Principal Cybersecurity & Technology Risk Architect - AI/Cloud
Fannie Mae
- Location
- Plano, TX, US
- Track
- AI Security
- Level
- Staff
- Salary
- $175K–$239K / yr
- Posted
- October 6, 2026
- Source
- Indeed
Job description
Playing an essential role in the U.S. economy, Fannie Mae is foundational to housing finance. Here, your expertise can help fuel purpose-driven innovation that expands access to homeownership and affordable rental housing across the country. Join Fannie Mae to grow your career and help people find a place to call home.
Job Description
In this first-line risk role, you will serve as a senior technical risk authority for Enterprise Architecture, Artificial Intelligence (AI), Cloud and Engineering, providing independent, evidence-based risk challenge on the enterprise's most consequential technology decisions.
You will partner with senior leaders and practitioners across Cybersecurity, Technology, Architecture, Engineering, Data, AI and Risk to identify and evaluate material cyber and technology risks before they are designed into the environment. You will translate complex technical conditions, emerging threats and incomplete evidence into clear risk positions that articulate the exposure, affected business capabilities, control effectiveness, uncertainty, accountable ownership and decisions required.
The role requires deep technical credibility combined with enterprise risk judgment. You will evaluate architecture and engineering patterns, challenge security assumptions and control dependencies, identify systemic and emerging risks, and help leaders determine whether to proceed, proceed with conditions, redesign, remediate or formally accept risk.
As a Principal, you will also serve as a senior integrator when risk crosses domains such as AI, cloud, identity, data, application security, cyber defense, resilience and third-party technology. You will help convert recurring exceptions and individual findings into reusable risk patterns, scalable control expectations, and enterprise-level actions.
The Way You Will Make a Difference
This Principal role will offer you the flexibility to make each day your own while working alongside people who care, so that you can deliver on the following
responsibilities
Lead first-line risk analysis and credible challenges for material architecture, AI/GenAI, agentic AI, cloud and engineering decisions, translating technical complexity into clear enterprise risk positions and actionable decisions.
Assess architecture and engineering risk early in the lifecycle, including security design, trust boundaries, threat scenarios, inherited controls, data flows, identity and privilege, APIs, cloud services, software supply chains and resilience dependencies.
Provide senior risk challenge for AI systems and emerging AI architectures, including risks associated with model and data integrity, prompt injection, sensitive-data exposure, excessive agency, non-human identities, tool access, third-party models/components and agentic workflows.
Evaluate control design and effectiveness using evidence, distinguishing implemented and effective controls from policies, activities, dashboards or assertions, and identifying where evidence or assurance remains insufficient.
Develop reusable risk scenarios, assessment approaches and minimum evidence expectations for established and emerging technology patterns, reducing reliance on one-off reviews and enabling consistent risk decisions at scale.
Interpret threat modeling and scenario analysis to identify credible failure modes, attack paths, concentration risks and business consequences across interconnected technology environments.
Connect technical exposures to enterprise impact, including critical business services, sensitive data, operational resilience, regulatory obligations and strategic initiatives.
Frame decision-ready recommendations for senior management, clearly articulating exposure, evidence, uncertainty, alternatives, conditions, accountable owners and the decision required.
Identify systemic and emerging cyber risks by connecting signals across architecture reviews, risk assessments, incidents, issues, exceptions, audit findings, technology change and industry threat intelligence.
Drive accountable remediation and sustainable risk reduction, challenging whether proposed corrective actions address root causes and validating that closure evidence demonstrates meaningful reduction in exposure.
Partner across Cybersecurity, Technology, Engineering, Data, AI and Risk while maintaining independence of judgment and clear accountability boundaries.
Serve as a senior technical risk integrator and mentor, raising the quality of risk reasoning, technical challenge and executive communication across the broader risk organization.
THE EXPERIENCE YOU BRING TO THE TEAM
Minimum Required Qualifications
8 years of progressively responsible experience in cybersecurity, security architecture, cloud security, AI/ML security, years of relevant professional experience .
Bachelor's degree or equivalent practical experience in cybersecurity, computer science, engineering, technology, risk or a related discipline.
Demonstrated expertise in enterprise security architecture and modern engineering environments, including cloud architectures, APIs, identity and access patterns, data protection, application/platform security and software supply-chain risk.
Demonstrated experience assessing AI/ML, Generative AI or emerging technology risk, including the security implications of models, data, AI applications, third-party AI services and increasingly autonomous/agentic systems.
Experience conducting threat modeling, architecture risk assessments, control evaluations and scenario-based risk analysis for complex technology environments.
Demonstrated ability to assess control design and operating effectiveness from technical evidence and distinguish control effectiveness from policy compliance or completion of risk-management activities.
Experience translating complex technical vulnerabilities, architectural weaknesses and control gaps into business exposure and executive-level risk decisions.
Working knowledge of relevant frameworks and practices such