1

Analyst Poam Jobs in Florida (NOW HIRING)

Perform analysis on the POAM from that report and compare it to the previous report. Develop the appropriate mitigation efforts and estimated completion dates and update the POAM that natively ...

Analyst Poam information

See Florida salary details

$12

$23

$36

How much do analyst poam jobs pay per hour?

As of Sep 7, 2026, the average hourly pay for analyst poam in Florida is $23.56, according to ZipRecruiter salary data. Most workers in this role earn between $18.85 and $26.78 per hour, depending on experience, location, and employer.

What is an analyst POAM?

An Analyst POAM (Plan of Actions and Milestones Analyst) is a professional responsible for managing and tracking security compliance issues within an organization. They focus on identifying, documenting, and monitoring the progress of remediation efforts for vulnerabilities or security gaps, typically as part of a cybersecurity or risk management team. Their work ensures that the organization addresses and resolves security findings in a timely manner to meet regulatory or internal compliance requirements.

What are some common challenges faced by an analyst POAM and how can they be addressed?

Analyst POAMs (Plan of Action and Milestones Analysts) often encounter challenges such as managing multiple compliance tasks simultaneously and ensuring all corrective actions are tracked and completed on time. They may also need to coordinate with various departments to gather necessary documentation and updates, which can be time-consuming. Effective communication, strong organizational skills, and familiarity with compliance frameworks like NIST or FISMA are key to overcoming these challenges. Leveraging project management tools and maintaining clear documentation can also help streamline the process and ensure timely progress.

What are the key skills and qualifications needed to thrive as an analyst POAM, and why are they important?

To thrive as an Analyst POA&M, you need a strong understanding of cybersecurity frameworks, risk management practices, and compliance requirements, typically supported by a degree in information security or a related field. Familiarity with tools like eMASS, RMF, and vulnerability assessment systems, as well as certifications such as Security+ or CISSP, is highly valued. Attention to detail, analytical thinking, and effective communication are crucial soft skills for accurately tracking issues and collaborating with stakeholders. These competencies ensure timely remediation of security gaps and ongoing compliance with regulatory standards, which are vital for organizational security and risk mitigation.

What is the difference between Analyst Poam vs Analyst Risk?

AspectAnalyst PoamAnalyst Risk
Required CredentialsBachelor's degree, certifications like CISA or CISSP often preferredBachelor's degree, certifications like FRM or CRM often preferred
Work EnvironmentFinancial institutions, consulting firms, or regulatory agenciesFinancial services, banking, or insurance companies
Employer & Industry UsageUsed in compliance, audit, and control functionsUsed in risk management, credit, and operational risk departments

Both Analyst Poam and Analyst Risk roles require similar credentials and often work within financial or consulting environments. While Analyst Poam focuses on assessing and testing controls to meet compliance standards, Analyst Risk concentrates on identifying and managing various types of risks within organizations. Understanding these distinctions helps candidates target the right roles based on their skills and career goals.

Is a policy analyst entry level?

Policy analyst roles can be entry-level or require several years of experience, depending on the organization. Entry-level positions typically require a bachelor's degree in a related field and may involve basic research, data analysis, and report writing. Advanced roles may require specialized knowledge, certifications, or prior experience.

IT Compliance Analyst with Security Clearance

CSA Global LLC

Pensacola, FL • On-site

Other

This job post has expired today. Applications are no longer accepted.


Key responsibilities

  • Support the RMF process for Security Plan Approval, Security Assessment Plan, System Assessment Report, Security Assessment Package Approval, and Continuous Monitoring.

  • Maintain and review artifacts such as hardware/software lists, diagrams, categorization forms, contingency plans, incident response plans, vulnerability and patch management plans, privacy impact assessments, and system-level continuous monitoring strategies.

  • Conduct and process monthly scans, ensure assets are scanned and credentialed, review scan findings, and update POAM items accordingly.


Job description

Client Solution Architects (CSA) is seeking an IT Compliance Analyst to join our growing company in support of our Navy client onsite at our Pensacola, FL location.  We are looking for someone to Provide Support utilizing the RMF Process Guide (Security Plan Approval, Security Assessment Plan (SAP) Approval, System Assessment Report (SAR) Approval, Security Assessment Package Approval, and Continuous Monitoring) for several ATO packages. For nearly 50 years, CSA has delivered integrated technology and operational support services to meet the defense and federal sector's most complex enterprise needs. Working from operations centers and shipyards to training sites and program offices, CSA deploys experienced teams, innovative tools and proven processes to advance federal missions.   How Role will make an impact: * This person will provide package support per Naval Education and Training Commands continuous monitoring guidance. 
* Establish periodic meetings/Meet with NETC Cyber RMF Team to discuss RMF timelines, tasks, and deliverables
* Maintain eMASS Record 
* Maintain Key artifacts (Package hardware/software lists, diagrams, etc).
* Maintain other artifacts required by RMF/eMASS( Categorization Form, Contingency Plan (CP), Disaster Recovery Plan (DRP),Incident Response Plan (IRP), Vulnerability and Patch Management Plan, Privacy Impact Assessment (PIA), System Level Continuous Monitoring (SLCM) Strategy)
* Ensure MONTHLY Scans are conducted per SCA Testing Guidance
* Ensure all assets in Hardware are scanned, and credentialed
* Process scans utilizing the eMASSter tool 
* Ensure all applicable STIGS are conducted for all assets in the Hardware List
* Ensure all QUARTERLY updated applicable STIGs from DISA website are implemented
* Review findings and associate each with applicable affected security control;
* Update POAM items (See POAM Section) Web Risk Assessment (WRA) Scan (if applicable) ATO Modifications (Use Case) Requirements What you’ll need to have to join our award-winning team: * Clearance: Must possess and maintain an active Secret Clearance. Must be able to meet security investigation and meet eligibility requirements for access to classified information.
* Minimum Education: High School Diploma or equivalent.
* Three (3) or more years of experience executing the NIST Risk Management Framework (RMF) and/or the DoD Information 
* Navy Cyber Security Workforce (CSWF) baseline certification at IAM Level I or a higher-level certification is required. Acceptable certifications include Security+ CE, CAP, CND, GSLC, Cloud+, and HCISPP.
* IA Contractor Training and Certification and Computing Environment (CE) certification may be required at the task order level.
* Assurance Certification and Accreditation Program (DIACAP).
* Supporting the security Assessment and Authorization/ATO process.
* Experience with reviewing, comprehending and documenting findings from ACAS (Assured Compliance Assessment Solution) Reports.
* Experience with SCAP (Security Content Automation Protocol).
* Experience with DoD Architecture Framework (DoDAF) standards and assessments of enterprise information security architecture, processes, procedures, activities, and operations.
* Experience with performing cyber security risk assessments and identifying, verifying, and consolidating specific vulnerabilities, causes, analysis of alternatives and identification of appropriate corrective actions from each risk assessment conducted.
* Experience with evaluation of Security Technical Implementation Guides (STIGs) to determine applicability to systems and assets.
* Functional expertise with Microsoft Office suite of products, including Word, Excel, PowerPoint, Visio, and Project.
What Sets you apart: * BA or BS degree from an accredited institution in related field (e.g., Management Information Systems, Information Technology, Computer Science, Math, Business, Engineering, or Physical Science, etc.)
* Prior experience with DoD Information Assurance Certification and Accreditation Program (DIACAP).
* IT project management experience supporting Navy or DoD network systems.
* Excellent oral and written communication skills, including drafting, reviewing, and editing technical graphs, briefs, or documents.
* Evidence of being detail oriented with strong critical thinking in areas of IT process analysis / process improvement.
* Possesses Good Team Skills having the ability to coordinate and work well with others.
* Working knowledge of Microsoft Visio, including the ability to create and maintain detailed diagrams and workflow visualizations in support of operational and technical requirements.
Physical Requirements: While performing the duties of this job, the employee is regularly required to: * Sit for extended periods of time and work at a computer workstation
* Use hands and fingers to operate keyboards, mice, and other input devices
* Communicate effectively, both verbally and in writing
* Specific vision abilities required may include close vision, distance vision, depth perception, and the ability to adjust
* Stand, walk, bend, or reach; Access equipment located in data centers, offices, or under desks
* Lift and/or move equipment weighing up to 25 pounds
Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions, in accordance with the Americans with Disabilities Act (ADA).