# CMMC Compliance & IT Support Specialist

**Company:** [Fathom Robotics](null/companies/2wchR19B6f1avvwxUG67iT.md)
**Location:** Fort Worth, United States
**Workplace:** hybrid
**Employment type:** Part-time

[Apply for this job](null/view/a6ee49f8-40ed-4a85-8958-d6bcf116b20e)

## Description

**ABOUT FATHOM ROBOTICS**

Fathom Robotics provides operations, maintenance, training, and applied engineering services for uncrewed maritime systems supporting U.S. Government and commercial defense programs. We have multiple active projects across a variety of government and commercial clients and are actively fielding systems in operational environments.

**ROLE OVERVIEW**

The CMMC Compliance & IT Support Specialist leads Fathom Robotics’ day-to-day readiness for CMMC Level 2 and supports the systems we use to handle Controlled Unclassified Information (CUI) on Department of Defense programs. Most of the role is compliance work; the rest is hands-on IT support for our team.

This person works closely with the Chief Administrative Officer and our outside IT providers. The aim is a security program that holds up at assessment and fits the way our engineering, operations, and field staff work.

_Meeting CMMC requirements is a condition of our DoD contract work._

**LOCATION:**  Fort Worth, TX (Hybrid)

**WORK TYPE:**  Part-Time, approximately 20 hours per week

**CLEARANCE:**  US Person Required | SECRET Eligible (Minimum)

**PROGRAM CONDITIONS**

This is a part-time, hybrid position of approximately 20 hours per week based in Fort Worth, TX, scheduled around agreed core hours with some flexibility. On-site time is needed for hands-on equipment work and in-person coordination. Workload increases in the weeks leading up to a self-assessment or third-party assessment, and system maintenance may occasionally need to happen outside normal business hours to avoid disrupting program work. Limited travel to other Fathom Robotics sites may be required.

**RESPONSIBILITIES:**

_**CMMC & Cybersecurity Compliance (Primary Focus)**_

Overall accountability for the security program rests with the Chief Administrative Officer.

-   Implement and maintain the NIST SP 800-171 security requirements that underpin CMMC Level 2
-   Own the System Security Plan (SSP), Plan of Action and Milestones (POA&M), and supporting policies and procedures, keeping them accurate as systems and programs change
-   Define and maintain the CUI assessment boundary, including where CUI is stored, processed, and transmitted
-   Conduct internal self-assessments, track gaps to closure, and help maintain the company’s SPRS score
-   Collect, organize, and maintain evidence for each control in preparation for third-party (C3PAO) assessments, and serve as a primary point of contact during assessments
-   Perform continuous monitoring of security controls, including patching, backups, endpoint protection, vulnerability scanning, and audit logs, and keep control status current between assessments
-   Review vendor and cloud service provider compliance, including FedRAMP status and flow-down requirements
-   Deliver security awareness training and help staff follow CUI handling procedures
-   Support cyber incident response and reporting in line with DFARS 252.204-7012

_**IT & Help Desk Support**_

-   Provide first- and second-level technical support for hardware, software, network, and account issues
-   Configure and deploy laptops, workstations, and mobile devices to company security baselines
-   Manage user accounts, access permissions, and multi-factor authentication, including onboarding and offboarding
-   Maintain the IT asset inventory and coordinate with managed service providers and vendors

_Overall accountability for the security program rests with the Chief Administrative Officer._

-   Implement and maintain the NIST SP 800-171 security requirements that underpin CMMC Level 2
-   Own the System Security Plan (SSP), Plan of Action and Milestones (POA&M), and supporting policies and procedures, keeping them accurate as systems and programs change
-   Define and maintain the CUI assessment boundary, including where CUI is stored, processed, and transmitted
-   Conduct internal self-assessments, track gaps to closure, and help maintain the company’s SPRS score
-   Collect, organize, and maintain evidence for each control in preparation for third-party (C3PAO) assessments, and serve as a primary point of contact during assessments
-   Perform continuous monitoring of security controls, including patching, backups, endpoint protection, vulnerability scanning, and audit logs, and keep control status current between assessments
-   Review vendor and cloud service provider compliance, including FedRAMP status and flow-down requirements
-   Deliver security awareness training and help staff follow CUI handling procedures
-   Support cyber incident response and reporting in line with DFARS 252.204-7012

IT & Help Desk Support

-   Provide first- and second-level technical support for hardware, software, network, and account issues
-   Configure and deploy laptops, workstations, and mobile devices to company security baselines
-   Manage user accounts, access permissions, and multi-factor authentication, including onboarding and offboarding
-   Maintain the IT asset inventory and coordinate with managed service providers and vendors

## Requirements

**REQUIRED QUALIFICATIONS**

-   3+ years of experience in cybersecurity compliance, IT security, or systems administration, including direct work implementing NIST SP 800-171 or CMMC requirements
-   Experience writing and maintaining an SSP and POA&M
-   Working knowledge of DFARS 252.204-7012, CUI handling requirements, and the CMMC assessment process
-   Working knowledge of Windows endpoints, Microsoft 365 administration, and networking fundamentals
-   Strong written documentation skills and the ability to explain security requirements clearly to non-technical teammates
-   US person status required (defense program context)
-   Must be able to pass a background check and be eligible to obtain a SECRET clearance

**PREFERRED BACKGROUNDS**

-   CMMC Certified Professional (CCP) or Certified CMMC Assessor (CCA) credential
-   CompTIA Security+ or equivalent security certification
-   Experience supporting a small defense contractor through a C3PAO assessment or DIBCAC review
-   Experience with Microsoft 365 GCC High or Azure Government environments

## Benefits

This is a part-time position and is not eligible for health benefits.

**COMPENSATION:**  $30–$40/hour, commensurate with experience
