1

Poam Jobs in Texas (NOW HIRING)

Lead DevSecOps Engineer

Dallas, TX · On-site

$101K - $133K/yr

Own the Definition of Done for vulnerability remediation across all 130 mnemonics, ensuring proper validation, closure, and compliance with Archer POAM closure requirements. * Coach offshore ...

Lead DevSecOps Engineer

Dallas, TX · On-site

$101K - $133K/yr

Own the Definition of Done for vulnerability remediation across all 130 mnemonics, ensuring proper validation, closure, and compliance with Archer POAM closure requirements. * Coach offshore ...

Lead DevSecOps Engineer

Dallas, TX · On-site

$101K - $133K/yr

Own the Definition of Done for vulnerability remediation across all 130 mnemonics, ensuring proper validation, closure, and compliance with Archer POAM closure requirements. * Coach offshore ...

Lead DevSecOps Engineer

Dallas, TX · On-site

$101K - $133K/yr

Own the Definition of Done for vulnerability remediation across all 130 mnemonics, ensuring proper validation, closure, and compliance with Archer POAM closure requirements. * Coach offshore ...

Lead DevSecOps Engineer

Dallas, TX · On-site

$101K - $134K/yr

Own the Definition of Done for vulnerability remediation across all 130 mnemonics: what constitutes a properly remediated, validated, and closed item before Archer POAM closure and rescan submission.

Lead DevSecOps Engineer

Dallas, TX · On-site

$101K - $133K/yr

Own the Definition of Done for vulnerability remediation across all 130 mnemonics, ensuring proper validation, closure, and compliance with Archer POAM closure requirements. * Coach offshore ...

Lead DevSecOps Engineer

Dallas, TX · On-site

$101K - $133K/yr

Own the Definition of Done for vulnerability remediation across all 130 mnemonics, ensuring proper validation, closure, and compliance with Archer POAM closure requirements. * Coach offshore ...

Lead DevSecOps Engineer

Dallas, TX · On-site

$101K - $133K/yr

Own the Definition of Done for vulnerability remediation across all 130 mnemonics, ensuring proper validation, closure, and compliance with Archer POAM closure requirements. * Coach offshore ...

Showing results 21-35

Poam information

What is a POAM?

POAMs, or Plans of Action and Milestones, are management tools used in cybersecurity and compliance to identify, track, and remediate security weaknesses within an organization’s information systems. They document specific steps needed to address vulnerabilities, assign responsibilities, and set deadlines for completion. POAMs are essential for maintaining compliance with standards such as NIST and FedRAMP, ensuring that organizations have a clear plan to achieve and maintain security requirements.

What skills and qualifications are needed to thrive as a POAM manager?

To thrive as a POAM Manager, you need a solid understanding of cybersecurity compliance frameworks, risk assessment, and project management, typically supported by experience in IT security or compliance roles. Familiarity with tools such as GRC (Governance, Risk, and Compliance) platforms, NIST SP 800-53, and related certification like CISSP or CISA is highly valuable. Strong organizational skills, attention to detail, and effective communication are crucial soft skills for coordinating remediation efforts and reporting to stakeholders. These competencies ensure that security gaps are properly tracked, managed, and remediated to maintain organizational compliance and reduce risk.

What are common challenges faced by POAM managers when managing multiple projects?

POAMs often juggle several projects with competing deadlines and priorities, which can make it challenging to allocate resources and maintain clear communication across teams. Balancing the need for thorough documentation with timely progress reporting—especially in highly regulated environments—requires strong organizational skills and attention to detail. Collaborating with diverse stakeholders, such as technical leads, compliance officers, and executive sponsors, is essential to ensure all program objectives are met and risks are effectively managed. Successful POAMs develop efficient tracking systems and proactive communication strategies to stay ahead of potential issues.

What is the difference between Poam vs Network Security Analyst?

AspectPoamNetwork Security Analyst
Required CredentialsTypically security certifications like CISSP, CEH, or CompTIA Security+Same certifications, often with additional network-specific credentials
Work EnvironmentSecurity teams, government agencies, or private firms focusing on security plansIT departments, cybersecurity firms, or corporate security teams
Employer & Industry UsageUsed in security planning and compliance documentationUsed in monitoring, analyzing, and responding to security threats

Poam (Plan of Action and Milestones) and Network Security Analyst roles both require security certifications and work within cybersecurity environments. Poam focuses on security planning and compliance, while Network Security Analysts actively monitor and respond to security threats. Both roles are essential in maintaining organizational security but serve different functions within the cybersecurity landscape.

What are popular job titles related to Poam jobs in Texas?

For Poam jobs in Texas, the most frequently searched job titles are:

Infographic showing various Poam job openings in Texas as of August 2026, with employment types broken down into 92% Full Time, and 8% Contract. Highlights an 88% Physical, 3% Hybrid, and 9% Remote job distribution.

Lead DevSecOps Engineer

System One

Dallas, TX • On-site

$101K - $133K/yr

Other

Medical, Dental, Vision, Life, Retirement

Re-posted 7 days ago


Job description

Job Title: Lead DevSecOps Engineer Location: Dallas, Texas

Responsibilities

  • Lead the integration of security into CI/CD pipelines, architect secure cloud environments, and guide teams in adopting modern DevSecOps practices to ensure a secure-by-design engineering approach across cloud and application platforms.
  • Build and lead the DevSecOps engineering practice across all three execution crews: Platform & Infra, Application/Data/Middleware, and Container & TRC.
  • Own the Definition of Done for vulnerability remediation across all 130 mnemonics, ensuring proper validation, closure, and compliance with Archer POAM closure requirements.
  • Coach offshore engineers on PNC-specific practices including Bitbucket branching standards, Jenkins pipeline security gates, PAC enforcement, and container security policies.
  • Manage the security and reliability of Jenkins pipelines used for vulnerability remediation automation, including implementing and maintaining security gates and reusable pipeline components.
  • Own Bitbucket repository structure, branching standards, and manage workflow configurations to enforce quality and security standards.
  • Implement and maintain client PAC policy rules governing vulnerability automation, ensuring compliance with security policies before execution.
  • Develop Ansible playbooks and Terraform modules for infrastructure remediations, ensuring automated compliance evidence generation for audits.
  • Own operations and health of vulnerability tools (Archer, Tanium, Sysdig, SecurityCenter, Imperva), maintaining integrations and ensuring correct alert processing and scan coverage.
  • Manage secrets via CyberArk, ensuring least-privilege access and integrating secrets management within pipelines.
  • Build and maintain a unified vulnerability SLA dashboard in Archer with real-time vulnerability data, along with automated weekly SLA reports.
  • Drive shift-left security practices within client application teams by embedding PAC checks and container security scans in the development pipeline.
  • Identify automation improvements to increase efficiency and contribute operational insights to improve AI/ML triage engines.

Requirements

  • 7+ years of hands-on DevSecOps or security automation engineering experience in enterprise environments.
  • Deep experience with Jenkins: shared libraries, pipeline-as-code, credential management, plugin administration, troubleshooting.
  • Proficiency with Bitbucket: branch permissions, PR workflows, webhook automation, Jenkins integration.
  • Strong knowledge of Artifactory: dependency management, artifact promotion, repository configuration, security scanning.
  • Advanced Python skills: REST API integrations, automation scripting, data pipeline code.
  • Expertise in Ansible: playbook creation for OS and middleware remediations on Linux and Windows.
  • Experience with Terraform: module writing, state management, change governance.
  • Familiarity with policy-as-code tools like OPA/Conftest and runtime enforcement.
  • REST API integrations with Archer GRC, ServiceNow, Jira.
  • Container operations: Docker, OpenShift/OCP, image management, container security.
  • Practical experience with vulnerability platforms: Archer GRC, Tanium, SecurityCenter.
  • Secrets management expertise, specifically CyberArk.
  • Understanding of banking/financial services environment, including CAB process, change windows, deployment governance, and audit requirements.

Preferred Qualifications

  • Familiarity with Converge, Micron framework, CaaS/OCP configurations, or BTI retail/lending mnemonic structures.
  • Sysdig operational experience for container vulnerability scanning and alert management.
  • Tanium endpoint detection and vulnerability data extraction.
  • AI/ML pipeline experience, including LangChain or similar AI agent integration.
  • Production-level Jira administration and Confluence documentation.

System One, and its subsidiaries including Joulé and Mountain Ltd., are leaders in delivering outsourced services and workforce solutions across North America. We help clients get work done more efficiently and economically, without compromising quality. System One not only serves as a valued partner for our clients, but we offer eligible employees health and welfare benefits coverage options including medical, dental, vision, spending accounts, life insurance, voluntary plans, as well as participation in a 401(k) plan.

System One is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender identity, age, national origin, disability, family care or medical leave status, genetic information, veteran status, marital status, or any other characteristic protected by applicable federal, state, or local law.

#M- #LI- Ref: #404-IT Pittsburgh


System One logo

About System One

Sourced by ZipRecruiter

System One helps employers get work done more efficiently and economically without compromising quality. Over our 35+ year history, we've helped connect thousands of talented people with innovative companies. The excitement of a perfect fit motivates us every single day.

Industry

Business consulting services and recruiting and staffing services

Company size

5,001 - 10,000 Employees

Headquarters location

Pittsburgh, PA, US