Principal Security Engineer
Fannie Mae
Playing an essential role in the U.S. economy, Fannie Mae is foundational to housing finance. Here, your expertise can help fuel purpose-driven innovation that expands access to homeownership and affordable rental housing across the country. Join Fannie Mae to grow your career and help people find a place to call home.
Job Description Fannie Mae is seeking a highly experienced Principal Security Engineer to serve as a senior technical authority for enterprise infrastructure security. This role leads the research, architecture, design, implementation, integration, and ongoing support of security capabilities spanning cloud, network, server, endpoint, application, DevSecOps, and artificial intelligence environments. The ideal candidate combines deep cybersecurity, cloud, infrastructure, and network expertise with hands-on full-stack engineering experience. This role will shape enterprise-scale security architecture, automate and integrate controls, review code and configurations, secure AI-enabled systems, and communicate clear recommendations to engineers, business partners, and leaders. THE IMPACT YOU WILL MAKE The Principal Security Engineer role will offer you the flexibility to make each day your own, while working alongside people who care so that you can deliver on the following responsibilities:Cybersecurity Engineering and Technical Leadership • Lead the evaluation, architecture, implementation, integration, and lifecycle support of enterprise security solutions using established cybersecurity and engineering principles. • Provide principal-level technical direction for projects, products, platforms, applications, and infrastructure; identify systemic risks and drive remediation from design through operations. • Develop strategic recommendations on security technologies, architecture, implementation approaches, and long-term technical direction. • Maintain expertise in evolving technologies, vulnerabilities, attack techniques, products, and industry trends; mentor engineers and influence decisions across teams without relying on direct authority. • Promote security as an enabler of resilient technology delivery, cloud adoption, product innovation, and responsible AI. Cloud and Infrastructure Security • Define and implement security architecture, standards, reusable patterns, guardrails, and landing-zone controls across AWS, Google Cloud, Microsoft Azure, hybrid, and multi-cloud environments. • Design identity-centric and zero-trust controls for segmentation, private connectivity, federation, encryption, key and secrets management, centralized logging, monitoring, and policy-driven governance. • Secure virtual machines, containers, Kubernetes, serverless services, APIs, databases, storage, managed services, and data-processing platforms. • Implement and operate cloud security posture, workload protection, entitlement management, configuration compliance, vulnerability management, and threat detection capabilities. • Partner with platform teams to embed security through Infrastructure as Code, reusable modules, reference architectures, architecture reviews, migrations, and cloud-native modernization. • Analyze configurations and telemetry to identify misconfigurations, excessive privilege, exposed services, policy violations, vulnerabilities, and indicators of compromise. Server and Endpoint Security • Establish hardening standards and configuration baselines for Windows, Linux, virtualized, containerized, and cloud-hosted server environments. • Define and implement endpoint controls including EDR, anti-malware, host firewalls, encryption, application control, vulnerability management, privileged access management, and device posture validation. • Improve visibility through centralized logging, monitoring, asset inventory, configuration management, vulnerability assessment, and security telemetry. • Automate secure configuration, patching, vulnerability remediation, credential and certificate management, backup protection, recovery, remote administration, and system lifecycle processes. • Evaluate, deploy, integrate, and operate server and endpoint security technologies; analyze findings and compliance results to prioritize remediation. Application and Artificial Intelligence Security • Lead application and AI security policies, standards, design patterns, control frameworks, and technical guardrails across traditional applications, machine-learning platforms, generative AI, and agentic systems. • Architect and review secure designs for LLMs, foundation models, RAG pipelines, AI agents, tool-using workflows, automated decision-making, and AI-enabled business processes. • Define controls for prompts, tools, agent memory, service identities, authorization, data access, autonomy limits, human approval, escalation and shutdown, observability, output validation, and content safety. • Lead threat modeling, abuse-case and misuse analysis, red teaming, security testing, and risk assessments for AI pipelines, training and inference data, vector databases, retrieval systems, plugins, APIs, and external model providers. Security Requirements, Architecture, and Documentation • Develop and maintain security requirements, architecture artifacts, technical designs, implementation and test plans, policies, standards, procedures, control specifications, and operational documentation. • Create