Regulatory Cybersecurity Specialist
This position is being filled under a stream-lined hiring authority, Title 21 of the United States Code (21 US Code 379d-3a) as amended by the 21st Century Cures Act of 2016, section 3072 and the Consolidated Appropriations Act of 2023, Section 3624. The candidate selected for this position will serve under a career or career-conditional appointment and be paid under the provisions of this authority. This position is being recruited based on the Title 21 Pay Table 2, Band D.
Develops and implements cybersecurity legislation, policies, guidance documents, and white papers to establish and advance cybersecurity requirements for medical devices. Ensures requirements address key areas including risk management, secure architectures, security controls, secure update mechanisms, software bill of materials (SBOM), coordinated vulnerability disclosure (CVD) and other controls as identified. Supports the development and implementation of a cybersecurity strategic plan and roadmap. Incorporates lessons learned and continuously re-evaluates cybersecurity policy to ensure the Center's frameworks evolve in response to emerging cybersecurity challenges. Reviews, analyzes, and assesses proposed initiatives, agreements, and legislation from other organizations and governments to determine the feasibility of FDA participation and identify potential conflicts with FDA's regulatory mandates. Provides expert recommendations on the impact of external proposals on FDA's cybersecurity program. Provides routine cybersecurity incident and vulnerability response Provides expert consultation and recommendations of cybersecurity implementation to premarket submissions as needed Active in industry discussions and working groups to support cybersecurity of medical devices Other duties as assigned