
Principal Cybersecurity, Technology Risk Architect – AI/Cloud
Posted 2 days ago

Posted 2 days ago
This is a fully remote position, open to applicants in Texas, +1 more state.
• Act as a senior technical risk authority in the realms of Enterprise Architecture, AI, Cloud, and Engineering.
• Lead initial risk analyses and provide credible challenges for significant architecture, AI/GenAI, agentic AI, cloud, and engineering decisions.
• Evaluate architecture and engineering risks early in the development lifecycle, focusing on security design, trust boundaries, threat scenarios, inherited controls, data flows, identity, privilege, APIs, cloud services, software supply chains, and resilience dependencies.
• Deliver senior risk challenges for AI systems and emerging AI architectures.
• Assess the design and effectiveness of controls using factual evidence.
• Create reusable risk scenarios, assessment methodologies, and minimum evidence expectations.
• Analyze threat modeling and scenario assessments to identify potential failure modes, attack vectors, concentration risks, and business repercussions.
• Link technical vulnerabilities to enterprise implications, including critical business services, sensitive data, resilience, regulatory requirements, and strategic initiatives.
• Develop decision-ready recommendations for senior management.
• Identify systemic and emerging cybersecurity risks through architecture reviews, assessments, incidents, issues, exceptions, audits, technology changes, and threat intelligence.
• Drive accountable remediation efforts and validate closure evidence.
• Collaborate across Cybersecurity, Technology, Engineering, Data, AI, and Risk while maintaining independent judgment.
• Function as a senior technical risk integrator and mentor within the risk organization.
• A minimum of 8 years of progressively responsible experience in cybersecurity, security architecture, cloud security, AI/ML security, or a related field.
• A Bachelor's degree or equivalent practical experience in cybersecurity, computer science, engineering, technology, risk, or a similar discipline.
• Expertise in enterprise security architecture, including cloud architectures, APIs, identity and access management, data protection, application/platform security, and software supply chain risk management.
• Experience in assessing risks associated with AI/ML, Generative AI, or emerging technologies.
• Proven experience in conducting threat modeling, architecture risk assessments, control evaluations, and scenario-based risk analyses.
• Capability to assess control design and operational effectiveness based on technical evidence.
• Proficiency in translating technical vulnerabilities, architectural weaknesses, and control gaps into business exposure and executive-level risk decisions.
• Familiarity with NIST CSF, NIST 800-53, NIST AI RMF, NIST SSDF/SP 800 218, ISO 27001, and other relevant frameworks.
• Ability to function effectively with incomplete evidence, clearly articulating assumptions and uncertainties.
• Strong skills in executive writing, synthesis, and presentation.
• Capacity to provide constructive challenges to senior engineers, architects, and executives.
• Experience in a complex, regulated enterprise, with an understanding of first-line ownership, independent risk oversight, and audit/assurance accountability.
• Desired: background in financial services, critical infrastructure, or another highly regulated industry.
• Desired: experience with public cloud and cloud-native security.
• Desired: familiarity with GenAI, RAG, AI agents, AI-enabled applications, or ML platforms.
• Desired: experience in secure software development and DevSecOps.
• Desired: experience in establishing security architecture patterns, risk scenarios, reference controls, or minimum evidence requirements.
• Desired: experience in systemic and emerging risk analysis.
• Desired: experience with risk metrics and leading indicators.
• Desired: experience presenting to executive management, governance committees, auditors, or regulators.
• Desired: ability to influence significant technology or investment decisions.
• Desired: experience in coaching or mentoring.
• Desired: certifications such as CISSP, CCSP, CISM, CRISC, SABSA, or relevant cloud/security architecture credentials.
• Desired: familiarity with enterprise GRC platforms and workflows.
• Eligible for participation in a Fannie Mae incentive program.
• Comprehensive benefits package that includes Health, Life, Voluntary Lifestyle, and other perks.
• Benefits and amenities that support physical, mental, emotional, and financial well-being.
• Opportunities for remote work.
Get handpicked remote jobs straight to your inbox weekly.