Fannie Mae

Principal Security Engineer

Fannie Mae$200K — $269K *
Information Technology
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • 8+ years of experience in cybersecurity, infrastructure, or network security
  • Extensive hands-on experience securing AWS, Google Cloud, and Azure environments
  • Deep understanding of cloud security architecture and IAM
  • Proficiency in programming languages such as Python, Go, or Java
  • Experience with Infrastructure as Code tools like Terraform and CloudFormation

Responsibilities

  • Lead architecture and implementation of enterprise security solutions
  • Provide technical direction on projects and infrastructure
  • Develop recommendations on security technologies and long-term direction
  • Mentor teams and influence decisions across departments
  • Define and implement security standards across multi-cloud environments

Benefits

  • Flexible work environment
  • Opportunities for professional development and mentorship
  • Access to cutting-edge security technologies
  • Engagement with diverse cross-functional teams
  • Contribution toward robust cloud and AI security solutions
Full Job Description
Job Description

Fannie Mae is seeking a highly experienced Principal Security Engineer to serve as a senior technical authority for enterprise infrastructure security. This role leads the research, architecture, design, implementation, integration, and ongoing support of security capabilities spanning cloud, network, server, endpoint, application, DevSecOps, and artificial intelligence environments.

The ideal candidate combines deep cybersecurity, cloud, infrastructure, and network expertise with hands-on full-stack engineering experience. This role will shape enterprise-scale security architecture, automate and integrate controls, review code and configurations, secure AI-enabled systems, and communicate clear recommendations to engineers, business partners, and leaders.

THE IMPACT YOU WILL MAKE

The Principal Security Engineer role will offer you the flexibility to make each day your own, while working alongside people who care so that you can deliver on the following responsibilities:

Cybersecurity Engineering and Technical Leadership

Lead the evaluation, architecture, implementation, integration, and lifecycle support of enterprise security solutions using established cybersecurity and engineering principles.

Provide principal-level technical direction for projects, products, platforms, applications, and infrastructure; identify systemic risks and drive remediation from design through operations.

Develop strategic recommendations on security technologies, architecture, implementation approaches, and long-term technical direction.

Maintain expertise in evolving technologies, vulnerabilities, attack techniques, products, and industry trends; mentor engineers and influence decisions across teams without relying on direct authority.

Promote security as an enabler of resilient technology delivery, cloud adoption, product innovation, and responsible AI.

Cloud and Infrastructure Security

Define and implement security architecture, standards, reusable patterns, guardrails, and landing-zone controls across AWS, Google Cloud, Microsoft Azure, hybrid, and multi-cloud environments.

Design identity-centric and zero-trust controls for segmentation, private connectivity, federation, encryption, key and secrets management, centralized logging, monitoring, and policy-driven governance.

Secure virtual machines, containers, Kubernetes, serverless services, APIs, databases, storage, managed services, and data-processing platforms.

Implement and operate cloud security posture, workload protection, entitlement management, configuration compliance, vulnerability management, and threat detection capabilities.

Partner with platform teams to embed security through Infrastructure as Code, reusable modules, reference architectures, architecture reviews, migrations, and cloud-native modernization.

Analyze configurations and telemetry to identify misconfigurations, excessive privilege, exposed services, policy violations, vulnerabilities, and indicators of compromise.

Server and Endpoint Security

Establish hardening standards and configuration baselines for Windows, Linux, virtualized, containerized, and cloud-hosted server environments.

Define and implement endpoint controls including EDR, anti-malware, host firewalls, encryption, application control, vulnerability management, privileged access management, and device posture validation.

Improve visibility through centralized logging, monitoring, asset inventory, configuration management, vulnerability assessment, and security telemetry.

Automate secure configuration, patching, vulnerability remediation, credential and certificate management, backup protection, recovery, remote administration, and system lifecycle processes.

Evaluate, deploy, integrate, and operate server and endpoint security technologies; analyze findings and compliance results to prioritize remediation.

Application and Artificial Intelligence Security

Lead application and AI security policies, standards, design patterns, control frameworks, and technical guardrails across traditional applications, machine-learning platforms, generative AI, and agentic systems.

Architect and review secure designs for LLMs, foundation models, RAG pipelines, AI agents, tool-using workflows, automated decision-making, and AI-enabled business processes.

Define controls for prompts, tools, agent memory, service identities, authorization, data access, autonomy limits, human approval, escalation and shutdown, observability, output validation, and content safety.

