LogoKode$word
Fannie Mae logo
Verified Tech Organization

Careers at Fannie Mae

Browse and filter through all verified positions currently open at Fannie Mae.

Total Company Roles9
Matching Filter9
fanniemae.comHQ: Washington, District of Columbia, United States

Fannie Mae serves the people who house America. We are a leading source of financing for mortgage lenders, providing access to affordable mortgage financing in all markets at all times. Our financing makes sustainable homeownership and workforce rental housing a reality for millions of Americans. We also help make possible the popular 30-year, fixed-rate mortgage, which provides homeowners with stable, predictable mortgage payments over the life of the loan. Our tools and resources help homebuyers, homeowners, and renters understand their housing options. We put our customers and partners at the center of everything we do. We apply our experience and expertise to deliver innovative solutions to help our customers succeed. At Fannie Mae, our people pour their hearts into everything they do. Because we know it makes a real difference in others' lives. We are committed to moving forward with our partners to build a stronger, safer, more efficient housing finance system. Join us at the heart of housing:

Sector:creditfinancefinancial servicesmortgageprocessing

All Openings (9)

Ordered by most recently published

Senior Sourcing Specialist - Software and SaaS

On-sitefull timeSeniorTexas, United States
Apply Now

Playing an essential role in the U.S. economy, Fannie Mae is foundational to housing finance. Here, your expertise can help fuel purpose-driven innovation that expands access to homeownership and affordable rental housing across the country. Join Fannie Mae to grow your career and help people find a place to call home. Job Description As a valued colleague on our Corporate Procurement team, you will lead and execute sourcing and contracting activities for software, SaaS, cloud-based applications, enterprise licenses, subscription renewals, and related technology services. In this role, you will partner with internal and stakeholders to define sourcing strategies, manage RFx events, negotiate supplier agreements, and support contract execution in accordance with Fannie Mae's strategic sourcing process. This role is focused on delivering value, reducing risk, and improving commercial outcomes across the software and SaaS supplier portfolio while supporting timely, compliant, and business-aligned contracting. THE IMPACT YOU WILL MAKE The Senior Sourcing Specialist – Software and SaaS role will offer you the flexibility to make each day your own while working alongside people who care so that you can deliver on the following responsibilities: Lead sourcing and contracting activities for software, SaaS, cloud-based applications, enterprise licenses, subscription renewals, and related technology services. Partner with stakeholders to gather business, technical, commercial, risk, and contracting requirements. Manage RFx events, supplier communications, proposal evaluations, negotiation strategies, and sourcing recommendations. Negotiate commercial and contractual terms with suppliers, working in partnership with business and legal counterparts. Analyze supplier proposals, software usage, spend, renewal history, market benchmarks, and business demand to identify savings, cost avoidance, risk reduction, and value creation opportunities. Prepare sourcing documentation, award recommendations, negotiation summaries, and stakeholder updates. Adapt sourcing strategies based on business priorities, market conditions, risk considerations, and timeline requirements. Apply procurement tools, contract systems, spend data, and emerging technologies, including artificial intelligence, to improve sourcing quality, efficiency, and decision-making. THE EXPERIENCE YOU BRING TO THE TEAM Minimum Required Experiences 2 years of experience in a Corporate Procurement function, preferably at a large for profit commercial company, or with a consulting / advisory firm. Experience sourcing or negotiating software, SaaS, cloud-based applications, enterprise licenses, or technology supplier agreements. Experience managing RFx events, supplier negotiations, sourcing recommendations, and contract execution processes. Working knowledge of software and SaaS commercial models, including subscription pricing, user-based licensing, enterprise agreements, usage-based pricing, renewal terms, and support models. Strong analytical, negotiation, communication, stakeholder management, and problem-solving skills. Shows curiosity and adaptability in learning and responsibly applying new technologies, including artificial intelligence, to reimagine how we work. Desired Experiences Bachelor's degree or equivalent experience. 5+ years of experience in software/SaaS sourcing, IT procurement, technology category management, supplier management, contract management, or contract negotiation. Experience negotiating SaaS order forms, master agreements, statements of work, service level agreements, data processing agreements, software license agreements, cloud terms, and renewal amendments. Experience in a regulated financial services, housing finance, banking, or similarly complex enterprise environment. Familiarity with third-party risk management, cybersecurity, privacy, business continuity, accessibility, supplier due diligence, and software asset management. Experience using procurement, sourcing, contract lifecycle management, spend analytics, supplier management, or ERP platforms. Corporate Procurement – Sourcing and Contracting – Senior Associate #LI-Hybrid Qualifications Education: Bachelor's Level Degree The future is what you make it to be. Discover compelling opportunities at Fanniemae.com/careers. For most roles, employees are expected to work onsite on a regular basis at their designated office location. In-office work cadence is determined by your manager. Proximity within a reasonable commute to your designated office location is preferred unless the job is noted as open to remote. Fannie Mae is an equal opportunity employer and considers qualified applicants for employment without regard to race, color, religion, sex, national origin, disability, age, sexual orientation, gender identity/gender expression, marital or parental status, or any other protected factor. Fannie Mae is committed to providing reasonable accommodations to qualified individuals with disabilities who are employees or applicants for employment, unless to do so would cause undue hardship to the company. If you need assistance using our online system and/or you need a reasonable accommodation related to the hiring/application process, please complete this form . The hiring range for this role is set forth below. Final salaries will generally vary within that range based on factors that include but are not limited to, skill set, depth of experience, certifications, and other relevant qualifications. This position is eligible to participate in a Fannie Mae incentive program (subject to the terms of the program). As part of our comprehensive benefits package, Fannie Mae offers a broad range of Health, Life, Voluntary Lifestyle, and other benefits and perks that enhance an employee's physical, mental, emotional, and financial well-being. See more here . Requisition compensation: 79000 to 97000

View more...
Software EngineeringVia Workday
Verified5 days ago

Senior Sourcing Specialist - Software and SaaS

On-sitefull timeSeniorReston, United States
Apply Now

Playing an essential role in the U.S. economy, Fannie Mae is foundational to housing finance. Here, your expertise can help fuel purpose-driven innovation that expands access to homeownership and affordable rental housing across the country. Join Fannie Mae to grow your career and help people find a place to call home. Job Description As a valued colleague on our Corporate Procurement team, you will lead and execute sourcing and contracting activities for software, SaaS, cloud-based applications, enterprise licenses, subscription renewals, and related technology services. In this role, you will partner with internal and stakeholders to define sourcing strategies, manage RFx events, negotiate supplier agreements, and support contract execution in accordance with Fannie Mae's strategic sourcing process. This role is focused on delivering value, reducing risk, and improving commercial outcomes across the software and SaaS supplier portfolio while supporting timely, compliant, and business-aligned contracting. THE IMPACT YOU WILL MAKE The Senior Sourcing Specialist – Software and SaaS role will offer you the flexibility to make each day your own while working alongside people who care so that you can deliver on the following responsibilities: Lead sourcing and contracting activities for software, SaaS, cloud-based applications, enterprise licenses, subscription renewals, and related technology services. Partner with stakeholders to gather business, technical, commercial, risk, and contracting requirements. Manage RFx events, supplier communications, proposal evaluations, negotiation strategies, and sourcing recommendations. Negotiate commercial and contractual terms with suppliers, working in partnership with business and legal counterparts. Analyze supplier proposals, software usage, spend, renewal history, market benchmarks, and business demand to identify savings, cost avoidance, risk reduction, and value creation opportunities. Prepare sourcing documentation, award recommendations, negotiation summaries, and stakeholder updates. Adapt sourcing strategies based on business priorities, market conditions, risk considerations, and timeline requirements. Apply procurement tools, contract systems, spend data, and emerging technologies, including artificial intelligence, to improve sourcing quality, efficiency, and decision-making. THE EXPERIENCE YOU BRING TO THE TEAM Minimum Required Experiences 2 years of experience in a Corporate Procurement function, preferably at a large for profit commercial company, or with a consulting / advisory firm. Experience sourcing or negotiating software, SaaS, cloud-based applications, enterprise licenses, or technology supplier agreements. Experience managing RFx events, supplier negotiations, sourcing recommendations, and contract execution processes. Working knowledge of software and SaaS commercial models, including subscription pricing, user-based licensing, enterprise agreements, usage-based pricing, renewal terms, and support models. Strong analytical, negotiation, communication, stakeholder management, and problem-solving skills. Shows curiosity and adaptability in learning and responsibly applying new technologies, including artificial intelligence, to reimagine how we work. Desired Experiences Bachelor's degree or equivalent experience. 5+ years of experience in software/SaaS sourcing, IT procurement, technology category management, supplier management, contract management, or contract negotiation. Experience negotiating SaaS order forms, master agreements, statements of work, service level agreements, data processing agreements, software license agreements, cloud terms, and renewal amendments. Experience in a regulated financial services, housing finance, banking, or similarly complex enterprise environment. Familiarity with third-party risk management, cybersecurity, privacy, business continuity, accessibility, supplier due diligence, and software asset management. Experience using procurement, sourcing, contract lifecycle management, spend analytics, supplier management, or ERP platforms. Corporate Procurement – Sourcing and Contracting – Senior Associate #LI-Hybrid Qualifications Education: Bachelor's Level Degree The future is what you make it to be. Discover compelling opportunities at Fanniemae.com/careers. For most roles, employees are expected to work onsite on a regular basis at their designated office location. In-office work cadence is determined by your manager. Proximity within a reasonable commute to your designated office location is preferred unless the job is noted as open to remote. Fannie Mae is an equal opportunity employer and considers qualified applicants for employment without regard to race, color, religion, sex, national origin, disability, age, sexual orientation, gender identity/gender expression, marital or parental status, or any other protected factor. Fannie Mae is committed to providing reasonable accommodations to qualified individuals with disabilities who are employees or applicants for employment, unless to do so would cause undue hardship to the company. If you need assistance using our online system and/or you need a reasonable accommodation related to the hiring/application process, please complete this form . The hiring range for this role is set forth below. Final salaries will generally vary within that range based on factors that include but are not limited to, skill set, depth of experience, certifications, and other relevant qualifications. This position is eligible to participate in a Fannie Mae incentive program (subject to the terms of the program). As part of our comprehensive benefits package, Fannie Mae offers a broad range of Health, Life, Voluntary Lifestyle, and other benefits and perks that enhance an employee's physical, mental, emotional, and financial well-being. See more here . Requisition compensation: 79000 to 97000

View more...
Software EngineeringVia Workday
Verified5 days ago

Senior Sourcing Specialist - Software and SaaS

On-sitefull timeSeniorWashington, United States
Apply Now

Playing an essential role in the U.S. economy, Fannie Mae is foundational to housing finance. Here, your expertise can help fuel purpose-driven innovation that expands access to homeownership and affordable rental housing across the country. Join Fannie Mae to grow your career and help people find a place to call home. Job Description As a valued colleague on our Corporate Procurement team, you will lead and execute sourcing and contracting activities for software, SaaS, cloud-based applications, enterprise licenses, subscription renewals, and related technology services. In this role, you will partner with internal and stakeholders to define sourcing strategies, manage RFx events, negotiate supplier agreements, and support contract execution in accordance with Fannie Mae's strategic sourcing process. This role is focused on delivering value, reducing risk, and improving commercial outcomes across the software and SaaS supplier portfolio while supporting timely, compliant, and business-aligned contracting. THE IMPACT YOU WILL MAKE The Senior Sourcing Specialist – Software and SaaS role will offer you the flexibility to make each day your own while working alongside people who care so that you can deliver on the following responsibilities: Lead sourcing and contracting activities for software, SaaS, cloud-based applications, enterprise licenses, subscription renewals, and related technology services. Partner with stakeholders to gather business, technical, commercial, risk, and contracting requirements. Manage RFx events, supplier communications, proposal evaluations, negotiation strategies, and sourcing recommendations. Negotiate commercial and contractual terms with suppliers, working in partnership with business and legal counterparts. Analyze supplier proposals, software usage, spend, renewal history, market benchmarks, and business demand to identify savings, cost avoidance, risk reduction, and value creation opportunities. Prepare sourcing documentation, award recommendations, negotiation summaries, and stakeholder updates. Adapt sourcing strategies based on business priorities, market conditions, risk considerations, and timeline requirements. Apply procurement tools, contract systems, spend data, and emerging technologies, including artificial intelligence, to improve sourcing quality, efficiency, and decision-making. THE EXPERIENCE YOU BRING TO THE TEAM Minimum Required Experiences 2 years of experience in a Corporate Procurement function, preferably at a large for profit commercial company, or with a consulting / advisory firm. Experience sourcing or negotiating software, SaaS, cloud-based applications, enterprise licenses, or technology supplier agreements. Experience managing RFx events, supplier negotiations, sourcing recommendations, and contract execution processes. Working knowledge of software and SaaS commercial models, including subscription pricing, user-based licensing, enterprise agreements, usage-based pricing, renewal terms, and support models. Strong analytical, negotiation, communication, stakeholder management, and problem-solving skills. Shows curiosity and adaptability in learning and responsibly applying new technologies, including artificial intelligence, to reimagine how we work. Desired Experiences Bachelor's degree or equivalent experience. 5+ years of experience in software/SaaS sourcing, IT procurement, technology category management, supplier management, contract management, or contract negotiation. Experience negotiating SaaS order forms, master agreements, statements of work, service level agreements, data processing agreements, software license agreements, cloud terms, and renewal amendments. Experience in a regulated financial services, housing finance, banking, or similarly complex enterprise environment. Familiarity with third-party risk management, cybersecurity, privacy, business continuity, accessibility, supplier due diligence, and software asset management. Experience using procurement, sourcing, contract lifecycle management, spend analytics, supplier management, or ERP platforms. Corporate Procurement – Sourcing and Contracting – Senior Associate #LI-Hybrid Qualifications Education: Bachelor's Level Degree The future is what you make it to be. Discover compelling opportunities at Fanniemae.com/careers. For most roles, employees are expected to work onsite on a regular basis at their designated office location. In-office work cadence is determined by your manager. Proximity within a reasonable commute to your designated office location is preferred unless the job is noted as open to remote. Fannie Mae is an equal opportunity employer and considers qualified applicants for employment without regard to race, color, religion, sex, national origin, disability, age, sexual orientation, gender identity/gender expression, marital or parental status, or any other protected factor. Fannie Mae is committed to providing reasonable accommodations to qualified individuals with disabilities who are employees or applicants for employment, unless to do so would cause undue hardship to the company. If you need assistance using our online system and/or you need a reasonable accommodation related to the hiring/application process, please complete this form . The hiring range for this role is set forth below. Final salaries will generally vary within that range based on factors that include but are not limited to, skill set, depth of experience, certifications, and other relevant qualifications. This position is eligible to participate in a Fannie Mae incentive program (subject to the terms of the program). As part of our comprehensive benefits package, Fannie Mae offers a broad range of Health, Life, Voluntary Lifestyle, and other benefits and perks that enhance an employee's physical, mental, emotional, and financial well-being. See more here . Requisition compensation: 79000 to 97000

View more...
Software EngineeringVia Workday
Verified5 days ago

Principal Security Engineer

On-sitefull timeLead / StaffReston, United States
Apply Now

Playing an essential role in the U.S. economy, Fannie Mae is foundational to housing finance. Here, your expertise can help fuel purpose-driven innovation that expands access to homeownership and affordable rental housing across the country. Join Fannie Mae to grow your career and help people find a place to call home. Job Description Fannie Mae is seeking a highly experienced Principal Security Engineer to serve as a senior technical authority for enterprise infrastructure security. This role leads the research, architecture, design, implementation, integration, and ongoing support of security capabilities spanning cloud, network, server, endpoint, application, DevSecOps, and artificial intelligence environments. The ideal candidate combines deep cybersecurity, cloud, infrastructure, and network expertise with hands-on full-stack engineering experience. This role will shape enterprise-scale security architecture, automate and integrate controls, review code and configurations, secure AI-enabled systems, and communicate clear recommendations to engineers, business partners, and leaders. THE IMPACT YOU WILL MAKE The Principal Security Engineer role will offer you the flexibility to make each day your own, while working alongside people who care so that you can deliver on the following responsibilities: Cybersecurity Engineering and Technical Leadership • Lead the evaluation, architecture, implementation, integration, and lifecycle support of enterprise security solutions using established cybersecurity and engineering principles. • Provide principal-level technical direction for projects, products, platforms, applications, and infrastructure; identify systemic risks and drive remediation from design through operations. • Develop strategic recommendations on security technologies, architecture, implementation approaches, and long-term technical direction. • Maintain expertise in evolving technologies, vulnerabilities, attack techniques, products, and industry trends; mentor engineers and influence decisions across teams without relying on direct authority. • Promote security as an enabler of resilient technology delivery, cloud adoption, product innovation, and responsible AI. Cloud and Infrastructure Security • Define and implement security architecture, standards, reusable patterns, guardrails, and landing-zone controls across AWS, Google Cloud, Microsoft Azure, hybrid, and multi-cloud environments. • Design identity-centric and zero-trust controls for segmentation, private connectivity, federation, encryption, key and secrets management, centralized logging, monitoring, and policy-driven governance. • Secure virtual machines, containers, Kubernetes, serverless services, APIs, databases, storage, managed services, and data-processing platforms. • Implement and operate cloud security posture, workload protection, entitlement management, configuration compliance, vulnerability management, and threat detection capabilities. • Partner with platform teams to embed security through Infrastructure as Code, reusable modules, reference architectures, architecture reviews, migrations, and cloud-native modernization. • Analyze configurations and telemetry to identify misconfigurations, excessive privilege, exposed services, policy violations, vulnerabilities, and indicators of compromise. Server and Endpoint Security • Establish hardening standards and configuration baselines for Windows, Linux, virtualized, containerized, and cloud-hosted server environments. • Define and implement endpoint controls including EDR, anti-malware, host firewalls, encryption, application control, vulnerability management, privileged access management, and device posture validation. • Improve visibility through centralized logging, monitoring, asset inventory, configuration management, vulnerability assessment, and security telemetry. • Automate secure configuration, patching, vulnerability remediation, credential and certificate management, backup protection, recovery, remote administration, and system lifecycle processes. • Evaluate, deploy, integrate, and operate server and endpoint security technologies; analyze findings and compliance results to prioritize remediation. Application and Artificial Intelligence Security • Lead application and AI security policies, standards, design patterns, control frameworks, and technical guardrails across traditional applications, machine-learning platforms, generative AI, and agentic systems. • Architect and review secure designs for LLMs, foundation models, RAG pipelines, AI agents, tool-using workflows, automated decision-making, and AI-enabled business processes. • Define controls for prompts, tools, agent memory, service identities, authorization, data access, autonomy limits, human approval, escalation and shutdown, observability, output validation, and content safety. • Lead threat modeling, abuse-case and misuse analysis, red teaming, security testing, and risk assessments for AI pipelines, training and inference data, vector databases, retrieval systems, plugins, APIs, and external model providers. Security Requirements, Architecture, and Documentation • Develop and maintain security requirements, architecture artifacts, technical designs, implementation and test plans, policies, standards, procedures, control specifications, and operational documentation. • Create architecture and data-flow diagrams, threat models, control mappings, integration designs, technical specifications, and support documentation. • Translate regulatory, privacy, risk, business, and responsible AI obligations into measurable technical controls and acceptance criteria. • Validate control implementation and effectiveness before production deployment and maintain accurate documentation of architecture, dependencies, data flows, configurations, support, and recovery processes. • Define reusable reference architectures and secure design patterns for cloud, network, infrastructure, application, and AI environments. Collaboration, Leadership, and Influence • Partner across cybersecurity, engineering, product, cloud, infrastructure, networking, operations, application development, data, privacy, compliance, legal, architecture, and responsible AI teams. • Influence product roadmaps, architecture decisions, development practices, and operating models while balancing security, privacy, compliance, cost, performance, availability, and delivery priorities. • Lead technical discussions on architecture, engineering solutions, implementation options, platform capabilities, and risk tradeoffs. • Build productive relationships with internal teams, technology vendors, managed service providers, and external support organizations; mentor senior and principal engineers and raise organizational security maturity. Communication and Executive Engagement • Communicate complex technical concepts to engineering, operations, product, risk, compliance, business, and executive audiences. • Develop and deliver architecture presentations, technical briefings, risk assessments, implementation plans, engineering recommendations, and executive summaries. • Facilitate design reviews, architecture forums, technical evaluations, incident discussions, and stakeholder decision meetings. • Translate cybersecurity issues into business impact, risk exposure, operational considerations, tradeoffs, and actionable decisions. • Address risks such as prompt injection, indirect prompt injection, sensitive-data leakage, insecure tool use, model poisoning, excessive privileges, hallucinated actions, and unsafe autonomous behavior. • Partner with AI, product, application, data, privacy, legal, compliance, and responsible AI teams; evaluate emerging tools and standards; advise leadership on risk, regulation, investment, and roadmap priorities. Security Requirements, Architecture, and Documentation • Develop and maintain security requirements, architecture artifacts, technical designs, implementation and test plans, policies, standards, procedures, control specifications, and operational documentation. • Create architecture and data-flow diagrams, threat models, control mappings, integration designs, technical specifications, and support documentation. • Translate regulatory, privacy, risk, business, and responsible AI obligations into measurable technical controls and acceptance criteria. • Validate control implementation and effectiveness before production deployment and maintain accurate documentation of architecture, dependencies, data flows, configurations, support, and recovery processes. • Define reusable reference architectures and secure design patterns for cloud, network, infrastructure, application, and AI environments. Collaboration, Leadership, and Influence • Partner across cybersecurity, engineering, product, cloud, infrastructure, networking, operations, application development, data, privacy, compliance, legal, architecture, and responsible AI teams. • Influence product roadmaps, architecture decisions, development practices, and operating models while balancing security, privacy, compliance, cost, performance, availability, and delivery priorities. • Lead technical discussions on architecture, engineering solutions, implementation options, platform capabilities, and risk tradeoffs. • Build productive relationships with internal teams, technology vendors, managed service providers, and external support organizations; mentor senior and principal engineers and raise organizational security maturity. THE EXPERIENCE YOU BRING TO THE TEAM Minimum Required Experiences 8 years of experience. Extensive experience in cybersecurity engineering, infrastructure or network security, cloud engineering, application security, software engineering, or a related technical discipline. Significant hands-on experience securing production environments in AWS, Google Cloud, and Microsoft Azure. Deep knowledge of cloud security architecture, IAM, networking, encryption, logging, monitoring, workload protection, governance, and enterprise network security, including segmentation, firewalls, proxies, VPNs, DNS security, secure web gateways, IPS, load balancing, ZTNA, and SASE. Experience securing Windows and Linux servers, endpoints, databases, containers, Kubernetes, and cloud-hosted workloads. Hands-on experience designing, integrating, and securing CI/CD pipelines and implementing automated security testing, secure release controls, and policy enforcement. Experience with Infrastructure as Code, including Terraform, CloudFormation, Bicep, ARM templates, or equivalent tools. Full-stack engineering experience across front-end applications, back-end services, APIs, databases, cloud services, identity platforms, and supporting infrastructure. Proficiency in one or more languages such as Python, Go, Java, JavaScript, TypeScript, C#, PowerShell, Bash, or Ruby; experience building integrations through APIs, automation, orchestration, and vendor-supported methods. Strong knowledge of secure software development, application and API security, cloud-native development, containers and registries, Kubernetes security, and software supply chain risks. Experience with SIEM, EDR, vulnerability management, network security platforms, cloud-native security services, IAM, PAM, secrets, certificates, keys, and cryptographic controls. Experience developing security requirements, architecture artifacts, technical designs, implementation and test plans, policies, standards, procedures, proofs of concept, product evaluations, technical testing, data analysis, and architecture assessments. Knowledge of AI security risks and experience applying threat modeling and secure design practices to modern applications, APIs, cloud platforms, or AI-enabled systems. Demonstrated ability to lead complex, cross-functional technical initiatives and communicate effectively with engineers, administrators, executives, and technical decision-makers. Strong analytical, problem-solving, troubleshooting, writing, presentation, and stakeholder-management skills. Ability and willingness to participate in an on-call rotation and support major outages, critical service issues, and cybersecurity incidents. Desired Experiences Experience designing security controls for large-scale, regulated, highly available, geographically distributed, or global enterprise environments. Experience with CSPM, CWPP, CIEM, DSPM, attack-path management, cloud-delivered security platforms, and zero-trust architecture across users, devices, networks, applications, services, and workloads. Experience with AI security architecture, generative AI, LLM applications, RAG pipelines, agent frameworks, model gateways, responsible AI controls, AI red teaming, adversarial testing, model risk assessment, or abuse-case analysis. Experience with threat-modeling methodologies, security architecture frameworks, penetration testing, red-team, purple-team, and adversarial simulation activities. Familiarity with NIST Cybersecurity Framework, NIST 800-53, CIS Benchmarks, ISO 27001, SOC 2, PCI DSS, OWASP, MITRE ATT&CK, MITRE ATLAS, or comparable standards. Professional Certifications: Relevant industry certifications such as CISSP, CCSP, PCNSE, AWS Certified Security – Specialty, AWS Certified Advanced Networking – Specialty, Google Professional Cloud Security Engineer, Microsoft Certified: Azure Security Engineer Associate, GIAC certifications, or equivalent credentials. Information Security Technology - Engineering - Principal 200,000.00 - 269,000.00 JR2746 Qualifications Education: Bachelor's Level Degree (Required) The future is what you make it to be. Discover compelling opportunities at Fanniemae.com/careers. For most roles, employees are expected to work onsite on a regular basis at their designated office location. In-office work cadence is determined by your manager. Proximity within a reasonable commute to your designated office location is preferred unless the job is noted as open to remote. Fannie Mae is an equal opportunity employer and considers qualified applicants for employment without regard to race, color, religion, sex, national origin, disability, age, sexual orientation, gender identity/gender expression, marital or parental status, or any other protected factor. Fannie Mae is committed to providing reasonable accommodations to qualified individuals with disabilities who are employees or applicants for employment, unless to do so would cause undue hardship to the company. If you need assistance using our online system and/or you need a reasonable accommodation related to the hiring/application process, please complete this form . The hiring range for this role is set forth below. Final salaries will generally vary within that range based on factors that include but are not limited to, skill set, depth of experience, certifications, and other relevant qualifications. This position is eligible to participate in a Fannie Mae incentive program (subject to the terms of the program). As part of our comprehensive benefits package, Fannie Mae offers a broad range of Health, Life, Voluntary Lifestyle, and other benefits and perks that enhance an employee's physical, mental, emotional, and financial well-being. See more here . Requisition compensation: 200000 to 269000

View more...
CybersecurityVia Workday
Verified13 days ago

Principal Security Engineer

On-sitefull timeLead / StaffTexas, United States
Apply Now

Playing an essential role in the U.S. economy, Fannie Mae is foundational to housing finance. Here, your expertise can help fuel purpose-driven innovation that expands access to homeownership and affordable rental housing across the country. Join Fannie Mae to grow your career and help people find a place to call home. Job Description Fannie Mae is seeking a highly experienced Principal Security Engineer to serve as a senior technical authority for enterprise infrastructure security. This role leads the research, architecture, design, implementation, integration, and ongoing support of security capabilities spanning cloud, network, server, endpoint, application, DevSecOps, and artificial intelligence environments. The ideal candidate combines deep cybersecurity, cloud, infrastructure, and network expertise with hands-on full-stack engineering experience. This role will shape enterprise-scale security architecture, automate and integrate controls, review code and configurations, secure AI-enabled systems, and communicate clear recommendations to engineers, business partners, and leaders. THE IMPACT YOU WILL MAKE The Principal Security Engineer role will offer you the flexibility to make each day your own, while working alongside people who care so that you can deliver on the following responsibilities: Cybersecurity Engineering and Technical Leadership • Lead the evaluation, architecture, implementation, integration, and lifecycle support of enterprise security solutions using established cybersecurity and engineering principles. • Provide principal-level technical direction for projects, products, platforms, applications, and infrastructure; identify systemic risks and drive remediation from design through operations. • Develop strategic recommendations on security technologies, architecture, implementation approaches, and long-term technical direction. • Maintain expertise in evolving technologies, vulnerabilities, attack techniques, products, and industry trends; mentor engineers and influence decisions across teams without relying on direct authority. • Promote security as an enabler of resilient technology delivery, cloud adoption, product innovation, and responsible AI. Cloud and Infrastructure Security • Define and implement security architecture, standards, reusable patterns, guardrails, and landing-zone controls across AWS, Google Cloud, Microsoft Azure, hybrid, and multi-cloud environments. • Design identity-centric and zero-trust controls for segmentation, private connectivity, federation, encryption, key and secrets management, centralized logging, monitoring, and policy-driven governance. • Secure virtual machines, containers, Kubernetes, serverless services, APIs, databases, storage, managed services, and data-processing platforms. • Implement and operate cloud security posture, workload protection, entitlement management, configuration compliance, vulnerability management, and threat detection capabilities. • Partner with platform teams to embed security through Infrastructure as Code, reusable modules, reference architectures, architecture reviews, migrations, and cloud-native modernization. • Analyze configurations and telemetry to identify misconfigurations, excessive privilege, exposed services, policy violations, vulnerabilities, and indicators of compromise. Server and Endpoint Security • Establish hardening standards and configuration baselines for Windows, Linux, virtualized, containerized, and cloud-hosted server environments. • Define and implement endpoint controls including EDR, anti-malware, host firewalls, encryption, application control, vulnerability management, privileged access management, and device posture validation. • Improve visibility through centralized logging, monitoring, asset inventory, configuration management, vulnerability assessment, and security telemetry. • Automate secure configuration, patching, vulnerability remediation, credential and certificate management, backup protection, recovery, remote administration, and system lifecycle processes. • Evaluate, deploy, integrate, and operate server and endpoint security technologies; analyze findings and compliance results to prioritize remediation. Application and Artificial Intelligence Security • Lead application and AI security policies, standards, design patterns, control frameworks, and technical guardrails across traditional applications, machine-learning platforms, generative AI, and agentic systems. • Architect and review secure designs for LLMs, foundation models, RAG pipelines, AI agents, tool-using workflows, automated decision-making, and AI-enabled business processes. • Define controls for prompts, tools, agent memory, service identities, authorization, data access, autonomy limits, human approval, escalation and shutdown, observability, output validation, and content safety. • Lead threat modeling, abuse-case and misuse analysis, red teaming, security testing, and risk assessments for AI pipelines, training and inference data, vector databases, retrieval systems, plugins, APIs, and external model providers. Security Requirements, Architecture, and Documentation • Develop and maintain security requirements, architecture artifacts, technical designs, implementation and test plans, policies, standards, procedures, control specifications, and operational documentation. • Create architecture and data-flow diagrams, threat models, control mappings, integration designs, technical specifications, and support documentation. • Translate regulatory, privacy, risk, business, and responsible AI obligations into measurable technical controls and acceptance criteria. • Validate control implementation and effectiveness before production deployment and maintain accurate documentation of architecture, dependencies, data flows, configurations, support, and recovery processes. • Define reusable reference architectures and secure design patterns for cloud, network, infrastructure, application, and AI environments. Collaboration, Leadership, and Influence • Partner across cybersecurity, engineering, product, cloud, infrastructure, networking, operations, application development, data, privacy, compliance, legal, architecture, and responsible AI teams. • Influence product roadmaps, architecture decisions, development practices, and operating models while balancing security, privacy, compliance, cost, performance, availability, and delivery priorities. • Lead technical discussions on architecture, engineering solutions, implementation options, platform capabilities, and risk tradeoffs. • Build productive relationships with internal teams, technology vendors, managed service providers, and external support organizations; mentor senior and principal engineers and raise organizational security maturity. Communication and Executive Engagement • Communicate complex technical concepts to engineering, operations, product, risk, compliance, business, and executive audiences. • Develop and deliver architecture presentations, technical briefings, risk assessments, implementation plans, engineering recommendations, and executive summaries. • Facilitate design reviews, architecture forums, technical evaluations, incident discussions, and stakeholder decision meetings. • Translate cybersecurity issues into business impact, risk exposure, operational considerations, tradeoffs, and actionable decisions. • Address risks such as prompt injection, indirect prompt injection, sensitive-data leakage, insecure tool use, model poisoning, excessive privileges, hallucinated actions, and