Skip to content

Open nowPosted today

Principal Cybersecurity & Technology Risk Architect - AI/Cloud

Fannie Mae21 open roles

Where
Plano TX
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowPrincipal Cybersecurity & Technology Risk Architect - AI/CloudFannie Mae · Plano TX
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Fannie Mae's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

8.1% of postings close within 7 days. Measured by our own scanner across the market. Fannie Mae postings stay open a median of 4 days.

Share of postings closed within
  1. 1.7%1 day
  2. 3.6%3 days
  3. 8.1%7 days
  4. 15.1%14 days
  5. 34.0%30 days
This job: posted today

Fannie Mae median: 4 days open

The posting

Playing an essential role in the U.S. economy, Fannie Mae is foundational to housing finance. Here, your expertise can help fuel purpose-driven innovation that expands access to homeownership and affordable rental housing across the country. Join Fannie Mae to grow your career and help people find a place to call home.

Job Description

In this first-line risk role, you will serve as a senior technical risk authority for Enterprise Architecture, Artificial Intelligence (AI), Cloud and Engineering, providing independent, evidence-based risk challenge on the enterprise's most consequential technology decisions.

You will partner with senior leaders and practitioners across Cybersecurity, Technology, Architecture, Engineering, Data, AI and Risk to identify and evaluate material cyber and technology risks before they are designed into the environment. You will translate complex technical conditions, emerging threats and incomplete evidence into clear risk positions that articulate the exposure, affected business capabilities, control effectiveness, uncertainty, accountable ownership and decisions required.

The role requires deep technical credibility combined with enterprise risk judgment. You will evaluate architecture and engineering patterns, challenge security assumptions and control dependencies, identify systemic and emerging risks, and help leaders determine whether to proceed, proceed with conditions, redesign, remediate or formally accept risk.

As a Principal, you will also serve as a senior integrator when risk crosses domains such as AI, cloud, identity, data, application security, cyber defense, resilience and third-party technology. You will help convert recurring exceptions and individual findings into reusable risk patterns, scalable control expectations, and enterprise-level actions.

The Way You Will Make a Difference

This Principal role will offer you the flexibility to make each day your own while working alongside people who care, so that you can deliver on the following responsibilities:

  • Lead first-line risk analysis and credible challenges for material architecture, AI/GenAI, agentic AI, cloud and engineering decisions, translating technical complexity into clear enterprise risk positions and actionable decisions.
  • Assess architecture and engineering risk early in the lifecycle, including security design, trust boundaries, threat scenarios, inherited controls, data flows, identity and privilege, APIs, cloud services, software supply chains and resilience dependencies.
  • Provide senior risk challenge for AI systems and emerging AI architectures, including risks associated with model and data integrity, prompt injection, sensitive-data exposure, excessive agency, non-human identities, tool access, third-party models/components and agentic workflows.
  • Evaluate control design and effectiveness using evidence, distinguishing implemented and effective controls from policies, activities, dashboards or assertions, and identifying where evidence or assurance remains insufficient.
  • Develop reusable risk scenarios, assessment approaches and minimum evidence expectations for established and emerging technology patterns, reducing reliance on one-off reviews and enabling consistent risk decisions at scale.
  • Interpret threat modeling and scenario analysis to identify credible failure modes, attack paths, concentration risks and business consequences across interconnected technology environments.
  • Connect technical exposures to enterprise impact, including critical business services, sensitive data, operational resilience, regulatory obligations and strategic initiatives.
  • Frame decision-ready recommendations for senior management, clearly articulating exposure, evidence, uncertainty, alternatives, conditions, accountable owners and the decision required.
  • Identify systemic and emerging cyber risks by connecting signals across architecture reviews, risk assessments, incidents, issues, exceptions, audit findings, technology change and industry threat intelligence.
  • Drive accountable remediation and sustainable risk reduction, challenging whether proposed corrective actions address root causes and validating that closure evidence demonstrates meaningful reduction in exposure.
  • Partner across Cybersecurity, Technology, Engineering, Data, AI and Risk while maintaining independence of judgment and clear accountability boundaries.
  • Serve as a senior technical risk integrator and mentor, raising the quality of risk reasoning, technical challenge and executive communication across the broader risk organization.

THE EXPERIENCE YOU BRING TO THE TEAM

Minimum Required Qualifications

  • 8 years of progressively responsible experience in cybersecurity, security architecture, cloud security, AI/ML security, years of relevant professional experience.
  • Bachelor's degree or equivalent practical experience in cybersecurity, computer science, engineering, technology, risk or a related discipline.
  • Demonstrated expertise in enterprise security architecture and modern engineering environments, including cloud architectures, APIs, identity and access patterns, data protection, application/platform security and software supply-chain risk.
  • Demonstrated experience assessing AI/ML, Generative AI or emerging technology risk, including the security implications of models, data, AI applications, third-party AI services and increasingly autonomous/agentic systems.
  • Experience conducting threat modeling, architecture risk assessments, control evaluations and scenario-based risk analysis for complex technology environments.
  • Demonstrated ability to assess control design and operating effectiveness from technical evidence and distinguish control effectiveness from policy compliance or completion of risk-management activities.
  • Experience translating complex technical vulnerabilities, architectural weaknesses and control gaps into business exposure and executive-level risk decisions.
  • Working knowledge of relevant frameworks and practices such as NIST CSF, NIST 800-53, NIST AI RMF, NIST SSDF/SP 800 218, ISO 27001 and comparable cybersecurity and AI-risk frameworks.
  • Demonstrated ability to operate effectively where evidence is incomplete, articulate assumptions and uncertainty, and reach defensible risk conclusions without false precision.
  • Strong executive writing, synthesis and presentation skills, including the ability to communicate technical risk clearly to senior technology, cybersecurity, business and risk leaders.
  • Demonstrated ability to provide constructive, credible challenges to senior engineers, architects and executives while maintaining productive working relationships and enabling business mission.
  • Experience operating within a complex, regulated enterprise and navigating first-line ownership, independent risk oversight and audit/assurance accountability.

Desired Experience

  • Significant experience in financial services, critical infrastructure or another highly regulated industry, with an understanding of how cybersecurity, operational resilience and regulatory expectations intersect.
  • Hands-on or architecture-level experience with public cloud environments and cloud-native security, including shared responsibility models, workload identity, containers/serverless services, APIs and modern software-delivery pipelines.
  • Experience evaluating GenAI, RAG, AI agents, AI-enabled applications or ML platforms, including associated identity, data, model, tool-use, supply-chain and runtime risks.
  • Experience with secure software development and DevSecOps, including software supply-chain controls, CI/CD security, secrets management, dependency risk and secure-by-design engineering practices. ▪
  • Experience establishing security architecture patterns, risk scenarios, reference controls or minimum evidence requirements that can be reused across an enterprise.
  • Experience analyzing systemic and emerging risk, connecting multiple findings, exceptions, incidents or technical conditions into an enterprise-level risk theme and recommended action.
  • Experience developing risk metrics and leading indicators that measure exposure and control effectiveness rather than activity volume.
  • Experience presenting complex technology-risk positions to executive management, governance committees, auditors and/or regulators. ▪
  • Experience influencing material technology or investment decisions without direct ownership of engineering delivery.
  • Experience coaching or mentoring senior cyber-risk or technology professionals; formal people-management experience is beneficial but not required. ▪
  • Certifications such as CISSP, CCSP, CISM, CRISC, SABSA or relevant cloud/security architecture credentials. ▪
  • Experience working with enterprise GRC platforms and workflows for risk assessments, issues, exceptions, control evidence, risk acceptance and remediation tracking.

Target Salary Range: $175,000 to $239,000

Technology Risk - Risk Management - Principal

#LI-Hybrid

#LI-SB1

Qualifications

Education:

Bachelor's Level Degree (Required), Master's Level Degree

The future is what you make it to be. Discover compelling opportunities at Fanniemae.com/careers.

For most roles, employees are expected to work onsite on a regular basis at their designated office location. In-office work cadence is determined by your manager. Proximity within a reasonable commute to your designated office location is preferred unless the job is noted as open to remote.

Fannie Mae is an equal opportunity employer and considers qualified applicants for employment without regard to race, color, religion, sex, national origin, disability, age, sexual orientation, gender identity/gender expression, marital or parental status, or any other protected factor. Fannie Mae is committed to providing reasonable accommodations to qualified individuals with disabilities who are employees or applicants for employment, unless to do so would cause undue hardship to the company. If you need assistance using our online system and/or you need a reasonable accommodation related to the hiring/application process, please complete this form.

The hiring range for this role is set forth below. Final salaries will generally vary within that range based on factors that include but are not limited to, skill set, depth of experience, certifications, and other relevant qualifications. This position is eligible to participate in a Fannie Mae incentive program (subject to the terms of the program). As part of our comprehensive benefits package, Fannie Mae offers a broad range of Health, Life, Voluntary Lifestyle, and other benefits and perks that enhance an employee's physical, mental, emotional, and financial well-being. See more here.

Requisition compensation:

175000

to

239000

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Fannie Mae's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Fannie Mae's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Fannie Mae's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.