Senior Director of Security Configuration Management & Cyber Governance
Job in
Reston, Fairfax County, Virginia, 22090, USA
Listed on 2026-07-30
Listing for:
Fannie Mae
Full Time
position Listed on 2026-07-30
Job specializations:
-
IT/Tech
Cybersecurity, Information Security & Data Protection
Job Description & How to Apply Below
Playing an essential role in the U.S. economy, Fannie Mae is foundational to housing finance. Here, your expertise can help fuel purpose-driven innovation that expands access to home ownership and affordable rental housing across the country. Join Fannie Mae to grow your career and help people find a place to call home. In this compelling leadership position, you will plan and direct a function and team responsible for designing, developing, testing, or maintaining hardware, technology, or processes, and ensure the coordination of business unit operational activities.
Key Responsibilities Strategic Information Security Leadership & Governance- Develop and execute the enterprise strategy for security configuration management and cyber governance.
- Provide executive-level reporting on cyber risk, control effectiveness, compliance posture, and configuration management maturity aligned with risk appetite.
- Partner with business, technology, risk, legal, compliance, and audit stakeholders to ensure consistent governance practices across the Information Security organization.
- Drive continuous improvement initiatives that enhance operational resilience, security effectiveness, and regulatory readiness.
- Monitor emerging cyber threats, vulnerabilities, and industry trends to proactively address risks.
- Establish enterprise security configuration standards, baselines, and hardening requirements across Cloud, SaaS and On Prem software services.
- Ensure secure configuration controls are integrated into system development, deployment, and operational processes.
- Oversee configuration compliance monitoring, risk prioritization, remediation governance and executive reporting.
- Lead initiatives to automate configuration management, compliance validation, and security configuration enforcement.
- Define key performance indicators (KPIs), key risk indicators (KRIs), and metrics to measure security configuration compliance and risk reduction outcomes.
- Ensure alignment with industry frameworks such as NIST, CIS Benchmarks and relevant regulatory requirements.
- Drive continuous improvement of configuration compliance, and security control effectiveness.
- Ensure timely remediation of security misconfigurations across the enterprise.
- Lead security configuration management assessments and audits conducted by internal audit, regulators, and external parties.
- Ensure effective remediation of audit findings and regulatory observations.
- Lead cyber assurance governance program, partnering with Information Security Standard owners to define key requirements and monitors.
- Lead development of governance dashboards, scorecards, and metrics that provide transparency into control performance, compliance posture, risk trends, and remediation progress.
- Present cybersecurity risks, trends, and remediation status to executive leadership, risk committees, and governance forums.
- Monitor emerging cybersecurity threats, regulatory developments, and industry trends to proactively evolve governance practices.
- Ensure alignment with enterprise risk management frameworks and regulatory expectations.
- Build, lead, mentor, and develop high-performing teams focused on security governance, security configuration management, and cyber risk oversight.
- Foster a culture of accountability, innovation, collaboration, and continuous learning.
- Establish clear goals, performance expectations, and development plans for leaders and team members.
- Drive workforce planning, succession planning, talent acquisition, and leadership development initiatives.
- Manage budgets, vendor relationships, and strategic initiatives.
- Influence and inspire cross-functional teams without direct authority to achieve strategic cybersecurity objectives.
- Promote strong partnerships across technology, security operations, engineering, architecture, risk, compliance, and business functions.
- Serve as a key cybersecurity representative to executive leadership committees and governance forums.
- Communicate complex technical and risk topics in clear business terms appropriate for executive and board-level audiences.
- Build strong relationships with regulators, auditors, industry peers, and external partners.
- Influence strategic technology decisions through cybersecurity governance and risk management expertise.
- Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Engineering, or related field.
- 8 years of progressive experience in cybersecurity, information security, risk management, governance, or technology leadership roles.
- 8+ years of leadership experience managing large teams and senior-level managers.
- Demonstrated experience leading enterprise-scale security configuration management, cyber governance, risk, compliance, or security engineering programs.
- Deep understanding of cybersecurity frameworks, standards, and regulations including NIST CSF, NIST 800‑53, CIS Controls, ISO 27001, COBIT, and relevant regulatory…
Position Requirements
10+ Years
work experience
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
Search for further Jobs Here:
×