unsafe autonomous behavior. • Partner with AI, product, application, data, privacy, legal, compliance, and responsible AI teams; evaluate emerging tools and standards; advise leadership on risk, regulation, investment, and roadmap priorities. Security Requirements, Architecture, and Documentation • Develop and maintain security requirements, architecture artifacts, technical designs, implementation and test plans, policies, standards, procedures, control specifications, and operational documentation. • Create architecture and data-flow diagrams, threat models, control mappings, integration designs, technical specifications, and support documentation. • Translate regulatory, privacy, risk, business, and responsible AI obligations into measurable technical controls and acceptance criteria. • Validate control implementation and effectiveness before production deployment and maintain accurate documentation of architecture, dependencies, data flows, configurations, support, and recovery processes. • Define reusable reference architectures and secure design patterns for cloud, network, infrastructure, application, and AI environments. Collaboration, Leadership, and Influence • Partner across cybersecurity, engineering, product, cloud, infrastructure, networking, operations, application development, data, privacy, compliance, legal, architecture, and responsible AI teams. • Influence product roadmaps, architecture decisions, development practices, and operating models while balancing security, privacy, compliance, cost, performance, availability, and delivery priorities. • Lead technical discussions on architecture, engineering solutions, implementation options, platform capabilities, and risk tradeoffs. • Build productive relationships with internal teams, technology vendors, managed service providers, and external support organizations; mentor senior and principal engineers and raise organizational security maturity. THE EXPERIENCE YOU BRING TO THE TEAM Minimum Required Experiences 8 years of experience. Extensive experience in cybersecurity engineering, infrastructure or network security, cloud engineering, application security, software engineering, or a related technical discipline. Significant hands-on experience securing production environments in AWS, Google Cloud, and Microsoft Azure. Deep knowledge of cloud security architecture, IAM, networking, encryption, logging, monitoring, workload protection, governance, and enterprise network security, including segmentation, firewalls, proxies, VPNs, DNS security, secure web gateways, IPS, load balancing, ZTNA, and SASE. Experience securing Windows and Linux servers, endpoints, databases, containers, Kubernetes, and cloud-hosted workloads. Hands-on experience designing, integrating, and securing CI/CD pipelines and implementing automated security testing, secure release controls, and policy enforcement. Experience with Infrastructure as Code, including Terraform, CloudFormation, Bicep, ARM templates, or equivalent tools. Full-stack engineering experience across front-end applications, back-end services, APIs, databases, cloud services, identity platforms, and supporting infrastructure. Proficiency in one or more languages such as Python, Go, Java, JavaScript, TypeScript, C#, PowerShell, Bash, or Ruby; experience building integrations through APIs, automation, orchestration, and vendor-supported methods. Strong knowledge of secure software development, application and API security, cloud-native development, containers and registries, Kubernetes security, and software supply chain risks. Experience with SIEM, EDR, vulnerability management, network security platforms, cloud-native security services, IAM, PAM, secrets, certificates, keys, and cryptographic controls. Experience developing security requirements, architecture artifacts, technical designs, implementation and test plans, policies, standards, procedures, proofs of concept, product evaluations, technical testing, data analysis, and architecture assessments. Knowledge of AI security risks and experience applying threat modeling and secure design practices to modern applications, APIs, cloud platforms, or AI-enabled systems. Demonstrated ability to lead complex, cross-functional technical initiatives and communicate effectively with engineers, administrators, executives, and technical decision-makers. Strong analytical, problem-solving, troubleshooting, writing, presentation, and stakeholder-management skills. Ability and willingness to participate in an on-call rotation and support major outages, critical service issues, and cybersecurity incidents. Desired Experiences Experience designing security controls for large-scale, regulated, highly available, geographically distributed, or global enterprise environments. Experience with CSPM, CWPP, CIEM, DSPM, attack-path management, cloud-delivered security platforms, and zero-trust architecture across users, devices, networks, applications, services, and workloads. Experience with AI security architecture, generative AI, LLM applications, RAG pipelines, agent frameworks, model gateways, responsible AI controls, AI red teaming, adversarial testing, model risk assessment, or abuse-case analysis. Experience with threat-modeling methodologies, security architecture frameworks, penetration testing, red-team, purple-team, and adversarial simulation activities. Familiarity with NIST Cybersecurity Framework, NIST 800-53, CIS Benchmarks, ISO 27001, SOC 2, PCI DSS, OWASP, MITRE ATT&CK, MITRE ATLAS, or comparable standards. Professional Certifications: Relevant industry certifications such as CISSP, CCSP, PCNSE, AWS Certified Security – Specialty, AWS Certified Advanced Networking – Specialty, Google Professional Cloud Security Engineer, Microsoft Certified: Azure Security Engineer Associate, GIAC certifications, or equivalent credentials. Information Security Technology - Engineering - Principal 200,000.00 - 269,000.00 JR2746 Qualifications Education: Bachelor's Level Degree (Required) The future is what you make it to be. Discover compelling opportunities at Fanniemae.com/careers. For most roles, employees are expected to work onsite on a regular basis at their designated office location. In-office work cadence is determined by your manager. Proximity within a reasonable commute to your designated office location is preferred unless the job is noted as open to remote. Fannie Mae is an equal opportunity employer and considers qualified applicants for employment without regard to race, color, religion, sex, national origin, disability, age, sexual orientation, gender identity/gender expression, marital or parental status, or any other protected factor. Fannie Mae is committed to providing reasonable accommodations to qualified individuals with disabilities who are employees or applicants for employment, unless to do so would cause undue hardship to the company. If you need assistance using our online system and/or you need a reasonable accommodation related to the hiring/application process, please complete this form . The hiring range for this role is set forth below. Final salaries will generally vary within that range based on factors that include but are not limited to, skill set, depth of experience, certifications, and other relevant qualifications. This position is eligible to participate in a Fannie Mae incentive program (subject to the terms of the program). As part of our comprehensive benefits package, Fannie Mae offers a broad range of Health, Life, Voluntary Lifestyle, and other benefits and perks that enhance an employee's physical, mental, emotional, and financial well-being. See more here . Requisition compensation: 200000 to 269000

View more...
CybersecurityVia Workday
Verified13 days ago

Windows Engineering Manager

On-sitefull timeSeniorReston, United States
Apply Now

Playing an essential role in the U.S. economy, Fannie Mae is foundational to housing finance. Here, your expertise can help fuel purpose-driven innovation that expands access to homeownership and affordable rental housing across the country. Join Fannie Mae to grow your career and help people find a place to call home. Job Description THE IMPACT YOU WILL MAKE The Windows Engineering Manager is responsible for leading the engineering, delivery, and operational support of the enterprise Windows endpoint platform. This role provides technical and people leadership for a team of engineers responsible for the design, deployment, management, security, and lifecycle of end-user computing services across the organization. The Manager drives the execution of the enterprise end-user computing strategy, ensuring Windows platforms remain secure, compliant, reliable, and aligned with business objectives. This role oversees engineering standards, operational processes, platform modernization initiatives, and service performance while fostering a culture of accountability, continuous improvement, and technical excellence. Leading a distributed team of approximately 8-10 desktop engineers and technicians, the Manager is responsible for Windows endpoint management, device provisioning, operating system lifecycle management, and endpoint security capabilities. The role partners closely with Infrastructure, Information Security, Network, and Enterprise Operations teams to deliver scalable and resilient solutions that support a hybrid workforce. This leader is accountable for platform health, service quality, operational stability, and engineering execution. They establish priorities, remove barriers, develop talent, and ensure successful delivery of strategic initiatives including operating system upgrades, endpoint management modernization, automation, and device lifecycle programs. The Windows Engineering Manager serves as a trusted advisor to Digital Workplace leadership, balancing strategic planning with operational execution to ensure enterprise endpoint services deliver a secure, productive, and consistent user experience. There is 1 opening for this position which can be based in our Reston, VA office. THE EXPERIENCE YOU BRING TO THE TEAM Minimum Required Experiences 6 years in IT engineering and 5+ years in enterprise desktop or end‑user computing roles, including leadership responsibilities. Deep, hands‑on knowledge of Windows in large enterprise environments, including OS deployment, imaging, troubleshooting, and lifecycle management. Endpoint Management Mastery: Expert‑level experience with Microsoft SCCM/MECM and Microsoft Intune, including software distribution, patching, compliance, and co‑management models. VDI & Remote Computing: Strong understanding of virtual desktop technologies (e.g., Citrix, VMware Horizon, Azure Virtual Desktop) and their integration with endpoint environments. Automation & Scripting: Proven ability to automate endpoint operations using PowerShell, Python, or similar scripting, including support for zero touch‑touch provisioning and configuration management. Security & Networking Acumen: Solid understanding of endpoint security best practices (encryption, EDR, identity, hardening) and desktop‑relevant networking concepts (LAN/Wi‑Fi, VPN, DNS/DHCP). Leadership & Communication: Demonstrated experience leading enterprise testing strategies, pilot programs, and vendor technical evaluations, including POCs and data‑driven recommendations for platform and tooling decisions. Large‑Scale Environment Experience: Leadership experience supporting thousands of endpoints across multiple locations and hybrid work models. Modern Endpoint Initiatives: Direct experience with Windows 365 Cloud PC, Autopilot, Intune‑first strategies, or major OS migrations (e.g., Windows 10 to 11). Innovation Mindset: A track record of improving end‑user experience through automation, analytics, or modern support models. Bachelor’s degree in Information Technology, Computer Science, or equivalent experience. Desired Experiences Regulated Industry Background: Experience in financial services or similarly regulated environments with strong compliance and availability requirements. Vendor & Financial Management: Experience managing OEMs, software vendors, and service providers, including budgeting, licensing optimization, and contract oversight. End User Services - Technology Engineering - Manager 155,000.00 - 209,000.00 JR2735 Qualifications Active Directory (AD), Active Directory (AD), Amazon Web Services (AWS), Artificial Intelligence (AI), Atlassian JIRA, Authentication Management, Backup and Recovery (Software), Business Insight Skills, Business Process Management Skills, Calendar and Scheduling Tools, Cleaning and Transforming Data, Cloud Technology, Collaborating Cross-Functionally, Communicating in Technical Writing, Communicating Technical Information, Communication, Configuration Management (CM), Conflict Resolution, Coordination, Customer and Market Insights, Customer Relationship Management (CRM), CyberArk, Cybersecurity Analysis, Data Analysis, Data Analysis Interpretation {+ 75 more} Education: Bachelor's Level Degree (Required) The future is what you make it to be. Discover compelling opportunities at Fanniemae.com/careers. For most roles, employees are expected to work onsite on a regular basis at their designated office location. In-office work cadence is determined by your manager. Proximity within a reasonable commute to your designated office location is preferred unless the job is noted as open to remote. Fannie Mae is an equal opportunity employer and considers qualified applicants for employment without regard to race, color, religion, sex, national origin, disability, age, sexual orientation, gender identity/gender expression, marital or parental status, or any other protected factor. Fannie Mae is committed to providing reasonable accommodations to qualified individuals with disabilities who are employees or applicants for employment, unless to do so would cause undue hardship to the company. If you need assistance using our online system and/or you need a reasonable accommodation related to the hiring/application process, please complete this form . The hiring range for this role is set forth below. Final salaries will generally vary within that range based on factors that include but are not limited to, skill set, depth of experience, certifications, and other relevant qualifications. This position is eligible to participate in a Fannie Mae incentive program (subject to the terms of the program). As part of our comprehensive benefits package, Fannie Mae offers a broad range of Health, Life, Voluntary Lifestyle, and other benefits and perks that enhance an employee's physical, mental, emotional, and financial well-being. See more here . Requisition compensation: 155000 to 209000

View more...
Engineering ManagementVia Workday
Verified13 days ago

Windows Engineering Manager

On-sitefull timeSeniorTexas, United States
Apply Now

Playing an essential role in the U.S. economy, Fannie Mae is foundational to housing finance. Here, your expertise can help fuel purpose-driven innovation that expands access to homeownership and affordable rental housing across the country. Join Fannie Mae to grow your career and help people find a place to call home. Job Description THE IMPACT YOU WILL MAKE The Windows Engineering Manager is responsible for leading the engineering, delivery, and operational support of the enterprise Windows endpoint platform. This role provides technical and people leadership for a team of engineers responsible for the design, deployment, management, security, and lifecycle of end-user computing services across the organization. The Manager drives the execution of the enterprise end-user computing strategy, ensuring Windows platforms remain secure, compliant, reliable, and aligned with business objectives. This role oversees engineering standards, operational processes, platform modernization initiatives, and service performance while fostering a culture of accountability, continuous improvement, and technical excellence. Leading a distributed team of approximately 8-10 desktop engineers and technicians, the Manager is responsible for Windows endpoint management, device provisioning, operating system lifecycle management, and endpoint security capabilities. The role partners closely with Infrastructure, Information Security, Network, and Enterprise Operations teams to deliver scalable and resilient solutions that support a hybrid workforce. This leader is accountable for platform health, service quality, operational stability, and engineering execution. They establish priorities, remove barriers, develop talent, and ensure successful delivery of strategic initiatives including operating system upgrades, endpoint management modernization, automation, and device lifecycle programs. The Windows Engineering Manager serves as a trusted advisor to Digital Workplace leadership, balancing strategic planning with operational execution to ensure enterprise endpoint services deliver a secure, productive, and consistent user experience. There is 1 opening for this position which can be based in our Reston, VA office. THE EXPERIENCE YOU BRING TO THE TEAM Minimum Required Experiences 6 years in IT engineering and 5+ years in enterprise desktop or end‑user computing roles, including leadership responsibilities. Deep, hands‑on knowledge of Windows in large enterprise environments, including OS deployment, imaging, troubleshooting, and lifecycle management. Endpoint Management Mastery: Expert‑level experience with Microsoft SCCM/MECM and Microsoft Intune, including software distribution, patching, compliance, and co‑management models. VDI & Remote Computing: Strong understanding of virtual desktop technologies (e.g., Citrix, VMware Horizon, Azure Virtual Desktop) and their integration with endpoint environments. Automation & Scripting: Proven ability to automate endpoint operations using PowerShell, Python, or similar scripting, including support for zero touch‑touch provisioning and configuration management. Security & Networking Acumen: Solid understanding of endpoint security best practices (encryption, EDR, identity, hardening) and desktop‑relevant networking concepts (LAN/Wi‑Fi, VPN, DNS/DHCP). Leadership & Communication: Demonstrated experience leading enterprise testing strategies, pilot programs, and vendor technical evaluations, including POCs and data‑driven recommendations for platform and tooling decisions. Large‑Scale Environment Experience: Leadership experience supporting thousands of endpoints across multiple locations and hybrid work models. Modern Endpoint Initiatives: Direct experience with Windows 365 Cloud PC, Autopilot, Intune‑first strategies, or major OS migrations (e.g., Windows 10 to 11). Innovation Mindset: A track record of improving end‑user experience through automation, analytics, or modern support models. Bachelor’s degree in Information Technology, Computer Science, or equivalent experience. Desired Experiences Regulated Industry Background: Experience in financial services or similarly regulated environments with strong compliance and availability requirements. Vendor & Financial Management: Experience managing OEMs, software vendors, and service providers, including budgeting, licensing optimization, and contract oversight. End User Services - Technology Engineering - Manager 155,000.00 - 209,000.00 JR2735 Qualifications Active Directory (AD), Active Directory (AD), Amazon Web Services (AWS), Artificial Intelligence (AI), Atlassian JIRA, Authentication Management, Backup and Recovery (Software), Business Insight Skills, Business Process Management Skills, Calendar and Scheduling Tools, Cleaning and Transforming Data, Cloud Technology, Collaborating Cross-Functionally, Communicating in Technical Writing, Communicating Technical Information, Communication, Configuration Management (CM), Conflict Resolution, Coordination, Customer and Market Insights, Customer Relationship Management (CRM), CyberArk, Cybersecurity Analysis, Data Analysis, Data Analysis Interpretation {+ 75 more} Education: Bachelor's Level Degree (Required) The future is what you make it to be. Discover compelling opportunities at Fanniemae.com/careers. For most roles, employees are expected to work onsite on a regular basis at their designated office location. In-office work cadence is determined by your manager. Proximity within a reasonable commute to your designated office location is preferred unless the job is noted as open to remote. Fannie Mae is an equal opportunity employer and considers qualified applicants for employment without regard to race, color, religion, sex, national origin, disability, age, sexual orientation, gender identity/gender expression, marital or parental status, or any other protected factor. Fannie Mae is committed to providing reasonable accommodations to qualified individuals with disabilities who are employees or applicants for employment, unless to do so would cause undue hardship to the company. If you need assistance using our online system and/or you need a reasonable accommodation related to the hiring/application process, please complete this form . The hiring range for this role is set forth below. Final salaries will generally vary within that range based on factors that include but are not limited to, skill set, depth of experience, certifications, and other relevant qualifications. This position is eligible to participate in a Fannie Mae incentive program (subject to the terms of the program). As part of our comprehensive benefits package, Fannie Mae offers a broad range of Health, Life, Voluntary Lifestyle, and other benefits and perks that enhance an employee's physical, mental, emotional, and financial well-being. See more here . Requisition compensation: 155000 to 209000

View more...
Engineering ManagementVia Workday
Verified13 days ago

VP, Cybersecurity

On-sitefull timeExecutiveWashington, United States
Apply Now

Playing an essential role in the U.S. economy, Fannie Mae is foundational to housing finance. Here, your expertise can help fuel purpose-driven innovation that expands access to homeownership and affordable rental housing across the country. Join Fannie Mae to grow your career and help people find a place to call home. Job Description THE IMPACT YOU WILL MAKE The Vice President, Cybersecurity is a senior cybersecurity executive responsible for helping define and execute Fannie Mae's enterprise cybersecurity strategy. This leader will oversee a broad portfolio of cybersecurity capabilities and programs designed to protect the organization's information assets, technology platforms, business operations, customers, and reputation. The VP will provide strategic leadership across cybersecurity domains, which may include security architecture, engineering, operations, cyber risk management, governance, data protection, cloud security, vulnerability management, and emerging security technologies. The role is responsible for ensuring cybersecurity capabilities remain effective, scalable, resilient, and aligned with business objectives in a complex on-premises, cloud, and hybrid technology environment. This executive will partner closely with business, technology, and risk leaders to strengthen the organization's security posture, drive modernization initiatives, enhance cyber resilience, and ensure compliance with applicable regulatory and industry requirements. The VP will foster a culture of security, operational excellence, innovation, and continuous improvement while leveraging data, automation, and emerging technologies to improve cybersecurity outcomes across the enterprise. Lead and develop high-performing cybersecurity teams responsible for the strategy, design, implementation, operation, and continuous improvement of enterprise cybersecurity capabilities. Establish and execute enterprise cybersecurity strategies, roadmaps, and programs that align with organizational priorities, business objectives, and evolving threat landscapes. Provide cross-functional leadership across multiple cybersecurity disciplines, which may include security engineering, cyber risk management, governance, security architecture, data protection, cloud security and vulnerability management. Provide executive leadership for emerging cyber risks, including those associated with AI, automation, and advanced digital technologies, ensuring the organization's security posture evolves to address changing threats and business opportunities. Partner with technology and business leaders to integrate security into enterprise initiatives, digital transformation efforts, and emerging technology strategies. Oversee the development, implementation, and maturity of cybersecurity capabilities that protect enterprise infrastructure, applications, data, users, and cloud environments. Ensure effective cyber threat monitoring, intelligence, detection, incident response, crisis management, and recovery capabilities across the organization. Drive cyber resilience and operational readiness through proactive risk management, security assessments, testing, and continuous improvement programs. Lead the development and execution of cybersecurity governance frameworks, standards, policies, and operating models that support regulatory, compliance, and business requirements. Provide executive oversight of cybersecurity risk management activities, audits, assessments, and remediation efforts, ensuring timely resolution of identified issues. Partner with enterprise risk, compliance, legal, and audit functions to maintain alignment on cybersecurity priorities, controls, and regulatory obligations. Oversee cybersecurity metrics, reporting, analytics, and data-driven decision-making capabilities that enable effective monitoring of security performance and risk. Promote the adoption of innovative technologies, automation, and modern security practices to improve operational effectiveness, scalability, and efficiency. Provide strategic guidance on security architecture and technology decisions to ensure secure, resilient, and sustainable solutions across the enterprise. Build and maintain strong relationships with internal and external stakeholders, including executive leadership, regulators, industry partners, and third-party service providers. Drive talent development, succession planning, workforce strategy, and organizational effectiveness across the cybersecurity organization. Communicate cybersecurity strategies, priorities, risks, and performance to executive leadership and key stakeholders in clear business terms. THE EXPERIENCE YOU BRING TO THE TEAM 10+ years of progressive leadership experience in cybersecurity, information security, technology risk, or related technology disciplines, with a demonstrated ability to lead large-scale programs, organizations, and strategic initiatives. Broad knowledge of cybersecurity principles, practices, and frameworks across one or more domains, including security operations, security engineering, threat management, cyber risk, governance, vulnerability management, identity and access management, cloud security, data protection, security architecture, or related disciplines. Proven experience developing and executing cybersecurity strategies that align security objectives with business priorities in complex, highly regulated, and evolving environments. Demonstrated ability to lead organizational transformation, technology modernization, and operational improvement initiatives. Experience building strong partnerships and influencing stakeholders across business, technology, risk, audit, and executive leadership functions. Strong strategic thinking, problem-solving, and analytical capabilities, with the ability to evaluate complex issues, assess risk, and drive effective business and technology solutions. Excellent written, verbal, and executive communication skills, including the ability to translate complex cybersecurity concepts into clear business outcomes and recommendations for senior leaders and executive audiences. Proven ability to lead, develop, and inspire high-performing teams while fostering a culture of collaboration, accountability, innovation, and continuous improvement. Experience managing multiple priorities and delivering results in a fast-paced, dynamic environment. Demonstrated success communicating cybersecurity strategy, risk, and program performance to executive leadership, boards, regulators, and other key stakeholders. Target Pay Range: $250,000.00 - $350,000.00 Qualifications Education: The future is what you make it to be. Discover compelling opportunities at Fanniemae.com/careers. For most roles, employees are expected to work onsite on a regular basis at their designated office location. In-office work cadence is determined by your manager. Proximity within a reasonable commute to your designated office location is preferred unless the job is noted as open to remote. Fannie Mae is an equal opportunity employer and considers qualified applicants for employment without regard to race, color, religion, sex, national origin, disability, age, sexual orientation, gender identity/gender expression, marital or parental status, or any other protected factor. Fannie Mae is committed to providing reasonable accommodations to qualified individuals with disabilities who are employees or applicants for employment, unless to do so would cause undue hardship to the company. If you need assistance using our online system and/or you need a reasonable accommodation related to the hiring/application process, please complete this form . The hiring range for this role is set forth below. Final salaries will generally vary within that range based on factors that include but are not limited to, skill set, depth of experience, certifications, and other relevant qualifications. This position is eligible to participate in a Fannie Mae incentive program (subject to the terms of the program). As part of our comprehensive benefits package, Fannie Mae offers a broad range of Health, Life, Voluntary Lifestyle, and other benefits and perks that enhance an employee's physical, mental, emotional, and financial well-being. See more here .

