> Markdown version of [/jobs/ext/2307133-information-security-analyst-dod-secret](https://www.wearedevelopers.com/jobs/ext/2307133-information-security-analyst-dod-secret). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Security Analyst - DoD Secret - **Company:** The Aoc - **Location:** Hanscom Air Force Base, MA, United States - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Active Directory, Configuration Management, CompTIA Security+, Cyber Security, Information Systems, Issue Tracking Systems, Information Technology Operations, System Center Configuration Manager, Windows Servers, Windows PowerShell, Software Vulnerability Management, Tanium Platform Expertise, Patch Management, Nessus, Qualys, Servicenow, Vulnerability Analysis - **Published:** August 30, 2026 - **Apply:** https://www.clearancejobs.com/jobs/9123712/information-security-analyst-dod-secret ## About the Role * Strong understanding of Windows OS (Windows 10/11) and Windows Server environments. * Experience with vulnerability management tools such as ACAS, Tenable, Nessus, Tanium, or Qualys. * Demonstrated experience with patch management and configuration management processes. * Intermediate to advanced PowerShell scripting for automation and remediation workflows. * Working knowledge of Active Directory, Group Policy, and system hardening techniques. * Familiarity with enterprise ITSM platforms; ServiceNow preferred. * Excellent written and verbal communication skills, including the ability to convey technical details clearly. * Proven ability to manage competing priorities in a mission-focused environment. * Active DoD Secret clearance required. * CompTIA Security+ CE required, or higher certification such as CISSP or CISM. ## Description American Operations Corporation (AOC) is seeking a Information Security Analyst to support the BLITS 3.0 program at Hanscom Air Force Base, Massachusetts. The position will support the 66th Air Base Group mission to secure information and information systems, support mission success through effective and efficient service delivery, and sustain required infrastructure and capabilities. The analyst will identify, analyze, and remediate vulnerabilities across enterprise systems, with an emphasis on proactive collaboration and automation-driven patch management. Principal duties and responsibilities: * Perform vulnerability scanning, assessment, and remediation tracking using ACAS (Nessus/Security Center), ARAD (Tanium), or similar tools. * Analyze scan data and coordinate patching activities with system administrators and functional owners. * Develop and maintain PowerShell scripts to automate configuration management and patch deployment tasks. * Work in Active Directory and Windows Server environments to implement secure baselines and GPO configurations. * Coordinate vulnerability closure through ServiceNow or equivalent ticketing systems, ensuring timely and accurate updates. * Prepare tracking and status reports on vulnerability status, patch compliance, and risk posture for leadership and compliance reviews. * Collaborate with Cybersecurity, IT Operations, and Compliance teams to support RMF and STIG compliance requirements. * Proactively communicate findings, remediation guidance, tracking insights, and risk impacts to technical and non-technical stakeholders. * Support HBSS/MECM and related endpoint management tools as required to deploy patches or security updates. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Applying Agile Principles to Incident Management ](https://www.wearedevelopers.com/videos/101-applying-agile-principles-to-incident-management) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) - [AI in Production: applied AI & enterprise use cases](https://www.wearedevelopers.com/videos/100130-ai-in-production-applied-ai-enterprise-use-cases) - [Robots are coming into the wild! Full-Stack Robotics Engineers, be ready!](https://www.wearedevelopers.com/videos/479-robots-are-coming-into-the-wild-full-stack-robotics-engineers-be-ready) - [Organizational Change Through The Power Of Why - DevSecOps Enablement](https://www.wearedevelopers.com/videos/478-organizational-change-through-the-power-of-why-devsecops-enablement) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed)