Jobs and Careers
AR

Cybersecurity Specialist

Aretum
Washington, United Statesfull_timeVerifiedPosted 24 Sept 2025

About the role

Aretum is a mission-driven organization committed to delivering innovative, technology-enabled solutions to our customers across defense, civilian, and homeland security sectors. Our teams work at the intersection of strategy, technology, and transformation, helping agencies solve their most critical challenges. We believe in investing in our people and creating a culture where collaboration, inclusion, and professional growth are at the forefront. 
 
Join us to be part of meaningful work that drives national impact and grow your career alongside exceptional peers. 

Due to the nature of our work as a federal consulting organization, employees may be expected to handle Controlled Unclassified Information (CUI) and must adhere to applicable safeguarding and compliance requirements. Additionally, all team members may be called upon to support proposal efforts as needed. This could include resume formatting, providing skills alignment summaries, participating in meetings, or contributing to solutioning activities based on subject matter expertise or functional experience. 

Responsibilities

  • Lead authorship of the System Security Plan from first draft to approval, written in clear, testable language that supports an ATO decision.
  • Perform security categorization under FIPS 199 and derive baseline requirements from FIPS 200 and NIST SP 800-53 Rev 5 with appropriate tailoring.
  • Build a complete and coherent authorization package that explains the system boundary, users, data types and flows, risks, and how controls are met.
  • Translate technical inputs into specific control narratives that can be verified by assessors and traced to actual configurations.
  • Collect, verify, and index evidence for every control, linking statements to diagrams, configurations, tickets, and scan results.
  • Record, organize, and quality-check all artifacts in CSAM with consistent naming, metadata, and cross-references ready for audit.
  • Keep documentation current as the system changes by capturing deltas promptly and updating only the affected sections.
  • Plan and run readiness reviews before assessments, close gaps, and prepare concise responses to findings.
  • Manage POA&M items through closure with clear actions, owners, and target dates.
  • Create and maintain templates and checklists that reduce review time and improve consistency across systems.
  • Coordinate with the ISSO, assessors, the Authorizing Official, engineers, and vendors to keep schedules and deliverables on track.
  • When cloud services are used, align with applicable FedRAMP baselines and document inherited controls clearly.
  • Communicate risks and decisions in straightforward terms so leadership can approve with confidence and reviewers can verify quickly.

Requirements

  • 3 years of experience supporting federal government compliance.
  • Demonstrated experience producing federal FISMA RMF authorization documentation that resulted in an ATO or successful assessments.
  • Strong track record authoring SSP and POA&M with precise control statements and accurate mapping to evidence.
  • Working knowledge of NIST SP 800-37, NIST SP 800-53 Rev 5, NIST SP 800-53A, NIST SP 800-18, NIST SP 800-30, FIPS 199, and FIPS 200.
  • Ability to elicit engineering details and turn them into assessor-ready narratives with clear boundaries and data flows.
  • Hands-on experience managing authorization packages in CSAM with disciplined organization and traceability.
  • Familiarity with common assessment evidence and scanner outputs and how they map to NIST 800-53 controls and POA&M entries.
  • Clear, concise writing, strong attention to detail, version control discipline, and the ability to drive edits and approvals across teams.
  • Willing to commute to Washington, D.C. 4 days a week.
  • Eligible to obtain a Public Trust.

Work Environment and Physical Requirements

This is a hybrid position, with work performed both remotely and at client or corporate office locations as needed. The employee is expected to maintain a professional remote work environment with reliable internet access and the ability to participate in virtual meetings. Onsite work may involve a traditional office setting with standard office equipment and moderate noise levels. Travel to client or corporate locations will be communicated in advance. 

The physical demands described here are representative of those that must be met to successfully perform the essential functions of this job: 

  • Prolonged periods of sitting at a desk and working on a computer. 
  • Frequent use of hands and fingers to operate computer equipment and communicate via phone or video. 
  • Ability to move about office spaces and attend

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Aretum

View company profile →