Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy
Jobs / Job page
VP, Information Security - Technology Management image - Rise Careers
Job details

VP, Information Security - Technology Management

Company Description

At Fannie Mae, futures are made. The inspiring work we do helps make a home a possibility for millions of homeowners and renters. Every day offers compelling opportunities to impact the future of the housing industry while being part of an inclusive team thriving in an energizing, flexible environment. Here, you will grow your career and help create access to fair, affordable housing finance.

Job Description

THE IMPACT YOU WILL MAKE

The VP, Information Security - Technology Management will set the strategic direction for the cybersecurity and information security architecture for cloud, on-prem and hybrid environments. Part of this leader’s remit will be to develop the cybersecurity architecture, build our technology target state and roadmaps, and support the build-out of related technologies. This VP will ensure cybersecurity technologies remain viable, scalable, and aligned to business needs. Finally, s/he will drive process optimization and efficiency through automation, technology enhancements, and structured continuous improvement plans.

The VP, Information Security - Technology Management role will offer you the flexibility to make each day your own, while working alongside people who care so that you can deliver on the following responsibilities:

Develop the cybersecurity architecture while ensuring alignment with broader functional and corporate strategies, including a specific focus on the following:

  • Enterprise Cyber Security Cloud Architecture. Lead the development and implementation of strategies for maturing the enterprise cyber security posture to meet or exceed industry standards in a complex, on-prem/multi-cloud environment undergoing digital transformation.
    • Defining and driving implementation of the Fannie Mae Cyber Security Strategy in alignment with the Fannie Business and Enterprise Risk Management strategies.
    • Driving adoption of cyber security best practices for emerging technology areas including multi-cloud, ML, AI, etc.
    • Evaluate emerging cyber security solutions and incorporate into Cyber Security Enterprise-wide architecture (e.g., SOAR, AI, ML, etc.)
  • Cyber Security Enterprise-Wide Architecture. Drive the standardization and guiding principles for overlaying security architecture patterns over enterprise architecture to enable technical & process controls for risk management.
    • Developing technical strategies and multi-year roadmaps spanning across all InfoSec domains with clearly defined capabilities that enable Fannie Mae business goals and objectives.
    • Establishing detailed InfoSec technical integration/API architecture for the integration of security tools to support security controls automation and automated remediation.
    • Identifying and establishing tools selections criteria based on current and evolving business needs.
  • InfoSec Product/Portfolio Lead. Lead the prioritization, strategy, and development of cyber services for enterprise, as well as developing cyber security product portfolio strategy to enable rationalization through accountability & traceability between security objectives and security services delivery.
  • Cloud Security Standards and Policies. Drive the technical security standards of virtualization, cloud infrastructure, and public cloud offerings and designing security configuration and controls within cloud-based solutions for IaaS, PaaS, SaaS, and hybrid solutions.
  • Information Security Standards and Frameworks. Drive security controls, tools, processes and risk management alignment with common information security standards such as: NIST CSF, SOX, SOC2, FEDRAMP, and CIS Controls.
  • Infrastructure Security Architecture. Lead integration architecture and security requirements of common infrastructure security technologies and solutions into business solution architectures including the integration of identity & access management, intrusion detection and prevention, security monitoring, and data encryption solutions.
  • Application Security Architecture. Lead the design of security controls for business solutions including the design of application-level access and entitlement management, data tenancy and isolation, encryption, and logging.
  • Agile and DevOps Methodologies. Be a contributing member of a balanced team within an Agile development or DevOps environment. Focus on security-as-code and continuous compliance practices.
  • Lead the cybersecurity technology transformation to cloud and ensure the ongoing relevance, viability and scalability of cybersecurity applications and systems.  Provide leadership and direction in the innovation of bleeding edge cybersecurity technologies.

