Fathom Robotics logo

CMMC Compliance & IT Support Specialist

Salary
$30–$40/hr
USD per hour
Hiring from
United States
Work type
Hybrid
Posted
Sep 25, 2026
Is this job info correct?

ABOUT FATHOM ROBOTICS

Fathom Robotics provides operations, maintenance, training, and applied engineering services for uncrewed maritime systems supporting U.S. Government and commercial defense programs. We have multiple active projects across a variety of government and commercial clients and are actively fielding systems in operational environments.

ROLE OVERVIEW

The CMMC Compliance & IT Support Specialist leads Fathom Robotics’ day-to-day readiness for CMMC Level 2 and supports the systems we use to handle Controlled Unclassified Information (CUI) on Department of Defense programs. Most of the role is compliance work; the rest is hands-on IT support for our team.

This person works closely with the Chief Administrative Officer and our outside IT providers. The aim is a security program that holds up at assessment and fits the way our engineering, operations, and field staff work.

Meeting CMMC requirements is a condition of our DoD contract work.

LOCATION: Fort Worth, TX (Hybrid)

WORK TYPE: Part-Time, approximately 20 hours per week

CLEARANCE: US Person Required | SECRET Eligible (Minimum)

PROGRAM CONDITIONS

This is a part-time, hybrid position of approximately 20 hours per week based in Fort Worth, TX, scheduled around agreed core hours with some flexibility. On-site time is needed for hands-on equipment work and in-person coordination. Workload increases in the weeks leading up to a self-assessment or third-party assessment, and system maintenance may occasionally need to happen outside normal business hours to avoid disrupting program work. Limited travel to other Fathom Robotics sites may be required.

RESPONSIBILITIES:

CMMC & Cybersecurity Compliance (Primary Focus)

Overall accountability for the security program rests with the Chief Administrative Officer.

  • Implement and maintain the NIST SP 800-171 security requirements that underpin CMMC Level 2
  • Own the System Security Plan (SSP), Plan of Action and Milestones (POA&M), and supporting policies and procedures, keeping them accurate as systems and programs change
  • Define and maintain the CUI assessment boundary, including where CUI is stored, processed, and transmitted
  • Conduct internal self-assessments, track gaps to closure, and help maintain the company’s SPRS score
  • Collect, organize, and maintain evidence for each control in preparation for third-party (C3PAO) assessments, and serve as a primary point of contact during assessments
  • Perform continuous monitoring of security controls, including patching, backups, endpoint protection, vulnerability scanning, and audit logs, and keep control status current between assessments
  • Review vendor and cloud service provider compliance, including FedRAMP status and flow-down requirements
  • Deliver security awareness training and help staff follow CUI handling procedures
  • Support cyber incident response and reporting in line with DFARS 252.204-7012

IT & Help Desk Support

  • Provide first- and second-level technical support for hardware, software, network, and account issues
  • Configure and deploy laptops, workstations, and mobile devices to company security baselines
  • Manage user accounts, access permissions, and multi-factor authentication, including onboarding and offboarding
  • Maintain the IT asset inventory and coordinate with managed service providers and vendors

Overall accountability for the security program rests with the Chief Administrative Officer.

  • Implement and maintain the NIST SP 800-171 security requirements that underpin CMMC Level 2
  • Own the System Security Plan (SSP), Plan of Action and Milestones (POA&M), and supporting policies and procedures, keeping them accurate as systems and programs change
  • Define and maintain the CUI assessment boundary, including where CUI is stored, processed, and transmitted
  • Conduct internal self-assessments, track gaps to closure, and help maintain the company’s SPRS score
  • Collect, organize, and maintain evidence for each control in preparation for third-party (C3PAO) assessments, and serve as a primary point of contact during assessments
  • Perform continuous monitoring of security controls, including patching, backups, endpoint protection, vulnerability scanning, and audit logs, and keep control status current between assessments
  • Review vendor and cloud service provider compliance, including FedRAMP status and flow-down requirements
  • Deliver security awareness training and help staff follow CUI handling procedures
  • Support cyber incident response and reporting in line with DFARS 252.204-7012

IT & Help Desk Support

  • Provide first- and second-level technical support for hardware, software, network, and account issues
  • Configure and deploy laptops, workstations, and mobile devices to company security baselines
  • Manage user accounts, access permissions, and multi-factor authentication, including onboarding and offboarding
  • Maintain the IT asset inventory and coordinate with managed service providers and vendors

REQUIRED QUALIFICATIONS

  • 3+ years of experience in cybersecurity compliance, IT security, or systems administration, including direct work implementing NIST SP 800-171 or CMMC requirements
  • Experience writing and maintaining an SSP and POA&M
  • Working knowledge of DFARS 252.204-7012, CUI handling requirements, and the CMMC assessment process
  • Working knowledge of Windows endpoints, Microsoft 365 administration, and networking fundamentals
  • Strong written documentation skills and the ability to explain security requirements clearly to non-technical teammates
  • US person status required (defense program context)
  • Must be able to pass a background check and be eligible to obtain a SECRET clearance

PREFERRED BACKGROUNDS

  • CMMC Certified Professional (CCP) or Certified CMMC Assessor (CCA) credential
  • CompTIA Security+ or equivalent security certification
  • Experience supporting a small defense contractor through a C3PAO assessment or DIBCAC review
  • Experience with Microsoft 365 GCC High or Azure Government environments

This is a part-time position and is not eligible for health benefits.

COMPENSATION: $30–$40/hour, commensurate with experience

Similar jobs

Apply for this job