architecture and data-flow diagrams, threat models, control mappings, integration designs, technical specifications, and support documentation. • Translate regulatory, privacy, risk, business, and responsible AI obligations into measurable technical controls and acceptance criteria. • Validate control implementation and effectiveness before production deployment and maintain accurate documentation of architecture, dependencies, data flows, configurations, support, and recovery processes. • Define reusable reference architectures and secure design patterns for cloud, network, infrastructure, application, and AI environments. Collaboration, Leadership, and Influence • Partner across cybersecurity, engineering, product, cloud, infrastructure, networking, operations, application development, data, privacy, compliance, legal, architecture, and responsible AI teams. • Influence product roadmaps, architecture decisions, development practices, and operating models while balancing security, privacy, compliance, cost, performance, availability, and delivery priorities. • Lead technical discussions on architecture, engineering solutions, implementation options, platform capabilities, and risk tradeoffs. • Build productive relationships with internal teams, technology vendors, managed service providers, and external support organizations; mentor senior and principal engineers and raise organizational security maturity. Communication and Executive Engagement • Communicate complex technical concepts to engineering, operations, product, risk, compliance, business, and executive audiences. • Develop and deliver architecture presentations, technical briefings, risk assessments, implementation plans, engineering recommendations, and executive summaries. • Facilitate design reviews, architecture forums, technical evaluations, incident discussions, and stakeholder decision meetings. • Translate cybersecurity issues into business impact, risk exposure, operational considerations, tradeoffs, and actionable decisions. • Address risks such as prompt injection, indirect prompt injection, sensitive-data leakage, insecure tool use, model poisoning, excessive privileges, hallucinated actions, and unsafe autonomous behavior. • Partner with AI, product, application, data, privacy, legal, compliance, and responsible AI teams; evaluate emerging tools and standards; advise leadership on risk, regulation, investment, and roadmap priorities. Security Requirements, Architecture, and Documentation • Develop and maintain security requirements, architecture artifacts, technical designs, implementation and test plans, policies, standards, procedures, control specifications, and operational documentation. • Create architecture and data-flow diagrams, threat models, control mappings, integration designs, technical specifications, and support documentation. • Translate regulatory, privacy, risk, business, and responsible AI obligations into measurable technical controls and acceptance criteria. • Validate control implementation and effectiveness before production deployment and maintain accurate documentation of architecture, dependencies, data flows, configurations, support, and recovery processes. • Define reusable reference architectures and secure design patterns for cloud, network, infrastructure, application, and AI environments. Collaboration, Leadership, and Influence • Partner across cybersecurity, engineering, product, cloud, infrastructure, networking, operations, application development, data, privacy, compliance, legal, architecture, and responsible AI teams. • Influence product roadmaps, architecture decisions, development practices, and operating models while balancing security, privacy, compliance, cost, performance, availability, and delivery priorities. • Lead technical discussions on architecture, engineering solutions, implementation options, platform capabilities, and risk tradeoffs. • Build productive relationships with internal teams, technology vendors, managed service providers, and external support organizations; mentor senior and principal engineers and raise organizational security maturity. THE EXPERIENCE YOU BRING TO THE TEAM Minimum Required Experiences
- 8 years of experience.
- Extensive experience in cybersecurity engineering, infrastructure or network security, cloud engineering, application security, software engineering, or a related technical discipline.
- Significant hands-on experience securing production environments in AWS, Google Cloud, and Microsoft Azure.
- Deep knowledge of cloud security architecture, IAM, networking, encryption, logging, monitoring, workload protection, governance, and enterprise network security, including segmentation, firewalls, proxies, VPNs, DNS security, secure web gateways, IPS, load balancing, ZTNA, and SASE.
- Experience securing Windows and Linux servers, endpoints, databases, containers, Kubernetes, and cloud-hosted workloads.
- Hands-on experience designing, integrating, and securing CI/CD pipelines and implementing automated security testing, secure release controls, and policy enforcement.
- Experience with Infrastructure as Code, including Terraform, CloudFormation, Bicep, ARM templates, or equivalent tools.
- Full-stack engineering experience across front-end applications, back-end services, APIs, databases, cloud services, identity platforms, and supporting infrastructure.
- Proficiency in one or more languages such as Python, Go, Java, JavaScript, TypeScript, C#, PowerShell, Bash, or Ruby; experience building integrations through APIs, automation, orchestration, and vendor-supported methods.
- Strong knowledge of secure software development, application and API security, cloud-native development, containers and registries, Kubernetes security, and software supply chain risks.
- Experience with SIEM, EDR, vulnerability management, network security platforms, cloud-native security services, IAM, PAM, secrets, certificates, keys, and cryptographic controls.
- Experience developing security requirements, architecture artifacts, technical designs, implementation and test plans, policies, standards, procedures, proofs of concept, product evaluations, technical testing, data analysis, and architecture assessments.
- Knowledge of AI security risks and experience applying threat modeling and secure design practices to modern applications, APIs, cloud platforms, or AI-enabled systems.
- Demonstrated ability to lead complex, cross-functional technical initiatives and communicate effectively with engineers, administrators, executives, and technical decision-makers.
- Strong analytical, problem-solving, troubleshooting, writing, presentation, and stakeholder-management skills.
- Ability and willingness to participate in an on-call rotation and support major outages, critical service issues, and cybersecurity incidents.
- Experience designing security controls for large-scale, regulated, highly available, geographically distributed, or global enterprise environments.
- Experience with CSPM, CWPP, CIEM, DSPM, attack-path management, cloud-delivered security platforms, and zero-trust architecture across users, devices, networks, applications, services, and workloads.
- Experience with AI security architecture, generative AI, LLM applications, RAG pipelines, agent frameworks, model gateways, responsible AI controls, AI red teaming, adversarial testing, model risk assessment, or abuse-case analysis.
- Experience with threat-modeling methodologies, security architecture frameworks, penetration testing, red-team, purple-team, and adversarial simulation activities.
- Familiarity with NIST Cybersecurity Framework, NIST 800-53, CIS Benchmarks, ISO 27001, SOC 2, PCI DSS, OWASP, MITRE ATT&CK, MITRE ATLAS, or comparable standards.
- Professional Certifications: Relevant industry certifications such as CISSP, CCSP, PCNSE, AWS Certified Security - Specialty, AWS Certified Advanced Networking - Specialty, Google Professional Cloud Security Engineer, Microsoft Certified: Azure Security Engineer Associate, GIAC certifications, or equivalent credentials.
Bachelor's Level Degree (Required) The future is what you make it to be. Discover compelling opportunities at Fanniemae.com/careers. For most roles, employees are expected to work onsite on a regular basis at their designated office location. In-office work cadence is determined by your manager. Proximity within a reasonable commute to your designated office location is preferred unless the job is noted as open to remote. Fannie Mae is an equal opportunity employer and considers qualified applicants for employment without regard to race, color, religion, sex, national origin, disability, age, sexual orientation, gender identity/gender expression, marital or parental status, or any other protected factor. Fannie Mae is committed to providing reasonable accommodations to qualified individuals with disabilities who are employees or applicants for employment, unless to do so would cause undue hardship to the company. If you need assistance using our online system and/or you need a reasonable accommodation related to the hiring/application process, please complete this form. The hiring range for this role is set forth below. Final salaries will generally vary within that range based on factors that include but are not limited to, skill set, depth of experience, certifications, and other relevant qualifications. This position is eligible to participate in a Fannie Mae incentive program (subject to the terms of the program). As part of our comprehensive benefits package, Fannie Mae offers a broad range of Health, Life, Voluntary Lifestyle, and other benefits and perks that enhance an employee's physical, mental, emotional, and financial well-being. See more here. Requisition compensation:
200000
to
269000
Vacancy posted 1 day ago
Similar jobs that could be interesting for youBased on the Principal Security Engineer in Reston, VA vacancy
- ...Redhorse transforms the way government uses data and technology. To support this mission, we are seeking a Principal Information System Security Engineer (ISSE) who is a recognized authority in the field. This is a high-impact role where you will tackle unusually complex...SuggestedContract work
