1

Poam Jobs (NOW HIRING)

Experience as an RMF or POAM Analyst (current or past) * Excellent verbal and written communication skills, specifically in report writing * Ability to commute to client office as needed per week ...

Experience as an RMF or POAM Analyst (current or past) * Excellent verbal and written communication skills, specifically in report writing * Ability to commute to client office as needed per week ...

The Technical Security Analyst will be responsible for maintenance of the commercial and corporate environment POAM and analysis of the corresponding vulnerability scans; development of the metrics ...

Plan of Action & Milestone      (POAM) trackin * Excellent customer support and attention to detail - Tier 3 and Tier 4 level support to team and customer base. * Provide Release Management ...

Union POAM Union Pay Grade F1-POAM Wage Scale Wage Range: Hire $29.65; 6 months $30.09; YR 1 $30.52; YR 2 $31.43; YR 3 $32.61; YR 4 $33.85 Full-Time/Part-Time Full-Time Shift Various Shifts Exempt ...

Senior Security Engineer

Dallas, TX · On-site

$113K - $155K/yr

Maintain accurate POAM records for all security-classified vulnerabilities ensuring * remediation dates, risk classifications, and fix approaches are documented to audit standards required in a ...

Senior Security Engineer

Dallas, TX · On-site

$113K - $155K/yr

Maintain accurate POAM records for all security-classified vulnerabilities ensuring * remediation dates, risk classifications, and fix approaches are documented to audit standards required in a ...

Senior Security Engineer

Dallas, TX · On-site

$113K - $155K/yr

Maintain accurate POAM records for all security-classified vulnerabilities ensuring * remediation dates, risk classifications, and fix approaches are documented to audit standards required in a ...

Senior Security Engineer

Dallas, TX · On-site

$113K - $155K/yr

Maintain accurate POAM records for all security-classified vulnerabilities ensuring * remediation dates, risk classifications, and fix approaches are documented to audit standards required in a ...

Senior Security Engineer

Dallas, TX · On-site

$113K - $155K/yr

Maintain accurate POAM records for all security-classified vulnerabilities ensuring * remediation dates, risk classifications, and fix approaches are documented to audit standards required in a ...

next page

Showing results 1-20

Poam information

See salary details

$14

$24

$41

How much do poam jobs pay per hour?

As of Aug 30, 2026, the average hourly pay for poam in the United States is $24.25, according to ZipRecruiter salary data. Most workers in this role earn between $18.27 and $26.44 per hour, depending on experience, location, and employer.

What is a POAM?

POAMs, or Plans of Action and Milestones, are management tools used in cybersecurity and compliance to identify, track, and remediate security weaknesses within an organization’s information systems. They document specific steps needed to address vulnerabilities, assign responsibilities, and set deadlines for completion. POAMs are essential for maintaining compliance with standards such as NIST and FedRAMP, ensuring that organizations have a clear plan to achieve and maintain security requirements.

What skills and qualifications are needed to thrive as a POAM manager?

To thrive as a POAM Manager, you need a solid understanding of cybersecurity compliance frameworks, risk assessment, and project management, typically supported by experience in IT security or compliance roles. Familiarity with tools such as GRC (Governance, Risk, and Compliance) platforms, NIST SP 800-53, and related certification like CISSP or CISA is highly valuable. Strong organizational skills, attention to detail, and effective communication are crucial soft skills for coordinating remediation efforts and reporting to stakeholders. These competencies ensure that security gaps are properly tracked, managed, and remediated to maintain organizational compliance and reduce risk.

What are common challenges faced by POAM managers when managing multiple projects?

POAMs often juggle several projects with competing deadlines and priorities, which can make it challenging to allocate resources and maintain clear communication across teams. Balancing the need for thorough documentation with timely progress reporting—especially in highly regulated environments—requires strong organizational skills and attention to detail. Collaborating with diverse stakeholders, such as technical leads, compliance officers, and executive sponsors, is essential to ensure all program objectives are met and risks are effectively managed. Successful POAMs develop efficient tracking systems and proactive communication strategies to stay ahead of potential issues.

What is the difference between Poam vs Network Security Analyst?

AspectPoamNetwork Security Analyst
Required CredentialsTypically security certifications like CISSP, CEH, or CompTIA Security+Same certifications, often with additional network-specific credentials
Work EnvironmentSecurity teams, government agencies, or private firms focusing on security plansIT departments, cybersecurity firms, or corporate security teams
Employer & Industry UsageUsed in security planning and compliance documentationUsed in monitoring, analyzing, and responding to security threats

Poam (Plan of Action and Milestones) and Network Security Analyst roles both require security certifications and work within cybersecurity environments. Poam focuses on security planning and compliance, while Network Security Analysts actively monitor and respond to security threats. Both roles are essential in maintaining organizational security but serve different functions within the cybersecurity landscape.

More about Poam jobs

What states have the most Poam jobs?

States with the most job openings for Poam jobs include:

Infographic showing various Poam job openings in the United States as of August 2026, with employment types broken down into 92% Full Time, and 8% Contract. Highlights an 89% Physical, 2% Hybrid, and 9% Remote job distribution, with an average salary of $50,446 per year, or $24.3 per hour.

