CybersecurityJobs.io
← Back to all jobs

Job Description

The Principal Cybersecurity & Technology Risk Architect (AI/Cloud) is a first-line senior risk position focused on independent, evidence-based risk challenge for enterprise architecture and emerging technology decisions. The role translates technical conditions and incomplete evidence into decision-ready enterprise risk positions while driving scalable improvements to risk remediation and control effectiveness at Fannie Mae.

Role Focus

Provide senior, first-line risk challenge for material architecture, AI (including GenAI and agentic AI), cloud, and engineering decisions. Convert complex technical detail into clear risk positions, actionable decisions, and sustainable remediation outcomes across interconnected environments.

Responsibilities

  • Lead first-line risk analysis and credible challenges for architecture, AI/GenAI, agentic AI, cloud, and engineering decisions, producing enterprise risk positions and decision-ready outcomes.
  • Assess architecture and engineering risk early across security design, trust boundaries, threat scenarios, inherited controls, data flows, identity and privilege, APIs, cloud services, software supply chains, and resilience dependencies.
  • Deliver senior risk challenge for AI systems and emerging AI architectures, including risks tied to model and data integrity, prompt injection, sensitive-data exposure, excessive agency, non-human identities, tool access, third-party models or components, and agentic workflows.
  • Evaluate control design and operating effectiveness using evidence, distinguishing implemented and effective controls from policies, activities, dashboards, or assertions, and identifying where assurance remains insufficient.
  • Create reusable risk scenarios, assessment approaches, and minimum evidence expectations for established and emerging technology patterns to reduce reliance on one-off reviews.
  • Interpret threat modeling and scenario analysis to identify credible failure modes, attack paths, concentration risks, and associated business consequences.
  • Connect technical exposures to enterprise impact, including critical business services, sensitive data, operational resilience, regulatory obligations, and strategic initiatives.
  • Frame decision-ready recommendations for senior management, clearly describing exposure, evidence, uncertainty, alternatives, conditions, accountable owners, and the decision required.
  • Identify systemic and emerging cyber risks by connecting signals from architecture reviews, risk assessments, incidents, issues, exceptions, audit findings, technology change, and industry threat intelligence.
  • Drive accountable remediation and sustainable risk reduction by challenging whether corrective actions address root causes and validating that closure evidence demonstrates meaningful exposure reduction.
  • Partner across Cybersecurity, Technology, Engineering, Data, AI, and Risk while maintaining independence of judgment and clear accountability boundaries.
  • Act as a senior technical risk integrator and mentor by improving the quality of risk reasoning, technical challenge, and executive communication across the broader risk organization.

Requirements

  • 8 years of progressively responsible experience in cybersecurity and security architecture, including cloud security and AI/ML security, plus years of relevant professional experience.
  • Bachelor’s degree or equivalent practical experience in cybersecurity, computer science, engineering, technology, risk, or a related discipline.
  • Proven expertise in enterprise security architecture and modern engineering environments, including cloud architectures, APIs, identity and access patterns, data protection, application or platform security, and software supply-chain risk.
  • Demonstrated experience assessing AI/ML, Generative AI, or emerging technology risk, including model and data security implications, third-party AI services, and risks in increasingly autonomous or agentic systems.
  • Experience conducting threat modeling, architecture risk assessments, control evaluations, and scenario-based risk analysis for complex technology environments.
  • Ability to assess control design and operating effectiveness from technical evidence, differentiating effectiveness from policy compliance or completion of risk-management activities.
  • Capability to translate technical vulnerabilities, architectural weaknesses, and control gaps into business exposure and executive-level risk decisions.
  • Working knowledge of relevant frameworks and practices including NIST CSF, NIST 800-53, NIST AI RMF, NIST SSDF/SP 800 218, ISO 27001, and comparable cybersecurity and AI-risk frameworks.
  • Demonstrated ability to operate with incomplete evidence, articulate assumptions and uncertainty, and reach defensible risk conclusions without false precision.
  • Strong executive writing, synthesis, and presentation skills for communicating technical risk to senior technology, cybersecurity, business, and risk leaders.
  • Ability to provide constructive, credible challenges to senior engineers, architects, and executives while maintaining productive working relationships.
  • Experience operating in a complex, regulated enterprise with first-line ownership, independent risk oversight, and audit or assurance accountability.

Technologies and Tools

  • Active Directory (AD)
  • Amazon Web Services (AWS)
  • Artificial Intelligence (AI)
  • Atlassian JIRA
  • CyberArk
  • NIST CSF
  • NIST 800-53
  • NIST AI RMF
  • NIST SSDF/SP 800 218
  • ISO 27001

Desired Experience

  • Significant experience in financial services, critical infrastructure, or another highly regulated industry, including understanding how cybersecurity, operational resilience, and regulatory expectations intersect.
  • Hands-on or architecture-level experience with public cloud environments and cloud-native security, including shared responsibility models, workload identity, containers/serverless services, APIs, and modern software-delivery pipelines.
  • Experience evaluating GenAI, RAG, AI agents, AI-enabled applications, or ML platforms, including associated identity, data, model, tool-use, supply-chain, and runtime risks.
  • Experience with secure software development and DevSecOps, including software supply-chain controls, CI/CD security, secrets management, dependency risk, and secure-by-design engineering practices.
  • Experience establishing security architecture patterns, risk scenarios, reference controls, or minimum evidence requirements that can be reused across an enterprise.
  • Experience analyzing systemic and emerging risk by connecting multiple findings, exceptions, incidents, or technical conditions into an enterprise-level risk theme and recommended action.
  • Experience developing risk metrics and leading indicators that measure exposure and control effectiveness rather than activity volume.
  • Experience presenting complex technology-risk positions to executive management, governance committees, auditors, and/or regulators.
  • Experience influencing material technology or investment decisions without direct engineering delivery ownership.
  • Experience coaching or mentoring senior cyber-risk or technology professionals; formal people-management experience is beneficial but not required.
  • Certifications such as CISSP, CCSP, CISM, CRISC, SABSA, or relevant cloud/security architecture credentials.
  • Experience working with enterprise GRC platforms and workflows for risk assessments, issues, exceptions, control evidence, risk acceptance, and remediation tracking.

Additional Qualifications

  • Active Directory (AD)
  • Amazon Web Services (AWS)
  • Artificial Intelligence (AI)
  • Atlassian JIRA
  • Authentication Management
  • Backup and Recovery (Software)
  • CyberArk
  • Cybersecurity Analysis
  • Cleaning and Transforming Data
  • Cloud Technology
  • Communicating in Technical Writing
  • Communicating Technical Information
  • Configuration Management (CM)
  • Coordination
  • Conflict Resolution
  • Data Analysis
  • Data Analysis Interpretation {+ 60 more}

Location and Work Type

  • Location: Plano, TX
  • Work arrangement: Onsite
  • Employment type: Full-time

Compensation

  • Salary range: USD 175,000 - 239,000 per year
  • Requisition compensation: 175000 to 239000

Benefits

Health, Life, Voluntary Lifestyle, and other benefits and perks that enhance an employee’s physical, mental, emotional, and financial well-being.

Similar Jobs