Principal Security Engineer
Reston, VA - USA
Job Summary
Playing an essential role in the U.S. economy Fannie Mae is foundational to housing finance. Here your expertise can help fuel purpose-driven innovation that expands access to homeownership and affordable rental housing across the country. Join Fannie Mae to grow your career and help people find a place to call home.
Job Description
Fannie Mae is seeking a highly experienced Principal Security Engineer to serve as a senior technical authority for enterprise infrastructure security. This role leads the research architecture design implementation integration and ongoing support of security capabilities spanning cloud network server endpoint application DevSecOps and artificial intelligence environments.
The ideal candidate combines deep cybersecurity cloud infrastructure and network expertise with hands-on full-stack engineering experience. This role will shape enterprise-scale security architecture automate and integrate controls review code and configurations secure AI-enabled systems and communicate clear recommendations to engineers business partners and leaders.
THE IMPACT YOU WILL MAKE
ThePrincipal Security Engineerrole will offer you the flexibility to make each day your own while working alongside people who care so that you can deliver on the following responsibilities:
Cybersecurity Engineering and Technical Leadership
Lead the evaluation architecture implementation integration and lifecycle support of enterprise security solutions using established cybersecurity and engineering principles.
Provide principal-level technical direction for projects products platforms applications and infrastructure; identify systemic risks and drive remediation from design through operations.
Develop strategic recommendations on security technologies architecture implementation approaches and long-term technical direction.
Maintain expertise in evolving technologies vulnerabilities attack techniques products and industry trends; mentor engineers and influence decisions across teams without relying on direct authority.
Promote security as an enabler of resilient technology delivery cloud adoption product innovation and responsible AI.
Cloud and Infrastructure Security
Define and implement security architecture standards reusable patterns guardrails and landing-zone controls across AWS Google Cloud Microsoft Azure hybrid and multi-cloud environments.
Design identity-centric and zero-trust controls for segmentation private connectivity federation encryption key and secrets management centralized logging monitoring and policy-driven governance.
Secure virtual machines containers Kubernetes serverless services APIs databases storage managed services and data-processing platforms.
Implement and operate cloud security posture workload protection entitlement management configuration compliance vulnerability management and threat detection capabilities.
Partner with platform teams to embed security through Infrastructure as Code reusable modules reference architectures architecture reviews migrations and cloud-native modernization.
Analyze configurations and telemetry to identify misconfigurations excessive privilege exposed services policy violations vulnerabilities and indicators of compromise.
Server and Endpoint Security
Establish hardening standards and configuration baselines for Windows Linux virtualized containerized and cloud-hosted server environments.
Define and implement endpoint controls including EDR anti-malware host firewalls encryption application control vulnerability management privileged access management and device posture validation.
Improve visibility through centralized logging monitoring asset inventory configuration management vulnerability assessment and security telemetry.
Automate secure configuration patching vulnerability remediation credential and certificate management backup protection recovery remote administration and system lifecycle processes.
Evaluate deploy integrate and operate server and endpoint security technologies; analyze findings and compliance results to prioritize remediation.
Application and Artificial Intelligence Security
Lead application and AI security policies standards design patterns control frameworks and technical guardrails across traditional applications machine-learning platforms generative AI and agentic systems.
Architect and review secure designs for LLMs foundation models RAG pipelines AI agents tool-using workflows automated decision-making and AI-enabled business processes.
Define controls for prompts tools agent memory service identities authorization data access autonomy limits human approval escalation and shutdown observability output validation and content safety.
Lead threat modeling abuse-case and misuse analysis red teaming security testing and risk assessments for AI pipelines training and inference data vector databases retrieval systems plugins APIs and external model providers.
Security Requirements Architecture and Documentation
Develop and maintain security requirements architecture artifacts technical designs implementation and test plans policies standards procedures control specifications and operational documentation.
Create architecture and data-flow diagrams threat models control mappings integration designs technical specifications and support documentation.
Translate regulatory privacy risk business and responsible AI obligations into measurable technical controls and acceptance criteria.
Validate control implementation and effectiveness before production deployment and maintain accurate documentation of architecture dependencies data flows configurations support and recovery processes.
Define reusable reference architectures and secure design patterns for cloud network infrastructure application and AI environments.
Collaboration Leadership and Influence
Partner across cybersecurity engineering product cloud infrastructure networking operations application development data privacy compliance legal architecture and responsible AI teams.
Influence product roadmaps architecture decisions development practices and operating models while balancing security privacy compliance cost performance availability and delivery priorities.
Lead technical discussions on architecture engineering solutions implementation options platform capabilities and risk tradeoffs.
Build productive relationships with internal teams technology vendors managed service providers and external support organizations; mentor senior and principal engineers and raise organizational security maturity.
Communication and Executive Engagement
Communicate complex technical concepts to engineering operations product risk compliance business and executive audiences.
Develop and deliver architecture presentations technical briefings risk assessments implementation plans engineering recommendations and executive summaries.
Facilitate design reviews architecture forums technical evaluations incident discussions and stakeholder decision meetings.
Translate cybersecurity issues into business impact risk exposure operational considerations tradeoffs and actionable decisions.
Address risks such as prompt injection indirect prompt injection sensitive-data leakage insecure tool use model poisoning excessive privileges hallucinated actions and unsafe autonomous behavior.
Partner with AI product application data privacy legal compliance and responsible AI teams; evaluate emerging tools and standards; advise leadership on risk regulation investment and roadmap priorities.
Security Requirements Architecture and Documentation
Develop and maintain security requirements architecture artifacts technical designs implementation and test plans policies standards procedures control specifications and operational documentation.
