1

Analyst Poam Jobs (NOW HIRING)

RMF and POAM Analyst

Mclean, VA ยท On-site

$110 - $150/hr

... POAM Analyst (current or past) Excellent verbal and written communication skills, specifically in report writing Ability to commute to client office as needed per week What Would Be Nice To Have

New

Experience as an RMF or POAM Analyst (current or past) * Excellent verbal and written communication skills, specifically in report writing * Ability to commute to client office as needed per week ...

Experience as an RMF or POAM Analyst (current or past) * Excellent verbal and written communication skills, specifically in report writing * Ability to commute to client office as needed per week ...

The Technical Security Analyst will be responsible for maintenance of the commercial and corporate environment POAM and analysis of the corresponding vulnerability scans; development of the metrics ...

The Technical Security Analyst will be responsible for maintenance of the commercial and corporate environment POAM and analysis of the corresponding vulnerability scans; development of the metrics ...

$75 - $85/hr

Manages POAM program for assigned base\location by working with SAs to ensure a POAMs for all open ... Base Analysts will provide the following support in addition to STIGs, POAMs, and ESS compliance:

New

... POAM) for review * Obtain certification and accreditation for departmental systems through the ... May provide guidance to lower level Analysts Required skills/knowledge areas include: * Windows and ...

IT Compliance Analyst

Virginia Beach, VA ยท On-site

$81K - $82K/yr

Description: Client Solution Architects (CSA) is seeking an IT Compliance Analyst to join our ... Update POAM items (See POAM Section) Web Risk Assessment (WRA) Scan (if applicable) ATO ...

Experience in developing cybersecurity documentation, Plan of Actions & Milestones (POAM ... Provided Cyber IT analysis results and test reports for government approval * Possesses strong ...

Experience in developing cybersecurity documentation, Plan of Actions & Milestones (POAM ... Provided Cyber IT analysis results and test reports for government approval * Possesses strong ...

next page

Showing results 1-20

Analyst Poam information

See salary details

$16

$31

$48

How much do analyst poam jobs pay per hour?

As of Sep 2, 2026, the average hourly pay for analyst poam in the United States is $31.53, according to ZipRecruiter salary data. Most workers in this role earn between $25.24 and $35.82 per hour, depending on experience, location, and employer.

What is an analyst POAM?

An Analyst POAM (Plan of Actions and Milestones Analyst) is a professional responsible for managing and tracking security compliance issues within an organization. They focus on identifying, documenting, and monitoring the progress of remediation efforts for vulnerabilities or security gaps, typically as part of a cybersecurity or risk management team. Their work ensures that the organization addresses and resolves security findings in a timely manner to meet regulatory or internal compliance requirements.

What are some common challenges faced by an analyst POAM and how can they be addressed?

Analyst POAMs (Plan of Action and Milestones Analysts) often encounter challenges such as managing multiple compliance tasks simultaneously and ensuring all corrective actions are tracked and completed on time. They may also need to coordinate with various departments to gather necessary documentation and updates, which can be time-consuming. Effective communication, strong organizational skills, and familiarity with compliance frameworks like NIST or FISMA are key to overcoming these challenges. Leveraging project management tools and maintaining clear documentation can also help streamline the process and ensure timely progress.

What are the key skills and qualifications needed to thrive as an analyst POAM, and why are they important?

To thrive as an Analyst POA&M, you need a strong understanding of cybersecurity frameworks, risk management practices, and compliance requirements, typically supported by a degree in information security or a related field. Familiarity with tools like eMASS, RMF, and vulnerability assessment systems, as well as certifications such as Security+ or CISSP, is highly valued. Attention to detail, analytical thinking, and effective communication are crucial soft skills for accurately tracking issues and collaborating with stakeholders. These competencies ensure timely remediation of security gaps and ongoing compliance with regulatory standards, which are vital for organizational security and risk mitigation.

What is the difference between Analyst Poam vs Analyst Risk?

AspectAnalyst PoamAnalyst Risk
Required CredentialsBachelor's degree, certifications like CISA or CISSP often preferredBachelor's degree, certifications like FRM or CRM often preferred
Work EnvironmentFinancial institutions, consulting firms, or regulatory agenciesFinancial services, banking, or insurance companies
Employer & Industry UsageUsed in compliance, audit, and control functionsUsed in risk management, credit, and operational risk departments

Both Analyst Poam and Analyst Risk roles require similar credentials and often work within financial or consulting environments. While Analyst Poam focuses on assessing and testing controls to meet compliance standards, Analyst Risk concentrates on identifying and managing various types of risks within organizations. Understanding these distinctions helps candidates target the right roles based on their skills and career goals.

Is a policy analyst entry level?