Lead threat modeling, abuse-case and misuse analysis, red teaming, security testing, and risk assessments for AI pipelines, training and inference data, vector databases, retrieval systems, plugins, APIs, and external model providers.

Security Requirements, Architecture, and Documentation

Develop and maintain security requirements, architecture artifacts, technical designs, implementation and test plans, policies, standards, procedures, control specifications, and operational documentation.

Create architecture and data-flow diagrams, threat models, control mappings, integration designs, technical specifications, and support documentation.

Translate regulatory, privacy, risk, business, and responsible AI obligations into measurable technical controls and acceptance criteria.

Validate control implementation and effectiveness before production deployment and maintain accurate documentation of architecture, dependencies, data flows, configurations, support, and recovery processes.

Define reusable reference architectures and secure design patterns for cloud, network, infrastructure, application, and AI environments.

Collaboration, Leadership, and Influence

Partner across cybersecurity, engineering, product, cloud, infrastructure, networking, operations, application development, data, privacy, compliance, legal, architecture, and responsible AI teams.

Influence product roadmaps, architecture decisions, development practices, and operating models while balancing security, privacy, compliance, cost, performance, availability, and delivery priorities.

Lead technical discussions on architecture, engineering solutions, implementation options, platform capabilities, and risk tradeoffs.

Build productive relationships with internal teams, technology vendors, managed service providers, and external support organizations; mentor senior and principal engineers and raise organizational security maturity.

THE EXPERIENCE YOU BRING TO THE TEAM

Minimum Required Experiences
  • 8 years of experience.
  • Extensive experience in cybersecurity engineering, infrastructure or network security, cloud engineering, application security, software engineering, or a related technical discipline.
  • Significant hands-on experience securing production environments in AWS, Google Cloud, and Microsoft Azure.
  • Deep knowledge of cloud security architecture, IAM, networking, encryption, logging, monitoring, workload protection, governance, and enterprise network security, including segmentation, firewalls, proxies, VPNs, DNS security, secure web gateways, IPS, load balancing, ZTNA, and SASE.
  • Experience securing Windows and Linux servers, endpoints, databases, containers, Kubernetes, and cloud-hosted workloads.
  • Hands-on experience designing, integrating, and securing CI/CD pipelines and implementing automated security testing, secure release controls, and policy enforcement.
  • Experience with Infrastructure as Code, including Terraform, CloudFormation, Bicep, ARM templates, or equivalent tools.
  • Full-stack engineering experience across front-end applications, back-end services, APIs, databases, cloud services, identity platforms, and supporting infrastructure.
  • Proficiency in one or more languages such as Python, Go, Java, JavaScript, TypeScript, C#, PowerShell, Bash, or Ruby; experience building integrations through APIs, automation, orchestration, and vendor-supported methods.
  • Strong knowledge of secure software development, application and API security, cloud-native development, containers and registries, Kubernetes security, and software supply chain risks.
  • Experience with SIEM, EDR, vulnerability management, network security platforms, cloud-native security services, IAM, PAM, secrets, certificates, keys, and cryptographic controls.
  • Experience developing security requirements, architecture artifacts, technical designs, implementation and test plans, policies, standards, procedures, proofs of concept, product evaluations, technical testing, data analysis, and architecture assessments.
  • Knowledge of AI security risks and experience applying threat modeling and secure design practices to modern applications, APIs, cloud platforms, or AI-enabled systems.
  • Demonstrated ability to lead complex, cross-functional technical initiatives and communicate effectively with engineers, administrators, executives, and technical decision-makers.
  • Strong analytical, problem-solving, troubleshooting, writing, presentation, and stakeholder-management skills.
  • Ability and willingness to participate in an on-call rotation and support major outages, critical service issues, and cybersecurity incidents.


Desired Experiences
  • Experience designing security controls for large-scale, regulated, highly available, geographically distributed, or global enterprise environments.
  • Experience with CSPM, CWPP, CIEM, DSPM, attack-path management, cloud-delivered security platforms, and zero-trust architecture across users, devices, networks, applications, services, and workloads.
  • Experience with AI security architecture, generative AI, LLM applications, RAG pipelines, agent frameworks, model gateways, responsible AI controls, AI red teaming, adversarial testing, model risk assessment, or abuse-case analysis.
  • Experience with threat-modeling methodologies, security architecture frameworks, penetration testing, red-team, purple-team, and adversarial simulation activities.
  • Familiarity with NIST Cybersecurity Framework, NIST 800-53, CIS Benchmarks, ISO 27001, SOC 2, PCI DSS, OWASP, MITRE ATT&CK, MITRE ATLAS, or comparable standards.
  • Professional Certifications: Relevant industry certifications such as CISSP, CCSP, PCNSE, AWS Certified Security - Specialty, AWS Certified Advanced Networking - Specialty, Google Professional Cloud Security Engineer, Microsoft Certified: Azure Security Engineer Associate, GIAC certifications, or equivalent credentials.