RMF and POAM Analyst

Guidehouse

Mclean, VA • On-site

Full-time

Medical, Dental, Vision, Life, Retirement

Posted 5 days ago


Guidehouse rating

8.0

Company rating: 8.0 out of 10

Based on 28 frontline employees who took The Breakroom Quiz

35th of 72 rated business consultants


Job description

Job Family:
Technology Consulting
Travel Required:
Up to 10%
Clearance Required:
Active Public Trust
What You Will Do:
  • Lead and/or support the development of RMF and A&A documentation including SSPs, control implementation matrices, SARs, POA&Ms, and risk acceptance materials.
  • Support authorization of on premise and cloud services leveraging FedRAMP packages, considering agency specific control requirements, and support 3PAO readiness assessments and SAR development for cloud platforms.
  • Interpret and operationalize FISMA, NIST RMF, FedRAMP, and OSCAL standards to guide application enhancements, evidence automation, and RMF workflow modernization across a GRC platform.
  • Ensuring consistency and compliance across multi-tenant GRC environments, helping Components and customer agencies implement security controls, maintain accurate documentation, and sustain reliable continuous monitoring.
  • Collaborating across Agile teams to embed RMF discipline, support backlog refinement, and validate that modernization activities remain compliant with Federal requirements.
  • Coordinate A&A activities and requirements with System Owners, ISSOs, IAMs, and third-party assessors, reducing manual burden for ISSOs and system owners by shaping automated workflows, improving evidence pathways, and strengthening data integrity used for scoring, dashboards, and compliance reporting.
  • Providing compliance and RMF subject matter guidance throughout sprint cycles, planning, testing activities, and release readiness processes, ensuring enhancements align with RMF control requirements and governance expectations.
  • Supporting continuous authorization (cATO) goals through integration of automated control validation, vulnerability data ingestion, security tooling alignment, and machine-readable artifacts (OSCAL).

What You Will Need:
  • An ACTIVE and CURRENT Federal or DoD Public Trust
  • Bachelor's Degree AND Five (5) years of relevant cybersecurity experience, OR a Master's Degree AND Three (3) years of relevant experience
  • Experience as an RMF or POAM Analyst (current or past)
  • Excellent verbal and written communication skills, specifically in report writing
  • Ability to commute to client office as needed per week

What Would Be Nice To Have:
  • Security+, CAP, or equivalent certification, and strong working knowledge of NIST SP 800 37, 800 53, FISMA, and FedRAMP.
  • Familiarity with ServiceNow, GRC platforms, or audit tracking tools.
  • Experience consulting at large federal agencies such as the Department of State, Department of Justice or Department of Homeland Security related to GRC implementations
  • Demonstrated experience in the areas of external client-facing management and/or consulting for large firms

What We Offer:
Guidehouse offers a comprehensive, total rewards package that includes competitive compensation and a flexible benefits package that reflects our commitment to creating a diverse and supportive workplace.
Benefits include:
  • Medical, Rx, Dental & Vision Insurance
  • Personal and Family Sick Time & Company Paid Holidays
  • Position may be eligible for a discretionary variable incentive bonus
  • Parental Leave and Adoption Assistance
  • 401(k) Retirement Plan
  • Basic Life & Supplemental Life
  • Health Savings Account, Dental/Vision & Dependent Care Flexible Spending Accounts
  • Short-Term & Long-Term Disability
  • Student Loan PayDown
  • Tuition Reimbursement, Personal Development & Learning Opportunities
  • Skills Development & Certifications
  • Employee Referral Program
  • Corporate Sponsored Events & Community Outreach
  • Emergency Back-Up Childcare Program
  • Mobility Stipend

About Guidehouse
Guidehouse is an Equal Opportunity Employer-Protected Veterans, Individuals with Disabilities or any other basis protected by law, ordinance, or regulation.
Guidehouse will consider for employment qualified applicants with criminal histories in a manner consistent with the requirements of applicable law or ordinance including the Fair Chance Ordinance of Los Angeles and San Francisco.
If you have visited our website for information about employment opportunities, or to apply for a position, and you require an accommodation, please contact Guidehouse Recruiting at 1-571-633-1711 or via email at RecruitingAccommodation@guidehouse.com. All information you provide will be kept confidential and will be used only to the extent required to provide needed reasonable accommodation.
All communication regarding recruitment for a Guidehouse position will be sent from Guidehouse email domains including @guidehouse.com or guidehouse@myworkday.com. Correspondence received by an applicant from any other domain should be considered unauthorized and will not be honored by Guidehouse. Note that Guidehouse will never charge a fee or require a money transfer at any stage of the recruitment process and does not collect fees from educational institutions for participation in a recruitment event. Never provide your banking information to a third party purporting to need that information to proceed in the hiring process.
If any person or organization demands money related to a job opportunity with Guidehouse, please report the matter to Guidehouse's Ethics Hotline. If you want to check the validity of correspondence you have received, please contact recruiting@guidehouse.com. Guidehouse is not responsible for losses incurred (monetary or otherwise) from an applicant's dealings with unauthorized third parties.
Guidehouse does not accept unsolicited resumes through or from search firms or staffing agencies. All unsolicited resumes will be considered the property of Guidehouse and Guidehouse will not be obligated to pay a placement fee.

What Guidehouse employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom