Skip to content

Open nowPosted 12 days ago

CMMC Compliance & IT Support Specialist

Workable (global search)108,016 open roles

Where
Fort Worth, TX, United States
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowCMMC Compliance & IT Support SpecialistWorkable (global search) · Fort Worth, TX, United States
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Workable (global search)'s own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

7.9% of postings close within 7 days. Measured by our own scanner across the market. Workable (global search) postings stay open a median of 7 days.

Share of postings closed within
  1. 1.6%1 day
  2. 3.6%3 days
  3. 7.9%7 days
  4. 14.9%14 days
  5. 34.0%30 days
This job: posted 12 days ago

Workable (global search) median: 7 days open

The posting

ABOUT FATHOM ROBOTICS

Fathom Robotics provides operations, maintenance, training, and applied engineering services for uncrewed maritime systems supporting U.S. Government and commercial defense programs. We have multiple active projects across a variety of government and commercial clients and are actively fielding systems in operational environments.

ROLE OVERVIEW

The CMMC Compliance & IT Support Specialist leads Fathom Robotics’ day-to-day readiness for CMMC Level 2 and supports the systems we use to handle Controlled Unclassified Information (CUI) on Department of Defense programs. Most of the role is compliance work; the rest is hands-on IT support for our team.

This person works closely with the Chief Administrative Officer and our outside IT providers. The aim is a security program that holds up at assessment and fits the way our engineering, operations, and field staff work.

Meeting CMMC requirements is a condition of our DoD contract work.

LOCATION: Fort Worth, TX (Hybrid)

WORK TYPE: Part-Time, approximately 20 hours per week

CLEARANCE: US Person Required | SECRET Eligible (Minimum)

PROGRAM CONDITIONS

This is a part-time, hybrid position of approximately 20 hours per week based in Fort Worth, TX, scheduled around agreed core hours with some flexibility. On-site time is needed for hands-on equipment work and in-person coordination. Workload increases in the weeks leading up to a self-assessment or third-party assessment, and system maintenance may occasionally need to happen outside normal business hours to avoid disrupting program work. Limited travel to other Fathom Robotics sites may be required.

RESPONSIBILITIES:

CMMC & Cybersecurity Compliance (Primary Focus)

Overall accountability for the security program rests with the Chief Administrative Officer.

  • Implement and maintain the NIST SP 800-171 security requirements that underpin CMMC Level 2
  • Own the System Security Plan (SSP), Plan of Action and Milestones (POA&M), and supporting policies and procedures, keeping them accurate as systems and programs change
  • Define and maintain the CUI assessment boundary, including where CUI is stored, processed, and transmitted
  • Conduct internal self-assessments, track gaps to closure, and help maintain the company’s SPRS score
  • Collect, organize, and maintain evidence for each control in preparation for third-party (C3PAO) assessments, and serve as a primary point of contact during assessments
  • Perform continuous monitoring of security controls, including patching, backups, endpoint protection, vulnerability scanning, and audit logs, and keep control status current between assessments
  • Review vendor and cloud service provider compliance, including FedRAMP status and flow-down requirements
  • Deliver security awareness training and help staff follow CUI handling procedures
  • Support cyber incident response and reporting in line with DFARS 252.204-7012

IT & Help Desk Support

  • Provide first- and second-level technical support for hardware, software, network, and account issues
  • Configure and deploy laptops, workstations, and mobile devices to company security baselines
  • Manage user accounts, access permissions, and multi-factor authentication, including onboarding and offboarding
  • Maintain the IT asset inventory and coordinate with managed service providers and vendors

Overall accountability for the security program rests with the Chief Administrative Officer.

  • Implement and maintain the NIST SP 800-171 security requirements that underpin CMMC Level 2
  • Own the System Security Plan (SSP), Plan of Action and Milestones (POA&M), and supporting policies and procedures, keeping them accurate as systems and programs change
  • Define and maintain the CUI assessment boundary, including where CUI is stored, processed, and transmitted
  • Conduct internal self-assessments, track gaps to closure, and help maintain the company’s SPRS score
  • Collect, organize, and maintain evidence for each control in preparation for third-party (C3PAO) assessments, and serve as a primary point of contact during assessments
  • Perform continuous monitoring of security controls, including patching, backups, endpoint protection, vulnerability scanning, and audit logs, and keep control status current between assessments
  • Review vendor and cloud service provider compliance, including FedRAMP status and flow-down requirements
  • Deliver security awareness training and help staff follow CUI handling procedures
  • Support cyber incident response and reporting in line with DFARS 252.204-7012

IT & Help Desk Support

  • Provide first- and second-level technical support for hardware, software, network, and account issues
  • Configure and deploy laptops, workstations, and mobile devices to company security baselines
  • Manage user accounts, access permissions, and multi-factor authentication, including onboarding and offboarding
  • Maintain the IT asset inventory and coordinate with managed service providers and vendors

Requirements

REQUIRED QUALIFICATIONS

  • 3+ years of experience in cybersecurity compliance, IT security, or systems administration, including direct work implementing NIST SP 800-171 or CMMC requirements
  • Experience writing and maintaining an SSP and POA&M
  • Working knowledge of DFARS 252.204-7012, CUI handling requirements, and the CMMC assessment process
  • Working knowledge of Windows endpoints, Microsoft 365 administration, and networking fundamentals
  • Strong written documentation skills and the ability to explain security requirements clearly to non-technical teammates
  • US person status required (defense program context)
  • Must be able to pass a background check and be eligible to obtain a SECRET clearance

PREFERRED BACKGROUNDS

  • CMMC Certified Professional (CCP) or Certified CMMC Assessor (CCA) credential
  • CompTIA Security+ or equivalent security certification
  • Experience supporting a small defense contractor through a C3PAO assessment or DIBCAC review
  • Experience with Microsoft 365 GCC High or Azure Government environments

Benefits

This is a part-time position and is not eligible for health benefits.

COMPENSATION: $30–$40/hour, commensurate with experience

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Workable (global search)'s own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Workable (global search)'s form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Workable (global search)'s answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.