View more...
CybersecurityVia Workday
Verified26 days ago

VP, Cybersecurity

On-sitefull timeExecutiveReston, United States
Apply Now

Playing an essential role in the U.S. economy, Fannie Mae is foundational to housing finance. Here, your expertise can help fuel purpose-driven innovation that expands access to homeownership and affordable rental housing across the country. Join Fannie Mae to grow your career and help people find a place to call home. Job Description THE IMPACT YOU WILL MAKE The Vice President, Cybersecurity is a senior cybersecurity executive responsible for helping define and execute Fannie Mae's enterprise cybersecurity strategy. This leader will oversee a broad portfolio of cybersecurity capabilities and programs designed to protect the organization's information assets, technology platforms, business operations, customers, and reputation. The VP will provide strategic leadership across cybersecurity domains, which may include security architecture, engineering, operations, cyber risk management, governance, data protection, cloud security, vulnerability management, and emerging security technologies. The role is responsible for ensuring cybersecurity capabilities remain effective, scalable, resilient, and aligned with business objectives in a complex on-premises, cloud, and hybrid technology environment. This executive will partner closely with business, technology, and risk leaders to strengthen the organization's security posture, drive modernization initiatives, enhance cyber resilience, and ensure compliance with applicable regulatory and industry requirements. The VP will foster a culture of security, operational excellence, innovation, and continuous improvement while leveraging data, automation, and emerging technologies to improve cybersecurity outcomes across the enterprise. Lead and develop high-performing cybersecurity teams responsible for the strategy, design, implementation, operation, and continuous improvement of enterprise cybersecurity capabilities. Establish and execute enterprise cybersecurity strategies, roadmaps, and programs that align with organizational priorities, business objectives, and evolving threat landscapes. Provide cross-functional leadership across multiple cybersecurity disciplines, which may include security engineering, cyber risk management, governance, security architecture, data protection, cloud security and vulnerability management. Provide executive leadership for emerging cyber risks, including those associated with AI, automation, and advanced digital technologies, ensuring the organization's security posture evolves to address changing threats and business opportunities. Partner with technology and business leaders to integrate security into enterprise initiatives, digital transformation efforts, and emerging technology strategies. Oversee the development, implementation, and maturity of cybersecurity capabilities that protect enterprise infrastructure, applications, data, users, and cloud environments. Ensure effective cyber threat monitoring, intelligence, detection, incident response, crisis management, and recovery capabilities across the organization. Drive cyber resilience and operational readiness through proactive risk management, security assessments, testing, and continuous improvement programs. Lead the development and execution of cybersecurity governance frameworks, standards, policies, and operating models that support regulatory, compliance, and business requirements. Provide executive oversight of cybersecurity risk management activities, audits, assessments, and remediation efforts, ensuring timely resolution of identified issues. Partner with enterprise risk, compliance, legal, and audit functions to maintain alignment on cybersecurity priorities, controls, and regulatory obligations. Oversee cybersecurity metrics, reporting, analytics, and data-driven decision-making capabilities that enable effective monitoring of security performance and risk. Promote the adoption of innovative technologies, automation, and modern security practices to improve operational effectiveness, scalability, and efficiency. Provide strategic guidance on security architecture and technology decisions to ensure secure, resilient, and sustainable solutions across the enterprise. Build and maintain strong relationships with internal and external stakeholders, including executive leadership, regulators, industry partners, and third-party service providers. Drive talent development, succession planning, workforce strategy, and organizational effectiveness across the cybersecurity organization. Communicate cybersecurity strategies, priorities, risks, and performance to executive leadership and key stakeholders in clear business terms. THE EXPERIENCE YOU BRING TO THE TEAM 10+ years of progressive leadership experience in cybersecurity, information security, technology risk, or related technology disciplines, with a demonstrated ability to lead large-scale programs, organizations, and strategic initiatives. Broad knowledge of cybersecurity principles, practices, and frameworks across one or more domains, including security operations, security engineering, threat management, cyber risk, governance, vulnerability management, identity and access management, cloud security, data protection, security architecture, or related disciplines. Proven experience developing and executing cybersecurity strategies that align security objectives with business priorities in complex, highly regulated, and evolving environments. Demonstrated ability to lead organizational transformation, technology modernization, and operational improvement initiatives. Experience building strong partnerships and influencing stakeholders across business, technology, risk, audit, and executive leadership functions. Strong strategic thinking, problem-solving, and analytical capabilities, with the ability to evaluate complex issues, assess risk, and drive effective business and technology solutions. Excellent written, verbal, and executive communication skills, including the ability to translate complex cybersecurity concepts into clear business outcomes and recommendations for senior leaders and executive audiences. Proven ability to lead, develop, and inspire high-performing teams while fostering a culture of collaboration, accountability, innovation, and continuous improvement. Experience managing multiple priorities and delivering results in a fast-paced, dynamic environment. Demonstrated success communicating cybersecurity strategy, risk, and program performance to executive leadership, boards, regulators, and other key stakeholders. Target Pay Range: $250,000.00 - $350,000.00 Qualifications Education: The future is what you make it to be. Discover compelling opportunities at Fanniemae.com/careers. For most roles, employees are expected to work onsite on a regular basis at their designated office location. In-office work cadence is determined by your manager. Proximity within a reasonable commute to your designated office location is preferred unless the job is noted as open to remote. Fannie Mae is an equal opportunity employer and considers qualified applicants for employment without regard to race, color, religion, sex, national origin, disability, age, sexual orientation, gender identity/gender expression, marital or parental status, or any other protected factor. Fannie Mae is committed to providing reasonable accommodations to qualified individuals with disabilities who are employees or applicants for employment, unless to do so would cause undue hardship to the company. If you need assistance using our online system and/or you need a reasonable accommodation related to the hiring/application process, please complete this form . The hiring range for this role is set forth below. Final salaries will generally vary within that range based on factors that include but are not limited to, skill set, depth of experience, certifications, and other relevant qualifications. This position is eligible to participate in a Fannie Mae incentive program (subject to the terms of the program). As part of our comprehensive benefits package, Fannie Mae offers a broad range of Health, Life, Voluntary Lifestyle, and other benefits and perks that enhance an employee's physical, mental, emotional, and financial well-being. See more here .

View more...
CybersecurityVia Workday
Verified26 days ago