- ...Job Description Job Description Job Description: Senior Principal Cyber Systems Engineer (DevOps Engineer)The selected candidate will integrate a variety of software components in a secure container architecture working with cross functional teams to debug critical...Suggested
$141.5k - $236k
...Principal Cyber Security Engineer Unlock the secrets of intelligence with MANTECH! Join a dynamic team at the forefront of national security, providing advanced solutions to government intelligence agencies. Since 1968, we've been solving the toughest challenges with...SuggestedHourly payContract workTemporary workWork experience placementWork at officeLocal areaRemote work$141.5k - $236k
...MANTECH! Join a dynamic team at the forefront of national security, providing advanced solutions to government intelligence... ...seeks a motivated, career and customer-oriented Principal Cyber Security Engineer to join our team in Chantilly, VA . The Principal...SuggestedHourly payContract workTemporary workWork experience placementWork at officeLocal areaRemote work$100k - $140k
...experience in cybersecurity or network engineering. We need hands-on proficiency with routing... ...of traffic management and perimeter security tools such as load balancers, firewalls... ...seeking a motivated, mission-focused Principal Cyber Engineer with a network focus to...SuggestedFull timeWork at office$120.5k - $231k
...everywhere & always. Want in? Join the #VTeamLife.What you’ll be doing...The Verizon Network Security team is looking for a highly motivated and experienced Principal Engineer to join the Net-Sec Defense Organization under the Broadband Access team. You will be responsible...Full timeTemporary workPart timeWork experience placementWork at officeWork from homeShift work3 days per week$95k - $245k
...defense and space exploration to biomedical engineering, lives often depend on the solutions we... ...Summary:Draper is actively seeking a Principal Cyber Effects Engineer that will... ...innovate for the greater good of our Nation's security. As a part of the Draper Cyber Effects...Full timeLocal area$140k - $190k
...flexibility, and ingenuity to strengthen and protect our nation’s vital interests. Title : Information System Security Officers (ISSO), Senior Security Engineers & Security Engineering Leads (CBP) Clearance : Active Top Secret with SCI eligibility, Ability to obtain...Temporary workImmediate startRemote workRelocation packageDay shift$100k - $140k
...Experience with deploying and/or supporting enterprise security software products such as firewalls, IPS, Anti-Virus solutions... ...within 6 months of hire Responsibilities: As a Principal Cyber Security Engineer, you will: Engineer, design, implement, integrate,...Full timeWork at office- ...GuidePoint Security provides trusted cybersecurity expertise, solutions and services that help organizations make better decisions and... ...prime contractors. We are growing our federal presales engineering team and looking for technically exceptional engineers who thrive...Contract workFor contractorsRemote workFlexible hours
$82.2k - $187k
...Job Description Creates testing tools to help engineering teams identify security-related weaknesses. Recognizes and escalates complex security violations to senior team members. Contributes to compliance assessments to identify gaps and ensure compliance with internal...Temporary workFlexible hoursShift work$105k - $125k
...Senior Security Engineer Job Category Information Technology Market Location VA - Northern Virginia Location VA - Reston Apply Now ( NVR, Inc. is seeking a Senior Security Engineer to work on site in Reston, VA NVR’s technology teams thrive on providing...Work experience placement- ...Network Security Engineer LOCATION Reston, VA 20190 CLEARANCE TS/SCI Full Poly (Please note this position requires full U.S. Citizenship) KEY SUMMARY We are seeking a skilled and passionate Network Security Engineer to join our team and play a critical...Temporary workFor contractorsImmediate startFlexible hours
$110k - $150k
...are subject to change.* This position is fully onsite at the specified client location in Reston, Virginia. The Senior Security Engineer will assist in creating and maintaining IT security policies, architectures, standard operating procedures, and RMF security...Full timeTemporary workFor contractorsWork at officeImmediate start- ...Job Description About the Position An employer is seeking a Security Engineer II to design, integrate, operate, and maintain robust security monitoring and auditing capabilities across our global platform. The platform delivers a scalable and secure way to deploy...WorldwideShift workWeekend work
