1

Poam Jobs (NOW HIRING)

RMF Compliance Lead

MD · Remote

$165.50K/yr

Lead all RMF activities, including eMASS management, POAM tracking, and STIG compliance. * Maintain ATO posture across large-scale systems with complex security control frameworks. * Coordinate with ...

Cybersecurity Consultant

Reston, VA · On-site

$63.46 - $77.88/hr

The Cybersecurity Consultant supports CMMC client engagements including client environment as-is assessments, Plan of Action & Milestones (POAM) identification & documentation, non-compliance ...

Cybersecurity Consultant

Reston, VA · On-site

$132K - $162K/yr

The Cybersecurity Consultant supports CMMC client engagementsincludingclient environment as-is assessments, Plan of Action & Milestones (POAM) identification & documentation, non-compliance ...

The Technical Security Analyst will be responsible for maintenance of the commercial and corporate environment POAM and analysis of the corresponding vulnerability scans; development of the metrics ...

POAM- Asst. Pros. FLSA Status: Exempt Wage Grade: APA - II General Summary: Under the supervision of a higher classified Assistant Prosecuting Attorney, reviews and authorizes requests for warrants ...

Project Manager 3 at MI

Dimondale, MI · On-site

$104.60K - $123.80K/yr

Experience with System Security Plans (SSP) and Plan of Action and Milestones (POAM). * Utilize project portfolio management systems (e.g., Clarity) effectively. * Lead teams in a multi-vendor ...

... POAM). Reviews, analyzes and identifies opportunities and leads to PSP to reduce policy burden on enterprise and increase the proper alignment across the agency. Properly manages potential policy ...

Maintain up to date POAM throughout projects. Research current Army and TRADOC publications to discover any publication needing updates due to changes in organizations for all publications to be ...

Senior Security Engineer

Pittsburgh, PA · On-site

$111.20K - $152.40K/yr

... POAM records for all security-classified vulnerabilities ensuring remediation dates, risk classifications, and fix approaches are documented to audit standards required in a regulated banking ...

New

Senior Security Engineer

Cleveland, OH · On-site

$110.90K - $152K/yr

... POAM records for all security-classified vulnerabilities ensuring remediation dates, risk classifications, and fix approaches are documented to audit standards required in a regulated banking ...

New

next page

Showing results 1-20

Poam information

See salary details

$14

$24

$41

How much do poam jobs pay per hour?

As of May 31, 2026, the average hourly pay for poam in the United States is $24.25, according to ZipRecruiter salary data. Most workers in this role earn between $18.27 and $26.44 per hour, depending on experience, location, and employer.

What are the key skills and qualifications needed to thrive as a POAM (Plan of Action and Milestones) Manager, and why are they important?

To thrive as a POAM Manager, you need a solid understanding of cybersecurity compliance frameworks, risk assessment, and project management, typically supported by experience in IT security or compliance roles. Familiarity with tools such as GRC (Governance, Risk, and Compliance) platforms, NIST SP 800-53, and related certification like CISSP or CISA is highly valuable. Strong organizational skills, attention to detail, and effective communication are crucial soft skills for coordinating remediation efforts and reporting to stakeholders. These competencies ensure that security gaps are properly tracked, managed, and remediated to maintain organizational compliance and reduce risk.

What are some common challenges faced by POAMs (Program Objective Assessment Managers) when managing multiple projects simultaneously?

POAMs often juggle several projects with competing deadlines and priorities, which can make it challenging to allocate resources and maintain clear communication across teams. Balancing the need for thorough documentation with timely progress reporting—especially in highly regulated environments—requires strong organizational skills and attention to detail. Collaborating with diverse stakeholders, such as technical leads, compliance officers, and executive sponsors, is essential to ensure all program objectives are met and risks are effectively managed. Successful POAMs develop efficient tracking systems and proactive communication strategies to stay ahead of potential issues.

What are POAMs (Plans of Action and Milestones)?

POAMs, or Plans of Action and Milestones, are management tools used in cybersecurity and compliance to identify, track, and remediate security weaknesses within an organization’s information systems. They document specific steps needed to address vulnerabilities, assign responsibilities, and set deadlines for completion. POAMs are essential for maintaining compliance with standards such as NIST and FedRAMP, ensuring that organizations have a clear plan to achieve and maintain security requirements.

What is the difference between Poam vs Network Security Analyst?

AspectPoamNetwork Security Analyst
Required CredentialsTypically security certifications like CISSP, CEH, or CompTIA Security+Same certifications, often with additional network-specific credentials
Work EnvironmentSecurity teams, government agencies, or private firms focusing on security plansIT departments, cybersecurity firms, or corporate security teams
Employer & Industry UsageUsed in security planning and compliance documentationUsed in monitoring, analyzing, and responding to security threats

Poam (Plan of Action and Milestones) and Network Security Analyst roles both require security certifications and work within cybersecurity environments. Poam focuses on security planning and compliance, while Network Security Analysts actively monitor and respond to security threats. Both roles are essential in maintaining organizational security but serve different functions within the cybersecurity landscape.

More about Poam jobs
What states have the most Poam jobs? States with the most job openings for Poam jobs include:
What job categories do people searching Poam jobs look for? The top searched job categories for Poam jobs are:
Authorization & Accreditation Specialist

Authorization & Accreditation Specialist

Bespoke Technologies, Inc

Dulles, VA • On-site

$17.75 - $23.75/hr

Full-time

This job post has expired today. Applications are no longer accepted.


Job description

BT-282 - Authorization and Accreditation Specialist
Location: Dulles, VA (fully on-site, no remote option)
**MUST HAVE AN ACTVE CLEARANCE TO APPLY. Those without a security clearance will not be considered.**
Authorization and Accreditation (A&A) Support
The Contractor shall provide Authorization and Accreditation (A&A) and Risk Management Framework (RMF) support to facilitate the accreditation of the Sponsor's environments and applications through the following activities:
  • Preparing security documentation, such as the Body of Evidence (BOE) and System Security Plans
  • Applying control implementations and managing the Plan of Action and Milestones (POAM)
  • Achieving and maintaining accreditations for applications, including the EMMA system, on an accelerated timeline.
  • Prepare triage information, create sponsor briefings and debriefings, and prepare documentation for the required oversight organizations' work items.
  • Correctly apply criticality determinations, security objectives, intelligence overlays, assets, and project artifact requirements for various RMF Steps for differing applications.
  • Summarize and prepare technical descriptions, security details, architecture diagrams, and other information to deliver application-specific CONOPS and System Security Plans (SSP).
  • Apply Control Implementations consistent with the requirements of the application design to meet the Sponsor's security requirements.
  • Facilitate, communicate, and complete the required steps to achieve an Authorization to Develop or Interim Authority to Test or Authority to Operate status within the Sponsor's framework.
  • Manage Plan of Actions and Milestones (POAM).
  • Perform monitoring of accredited applications.
  • Interface with technical representatives, Cyber Security, and Information System Security Managers