Turn this role into an interview — a resume and cover letter built around what this employer wants.
Fannie Mae in Reston, VA seeks a Senior Director, Cybersecurity Risk Oversight Lead to advance the CRCD's independent oversight strategy and serve as a senior second line of defense leader overseeing governance, risk identification, appetite, issue management, and executive reporting.
You will partner with enterprise leadership, technology teams, and control functions to provide independent oversight, credible challenge, and transparent risk measurement across cybersecurity programs and emerging
Playing an essential role in the U.S. economy, Fannie Mae is foundational to housing finance. Here, your expertise can help fuel purpose-driven innovation that expands access to homeownership and affordable rental housing across the country. Join Fannie Mae to grow your career and help people find a place to call home.
The Senior Director, Cybersecurity Risk Oversight Lead is responsible for advancing the Chief Risk and Compliance Division's (CRCD) independent cybersecurity risk oversight strategy. This role serves as a senior second line of defense (2LOD) leader responsible for overseeing cybersecurity risk governance, risk identification and assessment, risk appetite, issue management, emerging risk monitoring, regulatory engagement, and executive reporting. Serving as a strategic partner to enterprise leadership, technology teams, and control functions, this role provides independent oversight and credible challenge to ensure cybersecurity risks are effectively identified, measured, monitored, managed, and reported. The position provides transparency into the firm's cybersecurity risk posture, control effectiveness, remediation progress, and emerging threats while supporting informed decision-making by executive management, risk committees, and regulators. The role also oversees cybersecurity risks associated with emerging technologies, including artificial intelligence, frontier models, agentic systems, and quantum computing, ensuring risks are appropriately governed and aligned with enterprise risk appetite.
independent oversight and credible challenge of the enterprise cybersecurity risk management program. Assess the effectiveness of cybersecurity governance, risk management practices, and control environments. Provide independent review and challenge of cybersecurity strategies, risk assessments, exceptions, risk acceptances, and remediation plans. Evaluate cybersecurity risk exposures against approved risk appetite statements, limits, and thresholds. Identify material risk concentrations, systemic control weaknesses, and emerging risk trends. Promote accountability, transparency, and effective risk management across the enterprise.
Oversee the assessment, aggregation, monitoring, and reporting of cybersecurity risks across the enterprise. Establish and maintain cybersecurity risk metrics, key risk indicators (KRIs), and risk appetite measures. Monitor cybersecurity events, control deficiencies, audit findings, and issue remediation activities. Develop executive-level dashboards, scorecards, and risk reporting for senior leadership, risk committees, and the Board. Translate complex cybersecurity risks into clear business impacts and actionable recommendations.
Provide independent oversight of cybersecurity risks associated with artificial intelligence, frontier models, autonomous agents, and other emerging technologies. Assess risks related to AI-enabled cyber threats, adversarial attacks, model compromise, data exposure, and AI supply-chain vulnerabilities. Evaluate cybersecurity implications of advanced AI capabilities and emerging technology adoption across the enterprise. Lead oversight of enterprise preparedness for quantum computing threats and post-quantum cryptography transition efforts. Monitor emerging cyber threats, technology developments, and regulatory expectations to identify risks that may impact the firm’s security posture.
Provide oversight of cybersecurity issues, corrective action plans, risk acceptances, and remediation activities. Review and challenge issue severity, root cause analysis, remediation effectiveness, and closure decisions. Support cybersecurity regulatory examinations, findings remediation, and supervisory commitments. Partner with Internal Audit, Compliance, and other assurance functions to assess cybersecurity risk management effectiveness. Escalate material cybersecurity risks, control concerns, and adverse trends through established governance channels.
Serve as a trusted cybersecurity risk advisor to executive leadership and governance committees. Build strong partnerships across technology, business, risk audit, compliance, and regulatory stakeholders. Develop board level presentations and present cybersecurity risk perspectives and recommendations to senior leadership and Executive-level forums. Lead and develop a high-performing team of cybersecurity risk professionals. Foster a culture of accountability, transparency, continuous improvement, and sound risk management.