Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
Scoutfield Logo

See all jobs on Scoutfield

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
Fannie Mae

Principal Cybersecurity & Technology Risk Architect – AI/Cloud

Fannie Mae

. Serve as a senior technical risk authority for Enterprise Architecture, AI, Cloud, and Engineering .

Posted 10/6/2026full-timeUnited StatesLead💰 $175,000 - $239,000 per yearWebsite

Core Competencies

Role fit
Core Competencies

Use this summary to align your resume positioning with the role.

Demonstrates expertise in enterprise security architecture, risk assessment, and cybersecurity, with a strong focus on AI/ML security and cloud security. Capable of translating technical vulnerabilities into business risks and providing strategic recommendations to senior management.

Highest-signal resume keywords
Enterprise Security Architecture ExpertiseAI/ML Security Risk AssessmentThreat Modeling and Scenario AnalysisNIST CSF and ISO 27001 KnowledgeExecutive Writing and Presentation Skills

ATS Keywords

Tailor your resume
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills
CybersecuritySecurity ArchitectureCloud SecurityAI/ML SecurityRisk AssessmentControl EvaluationThreat ModelingData ProtectionApplication SecuritySoftware Supply-Chain Risk
Soft Skills
Constructive ChallengeSynthesisPresentation SkillsMentoringCollaboration
Tools & Technologies
Enterprise GRC PlatformsCloud ServicesAPIsDevSecOpsGenAIAI AgentsAI-Enabled ApplicationsRisk Metrics Development
Certifications & Qualifications
CISSPCCSPCISMCRISCSABSA
Industry Keywords
Financial ServicesCritical InfrastructureRegulated EnterpriseCyber RiskEmerging Technology Risk

Tech Stack

Tools & technologies
CloudCyber Security

About the role

Key responsibilities & impact
  • Serve as a senior technical risk authority for Enterprise Architecture, AI, Cloud, and Engineering
  • Provide independent, evidence-based first-line risk challenge on consequential technology decisions
  • Partner with Cybersecurity, Technology, Architecture, Engineering, Data, AI, and Risk stakeholders
  • Translate technical conditions, emerging threats, and incomplete evidence into clear enterprise risk positions
  • Evaluate architecture and engineering patterns, security assumptions, control dependencies, systemic risks, and emerging risks
  • Lead risk analysis for architecture, AI/GenAI, agentic AI, cloud, and engineering decisions
  • Assess security design, trust boundaries, threat scenarios, inherited controls, data flows, identity, privilege, APIs, cloud services, software supply chains, and resilience dependencies
  • Evaluate AI-system risks including model and data integrity, prompt injection, sensitive-data exposure, excessive agency, non-human identities, tool access, third-party models/components, and agentic workflows
  • Evaluate control design and effectiveness using technical evidence
  • Develop reusable risk scenarios, assessment approaches, and minimum evidence expectations
  • Interpret threat modeling and scenario analysis to identify failure modes, attack paths, concentration risks, and business consequences
  • Connect technical exposures to critical business services, sensitive data, operational resilience, regulatory obligations, and strategic initiatives
  • Frame decision-ready recommendations for senior management
  • Identify systemic and emerging cyber risks across reviews, assessments, incidents, issues, exceptions, audit findings, technology change, and threat intelligence
  • Drive accountable remediation and validate closure evidence
  • Serve as a senior technical risk integrator and mentor across the broader risk organization

Requirements

What you’ll need
  • 8 years of progressively responsible experience in cybersecurity, security architecture, cloud security, AI/ML security, or related professional experience
  • Bachelor's degree or equivalent practical experience in cybersecurity, computer science, engineering, technology, risk, or a related discipline
  • Enterprise security architecture expertise, including cloud architectures, APIs, identity and access patterns, data protection, application/platform security, and software supply-chain risk
  • Experience assessing AI/ML, Generative AI, or emerging technology risk
  • Experience conducting threat modeling, architecture risk assessments, control evaluations, and scenario-based risk analysis
  • Ability to assess control design and operating effectiveness from technical evidence
  • Experience translating technical vulnerabilities, architectural weaknesses, and control gaps into business exposure and executive-level risk decisions
  • Working knowledge of NIST CSF, NIST 800-53, NIST AI RMF, NIST SSDF/SP 800-218, ISO 27001, and comparable frameworks
  • Ability to operate effectively with incomplete evidence and articulate assumptions and uncertainty
  • Strong executive writing, synthesis, and presentation skills
  • Ability to provide constructive challenges to senior engineers, architects, and executives
  • Experience in a complex, regulated enterprise
  • Desired: Experience in financial services, critical infrastructure, or another highly regulated industry
  • Desired: Public cloud and cloud-native security experience
  • Desired: GenAI, RAG, AI agents, AI-enabled applications, or ML platform experience
  • Desired: Secure software development and DevSecOps experience
  • Desired: Experience establishing reusable security architecture patterns, risk scenarios, reference controls, or minimum evidence requirements
  • Desired: Experience analyzing systemic and emerging risk
  • Desired: Experience developing risk metrics and leading indicators
  • Desired: Experience presenting technology-risk positions to executives, governance committees, auditors, or regulators
  • Desired: Experience influencing material technology or investment decisions
  • Desired: Experience coaching or mentoring senior cyber-risk or technology professionals
  • Desired: Certifications such as CISSP, CCSP, CISM, CRISC, SABSA, or relevant cloud/security architecture credentials
  • Desired: Experience with enterprise GRC platforms and workflows

Benefits

Comp & perks
  • Incentive program eligibility
  • Health benefits
  • Life benefits
  • Voluntary Lifestyle benefits
  • Other benefits and perks supporting physical, mental, emotional, and financial well-being
  • Flexible work arrangement (Flex)