- ...Security Engineer The Security Engineer implements and operates security controls on AWS. You will perform security testing, support ATO evidence and continuous monitoring, and remediate findings, helping keep a high-visibility federal filing platform secure and compliant...For contractorsFlexible hours
- ...Principal Engineer Herndon Virginia DigiCert is a global leader in intelligent trust. We protect the digital world by ensuring the security, privacy, and authenticity of every interaction. Our AI-powered DigiCert ONE platform unifies PKI, DNS, and certificate lifecycle...Flexible hours
- ...here. UltraViolet Cyber is a leading platform-enabled unified security operations company providing a comprehensive suite of security... ...U.S. and in India. UltraViolet Cyber is seeking a Security Engineer who will provide Security Operations Center (SOC) engineering...Contract workTemporary work2 days per week1 day per week
- ...Job Description Job Description Job Summary: The Security Engineer is responsible for identifying, analyzing, and mitigating security threats while ensuring the organization's cyber defenses remain strong. This role focuses on implementing advanced security measures...Contract workWork at officeRemote work
$140.44k - $202.3k
...HOME LOAN BANKS OFFICE OF FINANCE POSITION : Senior Security Engineer DATE : September 2026... ...through diversity, relationships, respect, and support PRINCIPAL RESPONSIBILITIES • Develop and maintain software...Work at officeLocal area$99k - $206k
## Principal Cyber Mobile CNO EngineerApplylocations: VA543: 22270 Pacific Blvd, Dulles 22... ...and commercial markets. **Principal Cyber Engineer**Nightwing provides technically advanced... ...work that is vital to our national security, apply today!**Principal Cyber Engineer*...RelocationRelocation package- ...Information System Security Engineer LOCATION Reston, VA 20190 CLEARANCE TS/SCI Full Poly (Please note this position requires full U.S. Citizenship) KEY SUMMARY We are seeking a skilled and proactive Information System Security Engineer to join...Temporary workFor contractorsImmediate startFlexible hours
$159.3k - $202.4k
...understanding of current cyber threat actors as well as experience performing question-driven analysis is required. As a Security Intelligence Engineer, you will help enhance our capabilities by identifying new data sources, formulating new analytic techniques, and...InternshipFlexible hours$135k - $216k
...Information Systems Security Engineer (ISSE) Job Locations US-VA-Herndon Requisition ID 2026-169081 Position Category Cyber Security Clearance Top Secret/SCI w/Poly Responsibilities Responsibilities The Information...Full timeContract workShift work- ...Description Guides the creation of testing tools and facilitates their integration into engineering workflows, ensuring team is equipped to identify and address security-related weaknesses efficiently. Establishes protocols for security violation escalation, managing...
- ...Overview VTG is seeking a highly skilled Information Systems Security Engineer (ISSE) to design, implement, and maintain security controls across enterprise systems and networks. This role ensures systems are compliant with security requirements while supporting mission...
- ...Information Systems Security Engineer (ISSE) LOCATION Reston, VA 20190 CLEARANCE TS/SCI Full Poly (Please note this position requires full U.S. Citizenship) KEY SUMMARY We are seeking a proactive and skilled **Information Systems Security Engineer...Temporary workFor contractorsImmediate startFlexible hours
$150.2k - $203.3k
We are seeking an experienced Physical Security Engineering Manager to lead our physical security technology team. In this role, you will be responsible for building and managing a high-performing team of security engineers who design, implement, and maintain physical...Flexible hours- ...F&A Technologies LLC (F&A) is seeking a skilled and motivated Information Systems Security Engineer (ISSE) to work hand-in-hand with our Development and Sustainment Teams in navigating Security policy/requirements that effectively deliver compliant and compelling technical...Work at officeFlexible hours
$126.2k - $264.1k
Guides the creation of testing tools and facilitates their integration into engineering workflows, ensuring team is equipped to identify and address security-related weaknesses efficiently. Establishes protocols for security violation escalation, managing communication...Temporary workFlexible hours
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Principal Security Engineer. Be the first to apply!
Related searches
- engineering director Reston, VA
- principal engineer Reston, VA
- general engineer Reston, VA
- data center chief engineer Reston, VA
- hotel chief engineer Reston, VA
- principal developer Reston, VA
- senior principal engineer Reston, VA
- senior director engineering Reston, VA
- senior chief engineer Reston, VA
- chief engineer Reston, VA


