Senior Director, Cybersecurity and AI Risk Oversight

Posted 11 Days Ago
Be an Early Applicant
Reston, VA, USA
In-Office
200K-269K Annually
Senior level
Financial Services
The Role
Leads independent second-line cybersecurity risk oversight, including governance, risk assessments, risk appetite, KRIs, issue remediation, regulatory engagement, emerging technology risk, and executive reporting. The role challenges cybersecurity strategies and controls, oversees AI and quantum computing risks, supports audits and regulatory examinations, advises senior leadership and boards, and manages a high-performing cybersecurity risk team.
Summary Generated by Built In

Playing an essential role in the U.S. economy, Fannie Mae is foundational to housing finance. Here, your expertise can help fuel purpose-driven innovation that expands access to homeownership and affordable rental housing across the country. Join Fannie Mae to grow your career and help people find a place to call home.

Job Description

The Senior Director, Cybersecurity Risk Oversight Lead is responsible for advancing the Chief Risk and Compliance Division's (CRCD) independent cybersecurity risk oversight strategy. This role serves as a senior second line of defense (2LOD) leader responsible for overseeing cybersecurity risk governance, risk identification and assessment, risk appetite, issue management, emerging risk monitoring, regulatory engagement, and executive reporting.


Serving as a strategic partner to enterprise leadership, technology teams, and control functions, this role provides independent oversight and credible challenge to ensure cybersecurity risks are effectively identified, measured, monitored, managed, and reported. The position provides transparency into the firm's cybersecurity risk posture, control effectiveness, remediation progress, and emerging threats while supporting informed decision-making by executive management, risk committees, and regulators.


The role also oversees cybersecurity risks associated with emerging technologies, including artificial intelligence, frontier models, agentic systems, and quantum computing, ensuring risks are appropriately governed and aligned with enterprise risk appetite.


THE IMPACT YOU WILL MAKE


Cybersecurity Risk Oversight & Governance


  • Lead independent oversight and credible challenge of the enterprise cybersecurity risk management program.
  • Assess the effectiveness of cybersecurity governance, risk management practices, and control environments.
  • Provide independent review and challenge of cybersecurity strategies, risk assessments, exceptions, risk acceptances, and remediation plans.
  • Evaluate cybersecurity risk exposures against approved risk appetite statements, limits, and thresholds.
  • Identify material risk concentrations, systemic control weaknesses, and emerging risk trends.
  • Promote accountability, transparency, and effective risk management across the enterprise.

Cyber Risk Assessment, Monitoring & Reporting


  • Oversee the assessment, aggregation, monitoring, and reporting of cybersecurity risks across the enterprise.
  • Establish and maintain cybersecurity risk metrics, key risk indicators (KRIs), and risk appetite measures.
  • Monitor cybersecurity events, control deficiencies, audit findings, and issue remediation activities.
  • Develop executive-level dashboards, scorecards, and risk reporting for senior leadership, risk committees, and the Board.
  • Translate complex cybersecurity risks into clear business impacts and actionable recommendations.

Emerging Technology & Cybersecurity Risk Oversight


  • Provide independent oversight of cybersecurity risks associated with artificial intelligence, frontier models, autonomous agents, and other emerging technologies.
  • Assess risks related to AI-enabled cyber threats, adversarial attacks, model compromise, data exposure, and AI supply-chain vulnerabilities.
  • Evaluate cybersecurity implications of advanced AI capabilities and emerging technology adoption across the enterprise.
  • Lead oversight of enterprise preparedness for quantum computing threats and post-quantum cryptography transition efforts.
  • Monitor emerging cyber threats, technology developments, and regulatory expectations to identify risks that may impact the firm's security posture.

Issue Management, Regulatory Engagement & Assurance


  • Provide oversight of cybersecurity issues, corrective action plans, risk acceptances, and remediation activities.
  • Review and challenge issue severity, root cause analysis, remediation effectiveness, and closure decisions.
  • Support cybersecurity regulatory examinations, findings remediation, and supervisory commitments.
  • Partner with Internal Audit, Compliance, and other assurance functions to assess cybersecurity risk management effectiveness.
  • Escalate material cybersecurity risks, control concerns, and adverse trends through established governance channels.

Executive Leadership & Stakeholder Management


  • Serve as a trusted cybersecurity risk advisor to executive leadership and governance committees.
  • Build strong partnerships across technology, business, risk, audit, compliance, and regulatory stakeholders.
  • Develop board level presentations and present cybersecurity risk perspectives and recommendations to senior leadership and Executive-level forums.
  • Lead and develop a high-performing team of cybersecurity risk professionals.
  • Foster a culture of accountability, transparency, continuous improvement, and sound risk management.

Minimum Required Experiences


  • 10 or more years of experience in cybersecurity risk management, technology risk, information security, operational risk, audit, compliance, or related disciplines.
  • 5 or more years of experience leading cybersecurity, technology risk, or risk management teams.
  • Experience providing independent oversight and credible challenge of cybersecurity risk management programs.
  • Experience developing cybersecurity risk assessments, executive reporting, dashboards, and governance materials.
  • Experience engaging with executive leadership, regulators, Internal Audit, and governance committees.
  • Strong knowledge of cybersecurity risk management frameworks, governance practices, and industry standards.
  • Strong written and verbal communication skills with the ability to communicate complex risks to executive audiences.
  • Shows curiosity and adaptability in learning and responsibly applying new technologies to strengthen risk management practices.
  • Curiosity and adaptability in learning and responsibly applying new technologies, including artificial intelligence, to reimagine how we work.

Desired Experiences


  • Experience in financial services or other highly regulated industries.
  • Experience overseeing cybersecurity risks associated with artificial intelligence, machine learning, frontier models, agentic systems, or emerging technologies.
  • Knowledge of AI security risks, adversarial AI threats, model security, and AI supply-chain risks.
  • Knowledge of quantum computing risks and post-quantum cryptography migration considerations.
  • Experience developing cybersecurity KRIs, risk appetite metrics, and risk governance frameworks.
  • Knowledge of NIST CSF, NIST AI RMF, ISO 27001, COBIT, and related frameworks.
  • Professional certifications such as CISSP, CISM, CRISC, or CISA.
  • Bachelor's degree or equivalent.

Qualifications

Active Directory (AD), Active Directory (AD), Amazon Web Services (AWS), Artificial Intelligence (AI), Atlassian JIRA, Authentication Management, Backup and Recovery (Software), Business Insight Skills, Business Process Management Skills, Calendar and Scheduling Tools, Cleaning and Transforming Data, Cloud Technology, Collaborating Cross-Functionally, Communicating in Technical Writing, Communicating Technical Information, Communication, Configuration Management (CM), Conflict Resolution, Coordination, Customer and Market Insights, Customer Relationship Management (CRM), CyberArk, Cybersecurity Analysis, Data Analysis, Data Analysis Interpretation {+ 60 more}

Education:

Bachelor's Level Degree (Required), Master's Level Degree

The future is what you make it to be. Discover compelling opportunities at Fanniemae.com/careers.

For most roles, employees are expected to work onsite on a regular basis at their designated office location. In-office work cadence is determined by your manager. Proximity within a reasonable commute to your designated office location is preferred unless the job is noted as open to remote.


Fannie Mae is an equal opportunity employer and considers qualified applicants for employment without regard to race, color, religion, sex, national origin, disability, age, sexual orientation, gender identity/gender expression, marital or parental status, or any other protected factor. Fannie Mae is committed to providing reasonable accommodations to qualified individuals with disabilities who are employees or applicants for employment, unless to do so would cause undue hardship to the company. If you need assistance using our online system and/or you need a reasonable accommodation related to the hiring/application process, please complete this form.

The hiring range for this role is set forth below. Final salaries will generally vary within that range based on factors that include but are not limited to, skill set, depth of experience, certifications, and other relevant qualifications. This position is eligible to participate in a Fannie Mae incentive program (subject to the terms of the program). As part of our comprehensive benefits package, Fannie Mae offers a broad range of Health, Life, Voluntary Lifestyle, and other benefits and perks that enhance an employee's physical, mental, emotional, and financial well-being. See more here.

Requisition compensation:

200000

to

269000

Skills Required

  • 10 or more years of experience in cybersecurity risk management, technology risk, information security, operational risk, audit, compliance, or related disciplines
  • 5 or more years of experience leading cybersecurity, technology risk, or risk management teams
  • Experience providing independent oversight and credible challenge of cybersecurity risk management programs
  • Experience developing cybersecurity risk assessments, executive reporting, dashboards, and governance materials
  • Experience engaging with executive leadership, regulators, Internal Audit, and governance committees
  • Strong knowledge of cybersecurity risk management frameworks, governance practices, and industry standards
  • Strong written and verbal communication skills, including communicating complex risks to executive audiences
  • Curiosity and adaptability in learning and responsibly applying emerging technologies, including artificial intelligence
  • Bachelor's degree or equivalent
  • Experience in financial services or other highly regulated industries
  • Experience overseeing cybersecurity risks associated with artificial intelligence, machine learning, frontier models, agentic systems, or emerging technologies
  • Knowledge of AI security risks, adversarial AI threats, model security, and AI supply-chain risks
  • Knowledge of quantum computing risks and post-quantum cryptography migration considerations
  • Experience developing cybersecurity KRIs, risk appetite metrics, and risk governance frameworks
  • Knowledge of NIST CSF, NIST AI RMF, ISO 27001, COBIT, and related frameworks
  • Professional certification such as CISSP, CISM, CRISC, or CISA
  • Master's degree

Fannie Mae Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Fannie Mae and has not been reviewed or approved by Fannie Mae.

  • Retirement Support — Employer 401(k) contributions are highlighted as a standout, alongside programs like student‑loan repayment and financial‑wellness resources. These offerings signal strong long‑term savings support.
  • Parental & Family Support — Generous paid parental leave, adoption and surrogacy assistance, and backup caregiving options are part of the package. These benefits demonstrate robust support for growing families and caregivers.
  • Leave & Time Off Breadth — Generous PTO, sick leave, paid holidays, and paid volunteer time are emphasized. This breadth supports work‑life balance and schedule flexibility.

Fannie Mae Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Washington, DC
10,886 Employees
Year Founded: 1938

What We Do

Fannie Mae serves the people who house America. We are a leading source of financing for mortgage lenders, providing access to affordable mortgage financing in all markets at all times. Our financing makes sustainable homeownership and workforce rental housing a reality for millions of Americans. We also help make possible the popular 30-year, fixed-rate mortgage, which provides homeowners with stable, predictable mortgage payments over the life of the loan. Our tools and resources help homebuyers, homeowners, and renters understand their housing options. We put our customers and partners at the center of everything we do. We apply our experience and expertise to deliver innovative solutions to help our customers succeed. At Fannie Mae, our people pour their hearts into everything they do. Because we know it makes a real difference in others’ lives. We are committed to moving forward with our partners to build a stronger, safer, more efficient housing finance system. Join us to help shape the future of housing: http://fanniemae.com/careers.

Similar Jobs

ServiceNow Logo ServiceNow

Senior Customer Success Manager

Artificial Intelligence • Cloud • HR Tech • Information Technology • Productivity • Software • Automation
Remote or Hybrid
Vienna, VA, USA
29000 Employees
114K-199K Annually

Eve Logo Eve

Revenue Enablement Manager, Enterprise & Strategic Sales

Legal Tech • Software • Generative AI
Easy Apply
Remote or Hybrid
United States
180 Employees
Easy Apply
Remote or Hybrid
United States
180 Employees

Tapestry - Coach and Kate Spade Logo Tapestry - Coach and Kate Spade

Sales Support Associate I

eCommerce • Fashion • Retail • Sales • Wearables • Design
Hybrid
Berkeley Hills, Williamsburg, VA, USA
16000 Employees
15-20 Hourly

Similar Companies Hiring

Granted Thumbnail
Artificial Intelligence • Healthtech • Insurance • Mobile • Financial Services
New York, New York
23 Employees
Hanover Park Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
42 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account