Policy analyst roles can be entry-level or require several years of experience, depending on the organization. Entry-level positions typically require a bachelor's degree in a related field and may involve basic research, data analysis, and report writing. Advanced roles may require specialized knowledge, certifications, or prior experience.
More about Analyst Poam jobs

What cities are hiring for Analyst Poam jobs?

Cities with the most Analyst Poam job openings:

What states have the most Analyst Poam jobs?

States with the most job openings for Analyst Poam jobs include:

Infographic showing various Analyst Poam job openings in the United States as of August 2026, with employment types broken down into 76% Full Time, 18% Part Time, and 6% Contract. Highlights an 82% In-person, 6% Hybrid, and 12% Remote job distribution, with an average salary of $65,589 per year, or $31.5 per hour.

RMF and POAM Analyst

Dovel Technologies, Inc

Mclean, VA โ€ข On-site

$110 - $150/hr

Other

Medical, Dental, Vision, Life, Retirement

Posted 3 days ago

New


Job description

Job Family: Technology Consulting Travel Required: Up to 10% Clearance Required: Active Public Trust

What You Will Do

Lead and/or support the development of RMF and A&A documentation including SSPs, control implementation matrices, SARs, POA&Ms, and risk acceptance materials. Support authorization of on premise and cloud services leveraging FedRAMP packages, considering agency specific control requirements, and support 3PAO readiness assessments and SAR development for cloud platforms. Interpret and operationalize FISMA, NIST RMF, FedRAMP, and OSCAL standards to guide application enhancements, evidence automation, and RMF workflow modernization across a GRC platform. Ensuring consistency and compliance across multiโ€‘tenant GRC environments, helping Components and customer agencies implement security controls, maintain accurate documentation, and sustain reliable continuous monitoring. Collaborating across Agile teams to embed RMF discipline, support backlog refinement, and validate that modernization activities remain compliant with Federal requirements. Coordinate A&A activities and requirements with System Owners, ISSOs, IAMs, and thirdโ€‘party assessors, reducing manual burden for ISSOs and system owners by shaping automated workflows, improving evidence pathways, and strengthening data integrity used for scoring, dashboards, and compliance reporting. Providing compliance and RMF subject matter guidance throughout sprint cycles, planning, testing activities, and release readiness processes, ensuring enhancements align with RMF control requirements and governance expectations. Supporting continuous authorization (cATO) goals through integration of automated control validation, vulnerability data ingestion, security tooling alignment, and machineโ€‘readable artifacts (OSCAL).

What You Will Need

An ACTIVE and CURRENT Federal or DoD Public Trust Bachelorโ€™s Degree AND Five (5) years of relevant cybersecurity experience, OR a Masterโ€™s Degree AND Three (3) years of relevant experience Experience as an RMF or POAM Analyst (current or past) Excellent verbal and written communication skills, specifically in report writing Ability to commute to client office as needed per week

What Would Be Nice To Have
  • Security+, CAP, or equivalent certification, and strong working knowledge of NIST SP 800 37, 800 53, FISMA, and FedRAMP.
  • Familiarity with ServiceNow, GRC platforms, or audit tracking tools.
  • Experience consulting at large federal agencies such as the Department of State, Department of Justice or Department of Homeland Security related to GRC implementations Demonstrated experience in the areas of external clientโ€‘facing management and/or consulting for large firms.
What We Offer
  • Medical, Rx, Dental & Vision Insurance
  • Personal and Family Sick Time & Company Paid Holidays
  • Position may be eligible for a discretionary variable incentive bonus
  • Parental Leave and Adoption Assistance
  • 401(k) Retirement Plan
  • Basic Life & Supplemental Life
  • Health Savings Account, Dental/Vision & Dependent Care
  • Flexible Spending Accounts
  • Short-Term & Long-Term Disability
  • Student Loan PayDown Tuition Reimbursement
  • Personal Development & Learning Opportunities
  • Skills Development & Certifications
  • Employee Referral Program
  • Corporate Sponsored Events & Community Outreach
  • Emergency Backโ€‘Up Childcare Program
  • Mobility Stipend

Guidehouse is an Equal Opportunity Employerโ€“Protected Veterans, Individuals with Disabilities or any other basis protected by law, ordinance, or regulation.

Guidehouse will consider for employment qualified applicants with criminal histories in a manner consistent with the requirements of applicable law or ordinance including the Fair Chance Ordinance of Los Angeles and San Francisco.

Guidehouse is a global AIโ€‘led professional services firm delivering advisory, technology, and managed services to the commercial and government sectors. With an integrated business technology approach, Guidehouse drives efficiency and resilience in the healthcare, financial services, energy, infrastructure, and national security markets. Built to help clients across industries outwit complexity, the firm brings together approximately 18,000 professionals to achieve lasting impact and shape a meaningful future.

#J-18808-Ljbffr