Regulatory Affairs Technical Writer (Medical Device Cybersecurity)
Turn complex medical device, regulatory, and cybersecurity material into clear, structured, submission-ready documentation for 510(k) and other premarket submissions.
- Reports to
- VP, Regulatory Affairs & Compliance
- Status
- Full-time employee
- Location
- Remote (United States), minimal travel
- Compensation
- Competitive, commensurate with experience, paid every two weeks, plus benefits including health, dental, vision, 401(k), and an educational allowance
- Equipment
- Bring your own laptop and setup, and we cover the project-specific hardware and lab gear the work needs
About the role
Blue Goat Cyber is expanding, and we are looking for a Regulatory Affairs Technical Writer who can turn complex medical device, regulatory, and cybersecurity information into clear, structured, submission-ready documentation. This role supports medical device manufacturers by drafting and coordinating cybersecurity documentation for 510(k) and other premarket submissions, while keeping architecture, risk, controls, testing evidence, and regulatory expectations aligned.
This role is ideal for someone who understands medical devices and regulatory affairs, writes exceptionally well, learns quickly, and can confidently work with clients and internal technical teams. You will work from Blue Goat Cyber templates and methodology, review client source material, identify gaps early, and produce accurate documentation aligned with current FDA guidance.
This is a full-time employee role requiring strong written and verbal communication, independent ownership, attention to detail, and the ability to manage multiple documents and client projects at once. You must be available for weekly internal meetings and client meetings as scheduled.
You are a fit if
You excel in execution and ownership
- You own your work, close loops, provide status without being chased, and flag delays before they become a problem.
- You work quickly and efficiently while maintaining quality across multiple documents and client projects.
- You ask sharp questions early and move work forward without needing the entire picture before starting.
- You manage your own workload and stay ahead of it rather than reacting to it.
You produce accurate, submission-ready work
- You are a strong writer who produces clean, structured, technically accurate prose that needs light editing, not a rewrite.
- You self-review grammar, structure, formatting, traceability, and internal consistency.
- You can pull what you need from architecture views, data flow diagrams, user manuals, design documents, SBOM outputs, and test reports.
- You follow established templates and methodology and raise improvement ideas through the right channel.
You communicate like a professional
- You answer client questions live with clarity and confidence, without rambling or guessing.
- You raise concerns in a way that lands well: flag the issue, recommend a path forward, and keep the work moving.
- You communicate proactively with clients and internal teams and do not go quiet when stuck.
- You take edits well and apply feedback to future work without needing the same correction twice.
You think flexibly and learn quickly
- You can be walked through a template, methodology, or piece of FDA guidance and then run with it.
- You stay within the defined cybersecurity scope and check before expanding the work.
- You are curious and willing to learn whichever side of the work, cybersecurity or regulatory affairs, is less familiar to you.
- You identify gaps, contradictions, and missing details early and bring solutions or focused questions forward.
You thrive in collaborative, remote-first work
- You work well with project managers, regulatory leads, penetration testers, and distributed client teams.
- You are reliable on dates, responsive, and transparent about blockers or timeline risk.
- You are willing to help teammates and share what you learn.
- You work independently in a remote environment while staying aligned with the team.
What you will own
Regulatory documentation and writing
- Draft cybersecurity sections of 510(k) and other premarket submissions for client medical device manufacturers.
- Produce threat models, cybersecurity risk assessments, security architecture views, SBOM and third-party component documentation, unresolved anomaly assessments, cybersecurity management plans, and security labeling content.
- Work from Blue Goat Cyber templates and methodology so output is consistent across clients and reviewers.
- Maintain traceability across the documentation set so architecture, risk, controls, and testing evidence align.
Source material review and analysis
- Review architecture views, data flow diagrams, user manuals, design documents, SBOM exports, and test reports and extract what the submission needs.
- Identify gaps, contradictions, and missing details early and build a focused list of client questions.
- Apply FDA cybersecurity guidance and Blue Goat Cyber methodology consistently, including risk scoring and acceptability calls.
- Understand the boundary of the cybersecurity scope and remain within it unless there is a reason to raise it.
Client communication and collaboration
- Attend kickoff calls, working sessions, and debriefs and answer client questions with confidence and clarity.
- Communicate proactively with clients and internal teams through Slack, email, and Asana.
- Flag concerns, risks, and gaps constructively and provide a recommendation.
- Follow up on outstanding information so projects do not stall.
- Partner with penetration testers, regulatory leads, and project managers so documentation and testing evidence remain aligned.
Project execution and quality
- Carry multiple documents and client projects simultaneously and meet committed dates.
- Keep Asana current so project status is visible without anyone having to ask.
- Raise blockers and timeline risks early with a suggested solution.
- Self-review all work for grammar, structure, formatting, technical accuracy, and internal consistency before handoff.
- Stay current on FDA cybersecurity guidance and relevant standards as they change.
Required skills and experience
- Experience in the medical device industry, or education in regulatory affairs or cybersecurity if medical device industry experience is not present.
- Strong written communication; clear, organized, technically accurate writing is core to this role.
- Strong verbal communication and professional presence on client calls.
- Fast learner with the aptitude to pick up new regulatory and technical material quickly and apply it.
- Comfort working at pace with a high volume of documents and multiple client projects.
- Ability to work independently in a remote, distributed team.
Preferred experience
- Regulatory affairs education or credential such as RAC, plus hands-on submission experience.
- Familiarity with FDA cybersecurity guidance, ISO 13485, ISO 14971, IEC 62304, IEC 81001-5-1, and AAMI TIR57 or ANSI/AAMI SW96.
- Prior exposure to 510(k), De Novo, or PMA submissions.
- Software or cybersecurity background.
- Medical device project or product management experience combined with a genuine interest in regulatory writing.
Your first 90 days
What success looks like early on, so you know what you are walking into.
- 1
First 30 days
- Work through our templates, methodology, and risk scoring approach with the regulatory lead.
- Shadow two live client projects and draft supporting sections under review.
- Read the current FDA premarket cybersecurity guidance and our internal mapping of it to each deliverable.
- 2
Days 30 to 60
- Own the cybersecurity documentation for your first client project end to end, with review before delivery.
- Run your own source material review and build the client question list without prompting.
- Join client working sessions and answer scope questions directly.
- 3
Days 60 to 90
- Carry a steady portfolio of concurrent documentation projects and hit committed dates.
- Deliver drafts that need editing, not rewriting, and keep traceability clean across the set.
- Bring at least one template or process improvement forward from what you saw in practice.
Tools we use
- Google Workspace
- Microsoft Word and Excel
- Slack
- Asana
- FDA guidance documents and recognized consensus standards
- FIRST.org CVSS calculator
- SBOM outputs from tools such as FOSSA and Snyk
- Penetration test reports and supporting evidence
About Blue Goat Cyber
Blue Goat Cyber is a medical device cybersecurity company dedicated to protecting patient lives by securing the technologies that power modern healthcare. We support medical device manufacturers as they build, test, and launch secure devices that meet FDA expectations and operate safely in the real world.
We are a remote, high-trust, high-ownership team that values clear communication, rigorous thinking, proactive problem solving, continuous learning, and attention to critical details. We expect every team member to own their work, communicate clearly, and support the mission without ego.
Before you apply
The terms every person here works under. Read them now rather than at offer stage, along with our core values and the honest list of who this is not for.
Work authorization
- You must be authorized to work in the United States. We do not sponsor visas for these roles.
- All roles are performed from within the United States.
Confidentiality and NDA
- You will sign a mutual nondisclosure agreement before you see any client material, and client-specific NDAs where a client requires one.
- You will see unreleased device designs, firmware, source code, vulnerabilities, and submission content. None of it is yours to discuss, publish, screenshot, or reference, during or after the engagement.
- Client material stays in company systems. No personal cloud storage, personal email, personal repositories, or unvetted AI tools.
- Anything we publish that draws on client work is anonymized and cleared with the client first.
How we expect you to use AI
- Use AI every day if it helps, on the company ChatGPT and Claude accounts we provide, and keep client material inside them: firmware, source code, submission documents, findings, and client names never go anywhere else.
- You own the accuracy of anything you send out, because models get recognition numbers, clause references, and test conclusions wrong in ways that read perfectly well. The full policy is in the careers FAQ.
Security and background
- Offers are contingent on a background check and on reference checks.
- You will use company-required security controls on any device that touches client data, including full-disk encryption, screen lock, and our password manager and multi-factor authentication.
- Report a suspected compromise or data exposure immediately. We treat honest, fast reporting as the right behavior, not a fault.
- Some client engagements require additional screening or training before you can be assigned.
Equal opportunity
- Blue Goat Cyber is an equal opportunity employer. We do not discriminate on the basis of race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, veteran status, or any other protected characteristic.
- If you need an accommodation at any point in the hiring process, tell us and we will arrange it.
Apply
Send your resume, any links to your work, and a short note about why this role fits. It takes a few minutes and a real person on our team reads every application.
If you do not hear back within two weeks, we have decided not to move forward for now. We keep applications on file for future openings.
