1

Poam Jobs in Virginia (NOW HIRING)

Generate POAM's (Plan of Action and Milestone) documents for the remediation of found gaps * Generate SSP (System Security Plan) documents to reflect deployed tools and assessment results * Interface ...

CyberSecurity Engineer

Arlington, VA · Hybrid

$100K - $150K/yr

You will serve as a technical expert responsible for continuous scanning, STIG application, POAM tracking, and remediation strategies to safeguard our federal client's assets. Location: Arlington, VA ...

CyberSecurity Engineer

Arlington, VA · On-site

$120 - $170/hr

You will serve as a technical expert responsible for continuous scanning, STIG application, POAM tracking, and remediation strategies to safeguard our federal client's assets. Location: Arlington, VA ...

CyberSecurity Engineer

Arlington, VA · On-site

$100K - $150K/yr

You will serve as a technical expert responsible for continuous scanning, STIG application, POAM tracking, and remediation strategies to safeguard our federal client's assets. Location: Arlington, VA ...

... poam, acas, emass, Cyber security, A&A, Vulnerability detection, Vulnerability, Vulnerability management, Vulnerability assessment Experience Level Expert Level Job Type & Location This is a Contract ...

Showing results 41-60

Poam information

What are common challenges faced by POAM managers when managing multiple projects?

POAMs often juggle several projects with competing deadlines and priorities, which can make it challenging to allocate resources and maintain clear communication across teams. Balancing the need for thorough documentation with timely progress reporting—especially in highly regulated environments—requires strong organizational skills and attention to detail. Collaborating with diverse stakeholders, such as technical leads, compliance officers, and executive sponsors, is essential to ensure all program objectives are met and risks are effectively managed. Successful POAMs develop efficient tracking systems and proactive communication strategies to stay ahead of potential issues.

What is a POAM?

POAMs, or Plans of Action and Milestones, are management tools used in cybersecurity and compliance to identify, track, and remediate security weaknesses within an organization’s information systems. They document specific steps needed to address vulnerabilities, assign responsibilities, and set deadlines for completion. POAMs are essential for maintaining compliance with standards such as NIST and FedRAMP, ensuring that organizations have a clear plan to achieve and maintain security requirements.

What skills and qualifications are needed to thrive as a POAM manager?

To thrive as a POAM Manager, you need a solid understanding of cybersecurity compliance frameworks, risk assessment, and project management, typically supported by experience in IT security or compliance roles. Familiarity with tools such as GRC (Governance, Risk, and Compliance) platforms, NIST SP 800-53, and related certification like CISSP or CISA is highly valuable. Strong organizational skills, attention to detail, and effective communication are crucial soft skills for coordinating remediation efforts and reporting to stakeholders. These competencies ensure that security gaps are properly tracked, managed, and remediated to maintain organizational compliance and reduce risk.

What is the difference between Poam vs Network Security Analyst?

AspectPoamNetwork Security Analyst
Required CredentialsTypically security certifications like CISSP, CEH, or CompTIA Security+Same certifications, often with additional network-specific credentials
Work EnvironmentSecurity teams, government agencies, or private firms focusing on security plansIT departments, cybersecurity firms, or corporate security teams
Employer & Industry UsageUsed in security planning and compliance documentationUsed in monitoring, analyzing, and responding to security threats

Poam (Plan of Action and Milestones) and Network Security Analyst roles both require security certifications and work within cybersecurity environments. Poam focuses on security planning and compliance, while Network Security Analysts actively monitor and respond to security threats. Both roles are essential in maintaining organizational security but serve different functions within the cybersecurity landscape.

What are popular job titles related to Poam jobs in Virginia?

For Poam jobs in Virginia, the most frequently searched job titles are:

Infographic showing various Poam job openings in Virginia as of August 2026, with employment types broken down into 90% Full Time, 4% Part Time, and 6% Contract. Highlights an 88% Physical, 4% Hybrid, and 8% Remote job distribution.

Cybersecurity Information System Security Engineer - Clearance Required

LMI

Fort Belvoir, VA

$64.75 - $79.50/hr

Full-time

Posted 23 days ago


Job description

Overview

LMI is seeking a skilledSenior Cybersecurity Information Systems Security Engineer (ISSE)to support US Army Capability Program Executive (CPE) Gound office at Ft. Belvoir, Virginia. The ISSE will drive efforts that support software and hardware cybersecurity Risk Management Framework (RMF) Authority to Operate (ATO). 

LMI is a new breed of digital solutions provider dedicated to accelerating government impact with innovation and speed. Investing in technology and prototypes ahead of need, LMI brings commercial-grade platforms and mission-ready AI to federal agencies at commercial speed.

Leveraging our mission-ready technology and solutions, proven expertise in federal deployment, and strategic relationships, we enhance outcomes for the government, efficiently and effectively. With a focus on agility and collaboration, LMI serves the defense, space, healthcare, and energy sectors-helping agencies navigate complexity and outpace change. Headquartered in Tysons, Virginia, LMI is committed to delivering impactful results that strengthen missions and drive lasting value.

This position requires an active Secret clearance and onsite presence at Ft. Belvoir, VA. 

Responsibilities

Responsibilities: 

  • Collaborate with system engineers, program managers, and Authorizing Officials (or their delegates) to define and implement system security requirements. 
  • Lead efforts to ensure continuous monitoring and verification of cybersecurity requirements throughout the system lifecycle. 
  • Serve as a trusted cybersecurity advisor, providing guidance and recommendations to government stakeholders and contractor teams. 
  • Design, review, and refine system security architectures for cloud, on-premises, and hybrid environments. 
  • Support the Risk Management Framework (RMF) process to achieve and maintain Authority to Operate (ATO) approvals. 
  • Identify, track, and mitigate security control gaps and areas of non-compliance, ensuring alignment with security standards. 
  • Conduct risk assessments, vulnerability assessments, and develop and maintain critical documentation, such as System Security Plans (SSPs). 
  • Manage and facilitate Interim Authority to Test (IATT) activities, risk assessments, and all ATO-related processes. 
  • Analyze and interpret security control deficiencies to assess their impact on enterprise risk levels and cybersecurity program effectiveness. 
  • Partner with the Information System Security Manager (ISSM) and product teams to identify control gaps, propose mitigations, and prepare Program of Action and Milestone (POAM) plans for ATO submission. 
  • Guide system engineers on the mitigation of vulnerability findings using state-of-the-art security scanning tools, DoD policies, and industry best practices. 
  • Provide cybersecurity engineering expertise in evaluating alternatives, assessing trade-offs, and recommending risk treatment strategies. 
  • Collaborate with cross-functional teams to ensure the delivery of secure and dependable systems. 
  • Develop and maintain dashboards to monitor platform system controls, logs, and compliance status, ensuring seamless reporting. 
  • Demonstrate expertise in implementing cloud cybersecurity solutions and practices. 
  • Apply NIST SP 800-53 Revision 4 or 5 security controls and security assessment procedures from NIST SP 800-53A. 

Core Knowledge, Skills, Abilities, and Tasks (KSATs) - DoD Cyber Workforce (DCWF): 

  • In-depth knowledge of computer networking concepts, protocols, and methodologies to ensure effective network security. 
  • Expertise in risk management processes, including methodologies for identifying, assessing, and mitigating risks. 
  • Comprehensive understanding of national and international laws, regulations, policies, and ethical standards impacting cybersecurity operations. 
  • Proficient knowledge of core cybersecurity principles and best practices for protecting information systems and data. 
  • Awareness of cyber threats, vulnerabilities, and emerging attack vectors that could compromise systems and information. 
  • Strong understanding of the specific operational impacts that cybersecurity lapses can impose on systems, data integrity, and organizational objectives. 
  • Expertise in cloud computing service models, including Software as a Service (SaaS), Infrastructure as a Service (IaaS), and Platform as a Service (PaaS). 
  • Solid understanding of cloud computing deployment models, including private, public, hybrid, and the key differences between on-premises and off-premises environments. 
  • Knowledge of cloud computing deployment models in private, public, and hybrid environment and the difference between on-premises and off-premises environments. 
Qualifications

Minimum Qualifications: 

  • Active SECRET security clearance (minimum requirement). 
  • Bachelor's degree in Information Technology, Cybersecurity, Computer Science, Information Systems, Data Science, or Software Engineering from an ABET-accredited or NCAE-C designated institution. 
  • 5+ years of hands-on experience in system and/or security engineering within U.S. Government systems. 
  • Practical experience working within government cloud platforms (e.g., Azure, Amazon C2S, Commercial Cloud, or GovCloud), including secure implementation of security planning, design, and operations. 
  • Proven ability to develop and maintain Risk Management Framework (RMF) documentation, including System Security Plans (SSPs) and Plans of Action and Milestones (POAMs). 
  • Experience working with DoD technologies, systems, and command & control policies and procedures. 
  • Hands-on experience utilizing Enterprise Mission Assurance Support Service (eMASS) for compliance management and reporting. 
  • Familiarity with federal IT security requirements, including DoD cyber regulations, FedRAMP, and FISMA compliance. 
  • Knowledge of DoD STIGs, SRGs, and security requirements outlined in NIST SP 800-53 and its corresponding assessment procedures. 
  • Strong communication and interpersonal skills, capable of effectively interacting with both technical teams and non-technical stakeholders. 
  • One or more of the following certifications: GISF, Security+, CASP+, CSSP, Cloud+, CSSLP, GSEC, or GSEC-equivalent. (If not currently held, must obtain within the first 30 days of employment). 

Preferred Additional Qualifications: 

  • Expertise in cloud security planning, design, and operations. 
  • Experience with systems engineering lifecycle processes and Agile development methodologies. 
  • Familiarity with Continuous Integration/Continuous Delivery (CI/CD) frameworks and DevSecOps practices. 
  • Tactical military experience is strongly preferred.

Target salary range: $92,075 - $158,138.39

Disclaimer: The salary range displayed represents the typical salary range for this position and is not a guarantee of compensation. Individual salaries are determined by various factors including, but not limited to location, internal equity, business considerations, client contract requirements, and candidate qualifications, such as education, experience, skills, and security clearances.

#LI-SH1

Applicants must meet eligibility requirements for a U.S. Government security clearance. Only US Citizens are eligible for a security clearance. For this position, LMI will only consider applicants with security clearances or applicants who are eligible for security clearances, due to the nature of the work.

Job LocationsUS-VA-Fort BelvoirEmployment Type: OTHER