Principal Cybersecurity & Technology Risk Architect - AI/Cloud
Job Description
Fannie Mae is seeking a Principal Cybersecurity & Technology Risk Architect - AI/Cloud to act as a first-line senior technical risk authority for enterprise architecture and AI and cloud engineering decisions. In this role, you will provide independent, evidence-based risk challenge, translate technical conditions into decision-ready risk positions, and help drive reusable risk patterns and sustainable remediation across critical technology domains.
Role Responsibilities
- Lead first-line risk analysis and credible technical challenges for material architecture, AI/GenAI, agentic AI, and cloud and engineering decisions, converting technical complexity into clear enterprise risk positions and actionable outcomes.
- Assess architecture and engineering risks early across security design, trust boundaries, threat scenarios, inherited controls, data flows, identity and privilege, APIs, cloud services, software supply chain risks, and resilience dependencies.
- Provide senior risk challenge for AI systems and emerging AI architectures, including risks related to model and data integrity, prompt injection, sensitive data exposure, excessive agency, non-human identities, tool access, third-party models or components, and agentic workflows.
- Evaluate control design and operating effectiveness using evidence, distinguishing implemented and effective controls from policies, activities, dashboards, or assertions, and flagging where evidence or assurance is insufficient.
- Create reusable risk scenarios, assessment approaches, and minimum evidence expectations for established and emerging technology patterns to reduce reliance on one-off reviews and enable consistent risk decisions at scale.
- Interpret threat modeling and scenario analysis to identify credible failure modes, attack paths, concentration risks, and business consequences across interconnected technology environments.
- Link technical exposures to enterprise impact, including critical business services, sensitive data, operational resilience, regulatory obligations, and strategic initiatives.
- Formulate decision-ready recommendations for senior management by articulating exposure, evidence, uncertainty, alternatives, conditions, accountable owners, and the specific decision required.
- Identify systemic and emerging cyber risks by connecting signals across architecture reviews, risk assessments, incidents, issues, exceptions, audit findings, technology change, and industry threat intelligence.
- Drive accountable remediation and sustainable risk reduction, challenging whether corrective actions address root causes and validating that closure evidence demonstrates meaningful reduction in exposure.
- Partner across Cybersecurity, Technology, Engineering, Data, AI, and Risk while maintaining independence of judgment and clear accountability boundaries.
- Serve as a senior technical risk integrator and mentor, improving the quality of risk reasoning, technical challenge, and executive communication across the broader risk organization.
Required Qualifications
- 8 years of progressively responsible experience in cybersecurity, security architecture, cloud security, AI/ML security, and related professional experience.
- Bachelor’s degree (or equivalent practical experience) in cybersecurity, computer science, engineering, technology, risk, or a related discipline.
- Demonstrated expertise in enterprise security architecture and modern engineering environments, including cloud architectures, APIs, identity and access patterns, data protection, application/platform security, and software supply-chain risk.
- Demonstrated experience assessing AI/ML, Generative AI, or emerging technology risk, including security implications of models, data, AI applications, third-party AI services, and autonomous or agentic systems.
- Experience conducting threat modeling, architecture risk assessments, control evaluations, and scenario-based risk analysis for complex technology environments.
- Demonstrated ability to assess control design and operating effectiveness from technical evidence, distinguishing effectiveness from policy compliance or completion of risk-management activities.
- Ability to translate technical vulnerabilities, architectural weaknesses, and control gaps into business exposure and executive-level risk decisions.
- Working knowledge of relevant frameworks and practices, including NIST CSF, NIST 800-53, NIST AI RMF, NIST SSDF/SP 800-218, ISO 27001, and comparable cybersecurity and AI-risk frameworks.
- Demonstrated ability to operate effectively when evidence is incomplete by articulating assumptions and uncertainty and reaching defensible conclusions without false precision.
- Strong executive writing, synthesis, and presentation skills to communicate technical risk to senior technology, cybersecurity, business, and risk leaders.
- Ability to provide constructive, credible challenges to senior engineers, architects, and executives while maintaining productive working relationships and supporting business mission.
- Experience working within a complex, regulated enterprise with first-line ownership, independent risk oversight, and audit or assurance accountability.
Technologies and Frameworks
- NIST CSF
- NIST 800-53
- NIST AI RMF
- NIST SSDF/SP 800-218
- ISO 27001
Location and Employment Details
- Location: Plano, TX (onsite)
- Employment Type: Full-time
Compensation
- Target Salary Range: USD 175,000 - 239,000 per year
- Requisition Compensation: 175,000 to 239,000
Education
- Bachelor’s Level Degree (Required)
- Master’s Level Degree
Similar Jobs
J
J