Fannie Mae sits at the center of U.S. housing finance - a government-sponsored enterprise that purchases mortgages from lenders, bundles them into mortgage-backed securities, and sells them to investors. Founded in 1938, the company facilitated $409 billion in funding in 2025, helping roughly 1.5 million households buy, refinance, or rent. That's the attack surface: systemic financial infrastructure underpinning a massive chunk of the American housing market, where a breach doesn't just leak data - it could ripple through mortgage-backed securities markets and disrupt lending pipelines nationwide.
Threat models here are layered. You're protecting mortgage origination and servicing data at scale, securing the platforms that manage multifamily and single-family loan pipelines, and defending the systems that securitize and distribute those products to institutional investors. The work spans identity and access controls across legacy and modernized financial systems, cloud security for workloads tied to high-throughput data processing, and the governance frameworks required to meet federal regulatory expectations. Fannie Mae operates under significant regulatory oversight given its conservatorship status and systemic importance.
Products like the 30-year fixed-rate mortgage and the Delegated Underwriting and Servicing (DUS) model for multifamily financing aren't just financial instruments - they're data-heavy workflows that depend on secure, reliable infrastructure. Security engineering here means working at the intersection of financial technology, compliance, and resilience, with the understanding that uptime and integrity aren't negotiable when your systems help finance a significant portion of the U.S. housing stock.