Create architecture and data-flow diagrams threat models control mappings integration designs technical specifications and support documentation.
Translate regulatory privacy risk business and responsible AI obligations into measurable technical controls and acceptance criteria.
Validate control implementation and effectiveness before production deployment and maintain accurate documentation of architecture dependencies data flows configurations support and recovery processes.
Define reusable reference architectures and secure design patterns for cloud network infrastructure application and AI environments.
Collaboration Leadership and Influence
Partner across cybersecurity engineering product cloud infrastructure networking operations application development data privacy compliance legal architecture and responsible AI teams.
Influence product roadmaps architecture decisions development practices and operating models while balancing security privacy compliance cost performance availability and delivery priorities.
Lead technical discussions on architecture engineering solutions implementation options platform capabilities and risk tradeoffs.
Build productive relationships with internal teams technology vendors managed service providers and external support organizations; mentor senior and principal engineers and raise organizational security maturity.
THE EXPERIENCEYOU BRING TO THE TEAM
Minimum Required Experiences
- 8 years of experience.
- Extensive experience in cybersecurity engineering infrastructure or network security cloud engineering application security software engineering or a related technical discipline.
- Significant hands-on experience securing production environments in AWS Google Cloud and Microsoft Azure.
- Deep knowledge of cloud security architecture IAM networking encryption logging monitoring workload protection governance and enterprise network security including segmentation firewalls proxies VPNs DNS security secure web gateways IPS load balancing ZTNA and SASE.
- Experience securing Windows and Linux servers endpoints databases containers Kubernetes and cloud-hosted workloads.
- Hands-on experience designing integrating and securing CI/CD pipelines and implementing automated security testing secure release controls and policy enforcement.
- Experience with Infrastructure as Code including Terraform CloudFormation Bicep ARM templates or equivalent tools.
- Full-stack engineering experience across front-end applications back-end services APIs databases cloud services identity platforms and supporting infrastructure.
- Proficiency in one or more languages such as Python Go Java JavaScript TypeScript C# PowerShell Bash or Ruby; experience building integrations through APIs automation orchestration and vendor-supported methods.
- Strong knowledge of secure software development application and API security cloud-native development containers and registries Kubernetes security and software supply chain risks.
- Experience with SIEM EDR vulnerability management network security platforms cloud-native security services IAM PAM secrets certificates keys and cryptographic controls.
- Experience developing security requirements architecture artifacts technical designs implementation and test plans policies standards procedures proofs of concept product evaluations technical testing data analysis and architecture assessments.
- Knowledge of AI security risks and experience applying threat modeling and secure design practices to modern applications APIs cloud platforms or AI-enabled systems.
- Demonstrated ability to lead complex cross-functional technical initiatives and communicate effectively with engineers administrators executives and technical decision-makers.
- Strong analytical problem-solving troubleshooting writing presentation and stakeholder-management skills.
- Ability and willingness to participate in an on-call rotation and support major outages critical service issues and cybersecurity incidents.
Desired Experiences
- Experience designing security controls for large-scale regulated highly available geographically distributed or global enterprise environments.
- Experience with CSPM CWPP CIEM DSPM attack-path management cloud-delivered security platforms and zero-trust architecture across users devices networks applications services and workloads.
- Experience with AI security architecture generative AI LLM applications RAG pipelines agent frameworks model gateways responsible AI controls AI red teaming adversarial testing model risk assessment or abuse-case analysis.
- Experience with threat-modeling methodologies security architecture frameworks penetration testing red-team purple-team and adversarial simulation activities.
- Familiarity with NIST Cybersecurity Framework NIST 800-53 CIS Benchmarks ISO 27001 SOC 2 PCI DSS OWASP MITRE ATT&CK MITRE ATLAS or comparable standards.
- Professional Certifications: Relevant industry certifications such as CISSP CCSP PCNSE AWS Certified Security Specialty AWS Certified Advanced Networking Specialty Google Professional Cloud Security Engineer Microsoft Certified: Azure Security Engineer Associate GIAC certifications or equivalent credentials.
Information Security Technology - Engineering - Principal
200000.00 - 269000.00
JR2746
Qualifications
Education:
Bachelors Level Degree (Required)The future is what you make it to be. Discover compelling opportunities at most roles employees are expected to work onsite on a regular basis at their designated office -office work cadence is determined by your manager. Proximity within a reasonable commute to your designated office location is preferred unless the job is noted as open to remote.
Fannie Mae is an equal opportunity employer and considers qualified applicants for employment without regard to race color religion sex national origin disability age sexual orientation gender identity/gender expression marital or parental status or any other protected factor. Fannie Mae is committed to providing reasonable accommodations to qualified individuals with disabilities who are employees or applicants for employment unless to do so would cause undue hardship to the company. If you need assistance using our online system and/or you need a reasonable accommodation related to the hiring/application process please complete this form.
The hiring range for this role is set forth below. Final salaries will generally vary within that range based on factors that include but are not limited to skill set depth of experience certifications and other relevant qualifications. This position is eligible to participate in a Fannie Mae incentive program (subject to the terms of the program). As part of our comprehensive benefits package Fannie Mae offers a broad range of Health Life Voluntary Lifestyle and other benefits and perks that enhance an employees physical mental emotional and financial well-being. See more here.
Requisition compensation:
200000to
269000Required Experience:
Staff IC
About Company
At Fannie Mae, futures are made. The inspiring work we do helps make a home a possibility for millions of homeowners and renters. Every day offers compelling opportunities to impact the future of the housing industry while being part of an inclusive team thriving in an energizing, fle ... View more