Qualifications

THE EXPERIENCE YOU BRING TO THE TEAM

  • 10+ years of experience managing the implementation and operation of security architecture and tools in a cloud-native environment (ideally a mastery of AWS).
  • Experience with Application Security, Vulnerability Management, Security Operations, and DevSecOps.
  • Understanding of key cyber security tools to ensure that they are consistently deployed, executed, and continuously improved in alignment with business requirements.
  • Strong background in IAM and credentials management solutions and technologies (Ping, Okta, AWS Secrets Manager, Hashicorp Vault, CyberArk, etc.).
  • Experience effectively communicating at senior levels within a customer organization and meeting with stakeholders to formulate, review, and execute task plans and deliverable items.
  • Experience leading high performing multi-disciplinary teams with a focus on attracting and developing talent.
  • Background in cyber security monitoring and measurements.
  • Experience with implementing security solutions for AWS, Azure and/or GCP.
  • Experience with Microservices architecture.
  • Experience Docker, Istio, Apigee, ECS, EKS, and Kafka.
  • Experience with managing security with SaaS providers.
  • Strong background in cyber security controls frameworks and regulatory requirements including NIST 800-53, NIST CSF, CSA CCM, SOX, and Privacy regulations.
  • Experience leading complex security infrastructure consolidation and modernization efforts to achieve standardized, consistent and repeatable processes for delivery of services across a large agency enterprise, and optimized use of shared resources.
  • Strong written and verbal communication skills to collaborate with customer representatives, domain experts, systems engineers and architects.
  • Active CISSP certification or equivalent is preferred.
  • Financial services industry experience and strong project management acumen is nice-to-have.

Additional Information

The future is what you make it to be. Discover compelling opportunities at careers.fanniemae.com.

Fannie Mae is an Equal Opportunity Employer, which means we are committed to fostering a diverse and inclusive workplace. All qualified applicants will receive consideration for employment without regard to race, religion, national origin, gender, gender identity, sexual orientation, personal appearance, protected veteran status, disability, age, or other legally protected status. For individuals with disabilities who would like to request an accommodation in the application process, email us at [email protected].

The hiring range for this role is set forth on each of our job postings located on Fannie Mae's Career Site. Final salaries will generally vary within that range based on factors that include but are not limited to, skill set, depth of experience, certifications, and other relevant qualifications. This position is eligible to participate in a Fannie Mae incentive program (subject to the terms of the program). As part of our comprehensive benefits package, Fannie Mae offers a broad range of Health, Life, Voluntary Lifestyle, and other benefits and perks that enhance an employee’s physical, mental, emotional, and financial well-being. See more here.

Fannie Mae Glassdoor Company Review
4.2 Glassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star icon Glassdoor star icon
Fannie Mae DE&I Review
No rating Glassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star icon
CEO of Fannie Mae
Fannie Mae CEO photo
Priscilla Almodovar
Approve of CEO

Average salary estimate

$175000 / YEARLY (est.)
min
max
$150000K
$200000K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

What You Should Know About VP, Information Security - Technology Management, Fannie Mae

At Fannie Mae, we’re redefining the future of housing finance, and we’re looking for a dynamic VP, Information Security - Technology Management to join our innovative team in Washington, DC. In this role, you’ll be at the forefront of shaping our cybersecurity strategies across diverse environments, including cloud and on-premises setups. Imagine being the architect of our cybersecurity framework, where your skills will directly influence our information security posture and tech stack. You’ll take the lead in developing robust cybersecurity architectures while aligning them with Fannie Mae’s broader business goals and risk management strategies. Your expertise will guide our adoption of cutting-edge technologies like AI and ML, ensuring we’re not just meeting industry standards, but setting them. Working collaboratively within a high-performing team, you’ll have the autonomy to prioritize and develop our cyber services portfolio. Each day presents the opportunity to innovate and streamline our processes through automation and continuous improvement initiatives, all while ensuring our cloud security standards are higher than ever. If you’re passionate about cybersecurity and want to contribute to a mission-driven organization that’s making a difference every day, we want to hear from you!

Frequently Asked Questions (FAQs) for VP, Information Security - Technology Management Role at Fannie Mae
What are the primary responsibilities of the VP, Information Security - Technology Management at Fannie Mae?

The VP, Information Security - Technology Management at Fannie Mae is responsible for shaping and implementing cybersecurity strategies, ensuring alignment with business objectives while developing a comprehensive cybersecurity architecture across multiple environments, including cloud and hybrid systems.

Join Rise to see the full answer
What qualifications are needed for the VP, Information Security - Technology Management position at Fannie Mae?

Candidates for the VP, Information Security - Technology Management role at Fannie Mae should possess at least 10 years of experience in managing security architecture, a strong grasp of cloud technologies, and a robust understanding of cybersecurity frameworks like NIST CSF and related regulatory requirements.

Join Rise to see the full answer
How does the VP, Information Security - Technology Management contribute to Fannie Mae’s cybersecurity posture?

In this position, the VP, Information Security - Technology Management plays a crucial role in elevating Fannie Mae’s cybersecurity posture through the development of an enterprise-wide cybersecurity strategy and by leveraging new technologies to address emerging security challenges.

Join Rise to see the full answer
What technologies and tools will the VP, Information Security - Technology Management be expected to manage?

The VP, Information Security - Technology Management will oversee a variety of technologies and tools, including IAM solutions, cloud security measures, and cybersecurity monitoring systems, to ensure they are effectively implemented and continuously improved.

Join Rise to see the full answer
What are the career growth opportunities for the VP, Information Security - Technology Management at Fannie Mae?

The VP, Information Security - Technology Management at Fannie Mae will have significant opportunities for career growth, including leading innovative cybersecurity projects, developing comprehensive strategies, and influencing company-wide security policies and practices.

Join Rise to see the full answer
Common Interview Questions for VP, Information Security - Technology Management
Can you describe your experience with developing cybersecurity strategies in a cloud-native environment?

When answering this question, detail your specific experiences in shaping cloud security strategies, highlighting your familiarity with cloud platforms like AWS, Azure, or GCP, and discuss how you ensured compliance with industry standards.

Join Rise to see the full answer
How do you approach the integration of security measures into existing DevOps processes?

Explain your strategies for incorporating security into DevOps, emphasizing a collaborative approach and discussing methodologies like security-as-code and continuous compliance practices to ensure that security is a fundamental component of the development process.

Join Rise to see the full answer
What methods do you use to evaluate and adopt emerging cybersecurity technologies?

Discuss your process for staying informed about new technologies, including your criteria for evaluating their effectiveness and suitability for the organization, as well as how you plan to pilot and integrate them within existing frameworks.

Join Rise to see the full answer
How do you ensure that the security architecture aligns with business goals?

Address your techniques for engaging with stakeholders to understand their needs and how you translate those priorities into actionable security strategies, ensuring that cybersecurity efforts directly support the organization's objectives.

Join Rise to see the full answer
Can you give an example of a successful security initiative you led?

Share a specific example of a security project you managed, highlighting your leadership role, the challenges you faced, the solutions you implemented, and the positive outcomes for the organization.

Join Rise to see the full answer
How do you keep a high-performing cybersecurity team motivated and productive?

Discuss your strategies for team management, emphasizing communication, recognition of achievements, professional development opportunities, and fostering an inclusive environment to motivate team members.

Join Rise to see the full answer
What experience do you have with compliance standards and regulations?

Talk about your familiarity with compliance frameworks such as NIST, SOX, and FedRAMP, and provide examples of how you've ensured compliance in your previous roles, including any challenges you faced and how you overcame them.

Join Rise to see the full answer
How do you assess risk and develop appropriate security controls?

Explain your approach to risk assessment, including the tools and methodologies you employ to identify and evaluate potential risks, and how you develop security controls that are proportionate to those risks.

Join Rise to see the full answer
What role does automation play in your information security strategy?

Discuss your views on automation in security, sharing examples of how you've implemented automation to improve processes such as incident response or vulnerability management and the benefits it has brought to the security architecture.

Join Rise to see the full answer
How do you handle security incidents and what is your incident response strategy?

Outline your incident response plan, detailing how you prepare for, detect, and respond to security incidents, including post-incident analysis to prevent future occurrences.

Join Rise to see the full answer
Similar Jobs
Photo of the Rise User
ServiceNow Remote Salarpuria Sattva Knowledge City Knowledge City, Unit II, 17 to 10 Floor Survey No. 83/1, Serilingampally Mandal, Hyderabad, India
Posted 12 days ago
Inclusive & Diverse
Mission Driven
Rise from Within
Diversity of Opinions
Work/Life Harmony
Empathetic
Feedback Forward
Take Risks
Collaboration over Competition
Medical Insurance
Dental Insurance
Vision Insurance
Mental Health Resources
Life insurance
Disability Insurance
Health Savings Account (HSA)
Flexible Spending Account (FSA)
Conferences Stipend
Paid Time-Off
Maternity Leave
Equity
Photo of the Rise User
CLEAR - Corporate Hybrid New York, New York, United States
Posted yesterday
Posted 2 days ago
Posted 7 days ago
Photo of the Rise User
Inclusive & Diverse
Empathetic
Mission Driven
Customer-Centric
Growth & Learning
Medical Insurance
Dental Insurance
Vision Insurance
Paid Time-Off
Mental Health Resources
Learning & Development
Photo of the Rise User
Greenlight Guru Remote Indianapolis, Indiana, United States
Posted 12 days ago
Caret Remote No location specified
Posted 14 days ago

Fannie Mae’s mission is to facilitate equitable and sustainable access to homeownership and quality, affordable rental housing across America.

139 jobs
MATCH
Calculating your matching score...
FUNDING
SENIORITY LEVEL REQUIREMENT
TEAM SIZE
EMPLOYMENT TYPE
Full-time, on-site
DATE POSTED
January 9, 2025

Subscribe to Rise newsletter

Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!