Critical Infrastructure Security Engineer

State of MarylandAnne Arundel, MD
1d

About The Position

The Department of Information Technology (DoIT) provides support to state agencies, the Executive Office of the Governor, the Governor’s coordinating offices, and a variety of independent agencies within the Executive Branch. Striving to provide the highest level of customer service to its internal and external customers, DoIT supports Maryland’s agencies and commissions through its leadership and strategic direction for Information Technology and Telecommunications, establishing a long range, target technology architecture, encouraging cross agency collaboration and advocating best practices for operations and project management. The Department of Information Technology is seeking a Critical Infrastructure Security Engineer. This is a contractual position, with limited benefits The Critical Infrastructure Security Engineer serves as a technical authority and advisor within the Maryland Department of Information Technology, supporting the Director of Local Cybersecurity and advancing the State’s mission to protect and secure critical infrastructure. The Engineer supports the Local Cybersecurity Program by leading the design, development, and implementation of Operational Technology and Industrial Control System cybersecurity standards, controls, and monitoring strategies for high-value, mission-critical sectors, with an initial focus on water and wastewater utilities. The Engineer works directly with local government leaders, public utilities, engineers, and IT and OT professionals to identify vulnerabilities, assess cyber risk, and drive risk-reduction measures aligned with NIST, EPA, CISA, and related federal guidance. The Engineer strengthens statewide cyber resilience by helping jurisdictions design secure network architectures, build incident response and continuity-of-operations plans, and deploy real-time monitoring tools, while shaping state policy and guidance for critical infrastructure protection. The Engineer supports statewide minimum OT cybersecurity standards aligned with NIST SP 800-82, NIST CSF 2.0, and IEC 62443, and ties this work into broader risk management and compliance efforts. In partnership with the Maryland Department of Emergency Management, the Public Service Commission, and federal partners such as CISA and the EPA, the Engineer coordinates interagency efforts to prevent, detect, and respond to incidents that threaten essential services, including incident reporting protocols, technical workshops, and tabletop exercises. The Engineer bridges engineering, policy, and operations by translating complex cybersecurity principles into practical actions for operators of all sizes, supporting service continuity, public safety, and statewide resilience against evolving threats. This is a contractual position, with limited benefits

Requirements

  • Five (5) years of experience in cybersecurity with at least two (2) years of experience in Operational Technology (OT) and Industrial Control Systems (ICS), or Supervisory Control and Data Acquisition (SCADA) technology.
  • Strong communication and documentation skills to communicate with a diverse range of stakeholders and effectively report findings.

Nice To Haves

  • Experience performing risk assessments for critical infrastructure.
  • An ICS related certification, such as: (CAP, CCTS, GICSP, GCIP, CISSP, ISA/IEC62443, CEH)
  • Experience with: NIST Cybersecurity Framework (CSF), NIST SP 800-82, IEC 62443, CISA CPGs, or other relevant industry or regulatory standards
  • Experience with security monitoring in OT environments (SIEM, anomaly detection for ICS).
  • Project management experience: Leading assessments, secure design initiatives, and incident response planning.

Responsibilities

  • Development and Implementation of Cybersecurity Standards
  • Cybersecurity Training and Workforce Development
  • Incident Preparedness, Response, and Recovery
  • Technical Consultation and Vulnerability Management
  • Collaboration and Stakeholder Engagement

Benefits

  • Contractual employees who work 30 or more hours a week (or on average 130 hours per month) will be eligible for subsidized health benefit coverage for themselves and their dependents.
  • Paid leave will accrue at a rate of one hour for every 30 hours worked.
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service