Jobs › Regulatory Cybersecurity Specialist
Regulatory Cybersecurity Specialist
Job at a glance
- Category
- GRC
- Work arrangement
- On-site
- Location
- Silver Spring, Maryland
- Salary range
- $143,913 to $226,144
- Posted
- Aug 23, 2026
Food and Drug Administration is hiring a Regulatory Cybersecurity Specialist in Silver Spring, Maryland. This is a GRC job in the governance, risk, and compliance field, with a posted range of $143,913 to $226,144. Review the full details below and apply directly with Food and Drug Administration.
This position is being filled under a stream-lined hiring authority, Title 21 of the United States Code (21 US Code 379d-3a) as amended by the 21st Century Cures Act of 2016, section 3072 and the Consolidated Appropriations Act of 2023, Section 3624. The candidate selected for this position will serve under a career or career-conditional appointment and be paid under the provisions of this authority. This position is being recruited based on the Title 21 Pay Table 2, Band D. Qualifications: In order to qualify for the Regulatory Cybersecurity Specialist position which falls under the 0301 occupational Series, you must meet the following requirements by 11:59 pm EST on 09/01/2026: Basic Qualification Requirements: Education: A bachelor's degree or higher in a science, technology, engineering, mathematics, computer science, statistics, or software engineering. The degree must be from an accredited program or institution. OR Experience: Comparable work in digital health policy, digital health technology support, digital health training, medical device cybersecurity, artificial intelligence/machine learning, regulatory science advancement, regulatory review support and coordination, advanced manufacturing, real world evidence and advanced clinical studies, regulatory innovation, or digital health strategic partnership Minimum Qualifications: Comparable experience is experience that equipped the applicant with the knowledge, skills, and abilities to perform successfully the duties of the position, and that is typically in or related to the work of the position to be filled. The relevant experience must demonstrate one year of full-time work experience, or the equivalent if part-time (for example, an employee working 20 hours per week for a 12-month period should be credited with 6 months of experience). Experience may have been obtained in either the federal service or its equivalent with state or local government, the private sector, or nongovernmental organizations. IN ADDITION TO MEETING THE BASIC REQUIREMENTS OUTLINED ABOVE, APPLICANTS MUST ALSO MEET ONE OF THE FOLLOWING MINIMUM YEARS OF EXPERIENCE REQUIREMENTS. Have a bachelor's degree and 5 years of comparable experience demonstrating understanding in cybersecurity vulnerability analysis, operational technology, information technology, information management, or a related field. OR Have a master's degree and 4 years of comparable experience demonstrating understanding in cybersecurity vulnerability
Full responsibilities and requirements are on Food and Drug Administration's application page.
Apply for this job →Location and market context
This job is based in Silver Spring, Maryland on-site. Local candidates benefit from being close to Food and Drug Administration's teams and regional hiring market. Confirm the exact in-office expectation and any relocation support with the employer.
About cybersecurity governance jobs
Cybersecurity governance connects security control frameworks to business and regulatory risk, covering policy, risk assessment, and control assurance rather than hands-on operations. Jobs like this one are typically evaluated against frameworks such as NIST CSF, ISO/IEC 27001, SOC 2, and security risk and control-assurance practices.
How to position yourself for this cybersecurity governance job
Strong candidates emphasize security control frameworks, risk assessment, policy and standards, and translating technical security posture into governance and board-level reporting. In your resume and outreach, tie your experience to how Food and Drug Administration would apply NIST CSF, ISO/IEC 27001, SOC 2, and security risk and control-assurance practices, and lead with concrete outcomes rather than duties.
Similar GRC jobs
More GRC jobs: All GRC jobs · Search by category & location