Documents design rationale and maintains configuration standards for consistency across agencies. Recommends changes to baseline rule templates and segmentation models to senior engineers and architects where broader improvement is warranted.
  • Investigates and resolves complex technical issues across edge security platforms that exceed routine operational handling, including intermittent protection failures, performance degradation, false-positive storms, and multi-platform interaction problems. Analyzes telemetry, packet-level data, and configuration state to isolate root cause, and designs corrective configurations. Provides engineering support during security incidents affecting edge controls, working with the Security Operations Center to contain and remediate. Documents findings and feeds recurring problems back into design and runbook improvements, escalating architectural implications to senior engineers.
  • Designs and implements the integration of edge security platform telemetry into the State’s centralized logging and SIEM pipelines. Configures log sources, ensures completeness and correct formatting of security-relevant events, and validates that data lands reliably for detection and analysis. Works with the logging and detection engineering teams to confirm that edge telemetry supports required monitoring use cases and coverage. Troubleshoots data-flow gaps and onboarding issues, and recommends improvements to log enrichment and routing to senior engineers and the responsible platform teams.
  • Supports periodic firewall and edge policy audits by analyzing rule bases for unused, overly permissive, conflicting, or outdated rules and preparing findings for review. Designs remediation configurations to tighten access toward least privilege while preserving required agency connectivity, and implements approved changes. Documents the rationale and disposition of audited rules to support compliance and continuity. Coordinates with agency IT staff to validate that proposed changes do not disrupt legitimate traffic, and recommends structural improvements to the rule base to senior engineers.

Requirements

Nine years of experience in network or application security engineering, including designing and implementing protections for public-facing applications and networks within an established architecture., 1. Candidates may substitute a bachelor’s degree in computer science, cybersecurity, information technology, software engineering, information systems, computer engineering or a related field from an accredited college or university for up to four years of the required experience.

  1. Candidates may substitute up to two years of the required experience for a graduate-level degree in one of the fields listed above from an accredited college or university., * Experience onboarding applications onto web application firewall or edge protection platforms * Experience designing rule sets and network segmentation within an established security architecture * Experience troubleshooting complex application-delivery and security issues and supporting incident response * Experience integrating edge platform logging with security information and event management tooling * Experience supporting firewall audits and rule-base reviews

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.disabledperson.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

1:10 min

Exposing sensitive information through partial search logs

Dennis Schulz Dennis Schulz +1 · World Congress 2026 Europe

4:43 min

Building portable Bluetooth logic using Kotlin multiplatform

Georg Dresler Georg Dresler · World Congress 2026 Europe

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

1:56 min

Discovering incidents using logs, metrics, and traces

Nele Uhlemann · World Congress 2023

Videos

See all

Related articles

See all