Senior Director of Security Configuration Management & Cyber Governance
Fannie Mae
Senior Director of Security Configuration Management & Cyber Governance
Playing an essential role in the U.S. economy, Fannie Mae is foundational to housing finance. Here, your expertise can help fuel purpose-driven innovation that expands access to homeownership and affordable rental housing across the country. Join Fannie Mae to grow your career and help people find a place to call home.
In this compelling leadership position, you will plan and direct a function and team responsible for designing, developing, testing, or maintaining hardware, technology, or processes, and ensure the coordination of business unit operational activities.
The Senior Director of Security Configuration Management & Cyber Governance is a strategic cybersecurity leader responsible for establishing, governing, and continuously improving enterprise-wide security configuration management, cyber governance, compliance, and risk oversight programs. This role ensures the organization's technology assets, platforms, and services are securely configured, governed according to industry best practices, and aligned with regulatory, business, and risk management objectives.
The Senior Director will lead multidisciplinary teams responsible for security baselines, configuration standards, governance frameworks, policy management, compliance oversight, control effectiveness, and cyber risk reporting. This leader serves as a trusted advisor to executive leadership, technology organizations, audit partners, regulators, and business stakeholders to strengthen the organization's cybersecurity posture while enabling business transformation and innovation.
Key Responsibilities
Strategic Information Security Leadership & Governance
- Develop and execute the enterprise strategy for security configuration management and cyber governance.
- Provide executive-level reporting on cyber risk, control effectiveness, compliance posture, and configuration management maturity aligned with risk appetite.
- Partner with business, technology, risk, legal, compliance, and audit stakeholders to ensure consistent governance practices across the Information Security organization.
- Drive continuous improvement initiatives that enhance operational resilience, security effectiveness, and regulatory readiness.
- Monitor emerging cyber threats, vulnerabilities, and industry trends to proactively address risks.
Security Configuration Management
- Establish enterprise security configuration standards, baselines, and hardening requirements across cloud, SaaS and on-prem software services.
- Ensure secure configuration controls are integrated into system development, deployment, and operational processes.
- Oversee configuration compliance monitoring, risk prioritization, remediation governance and executive reporting.
- Lead initiatives to automate configuration management, compliance validation, and security configuration enforcement.
- Define key performance indicators (KPIs), key risk indicators (KRIs), and metrics to measure security configuration compliance and risk reduction outcomes.
- Ensure alignment with industry frameworks such as NIST, CIS Benchmarks and relevant regulatory requirements.
- Drive continuous improvement of configuration compliance, and security control effectiveness.
- Ensure timely remediation of security misconfigurations across the enterprise.
- Lead security configuration management assessments and audits conducted by internal audit, regulators, and external parties. Ensure effective remediation of audit findings and regulatory observations.
Cyber Governance
- Lead cyber assurance governance program, partnering with Information Security Standard owners to define key requirements and monitor s.
- Lead development of governance dashboards, scorecards, and metrics that provide transparency into control performance, compliance posture, risk trends, and remediation progress.
- Present cybersecurity risks, trends, and remediation status to executive leadership, risk committees, and governance forums.
- Monitor emerging cybersecurity threats, regulatory developments, and industry trends to proactively evolve governance practices.
- Ensure alignment with enterprise risk management frameworks and regulatory expectations.
Leadership & People Management
- Build, lead, mentor, and develop high-performing teams focused on security governance, security configuration management, and cyber risk oversight.
- Foster a culture of accountability, innovation, collaboration, and continuous learning.
- Establish clear goals, performance expectations, and development plans for leaders and team members.
- Drive workforce planning, succession planning, talent acquisition, and leadership development initiatives.
- Manage budgets, vendor relationships, and strategic initiatives.
- Influence and inspire cross-functional teams without direct authority to achieve strategic cybersecurity objectives.
- Promote strong partnerships across technology, security operations, engineering, architecture, risk, compliance, and business functions.
- Serve as a key cybersecurity representative to executive leadership committees and governance forums.
- Communicate complex technical and risk topics in clear business terms appropriate for executive and board-level audiences.
- Build strong relationships with regulators, auditors, industry peers, and external partners.
- Influence strategic technology decisions through cybersecurity governance and risk management expertise.
Minimum Required Experiences
- Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Engineering, or related field.
