1

Analyst Poam Jobs (NOW HIRING)

Perform analysis on the POAM from that report and compare it to the previous report. Develop the appropriate mitigation efforts and estimated completion dates and update the POAM that natively ...

Cyber Security

Norfolk, VA · On-site

$75K - $158K/yr

Join our team as a Skilled Cybersecurity Analyst and play a crucial role in safeguarding our ... Prepare and review Authorization Packages, including SSP, SAR, POAM, and GCP * Collaborate with ...

... POAM) resolutions. Attend weekly Vulnerability Management Meetings and apply zero-day threat ... analyze centralized log data and critical counters. * Author and maintain architectural network ...

System Engineer - Navy Validator

San Diego, CA · On-site

$60.75 - $74.50/hr

... analyzing test results, drafting Risk Assessment Reports (RAR), C&A Plans, Plan of Actions and Milestones (POAM's), crafting mitigation statements, eMASS entry, and any other documents that are ...

System Engineer - Navy Validator

San Diego, CA

$60.75 - $74.50/hr

... analyzing test results, drafting Risk Assessment Reports (RAR), C&A Plans, Plan of Actions and Milestones (POAM's), crafting mitigation statements, eMASS entry, and any other documents that are ...

Showing results 41-60

Analyst Poam information

See salary details

$16

$31

$48

How much do analyst poam jobs pay per hour?

As of Aug 12, 2026, the average hourly pay for analyst poam in the United States is $31.53, according to ZipRecruiter salary data. Most workers in this role earn between $25.24 and $35.82 per hour, depending on experience, location, and employer.

Is an analyst poam entry level?

An Analyst POAM (Plan of Action and Milestones) role is typically considered entry-level, especially for those with basic knowledge of cybersecurity, risk management, or compliance. However, some positions may require prior experience or certifications such as CompTIA Security+ or CISSP, depending on the complexity of the tasks involved.

What are some common challenges faced by an analyst POAM and how can they be addressed?

Analyst POAMs (Plan of Action and Milestones Analysts) often encounter challenges such as managing multiple compliance tasks simultaneously and ensuring all corrective actions are tracked and completed on time. They may also need to coordinate with various departments to gather necessary documentation and updates, which can be time-consuming. Effective communication, strong organizational skills, and familiarity with compliance frameworks like NIST or FISMA are key to overcoming these challenges. Leveraging project management tools and maintaining clear documentation can also help streamline the process and ensure timely progress.

What is the difference between Analyst Poam vs Analyst Risk?

AspectAnalyst PoamAnalyst Risk
Required CredentialsBachelor's degree, certifications like CISA or CISSP often preferredBachelor's degree, certifications like FRM or CRM often preferred
Work EnvironmentFinancial institutions, consulting firms, or regulatory agenciesFinancial services, banking, or insurance companies
Employer & Industry UsageUsed in compliance, audit, and control functionsUsed in risk management, credit, and operational risk departments

Both Analyst Poam and Analyst Risk roles require similar credentials and often work within financial or consulting environments. While Analyst Poam focuses on assessing and testing controls to meet compliance standards, Analyst Risk concentrates on identifying and managing various types of risks within organizations. Understanding these distinctions helps candidates target the right roles based on their skills and career goals.

What is an analyst POAM?

An Analyst POAM (Plan of Actions and Milestones Analyst) is a professional responsible for managing and tracking security compliance issues within an organization. They focus on identifying, documenting, and monitoring the progress of remediation efforts for vulnerabilities or security gaps, typically as part of a cybersecurity or risk management team. Their work ensures that the organization addresses and resolves security findings in a timely manner to meet regulatory or internal compliance requirements.

What are the key skills and qualifications needed to thrive as an analyst POAM, and why are they important?

To thrive as an Analyst POA&M, you need a strong understanding of cybersecurity frameworks, risk management practices, and compliance requirements, typically supported by a degree in information security or a related field. Familiarity with tools like eMASS, RMF, and vulnerability assessment systems, as well as certifications such as Security+ or CISSP, is highly valued. Attention to detail, analytical thinking, and effective communication are crucial soft skills for accurately tracking issues and collaborating with stakeholders. These competencies ensure timely remediation of security gaps and ongoing compliance with regulatory standards, which are vital for organizational security and risk mitigation.
More about Analyst Poam jobs
What cities are hiring for Analyst Poam jobs? Cities with the most Analyst Poam job openings:
What states have the most Analyst Poam jobs? States with the most job openings for Analyst Poam jobs include:
Infographic showing various Analyst Poam job openings in the United States as of August 2026, with employment types broken down into 72% Full Time, 21% Part Time, and 7% Contract. Highlights an 86% In-person, and 14% Remote job distribution, with an average salary of $65,589 per year, or $31.5 per hour.

Information Assurance Engineer

Agile IT Synergy, LLC

Tampa, FL • On-site

$90 - $130/hr

Other

Posted 14 days ago


Job description

Agile IT Synergy, LLC is a Subject Matter Expert (SME) based technology company focused on innovative engineering and integration of relevant technologies combined with effective business practices to deliver complete solutions that meets customer mission needs.We are in search of customer focused professionals with a passion for solving difficult problems and exceeding our customer's expectations.

The successful candidate for the Information Systems Security Engineer is responsible for defining, implementing and maintaining information security policies, strategies, procedures and settings within the supported environment. The ISSM serves as a principal advisor on all matters, technical and otherwise, involving the security of information systems under his/her purview. In addition, the successful candidate collaborates with customers during the design and development phase to translate security and business requirements into achievable processes and systems. The ISSM is responsible for the overall Cybersecurity/Information Assurance (IA) of a program, organization, system, or enclave within AIT Synergy's highly dynamic and fast-paced environment.

Job Responsibilities:

  • Maintain and/or obtain systems accreditation and authorization for defense information systems and advise government Delegated Authorizing Official (DAO) as required.

  • Support RMF and information assurance (IA) support for continuous monitoring in accordance with applicable DoD policies.

  • Support industry partners and government agencies in the Risk Management Framework (RMF) Step 6 Phase, Continuous Monitoring, for major defense information systems.

  • Support deployment and accreditation of mission owner workloads in commercial cloud IaaS, PaaS, and SaaS environments.

  • Support continuous updates and plans of action and milestones (POAMs) as required for maintaining assigned DoD information systems

  • Maintain systems for compliance with CNSSI 1253 at the Confidentiality, Integrity, and Availability of Moderate - Low - Low

  • Maintain documentation and engineering artifacts for mission representative System Integration Labs (SIL) to remain as like-in-kind for other deployed or potentially deployed systems.

  • Maintain system security plans currently in XACTA or EMASS as required on JWICS

  • Follow assigned DoD interface control documents (ICD), RMF Implementation Guides, and other assigned directives for any updates and POAMs, and collaborate with government and industry partner representatives as directed in the coordination of these duties.

  • Assist in the preparation of Contract Data Requirements List (CDRL) documents that are required to be reviewed and updated annually, and submit to the government for
    review/approvals. Examples include Security Concept of Operations, Incident Response Plan, Continuous Monitoring Plan, Configuration Management Plan, Contingency
    Plan, Ports, Protocols, and Services (PPS) Plan, and Program Protection Plans.

  • Complete and process scans through Vulnerator or other applicable IA tools as directed. Perform analysis on the POAM from that report and compare it to the previous report. Develop
    the appropriate mitigation efforts and estimated completion dates and update the POAM that natively resides in XACTA. Update POAMs at intervals assigned by the government.

  • Monitor quarterly service bulletins, and update program software lists with any version changes as required. Ensure that these bulletins are tracked and coordinated with designated engineering staff as required.

  • Maintain compliance with directed mission-specific DoD processes (e.g. Certificate to Field (CtF), Security Impact Analysis (SIA) and others as assigned).

  • Coordinate with designated Engineering and Management to ensure that the program source code for software and virtual machines (VM) created for any major version changes is reviewed and delivered to the government for Certificate to Field (CtF) or Authority to Operate (ATO) approval.

  • Ensure that software that is third-party and proprietary follows the scan-load-scan process, and the pre-scan and post-scan results are sent to the government for CtF/ATO approval.

  • Utilize government agency available sites to locate already approved CtFs/ATOs, and submit to applicable DoD agencies for reciprocity on specific assigned tasks as required.

  • Utilize current and past experience with any other relevant DoD agencies and programs to recommend reciprocity strategies for faster approvals where necessary or available.

  • Maintain hardware and software lists which are required to be uploaded to XACTA.

  • Provide all supporting documentation for the Body of Evidence, and submit to government agencies for all baseline changes following the CtF and SIA processes. Examples include hardware/software lists, data flow processes, network diagrams, PPS, rack elevations, high-level design document, scans, etc.

  • Update the PPS document that resides on varying networks of classification, and register any changes with the PPS Manager.

  • Assist with providing information assistance for any Interconnection Security Agreement (ISA), Service Level Agreement (SLA), Memorandum of Understanding/Agreement
    (MOU/MOA) as well as any authorities to connect (ATC) between agencies.

  • Submit tickets to get Radius Profiles created for any external consultants requesting remote VPN access to assigned test labs and platforms.

  • Manage and maintain all system access documentation as well as all paperwork for external stakeholders accessing assigned test platform areas or systems.

  • Support any customer meetings to include weekly tag-ups and Configuration Control Board (CCB) meetings.

  • Ensure successful implementation of two-factor authentication and incorporate these standards as required.

  • Implement and support continuous updates for Security Information and Event Management tools offering a holistic view of designated information security programs.

  • Recommend strategies to streamline more efficient RMF processes through the reduction in scan duplication.

  • Perform any other IA or cybersecurity activities as required by the government customer within the scope of the efforts and hours provided for each assigned task.
Education
  • Bachelor's degree in Systems Security, Network Engineering, Information Technology or other related field of study and typically 6 - 8 years of experience.
    Relevant experience and years of service may be considered in lieu of required education
Experience/Qualifications:

  • Active DoD Top Secret Clearance with SCI eligibility required.

  • Experience with software systems such as Splunk or ELK (other SIEM), ACAS / Nessus, HBSS, eMASS, Xacta , or ServiceNow

  • General technical understanding of virtualized and hyper scale environments like Amazon Web Services (AWS) and Azure Cloud.

  • Experience in successful submission of RMF packages for commercial cloud (AWS, Azure, Google, etc) environments.

  • Expert familiarity with the DISA Commercial Cloud Security Requirements Guide.

  • Leadership abilities inclusive of successful change management, mentoring, career development, training, succession planning, holding people accountable, and conducting yearly reviews

  • Experience with A&A requirements as outlined in the NISPOM, RMF for DOD, ICD 503, JSIG & NIST RMF

  • DoD 8570/8140 compliance required: CISSP and/or other equivalent advanced certifications preferred

  • Experience in dealing with high-level interfaces at Defense Information Systems Agency (DISA), National Security Agency (NSA), and other DoD COCOMS.
  • Proven verbal and written communication skills.

  • Proficiency with Microsoft Teams, Outlook, Word, Excel, and PowerPoint.

  • Ability to handle multiple, complex and competing priorities and projects.
#J-18808-Ljbffr