About the job
Public Trust Eligibility Required
About Aretum
Aretum is a mission-driven organization dedicated to providing cutting-edge, technology-driven solutions to our clients in defense, civilian, and homeland security sectors. Our teams operate at the intersection of strategy, technology, and transformation, empowering agencies to tackle their most pressing challenges. We prioritize investing in our workforce and foster a culture centered around collaboration, inclusivity, and professional development.
Job Summary
Aretum is searching for a talented and proactive Security / RMF Engineer. In this role, you will be responsible for ensuring adherence to VA security requirements while managing the Authorization to Operate (ATO) lifecycle.
As a federal consulting organization, our employees may be required to handle Controlled Unclassified Information (CUI) and must comply with relevant safeguarding and compliance standards.
Responsibilities
- Create and maintain RMF documentation (SSP, POA&M, SAR inputs)
- Identify and implement security controls across system layers
- Collaborate with VA security stakeholders
- Assist in vulnerability scanning and remediation efforts
- Facilitate continuous monitoring and compliance processes
Qualifications
- RMF Framework: Proficiency in NIST 800-53, control families, and tailoring
- ATO Process: Experience with SSP development, POA&M management, and authorization workflows
- ServiceNow GRC (or similar): Capable of documentation and tracking
- Cloud Security: Knowledge of AWS security controls and the shared responsibility model
- Identity & Access Management: Familiarity with RBAC, least privilege, and federation concepts
- Encryption: Understanding of TLS, data-at-rest encryption, and key management (KMS)
- Vulnerability Management: Experience with scanning tools and remediation workflows
- Logging & Monitoring: Knowledge of SIEM integration (e.g., Splunk, Datadog concepts)
- Network Security: Familiarity with segmentation, ingress/egress control, and TIC awareness
- Compliance Standards: Awareness of HIPAA, FISMA, and FEDRAMP basics
- DevSecOps Integration: Knowledge of integrating security into CI/CD pipelines
- Risk Assessment: Ability to identify and document system risks and mitigations
Travel Requirements
This is a remote position; however, occasional travel may be required based on project needs, client meetings, team collaboration events, or training sessions. Travel is expected to be less than 10% and will be communicated in advance whenever possible.
EEO Statement
Aretum is committed to fostering a workplace that values diversity and inclusion. We encourage all qualified individuals to apply.

