Principal Security Engineer
Fannie Mae
Playing an essential role in the U.S. economy, Fannie Mae is foundational to housing finance. Here, your expertise can help fuel purpose-driven innovation that expands access to homeownership and affordable rental housing across the country. Join Fannie Mae to grow your career and help people find a place to call home.Job DescriptionFannie Mae is seeking a highly experienced Principal Security Engineer to serve as a senior technical authority for enterprise infrastructure security. This role leads the research, architecture, design, implementation, integration, and ongoing support of security capabilities spanning cloud, network, server, endpoint, application, DevSecOps, and artificial intelligence environments.The ideal candidate combines deep cybersecurity, cloud, infrastructure, and network expertise with hands-on full-stack engineering experience. This role will shape enterprise-scale security architecture, automate and integrate controls, review code and configurations, secure AI-enabled systems, and communicate clear recommendations to engineers, business partners, and leaders.THE IMPACT YOU WILL MAKE The Principal Security Engineer role will offer you the flexibility to make each day your own, while working alongside people who care so that you can deliver on the following responsibilities: Cybersecurity Engineering and Technical Leadership• Lead the evaluation, architecture, implementation, integration, and lifecycle support of enterprise security solutions using established cybersecurity and engineering principles.• Provide principal-level technical direction for projects, products, platforms, applications, and infrastructure; identify systemic risks and drive remediation from design through operations.• Develop strategic recommendations on security technologies, architecture, implementation approaches, and long-term technical direction.• Maintain expertise in evolving technologies, vulnerabilities, attack techniques, products, and industry trends; mentor engineers and influence decisions across teams without relying on direct authority.• Promote security as an enabler of resilient technology delivery, cloud adoption, product innovation, and responsible AI.Cloud and Infrastructure Security• Define and implement security architecture, standards, reusable patterns, guardrails, and landing-zone controls across AWS, Google Cloud, Microsoft Azure, hybrid, and multi-cloud environments.• Design identity-centric and zero-trust controls for segmentation, private connectivity, federation, encryption, key and secrets management, centralized logging, monitoring, and policy-driven governance.• Secure virtual machines, containers, Kubernetes, serverless services, APIs, databases, storage, managed services, and data-processing platforms.• Implement and operate cloud security posture, workload protection, entitlement management, configuration compliance, vulnerability management, and threat detection capabilities.• Partner with platform teams to embed security through Infrastructure as Code, reusable modules, reference architectures, architecture reviews, migrations, and cloud-native modernization.• Analyze configurations and telemetry to identify misconfigurations, excessive privilege, exposed services, policy violations, vulnerabilities, and indicators of compromise.Server and Endpoint Security• Establish hardening standards and configuration baselines for Windows, Linux, virtualized, containerized, and cloud-hosted server environments.• Define and implement endpoint controls including EDR, anti-malware, host firewalls, encryption, application control, vulnerability management, privileged access management, and device posture validation.• Improve visibility through centralized logging, monitoring, asset inventory, configuration management, vulnerability assessment, and security telemetry.• Automate secure configuration, patching, vulnerability remediation, credential and certificate management, backup protection, recovery, remote administration, and system lifecycle processes.• Evaluate, deploy, integrate, and operate server and endpoint security technologies; analyze findings and compliance results to prioritize remediation.Application and Artificial Intelligence Security• Lead application and AI security policies, standards, design patterns, control frameworks, and technical guardrails across traditional applications, machine-learning platforms, generative AI, and agentic systems.• Architect and review secure designs for LLMs, foundation models, RAG pipelines, AI agents, tool-using workflows, automated decision-making, and AI-enabled business processes.• Define controls for prompts, tools, agent memory, service identities, authorization, data access, autonomy limits, human approval, escalation and shutdown, observability, output validation, and content safety.• Lead threat modeling, abuse-case and misuse analysis, red teaming, security testing, and risk assessments for AI pipelines, training and inference data, vector databases, retrieval systems, plugins, APIs, and external model providers.Security Requirements, Architecture, and Documentation• Develop and maintain security requirements, architecture artifacts, technical designs, implementation and test plans, policies, standards, procedures, control specifications, and operational documentation.• Create architecture and data-flow diagrams, threat models, control mappings, integration designs, technical specifications, and support documentation.• Translate regulatory, privacy, risk, business, and responsible AI obligations into measurable technical controls and acceptance criteria.• Validate control implementation and effectiveness before production deployment and maintain accurate documentation of architecture, dependencies, data flows, configurations, support, and recovery processes.• Define reusable reference architectures and secure design patterns for cloud, network, infrastructure, application, and AI environments.Collaboration, Leadership, and Influence• Partner across cybersecurity, engineering, product, cloud, infrastructure, networking, operations, application development, data, privacy, compliance, legal, architecture, and responsible AI teams.• Influence product roadmaps, architecture decisions, development practices, and operating models while balancing security, privacy, compliance, cost, performance, availability, and delivery priorities.• Lead technical discussions on architecture, engineering solutions, implementation options, platform capabilities, and risk tradeoffs.• Build productive relationships with internal teams, technology vendors, managed service providers, and external support organizations; mentor senior and principal engineers and raise organizational security maturity.Communication and Executive Engagement• Communicate complex technical concepts to engineering, operations, product, risk, compliance, business, and executive audiences.• Develop and deliver architecture presentations, technical briefings, risk assessments, implementation plans, engineering recommendations, and executive summaries.• Facilitate design reviews, architecture forums, technical evaluations, incident discussions, and stakeholder decision meetings.• Translate cybersecurity issues into business impact, risk exposure, operational considerations, tradeoffs, and actionable decisions.• Address risks such as prompt injection, indirect prompt injection, sensitive-data leakage, insecure tool use, model poisoning, excessive privileges, hallucinated actions, and unsafe autonomous behavior.• Partner with AI, product, application, data, privacy, legal, compliance, and responsible AI teams; evaluate emerging tools and standards; advise leadership on risk, regulation, investment, and roadmap priorities.Security Requirements, Architecture, and Documentation• Develop and maintain security requirements, architecture artifacts, technical designs, implementation and test plans, policies, standards, procedures, control specifications, and operational documentation.• Create architecture and data-flow diagrams, threat models, control mappings, integration designs, technical specifications, and support documentation.• Translate regulatory, privacy, risk, business, and responsible AI obligations into measurable technical controls and acceptance criteria.• Validate control implementation and effectiveness before production deployment and maintain accurate documentation of architecture, dependencies, data flows, configurations, support, and recovery processes.• Define reusable reference architectures and secure design patterns for cloud, network, infrastructure, application, and AI environments.Collaboration, Leadership, and Influence• Partner across cybersecurity, engineering, product, cloud, infrastructure, networking, operations, application development, data, privacy, compliance, legal, architecture, and responsible AI teams.• Influence product roadmaps, architecture decisions, development practices, and operating models while balancing security, privacy, compliance, cost, performance, availability, and delivery priorities.• Lead technical discussions on architecture, engineering solutions, implementation options, platform capabilities, and risk tradeoffs.• Build productive relationships with internal teams, technology vendors, managed service providers, and external support organizations; mentor senior and principal engineers and raise organizational security maturity.THE EXPERIENCE YOU BRING TO THE TEAMMinimum Required Experiences8 years of experience.Extensive experience in cybersecurity engineering, infrastructure or network security, cloud engineering, application security, software engineering, or a related technical discipline.Significant hands-on experience securing production environments in AWS, Google Cloud, and Microsoft Azure.Deep knowledge of cloud security architecture, IAM, networking, encryption, logging, monitoring, workload protection, governance, and enterprise network security, including segmentation, firewalls, proxies, VPNs, DNS security, secure web gateways, IPS, load balancing, ZTNA, and SASE.Experience securing Windows and Linux servers, endpoints, databases, containers, Kubernetes, and cloud-hosted workloads.Hands-on experience designing, integrating, and securing CI/CD pipelines and implementing automated security testing, secure release controls, and policy enforcement.Experience with Infrastructure as Code, including Terraform, CloudFormation, Bicep, ARM templates, or equivalent tools.Full-stack engineering experience across front-end applications, back-end services, APIs, databases, cloud services, identity platforms, and supporting infrastructure.Proficiency in one or more languages such as Python, Go, Java, JavaScript, TypeScript, C#, PowerShell, Bash, or Ruby; experience building integrations through APIs, automation, orchestration, and vendor-supported methods.Strong knowledge of secure software development, application and API security, cloud-native development, containers and registries, Kubernetes security, and software supply chain risks.Experience with SIEM, EDR, vulnerability management, network security platforms, cloud-native security services, IAM, PAM, secrets, certificates, keys, and cryptographic controls.Experience developing security requirements, architecture artifacts, technical designs, implementation and test plans, policies, standards, procedures, proofs of concept, product evaluations, technical testing, data analysis, and architecture assessments.Knowledge of AI security risks and experience applying threat modeling and secure design practices to modern applications, APIs, cloud platforms, or AI-enabled systems.Demonstrated ability to lead complex, cross-functional technical initiatives and communicate effectively with engineers, administrators, executives, and technical decision-makers.Strong analytical, problem-solving, troubleshooting, writing, presentation, and stakeholder-management skills.Ability and willingness to participate in an on-call rotation and support major outages, critical service issues, and cybersecurity incidents.Desired ExperiencesExperience designing security controls for large-scale, regulated, highly available, geographically distributed, or global enterprise environments.Experience with CSPM, CWPP, CIEM, DSPM, attack-path management, cloud-delivered security platforms, and zero-trust architecture across users, devices, networks, applications, services, and workloads.Experience with AI security architecture, generative AI, LLM applications, RAG pipelines, agent frameworks, model gateways, responsible AI controls, AI red teaming, adversarial testing, model risk assessment, or abuse-case analysis.Experience with threat-modeling methodologies, security architecture frameworks, penetration testing, red-team, purple-team, and adversarial simulation activities.Familiarity with NIST Cybersecurity Framework, NIST 800-53, CIS Benchmarks, ISO 27001, SOC 2, PCI DSS, OWASP, MITRE ATT&CK, MITRE ATLAS, or comparable standards.Professional Certifications: Relevant industry certifications such as CISSP, CCSP, PCNSE, AWS Certified Security – Specialty, AWS Certified Advanced Networking – Specialty, Google Professional Cloud Security Engineer, Microsoft Certified: Azure Security Engineer Associate, GIAC certifications, or equivalent credentials.Information Security Technology - Engineering - Principal 200,000.00 - 269,000.00 JR2746QualificationsEducation:Bachelor's Level Degree (Required)The future is what you make it to be. Discover compelling opportunities at Fanniemae.com/careers.For most roles, employees are expected to work onsite on a regular basis at their designated office location. In-office work cadence is determined by your manager. Proximity within a reasonable commute to your designated office location is preferred unless the job is noted as open to remote.Fannie Mae is an equal opportunity employer and considers qualified applicants for employment without regard to race, color, religion, sex, national origin, disability, age, sexual orientation, gender identity/gender expression, marital or parental status, or any other protected factor. Fannie Mae is committed to providing reasonable accommodations to qualified individuals with disabilities who are employees or applicants for employment, unless to do so would cause undue hardship to the company. If you need assistance using our online system and/or you need a reasonable accommodation related to the hiring/application process, please complete this form.The hiring range for this role is set forth below. Final salaries will generally vary within that range based on factors that include but are not limited to, skill set, depth of experience, certifications, and other relevant qualifications. This position is eligible to participate in a Fannie Mae incentive program (subject to the terms of the program). As part of our comprehensive benefits package, Fannie Mae offers a broad range of Health, Life, Voluntary Lifestyle, and other benefits and perks that enhance an employee's physical, mental, emotional, and financial well-being. See more here.Requisition compensation:200000to269000SummaryLocation: Reston, VA; Plano, TXType: Full time
$107.5k - $204.5k
...Requirements:Active and transferable U.S. government issued security clearance is required prior to start date. U.S.... ...protecting our nation and our products. We are seeking a Principal Systems Engineer - Cybersecurity, to function as a key contributor for the...SuggestedContract workTemporary workWork experience placementWork at officeRemote workRelocation packageFlexible hours$107.5k - $204.5k
...and transferable U.S. government issued security clearance is required prior to start... ...than 100 years of experience and renowned engineering expertise to meet the needs of today’s... ...aerospace and defense.Raytheon is seeking a Principal Systems Security Engineer - Anti-Tamper...SuggestedTemporary workWork experience placementWork at officeRemote workRelocation packageFlexible hours- ...Overview Principal Systems Engineer – Cybersecurity role onsite in Richardson, TX. Active and transferable U.S. government issued Top Secret security clearance is required prior to start date. U.S. citizenship is required for eligibility for a security clearance. Relocation...SuggestedRelocation package
$112k - $149k
...you want to be part of an inclusive, adaptable, and forward-thinking organization, apply now.We are currently seeking a Network Security Engineer -Hybrid - Plano, Texas to join our team in Plano, Texas (US-TX), United States (US).Prior to Applying, please review and...SuggestedTemporary workWork at officeRemote workFlexible hoursShift work- ...Business consulting services. We are in search of a highly motivated candidate to join our talented Team. Job Title: Network Security Engineer (Prisma SDWAN). Location: Richardson, TX. Description:This role is an SME remotely supporting the customer and viewed as a...SuggestedContract workFor subcontractorRemote work
- ...data analysis across systems, coordinate insights on system behavior, and support capacity planning to optimize performance Conduct security checks, recovery drills, and compliance audits, implement security measures, and coordinate continuity plans to maintain adherence...Permanent employmentFull timeTemporary workRelocation
- ...where you'll be a key part of a high-performing team delivering secure software solutions. Make a real impact as you help shape the... ...world's largest and most influential companies. As a Security Engineer at JPMorgan Chase within the Cybersecurity & Technology Controls...
- ...involvement in technology innovation, ERP and CRM counselling, Product Engineering, Business Intelligence, Data Management, SOA, BPM, Data... ...development and business keenness.Job DescriptionNetwork security engineers6+ MonthsRichardson, TX.Need GC AND USCTop Three Skills...Worldwide
- ...Business consulting services. We are in search of a highly motivated candidate to join our talented Team. Job Title: Network Security Engineer / EEC. Location: Richardson, TX. Job Description: Your CareerYou will provide guidance and technical support to clients...
- DESCRIPTION:Duties: Responsible for the design, security engineering, and development of an enterprise-grade crypto wallet platform. Design and implement high-performance, secure, resilient, fault-tolerant distributed systems. Implement advanced cryptographic protocols...
$156.5k - $230k
...with opportunities to learn, grow, and make an impact. Join us!Job Description:This job is responsible for defining and leading the engineering approach for solutions at the program or portfolio level, to deliver significant business outcomes. Key responsibilities include...Full timeWork experience placementWork at officeFlexible hoursShift workDay shift- ...transformation of information into intelligence, inspiring the world to learn, communicate and advance faster than ever.The Principal Engineer - HBM Design for Test (DFT) is a senior technical contributor responsible for defining, deploying, and sustaining best‑in‑class...Full timeLocal areaImmediate start
$156.5k - $230k
...Description:This job is responsible for defining and leading the engineering approach for solutions at the program or portfolio level, to... ...-e.g. pairing, code reviewsLead the design and development of secure, scalable financial blockchain applications, with a focus on...Full timeWork at officeDay shift- ...architectures, and deep system‑level thinking, we deliver the highest bandwidth with the lowest power per bit in the industry.As a Principal Engineer in HBM IO Design Architecture, you will be the technical authority for HBM IO circuits and PHY architecture. You will lead...Full timeLocal areaImmediate start
$146k - $309k
...transformation of information into intelligence, inspiring the world to learn, communicate and advance faster than ever.As a Principal SoC DFT Engineer within the Heterogeneous Integration Group (HIG), you will be responsible for the DFT architecture, implementation, and...Full timeLocal areaImmediate start$60 - $70 per hour
...shifts. Handles tunings, stakeholder requests, escalations, reporting, and trainings as part of Platform and Content Engineering. Administers security tools to gather security logs from the environment. Performs lifecycle management of supported security tools/...Temporary workRemote workFlexible hoursShift work- ...Network Security Engineer Location: Plano, TX (Onsite) Duration: Full-time only Job Description: Must Have Technical/Functional Skills • Network Protocols: • TCP/IP, UDP, BGP, OSPF, EIGRP, MPLS, ISIS • Layer 4 (Transport Layer): • TCP, UDP, SSL termination...Full timeImmediate startRelocation
- ...Network Security Engineer Location: Plano, TX – Onsite Fulltime Job Description Must Have Technical/Functional Skills • Experience: 10 years in network security engineering, application delivery, or similar roles. • Infoblox: Hands-on experience with Infoblox...Full timeLocal area
$112k - $149k
...Network Security Engineer - Hybrid NTT DATA strives to hire exceptional, innovative and passionate individuals who want to grow with us. If you want to be part of an inclusive, adaptable, and forward-thinking organization, apply now. We are currently seeking a Network...Temporary workRemote workFlexible hoursShift work- ...Network Security Engineer Position Responsibilities: Network Security Engineer Location: Jersey City, NJ, Plano, TX, Columbus OH (3 days onsite 2 days remote) W2 Contract Only SASE Solutions – Network Solutions Eng to Build out Web Proxy for SASE Need SSE experience...Contract workRemote work
- ...TTS-US with it's 8 TTS affiliates worldwide is establishing a secure and resilient Toyota global value chain. The creative capacity... ...and capacity planning. Essential Functions: Security Engineering : Lead implementation of cybersecurity tools and services. Provide...Worldwide
$160k - $190k
...military customers, to space research laboratories. The Principal RF Engineer is an Individual Contributor, with proficiency in electrical... ...candidates must be able to obtain and maintain a Secret security clearance issued by the U.S. Government throughout the course...Full timeContract workFlexible hours- Job Title: Network Security Engineer Location: TechM US Texas Plano Years of Experience: 10 15 Years Job Summary: We are seeking a highly skilled Network Security Engineer with extensive experience in firewall technologies, specifically Palo Alto, Fortigate, and Cisco...
- A network security firm based in Texas is seeking a Mid-Senior level contract technical advisor. The role involves providing expertise... ...Firewall technologies, working closely with Product and Engineering teams, and ensuring customer satisfaction. Candidates should possess...Contract work
- JPMorgan Chase is seeking a Senior Lead Security Engineer to join their team in Plano, Texas. In this role, you will be integral to developing secure software solutions and addressing cybersecurity challenges with technical expertise. The position requires significant experience...
- ...Intelligence, Surveillance & Reconnaissance), Aviation, and Security (IAS) business area is a leader in ISR and aviation, it is... ...united and sustain our way of living. Join our team! As a Principal Systems Engineer, you will demonstrate mastery in requirements engineering,...Full time
- ...Intelligence, Surveillance & Reconnaissance), Aviation, and Security (IAS) business area is a leader in ISR and aviation, it... ...in a rapid and agile production environment. As a Senior Principal Mechanical Engineer, you will be at the forefront of our mechanical...Full timeWork at office
$132.4k - $251.6k
...Requirements:Active and transferable U.S. government issued security clearance is required prior to start date. U.S.... ...don’t just build systems; we build the future. As a Senior Principal Systems Engineer, you’ll support programs involved in modernizing the U.S....Temporary workWork experience placementWork at officeRemote workRelocationFlexible hours$107.5k - $204.5k
...and transferable U.S. government issued security clearance is required prior to start date... ...required on day 1Principal Systems Engineer - NC3 Programs (Onsite)At RTX, the world... ...recapitalization programs. As our next Principal Systems Engineer and as a member of our...Temporary workWork experience placementWork at officeLocal areaRemote workRelocationRelocation packageFlexible hours$107.5k - $204.5k
...and transferable U.S. government issued security clearance is required prior to start... ...than 100 years of experience and renowned engineering expertise to meet the needs of today’s... ...Department has an immediate need for a Principal Electrical Engineer to serve as a senior...Contract workTemporary workWork experience placementWork at officeImmediate startRemote workFlexible hours
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Principal Security Engineer. Be the first to apply!
- principal network engineer Plano, TX
- principal engineer Plano, TX
- principal infrastructure engineer Plano, TX
- senior civil engineer project manager Plano, TX
- senior chief engineer Plano, TX
- engineering director Plano, TX
- senior director engineering Plano, TX
- principal developer Plano, TX
- general engineer Plano, TX
- data center chief engineer Plano, TX


