1

Poam Jobs (NOW HIRING)

Develop Plans of Action and Milestones (POAM) to mitigate risks, or document risk acceptance * Maintain list of Ports, Protocols, and Services (PPS) for systems * Update system documentation when ...

Develop Plans of Action and Milestones (POAM) to mitigate risks, or document risk acceptance * Maintain list of Ports, Protocols, and Services (PPS) for systems * Update system documentation when ...

Develop POAM and maintenance plans * Attend and/or coordinate AV meetings * Coordinate repair return authorizations with manufacturers and vendors as part of maintenance activities. Qualifications

Lead Business Systems Analyst

Fairfax, VA · On-site +1

$111K - $145K/yr

Develop Plans of Action and Milestones (POAM) to evolve systems to best practices. * Provide technical guidance on identity, credential, and access management systems (AMPS, SSO, PAM). * Create ...

System Engineer - Navy Validator

San Diego, CA · On-site

$60.75 - $74.50/hr

... POAM's), crafting mitigation statements, eMASS entry, and any other documents that are required as part of the NIST 800-53 and 800-37 Information Assurance (IA) Control and Risk Assessments Review ...

Showing results 41-60

Poam information

See salary details

$14

$24

$41

How much do poam jobs pay per hour?

As of Aug 6, 2026, the average hourly pay for poam in the United States is $24.25, according to ZipRecruiter salary data. Most workers in this role earn between $18.27 and $26.44 per hour, depending on experience, location, and employer.

What are common challenges faced by POAM managers when managing multiple projects?

POAMs often juggle several projects with competing deadlines and priorities, which can make it challenging to allocate resources and maintain clear communication across teams. Balancing the need for thorough documentation with timely progress reporting—especially in highly regulated environments—requires strong organizational skills and attention to detail. Collaborating with diverse stakeholders, such as technical leads, compliance officers, and executive sponsors, is essential to ensure all program objectives are met and risks are effectively managed. Successful POAMs develop efficient tracking systems and proactive communication strategies to stay ahead of potential issues.

What is a POAM?

POAMs, or Plans of Action and Milestones, are management tools used in cybersecurity and compliance to identify, track, and remediate security weaknesses within an organization’s information systems. They document specific steps needed to address vulnerabilities, assign responsibilities, and set deadlines for completion. POAMs are essential for maintaining compliance with standards such as NIST and FedRAMP, ensuring that organizations have a clear plan to achieve and maintain security requirements.

What skills and qualifications are needed to thrive as a POAM manager?

To thrive as a POAM Manager, you need a solid understanding of cybersecurity compliance frameworks, risk assessment, and project management, typically supported by experience in IT security or compliance roles. Familiarity with tools such as GRC (Governance, Risk, and Compliance) platforms, NIST SP 800-53, and related certification like CISSP or CISA is highly valuable. Strong organizational skills, attention to detail, and effective communication are crucial soft skills for coordinating remediation efforts and reporting to stakeholders. These competencies ensure that security gaps are properly tracked, managed, and remediated to maintain organizational compliance and reduce risk.

What is the difference between Poam vs Network Security Analyst?

AspectPoamNetwork Security Analyst
Required CredentialsTypically security certifications like CISSP, CEH, or CompTIA Security+Same certifications, often with additional network-specific credentials
Work EnvironmentSecurity teams, government agencies, or private firms focusing on security plansIT departments, cybersecurity firms, or corporate security teams
Employer & Industry UsageUsed in security planning and compliance documentationUsed in monitoring, analyzing, and responding to security threats

Poam (Plan of Action and Milestones) and Network Security Analyst roles both require security certifications and work within cybersecurity environments. Poam focuses on security planning and compliance, while Network Security Analysts actively monitor and respond to security threats. Both roles are essential in maintaining organizational security but serve different functions within the cybersecurity landscape.

More about Poam jobs
What states have the most Poam jobs? States with the most job openings for Poam jobs include:
What job categories do people searching Poam jobs look for? The top searched job categories for Poam jobs are:
Infographic showing various Poam job openings in the United States as of August 2026, with employment types broken down into 87% Full Time, 4% Part Time, and 9% Contract. Highlights an 91% Physical, 1% Hybrid, and 8% Remote job distribution, with an average salary of $50,446 per year, or $24.3 per hour.

Cloud ISSO with Security Clearance

22nd Century Technologies, Inc.

Fort Belvoir, VA • On-site

Other

Re-posted 6 days ago


Job description

Please find below the job details: Job Title: Cloud Security ISSO Location: Fort Belvoir VA Duration: FTE Clearance Required: Secret Certifications: Formal general security certification (e.g., CompTIA Security, Cloud Security, Alliance - Certificate of Cloud Security Knowledge, (ISC) 2 Certified in Cybersecurity / Systems Security Certified Practitioner, GSEC - Global Information Assurance Certification Security Essentials , Offensive Security, Certified Professional, EC-Council Certified Ethical Hacker.) Perform all Information Systems Security Officer / Information System Security (ISSO/ISSM) relate duties. This includes supporting ECMA's risk management of all cloud information systems/enclaves (AWS & AZURE). Responsible for all 7 steps of the NIST RMF (Prepare, Categorize, Select, Implement, Assess, Authorize & Monitor) to ensure compliance with Federal/DOD/Army reequipments. Also responsible for supporting the ECMA Cloud Security Operations team, in reviewing and approving security related tickets and other ad-hoc tasks. * Serve as an Information Systems Security Officer/Manager (ISSO/ISSM) for ensuring the security and compliance of sensitive and classified DOD/ARMY data within AWS and AWS(IL4/5/6) environments. * Collaborate with various stakeholders and worked across multiple divisions/business units to identify and mitigate potential cyber risks to the agency cloud environment. * Work cross-functionally with individual contributors and senior leadership in developing ATO packages. * Lead continuous monitoring efforts for multiple cloud enclaves to include ACAS scanning, POAM remediation, risk assessments (evidence collection for audits and reviews) * Conduct comprehensive audits and risk assessments (NIST 800-53rev5), ensuring vendor and tenant compliance with DOD SRG security standards and readiness for production deployment. * Develop and implement continuous monitoring and security strategies in collaboration with senior management, enhancing assessment and authorization initiatives. * Review and assess FEDRAMP CSP authorization packages (SSP, CRM, SAR, P&Ps, POAMs) prior to inclusion into the ARMY's Enterprise Cloud Management Agency production environment. * Manage, Track and Remediate over 400 POAMs to strengthen the ARMY cloud secure posture. * Completed four assessments on FEDRAMP CSO's to ensure compliance with ARMY rules and regulations prior to inclusion into the ARMY network.