- 8 years of progressive experience in cybersecurity, information security, risk management, governance, or technology leadership roles.
- 8+ years of leadership experience managing large teams and senior-level managers.
- Demonstrated experience leading enterprise-scale security configuration management, cyber governance, risk, compliance, or security engineering programs.
- Deep understanding of cybersecurity frameworks, standards, and regulations including NIST CSF, NIST 800-53, CIS Controls, ISO 27001, COBIT, and relevant regulatory requirements.
- Deep knowledge of cloud security, infrastructure security, endpoint security, security configuration management, and security operations.
- Experience presenting cybersecurity strategies, risks, and performance metrics to executive leadership and executive committees.
- Proven ability to lead organizational change and drive adoption of enterprise security initiatives.
- Bachelor's degree in Information Security, Cybersecurity, Computer Science, Information Systems, Risk Management, or related field.
- Strong understanding of regulatory requirements applicable to financial services or highly regulated industries.
- Shows curiosity and adaptability in learning and responsibly applying new technologies, including artificial intelligence, to reimagine how we work.
Desired Experiences
- Master's degree in Cybersecurity, Information Security, Business Administration, or related discipline.
- Industry certifications such as CISSP, CISM, CRISC, CGEIT, CISA, or equivalent.
- Experience within highly regulated industries such as financial services, government, healthcare, or critical infrastructure.
- Experience implementing governance and security configurations and controls across hybrid cloud and modern technology environments.
- Knowledge of DevSecOps, Infrastructure as Code (IaC), automated compliance monitoring, and security orchestration technologies.
Leadership Competencies
- Strategic Thinking and Vision
- Executive Presence and Influence
- Risk-Based Decision Making
- Talent Development and Coaching
- Organizational Leadership
- Change Management
- Cross-Functional Collaboration
- Operational Excellence
- Accountability and Results Orientation
Qualifications
Active Directory (AD), Amazon Web Services (AWS), Artificial Intelligence (AI), Atlassian JIRA, Authentication Management, Backup and Recovery (Software), Business Insight Skills, Business Process Management Skills, Calendar and Scheduling Tools, Cleaning and Transforming Data, Cloud Technology, Collaborating Cross-Functionally, Communicating in Technical Writing, Communicating Technical Information, Communication, Configuration Management (CM), Conflict Resolution, Coordination, Customer and Market Insights, Customer Relationship Management (CRM), CyberArk, Cybersecurity Analysis, Data Analysis, Data Analysis Interpretation {+ 60 more}
Education:
Bachelor's Level Degree (Required), Master's Level Degree
The future is what you make it be. Discover compelling opportunities at Fanniemae.com/careers.
For most roles, employees are expected to work onsite on a regular basis at their designated office location. In-office work cadence is determined by your manager. Proximity within a reasonable commute to your designated office location is preferred unless the job is noted as open to remote.
Fannie Mae is an equal opportunity employer and considers qualified applicants for employment without regard to race, color, religion, sex, national origin, disability, age, sexual orientation, gender identity/gender expression, marital or parental status, or any other protected factor. Fannie Mae is committed to providing reasonable accommodations to qualified individuals with disabilities who are employees or applicants for employment, unless to do so would cause undue hardship to the company. If you need assistance using our online system and/or you need a reasonable accommodation related to the hiring/application process,
- ...Everforth ECS is seeking a Senior Configuration Manager to work in the... ..., Joint Staff directorates, Senior Executive Service... ...baselines, and technical governance structures across IL... ...virtual machines, secured containers, and... ...enclave accreditation, cyber inspection cycles,...CyberSeniorContract work
- ...a Quality Assurance Lead - Senior to support the Army National... ...oversee quality assurance governance activities throughout the software... ...practices that support configuration management and release control.... ...DoD 8140.03 Compliance: DoD Cyber Workforce Framework (DCWF)...CyberSeniorContract workLocal area
- ...Lead Cyber Security Systems Engineer - Senior Summary: Supervise and direct the engineering effort for the... ...projects approved by the program management. Duties, Tasks, and Responsibilities... ...Maintain system baselines and configuration management items, including security...CyberSenior
- ...contract award The Senior Information... ...cybersecurity compliance, governance, and risk management across Army IMCOM-E... ...), supports Command Cyber Readiness Inspections... ...ensure compliance with security controls. Develop... ...design changes, configuration control boards, and...CyberSeniorContract work
- ...Senior Configuration Manager ACTIVE TS/SCI CLEARANCE with FS poly REQUIRED TO BE CONSIDERED FOR... ...TENICA and Associates is a provider of government services and consulting solutions... ...of national defense, homeland and cyber security. TENICA provides knowledgeable and...CyberSenior
- ...Senior VMWare Virtualization Architect/Engineer... ...and NSX-based network/security services. Engineer... ...host profiles, and image management; implement automation... ...provisioning, patching, and configuration drift remediation.... ...reporting; partner with cyber to close POA&Ms...CyberSenior
$140k - $175k
...Risk Senior Manager SC&H's Risk Practice is seeking a... ...with a strong focus on security-related consulting,... ...Assurance, Tax, and other Cyber/Technology teams.... ...implementation for AI governance. Oversee delivery... ...identity and access, change/configuration, secure engineering,...CyberSenior- ...connecting the space, air, land, sea and cyber domains in the interest of national security. Job Title: Senior Specialist, Configuration Management Job Code: 35444 Job Location:... ...of employment may be subject to government security investigation(s) and must meet...CyberSeniorLocal area
$147k - $179k
...Senior Systems Storage Engineer The Senior... ...Architect and manage enterprise storage... ...builds, zoning, and configuration baselines. Engineer... ...-optimized and secure storage... ...collaborate with cyber, network, and virtualization... ...needs of our Federal Government customers. We...CyberSeniorFull timeContract workTemporary workLocal areaShift work- ...Infrastructure Management-VMWare Lead - Senior Everforth ECS is seeking a Infrastructure... ...services. Oversee configurations of hypervisors and manage... ...teams to maintain secure virtualization platforms.... ...DoD 8140.03 Compliance: DoD Cyber Workforce Framework (DCWF)...CyberSeniorContract work
$137k - $169k
...Senior Infrastructure Service Lead The Senior Infrastructure... ...). Establish service governance frameworks, SLAs/SLOs, and... ...integration points. Ensure secure configurations aligned to STIG/SCAP... ...optimization, and service reliability management. Lead daily operational...SeniorFull timeContract workTemporary workLocal areaShift work- ...SOC Team Lead - Senior ECS is seeking a SOC Team Lead - Senior to support the... ...Support — by implementing, configuring, and maintaining security engineering solutions that enable SOC... ...environment such as the NETCOM Global Cyber Center, DISA DCDC, USIEM analytics,...CyberSeniorContract work
- ...in Virginia is seeking an experienced professional with at least 5 years in Cybersecurity or related fields and 3 years in People Management. Ideal candidates will possess relevant certifications like CISSP, CISA, or AIGP. The company offers inclusive health and...CyberSenior
- ...SOC Vulnerability Management AESS Lead - Senior ECS is seeking a SOC... ...role leads endpoint security scanning and... ...with the NETCOM Global Cyber Center, DISA DCDC, SOC... ...vulnerabilities. Oversee configuration, sustainment, and... ..., cybersecurity governance, and enterprise risk...CyberSeniorContract work
$200.7k - $229.1k
Capital One National Association is looking for a Sr. Manager, Cyber Risk & Analysis in McLean, VA. In this strategic leadership role, you will shape technology risk posture, design AI applications for risk management, and oversee large-scale architectural transformation...CyberSenior- ...SOC Vulnerability Management Team Lead - Senior ECS is seeking a SOC Vulnerability... ...- Senior helps sustain cyber readiness for Title 10 and... ...USIEM, eMASS, and enterprise security capabilities supporting... ...remediation effectiveness and configuration compliance against...CyberSeniorContract work
- ...SOC Vulnerability Management ACAS Lead - Senior ECS is seeking a SOC... ...vulnerability governance. This position directly... ...with NETCOM Global Cyber Center and DISA DCDC... ...reduction. Oversee configuration, sustainment, and... ...Citizenship is required Security Clearance: Secret...CyberSeniorContract work
- ...Infrastructure Management-UC Administrator - Senior Everforth ECS is seeking an Infrastructure... ...environments. Manage secure communications infrastructure and configure call routing and conferencing... ...DoD 8140.03 Compliance: DoD Cyber Workforce Framework (DCWF) Work...CyberSeniorContract work
- ...Maintenance Lead - Senior Everforth ECS... ...availability management and preventive maintenance... ...reporting to Government stakeholders.... ...with cybersecurity, configuration management, and... ...Compliance: DoD Cyber Workforce Framework... ...SecurityX / CASP+, CCNP Security, CCSP, FITSP-O,...CyberSeniorContract work
- ...Configuration Manager - Senior Everforth ECS is seeking a Configuration Manager... ...ensuring compliance with Government configuration control board... ...maintain the integrity and security of configuration items.... ...DoD 8140.03 Compliance: DoD Cyber Workforce Framework (DCWF)...CyberSeniorContract work
- ...Infrastructure Management-VDI Administrator - Senior Everforth ECS is seeking an Infrastructure... ..., and access control configurations. Perform system... ...network teams to maintain secure and scalable VDI services... ...8140.03 Compliance: DoD Cyber Workforce Framework (DCWF...CyberSeniorContract work
$177.7k - $202.8k
Senior Manager, Project Management - Learning Platforms Operations Lead Capital One’s Enterprise... ...team is seeking an analytical, governance-minded, and partner-first lead to serve... ...Associate Experience, access management, cyber) and negotiate for prioritization that...CyberSeniorFull timeLocal area$195k - $240k
...Job Description Senior Telecom Software... ...provides analytic and cyber solutions... ...engage directly with government customers on-site... ...participate in Program Management Reviews (PMRs) to... ...U.S. national security community and its... ...with network configuration and performance metrics...CyberSeniorWork at officeLocal areaRemote workFlexible hours$150.45k - $233.45k
Information Security Governance Senior Manager Company: The Boeing Company The Boeing Company is looking for a highly experienced and detail-oriented... ...succession candidate and bench-strength builder across Boeing’s cyber leadership cadre. Position Responsibilities: Oversee day-...CyberSeniorPermanent employmentFull timeRelocationVisa sponsorshipWork visaRelocation packageFlexible hoursShift work- ...SOC Security Engineering Team Lead - Senior ECS is seeking a SOC Security Engineering Team Lead - Senior to... ...team responsible for implementing, configuring, and sustaining security engineering... ...to deliver DoDIN services and cyber defense for more than 120,000 users...CyberSeniorContract work
- ...Architecture (EA) - provides architecture governance, data management, and IT planning services that ensure... ...traceability, thereby supporting the configuration control and publication processes. By... ...DoD 8140.03 Compliance: DoD Cyber Workforce Framework (DCWF) Work Role...CyberContract work
- ...SharePoint Service Lead - Senior Everforth ECS... ...Lead and manage enterprise SharePoint... ...effective platform governance and site... ...Develop and enforce configuration management standards... ...updates and ensure secure collaboration capabilities... ...3 Compliance: DoD Cyber Workforce...CyberSeniorContract work
- ...provides architecture governance, data management, and IT planning... ...infrastructure are robust, secure, and aligned with... ...closely with senior team members to drive... ...system enhancements with configuration management and... ....03 Compliance: DoD Cyber Workforce Framework...CyberContract work
- ...provides architecture governance, data management, and IT planning... ...collaborating with senior engineers to implement... ...with the installation, configuration, and maintenance of... ....03 Compliance: DoD Cyber Workforce Framework... ...Information Systems Security Professional (CISSP)...CyberContract work
- ...Services Lead - Senior Everforth ECS is... ...Identity and Access Management (IdAM) services.... ...adherence to identity governance procedures.... ...findings to maintain secure identity... ...policies and enterprise configuration management... ...Compliance: DoD Cyber Workforce Framework...CyberSeniorContract workLocal area
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Senior Director of Security Configuration Management & Cyber Governance. Be the first to apply!
- senior director clinical development Reston, VA
- senior cloud solutions architect Reston, VA
- senior strategic account manager Reston, VA
- sr technical product manager Reston, VA
- senior account executive Reston, VA
- senior director continuous improvement Reston, VA
- senior performance engineer Reston, VA
- senior sourcing engineer Reston, VA
- senior customer service manager Reston, VA
- senior manager diversity & inclusion Reston, VA


