> Markdown version of [/jobs/ext/464664-it-security-operations-analyst](https://www.wearedevelopers.com/jobs/ext/464664-it-security-operations-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # IT Security Operations Analyst - **Company:** REVOLVE - **Location:** Washington, DC, United States (Remote available) - **Experience:** Experienced - **Salary:** $93,600.0 - $104,000.0 - **Contract:** Permanent contract - **Skills:** CompTIA Security+, Cyber Security, Information Systems, Microsoft Operating Systems, System Center Configuration Manager, Software Vulnerability Management, Patch Management, Vulnerability Analysis - **Published:** June 7, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=cf6d53a1f258e0bc ## About the Role Do you have experience in Vuls?, * Minimum 2 years of experience with patching and vulnerability management * Hands-on experience with Microsoft Endpoint Configuration Manager (MECM) or SCCM * Knowledge of infrastructure security, compliance frameworks, and security policies and practices * Familiarity with FISMA, NIST SP 800-53, and federal information security standards * Ability to assess malware impact and interpret vulnerability scan results * Strong analytical, documentation, and communication skills Preferred Qualifications / Substitutions * CompTIA Security+ Certification may substitute for 1 year of required experience * Experience with ELMS (Enterprise License Management System) * Familiarity with DOJ or BOP IT security environments * Knowledge of NIST SP 800-37 Risk Management Framework Security Clearance Requirement All candidates must hold or be eligible to obtain a Public Trust clearance prior to commencing work under this contract. Candidates must: * Have legally resided in the United States for three of the five years immediately preceding performance * Be a U.S. citizen or lawful permanent resident seeking U.S. citizenship * Be willing to complete e-QIP (Electronic Questionnaires for Investigations Processing) * Successfully complete fingerprinting (FD-258), OF-306, and all DOJ security documentation * Comply with DOJ self-reporting requirements throughout the period of performance, * Do you have experience working with the DOJ? * Do you have a strong knowledge of NIST RMF? * Are you experienced with ELMS (Enterprise License Management System)? Work Location: Hybrid remote in Washington, DC 20534 ## Description The IT Security Operations Analyst works alongside the Patch Management Team to align security processes, policies, and procedures with DOJ security standards and operational goals. This position is responsible for vulnerability assessment, malware impact analysis, and the management and distribution of Microsoft and third-party software patches in a high-security federal environment., * Align security processes, policies, and procedures with established security standards and operational goals * Assess and document malware impact; inspect and analyze vulnerability scans * Manage and distribute Microsoft OS patches using ELMS and Microsoft Endpoint Configuration Manager (MECM) * Coordinate third-party patch management activities in collaboration with the Patch Management Team * Evaluate compliance with DOJ information security standards including FISMA and NIST SP 800-53 * Support continuous monitoring of covered information systems for security vulnerabilities * Assist in developing and implementing plans of action to correct security deficiencies * Document security findings and produce reports for the COR and program management * Participate in cybersecurity awareness training and security program activities * Submit weekly status reports to the Chief, Customer Support Section ## Related Videos - [Less Is More: How Lagom and Agile Can Create Harmonious Workflows](https://www.wearedevelopers.com/videos/1993-less-is-more-how-lagom-and-agile-can-create-harmonious-workflows) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Reporting Active Exploits in 24 Hours: Are You Ready for the CRA?](https://www.wearedevelopers.com/videos/100248-reporting-active-exploits-in-24-hours-are-you-ready-for-the-cra) - [Beyond SBOMs: The Future of Container Supply Chain Security](https://www.wearedevelopers.com/videos/100235-beyond-sboms-the-future-of-container-supply-chain-security) - [Kubernetes dev is fun, but setup and ops isn't! See a fun PaaS alternative to push any code, ipynbs or even just data!](https://www.wearedevelopers.com/videos/732-kubernetes-dev-is-fun-but-setup-and-ops-isn-t-see-a-fun-paas-alternative-to-push-any-code-ipynbs-or-even-just-data) ## Related Articles - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy)