1

Analyst Poam Jobs (NOW HIRING)

IT Controls & Compliance Analyst

Denver, CO · On-site

$96K - $97K/yr

... POAM management, remediation tracking, and security awareness initiatives. * Ensures IT staff ... Ability to analyze technical processes, system control environments, audit evidence, large data ...

... POAM management, remediation tracking, and security awareness initiatives. * Ensures IT staff ... Ability to analyze technical processes, system control environments, audit evidence, large data ...

Maintain up to date POAM throughout projects. Research current Army and TRADOC publications to ... Experience in eliciting, analyzing, validating and documenting business, organizational and/or ...

... Analysis and Evaluation Directorate or equivalent. The position will perform the following: • ... Maintain up to date POAM throughout projects. • Research current Army and TRADOC publications to ...

... analysis, timeline analysis, cost estimation, requirements allocation, and interfaced definition ... Plan of Action & Milestone (POAM) tracking • Excellent customer support and attention to detail ...

Senior Systems Engineer

Boonsboro, MD · Hybrid

$99K - $136K/yr

Conduct requirements analysis, gap analysis, and system trade-off studies to support technical ... POAM updates, and security risk assessments * Provide weekly status report updates at the weekly ...

next page

Showing results 1-20

Analyst Poam information

See salary details

$16

$31

$48

How much do analyst poam jobs pay per hour?

As of Jun 11, 2026, the average hourly pay for analyst poam in the United States is $31.53, according to ZipRecruiter salary data. Most workers in this role earn between $25.24 and $35.82 per hour, depending on experience, location, and employer.

What are some common challenges faced by an Analyst POAM and how can they be addressed?

Analyst POAMs (Plan of Action and Milestones Analysts) often encounter challenges such as managing multiple compliance tasks simultaneously and ensuring all corrective actions are tracked and completed on time. They may also need to coordinate with various departments to gather necessary documentation and updates, which can be time-consuming. Effective communication, strong organizational skills, and familiarity with compliance frameworks like NIST or FISMA are key to overcoming these challenges. Leveraging project management tools and maintaining clear documentation can also help streamline the process and ensure timely progress.

What is the difference between Analyst Poam vs Analyst Risk?

AspectAnalyst PoamAnalyst Risk
Required CredentialsBachelor's degree, certifications like CISA or CISSP often preferredBachelor's degree, certifications like FRM or CRM often preferred
Work EnvironmentFinancial institutions, consulting firms, or regulatory agenciesFinancial services, banking, or insurance companies
Employer & Industry UsageUsed in compliance, audit, and control functionsUsed in risk management, credit, and operational risk departments

Both Analyst Poam and Analyst Risk roles require similar credentials and often work within financial or consulting environments. While Analyst Poam focuses on assessing and testing controls to meet compliance standards, Analyst Risk concentrates on identifying and managing various types of risks within organizations. Understanding these distinctions helps candidates target the right roles based on their skills and career goals.

What is an Analyst POAM?

An Analyst POAM (Plan of Actions and Milestones Analyst) is a professional responsible for managing and tracking security compliance issues within an organization. They focus on identifying, documenting, and monitoring the progress of remediation efforts for vulnerabilities or security gaps, typically as part of a cybersecurity or risk management team. Their work ensures that the organization addresses and resolves security findings in a timely manner to meet regulatory or internal compliance requirements.

What are the key skills and qualifications needed to thrive as an Analyst POA&M (Plan of Action and Milestones), and why are they important?

To thrive as an Analyst POA&M, you need a strong understanding of cybersecurity frameworks, risk management practices, and compliance requirements, typically supported by a degree in information security or a related field. Familiarity with tools like eMASS, RMF, and vulnerability assessment systems, as well as certifications such as Security+ or CISSP, is highly valued. Attention to detail, analytical thinking, and effective communication are crucial soft skills for accurately tracking issues and collaborating with stakeholders. These competencies ensure timely remediation of security gaps and ongoing compliance with regulatory standards, which are vital for organizational security and risk mitigation.
More about Analyst Poam jobs
What states have the most Analyst Poam jobs? States with the most job openings for Analyst Poam jobs include:
Cyber Sec Analyst

Cyber Sec Analyst

Scientific Research Corporation

North Charleston, SC • On-site

Full-time

Medical, Dental, Vision, Life, Retirement, PTO

Posted 16 days ago


Job description

Description
  • Verifying configuration management and tracking security update implementation to the systems using existing automated tools
  • Adhering to pre-defined configuration management and change management policies and procedures for authorizing software prior to its implementation on systems
  • Ensuring systems are operated, used, maintained, and disposed of in accordance with all applicable security policies and practices
  • Performing cybersecurity testing, analysis, and reporting by conducting the following: Assured Compliance Assessment Solution (ACAS) scans, Security Technical Implementation Guide (STIG) checks, port scanning, application code review, Risk Management Framework (RMF) control review, and Plan of Action and Milestone (POAM)
  • Providing in depth analysis on cybersecurity test results, remediation steps, and potential mitigating factor(s)
  • Supporting the Information System Security Manager (ISSM) and Cybersecurity Lead in meeting all RMF documentation, process, policy, risk assessment, testing, and continuous monitoring requirements per the NIST SP-800 series
  • Providing RMF support for all future and/or new Assessment and Authorization (A-A)
  • Collaborating with the IPT Lead, PM, Developers, Engineers, and Test teams through guidance and options on how to meet all technical and policy security-control
  • Maintaining security reporting compliance requirements outlined in the System SLCM Strategy

#LI-LL1

Requirements
  • Must possess an active Secret clearance and be eligible for a Top Secret/SCI clearance
  • A minimum of three (3) years of cybersecurity experience, preferably Navy RMF
  • Must currently hold a DoD 8570-compliant IAT II certification (SSCP or Security+CE with appropriate CE/OS certificate) or be able to obtain within six months
    • CE/OS certificate may include Windows or Linux
  • Experience with eMASS, SSPs, POAMs, ACAS/Nessus, SCAP, Security Checklists, and STIG Viewer
  • Experience with Risk Management Framework processes
  • Have developed communication skills and the ability to express thoughts and ideas clearly and concisely
  • Must be capable of multitasking and working several complex and diverse tasks with simultaneous or near simultaneous deadlines
  • Be a self-starter who is accountable and requires minimal direction and supervision
  • Be open to new and innovative ideas
  • Be a team player willing to interface with client(s) and relay information back to team
Desired Skills
  • Experience in a RHEL environment
  • Experience with Networking Devices
  • Experience with DevSecOps
  • Experience with automation tools (Ansible, Puppet, Chef) preferred
  • Experience with being an NQV highly preferred
  • Experience authoring and editing RMF Control Family Plans
  • Experience with EvaluateSTIG and/or STIGManager
Clearance Information

SRC IS A CONTRACTOR FOR THE U.S. GOVERNMENT, THIS POSITION WILL REQUIRE U.S. CITIZENSHIP AS WELL AS, A U.S. GOVERNMENT SECURITY CLEARANCE AT THE SECRET LEVEL

Travel Requirements
  • up to 10% travel
About Us

Scientific Research Corporation is an advanced information technology and engineering company that provides innovative products and services to government and private industry, as well as independent institutions. At the core of our capabilities is a seasoned team of highly skilled engineers and scientists with multidisciplinary backgrounds. This team is challenged daily to provide cutting edge technology solutions to our clients.

SRC offers a generous benefit package, including medical, dental, and vision plans, 401(k) with a company match, life insurance, vacation and sick paid time off accruals starting at 10 days of vacation and 5 days of sick leave annually, 11 paid holidays, tuition reimbursement, and a work environment that encourages excellence and more. For positions requiring a security clearance, selected applicants will be subject to a government security investigation and must meet eligibility requirements for access to classified information.

EEO

Scientific Research Corporation is an equal opportunity employer that does not discriminate in employment.

All qualified applicants will receive consideration for employment without regard to their race, color, religion, sex, age, sexual orientation, gender identity, national origin, disability, protected veteran status, or any other protected characteristic under federal, state or local law.

Scientific Research Corporation endeavors to make www.scires.com accessible to any and all users. If you would like to contact us regarding the accessibility of our website or need assistance completing the application process, please contact jobs@scires.com for assistance. This contact information is for accommodation requests only and cannot be used to inquire about the status of applications.

Employment Type: FULL_TIME