Information Security Technology - Engineering - Principal

200,000.00 - 269,000.00

JR2746

Qualifications

Education:
Bachelor's Level Degree (Required)

About Fannie Mae

As the leading source of residential mortgage credit in the U.S. secondary market, Fannie Mae is supporting today's economic recovery and helping to build a sustainable housing finance system. They exist to provide reliable, large-scale access to affordable mortgage credit in all communities across the country at all times so people can buy, refinance, or rent homes. Fannie Mae is working to establish and implement industry standards‚ develop better tools to price and manage credit risk‚ build new infrastructure to ensure a liquid and efficient market and facilitate the collection and reporting of data for accurate financial reporting and improved risk management. Fannie Mae is committed to being their customers’ most valued business partner and delivering the products, services and tools their customers need to serve the entire market confidently, efficiently and profitably. Ultimately‚ Fannie Mae measures their progress not only by paying taxpayers and improving the housing finance system‚ but also by the difference they make in people’s lives.

Fannie Mae Careers

Join the vibrant team at Fannie Mae, where we are committed to solving the challenges of today's housing market while fostering inclusive growth and innovation. As a cornerstone of the American mortgage system, Fannie Mae offers unparalleled job opportunities that empower you to influence the future of housing finance. Work You’ll Do At Fannie Mae, you will collaborate with some of the brightest minds in the finance and technology sectors. Our mission is to ensure access to affordable housing for people across the United States, and your work here will contribute to that goal. With roles ranging from financial analysis to technology development, your career at Fannie Mae will be marked by growth, leadership, and the pursuit of excellence. Innovate and Lead Fannie Mae stands at the intersection of financial services and innovative technology solutions, making it an ideal place for those who are driven to explore new ideas and push boundaries. Our culture thrives on innovation and leadership, encouraging every team member to bring forward ideas that drive efficiency and effectiveness. Professional Growth and Development Career advancement at Fannie Mae is not just a possibility—it is an expectation. We are dedicated to the professional growth of our employees through robust training programs, leadership workshops, and continuous learning opportunities. Whether you are looking to sharpen your analytical skills, enhance your leadership capabilities, or dive deep into the housing market dynamics, Fannie Mae provides the resources to achieve your professional goals. Diversity and Inclusion At Fannie Mae, we believe that diversity fuels innovation. We are committed to fostering an inclusive environment where diverse voices are heard and valued. Through diversity training and a culture that celebrates unique perspectives, we ensure that all team members can contribute to their fullest potential. Join Our Team Explore the array of job opportunities at Fannie Mae, from internships for budding professionals to full-time positions for seasoned experts. We are hiring individuals who are passionate, curious, and eager to make a difference. Our team is looking for candidates who not only have the necessary skills but also embody our values of integrity, impartiality, and respect. Benefits and Perks Working at Fannie Mae comes with a comprehensive benefits package designed to support the health, well-being, and financial security of our employees and their families. From competitive health benefits and retirement plans to flexible working arrangements and wellness programs, we prioritize the well-being of our team members. Stay Connected Networking and staying connected are key components of building a successful career at Fannie Mae. Engage with us through various professional networking events, online communities, and social platforms to stay updated on new positions, company news, and industry trends. Apply Now Ready to take the next step in your career? Review our open positions, tailor your resume, and prepare for an interview that could set you on a path to a rewarding career at Fannie Mae. We are excited to see how your vision, skills, and enthusiasm can contribute to our team and the broader mission of affordable housing. Explore Fannie Mae Jobs Discover the exciting and impactful career paths available at Fannie Mae. Each position offers the opportunity to challenge yourself, contribute to a significant cause, and work within a culture that values innovation, leadership, and community impact. Join us in shaping the future of housing finance—apply today and be part of a team that is dedicated to making a difference.
Learn more about Fannie Mae
Size
7,400 employees
Industry
Founded
1938
NASDAQ

Similar Jobs

More Jobs at Fannie Mae

More Information Technology Jobs

Find similar Principal Security Engineer jobs: