Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Lead AI Security Engineer - Senior Manager

$125.5k - $261.6k
Full-time

Ernst & Young

Location: Anywhere in Country

At EY, we’re all in to shape your future with confidence.

We’ll help you succeed in a globally connected powerhouse of diverse teams and take your career wherever you want it to go. Join EY and help to build a better working world.

The opportunity

We are seeking an AI Security Engineer to own the security posture of EY’s Agentic AI platform end to end.

Agentic AI breaks the assumptions most enterprise security programs are built on. Systems now generate and execute their own code, invoke tools and external APIs autonomously, act on behalf of human principals across long delegation chains, and can be manipulated through the same channel that carries legitimate instructions. Perimeter controls, static code review, and human-in-the-loop approval do not contain any of this on their own.

This role exists to make EY’s agentic platform defensible in the most highly regulated client environments in the world, including tax, financial services, audit, and risk. It is the security engineering and assurance authority spanning the whole stack: from silicon-level attestation and Kubernetes hardening, through supply-chain integrity and sandboxed execution, to prompt-injection defense, agent authority containment, and audit-grade evidence.

This is a deliberately broad mandate. It is ideal for a principal security engineer who has genuine depth in cloud-native and platform security, who has moved decisively into AI and agentic threat models, and who is equally comfortable writing a threat model, breaking a system in a red-team exercise, defining policy-as-code, and defending the resulting engineering to a client’s CISO or a regulator.

Your key responsibilities

  • Own the platform threat model : covering agent autonomy, tool invocation, delegated authority, model and data supply chain, multi-tenancy, and every deployment target from cloud to air-gapped, and keep it current as the platform evolves through each build phase.
  • Define the security engineering and control set for every platform layer: infrastructure and boot chain, Kubernetes and cluster fabric, identity and secrets, secure execution and sandboxing, gateway and egress, data and state, delivery pipeline, and telemetry.
  • Set the secure-by-default contract so that platform capabilities arrive hardened, including agent templates, Helm charts, sandbox profiles, and network policy ship with correct controls rather than requiring teams to add them.
  • Own defense against agentic threat classes including direct and indirect prompt injection, jailbreak and instruction hijacking, excessive agency, confused-deputy and authority-escalation attacks, tool and function-call abuse, memory and context poisoning, and retrieval-augmented data exfiltration.
  • Work with the architecture team to help define the agent authority model : delegated and on-behalf-of authority, scope and delegation-depth limits, consent boundaries, and the non-escalation invariant that an agent never exceeds the authority of its initiating principal at any hop.
  • Own the sandboxing security standard for agent-generated code execution: isolation boundaries, filesystem and credential scope, egress restriction, resource containment, and the escape-test suite that proves the boundary holds.
  • Secure the model and knowledge supply chain: model provenance and integrity, upstream registry governance, poisoning and backdoor risk, embedding and vector-store integrity.
  • Secure agent-to-agent and tool protocols including MCP and A2A surfaces: discovery trust, tool registration and approval, schema validation, and authorization of inter-agent calls.
  • Lead AI red teaming and adversarial testing: build the offensive capability and the recurring exercise cadence that tests guardrails, sandboxes, and authority boundaries before adversaries and auditors do.
  • Own supply-chain integrity end to end: artifact signing and verification (Sigstore/Cosign, Notation), SBOM generation and attestation, provenance and SLSA-aligned build integrity, CVE management, dependency and license governance.
  • Own admission and runtime policy: policy-as-code across Kyverno and OPA, signature-verification enforcement, Pod Security Standards, and the guardrails that make non-compliant workloads unschedulable rather than merely reported.
  • Define Kubernetes and infrastructure hardening baselines: CIS-aligned cluster configuration, network default-deny and segmentation, node and boot-chain integrity, GPU and DPU isolation, and secrets-handling standards.
  • Own tenant isolation assurance: the security definition of a tenant boundary across compute, network, storage, secrets, telemetry, and evidence, and the testing that proves cross-tenant leakage is not possible.
  • Serve as the security authority in client engagements: lead security engineering reviews, respond to client CISO and regulator scrutiny, and produce the assurance artefacts that unblock deployment into regulated environments.
  • Drive security detection and response for the platform: detection engineering for agentic misbehavior, security telemetry requirements, alerting, incident response playbooks, and post-incident review.

Skills and attributes for success

  • Deep cloud-native security expertise: Kubernetes, container, and infrastructure security at production scale, with real operational experience rather than assessment-only exposure.
  • Genuine command of AI and agentic threat models, with the judgement to distinguish novel risk from familiar risk wearing new vocabulary.
  • Strong zero-trust and workload-identity foundations: SPIFFE/SPIRE, PKI and certificate lifecycle, secrets management, and delegated authorization patterns.
  • Fluency in policy-as-code, with the instinct to encode controls as enforced policy rather than documented expectation.
  • Software supply-chain security depth: signing, provenance, SBOM, and build integrity.
  • Offensive-security instinct: able to think like an attacker against systems that generate their own code and act autonomously.
  • Pragmatism about risk: able to distinguish controls that must exist before the first client workload from those that can follow, and to defend both decisions.
  • Exceptional communication: able to move between a deep technical design review, an executive risk conversation, and a regulator or client CISO discussion without losing precision.
  • Security-as-enablement mindset: measured by how much safe delivery velocity the controls unlock, not by how much they prevent.

To qualify you must have

  • Bachelor’s or Master’s degree in Computer Science, Security, or a related technical field, or demonstrably equivalent depth.
  • 10+ years in security engineering, security engineering, or offensive security, including hands-on production ownership.
  • Demonstrable depth in cloud-native and Kubernetes security: admission control, network policy, workload isolation, and runtime security in production.
  • Hands-on experience with workload identity and secrets management (SPIFFE/SPIRE, Vault/OpenBao or equivalents) and with PKI and certificate lifecycle.
  • Practical experience securing AI or ML systems in production, including familiarity with LLM and agentic attack surfaces, such as prompt injection, tool abuse, excessive agency, and model or data supply-chain risk.
  • Threat modelling capability applied to real systems, with evidence that the resulting controls were built and verified.
  • A track record delivering under compliance, security, or regulatory constraint with audit-grade evidence requirements.
  • Experience defining ownership boundaries and control contracts with platform, data, runtime, and delivery teams.

Ideally, you'll also have

  • Software supply-chain security experience: artifact signing, SBOM, provenance, and vulnerability management embedded in delivery pipelines.
  • Policy-as-code experience with OPA, Kyverno, or equivalent admission and authorisation engines.
  • Experience building or leading an AI red team, or running adversarial testing against LLM and agentic systems.
  • Familiarity with confidential computing and hardware attestation (Intel TDX, AMD SEV-SNP, SGX, NVIDIA CC) and secure boot / measured boot designs.
  • Working knowledge of the OWASP Top 10 for LLM Applications, MITRE ATLAS, NIST AI RMF, and the EU AI Act as applied to real engineering.
  • Experience with LLM guardrail and defense tooling (NeMo Guardrails, LLM Guard, LlamaFirewall, Guardrails AI, or equivalents) in production paths.
  • Experience securing multi-tenant platforms across cloud, on-prem, edge, client-managed, and air-gapped deployment modes.
  • Detection engineering and incident response experience, particularly for novel or behavioral threat classes.
  • Client-facing or consulting background, with credibility in front of CISOs, auditors, and regulators.
  • Relevant certifications (CISSP, OSCP, GIAC, cloud security specialties) or demonstrable equivalent depth.
  • Exposure to regulated industries: financial services, tax, audit, healthcare, or public sector.
  • Contribution to open-source security tooling, research, or public standards work in AI security.

What we offer you
At EY, we harness our collective strength to empower you to shape your future with confidence through professional growth, personal fulfillment and an inclusive culture. Learn more at ey.com/us/careers.

  • We offer a comprehensive compensation and benefits package where you’ll be rewarded based on your performance and recognized for the value you bring to the business. The base salary range for this job is:
    • New York City, Boston, and Washington DC Metro Areas, Washington State, and Southern California offices – $150,700 to $251,200
    • Bay Area California offices – $157,100 to $261,600
    • All other offices locations in the US, including Sacramento – $125,500 to $230,200
  • Individual salaries within these ranges are determined through a wide variety of factors including but not limited to education, experience, knowledge, skills and geography. In addition, our Total Rewards package includes medical and dental coverage, pension and 401(k) plans, and a wide range of paid time off options.
  • Under our flexible vacation policy, you’ll decide how much vacation time you need based on your own personal circumstances. You’ll also be granted time off for designated EY Paid Holidays, Winter/Summer breaks, Personal/Family Care, and other leaves of absence when needed to support your physical, financial, and emotional well-being.

Are you ready to shape your future with confidence? Apply today.

  • To make the most of your application experience, please limit yourself to two applications within a six-month period.
  • EY accepts applications for this position on an on-going basis.
  • For those living in California, please click here for additional information.
  • At EY, our values set the foundation for how we work and the behaviors we expect of our people. Any misrepresentation or falsification of information or lack of integrity at any point in the recruiting process may result in withdrawal of your candidacy, revocation of an offer or immediate termination of employment.

EY | Building a better working world

EY is building a better working world by creating new value for clients, people, society and the planet, while building trust in capital markets.

Enabled by data, AI and advanced technology, EY teams help clients shape the future with confidence and develop answers for the most pressing issues of today and tomorrow.

EY teams work across a full spectrum of services in assurance, consulting, tax, strategy and transactions. Fueled by sector insights, a globally connected, multi-disciplinary network and diverse ecosystem partners, EY teams can provide services in more than 150 countries and territories.

All in to shape the future with confidence.

EY provides equal employment opportunities to applicants and employees without regard to race, color, religion, age, sex, sexual orientation, gender identity/expression, pregnancy, genetic information, national origin, protected veteran status, disability status, or any other legally protected basis, including arrest and conviction records, in accordance with applicable law.

EY is committed to providing reasonable accommodation to qualified individuals with disabilities including veterans with disabilities. If you have a disability and either need assistance applying online or need to request an accommodation during any part of the application process, please call 1-800-EY-HELP3, select Option 2 for candidate related inquiries, then select Option 1 for candidate queries and finally select Option 2 for candidates with an inquiry which will route you to EY’s Talent Shared Services Team (TSS) or email the TSS at View email address on aiapply.co.

Vacancy posted 3 days ago
Similar jobs that could be interesting for youBased on the Lead AI Security Engineer - Senior Manager in Alabama vacancy
  •  ...Job Description Job Description Senior Information Protection & AI Security Engineer Job Type: Permanent Full-Time Job Category: Cybersecurity...  ...Protection, Data Loss Prevention (DLP), Insider Risk Management, Communication Compliance, data classification, and... 
    Senior
    Permanent employment
    Full time

    System One

    Birmingham, AL
    6 days ago
  • $118.7k - $243.7k

    As a Manager in AI Security Engineering, you will play a critical role in securing the development and deployment of AI/ML and Generative AI solutions...  ...and sustain professional relationships Ability to lead projects or workstreams Ability to manage and prioritize... 
    Suggested

    Deloitte LLP

    Alabama
    6 days ago
  •  ...Operations (PWS 1.16.6, 1.16.6.5): Serves as the deputy to the Senior Service Desk Lead, providing continuity of Service Desk leadership during...  ..., or personnel transitions. Assumes full Service Desk management authority in the Lead's absence, ensuring no gap in SLA enforcement... 
    Senior
    Contract work

    Technology, Automation, and Management, Inc.

    Huntsville, AL
    23 days ago
  •  ...Job Description Job Description Senior Artificial Engineer Always Forward Recruiting is currently seeking a Senior AI Engineer (direct-hire). This opportunity is centered...  ...lasting relationships we've cultivated to secure quality career advancement, passion pivot,... 
    Senior
    Remote work

    ALWAYS FORWARD RECRUITING LLC

    Tuscaloosa, AL
    a month ago
  •  ...Stream: IT Solutions Role: Technical Lead (TEL) Job Title: Technical Lead, IT Solutions...  ...motivated and technically proficient AI Engineer to join our growing Data & Analytics team...  ...with data engineers to ensure scalable, secure, and compliant data flows between enterprise... 
    Senior
    Work experience placement
    Work at office
    Local area
    Remote work

    Celestica

    Huntsville, AL
    2 days ago
  •  ...Description Overview Information Security & Program Protection...  ...to government stakeholders, leading the development, integration...  ...of acquisition, security engineering, and counterintelligence,...  ...Acquisition Security / Risk Management Strong working knowledge... 
    Full time
    For contractors
    Work at office

    Astrion

    Huntsville, AL
    3 days ago
  • $73.5k - $212.28k

     ...in data and analytics engineering focus on leveraging advanced...  ...unique strengths, and managing performance to deliver...  .... You are expected to lead with integrity and...  ...development of innovative AI solutions that drive...  ...client service accounts, securing the delivery of quality... 
    H1b

    PwC

    Birmingham, AL
    3 days ago
  •  ...to expand its development organization with the addition of a Senior AI Engineer. We are focused on applying state-of-the-art Artificial...  ...leadership, and communication skills and must be able to effectively lead a small to medium sized team. Qualifications Bachelor's... 
    Senior

    Camgian Corporation

    Huntsville, AL
    3 days ago
  • $144.18k - $219.52k

     ...part of the Blue National Security business unit, which is...  ...the forefront of systems engineering, formulation, and architecture...  .... We are seeking a Senior Assembly, Integration & Test (AI&T) Engineer to shape the...  ...note this is a publicly managed inbox. Please do not include... 
    Senior
    Permanent employment
    Full time
    Temporary work
    Work at office
    Local area
    Relocation
    Relocation package
    Shift work

    BLUE ORIGIN

    Huntsville, AL
    3 days ago
  • Senior Artificial Intelligence Engineer As a Senior Artificial Intelligence Engineer...  ...team, you will lead the design and development of AI/ML-powered prototypes...  ...branching, merging, and managing code repositories in...  ...maintain a U.S. Government Security Clearance which... 
    Senior
    Remote work

    Camgian

    Huntsville, AL
    3 days ago
  • Senior AI Engineer At Jack Henry, we're more than a technology company, we'...  ...institutions to deliver seamless, secure, and human centered...  ...responsible for: Performs and leads system analysis and programming...  ..., hiring, performance management, promotion, transfer, compensation... 
    Senior
    Permanent employment
    H1b
    Work at office
    Local area
    Shift work
    1 day per week

    Jack Henry and Associates

    Birmingham, AL
    3 days ago
  •  ...a customer-focused Databricks Solutions Engineer to work directly with business stakeholders...  ..., along with an interest in leveraging AI and emerging technologies to improve business...  ...data platforms and modern DevOps practices #J-18808-Ljbffr Coalesce Management Consulting
    Senior

    Coalesce Management Consulting

    Birmingham, AL
    4 days ago
  • $120k - $140k

     ...Technology Overview GovCIO is seeking a highly experienced Senior Network & Security Engineer to lead the design, operation, troubleshooting, and continuous...  ...the design, deployment, administration, and lifecycle management of Palo Alto Networks NGFW environments running PAN-OS... 
    Senior
    Full time
    Remote work
    Flexible hours

    GovCIO

    Montgomery, AL
    1 day ago
  • $126k - $188k

     ...applications and services by identifying security risks early, partnering closely with product and engineering teams, and guiding practical...  ...dynamic cloud environment and manage and update workflow of team's...  ...a resume for that opening. AI Notice Indeed is committed to... 
    Senior
    Work experience placement
    Local area
    Remote work

    Indeed

    Huntsville, AL
    3 days ago
  •  ...motivated, career and customer-oriented Senior Information System Security Engineer (ISSE) to join our team in...  ...GRC and enterprise tracking tools Lead stakeholder engagement through office...  ...to support vulnerability management and compliance efforts Provide rapid... 
    Senior
    Work at office

    ManTech

    Huntsville, AL
    1 day ago
  • AI Infrastructure Engineer Redstone Arsenal/Huntsville, AL At IPT Associates (IPTA), we enjoy solving...  ...Collaborate with platform engineers, product leads, mission users, and government...  ...verbal communication skills. Active Security Clearance Required. Desired Qualifications... 
    Senior

    Interactive Process Technology LLC

    Huntsville, AL
    3 days ago
  • $107.9k - $195.05k

     ...Portfolio is seeking a talented Senior AI/ML Engineer to integrate generative AI...  ...remain trusted and secure. We advance sensor system technologies...  .... Primary Responsibilities Lead the integration of LLMs,...  ...and rollback, and lifecycle management Collaborate with software engineers... 
    Senior
    Worldwide

    Leidos

    Huntsville, AL
    2 days ago
  • $135k - $167k

     ...Position Title: Senior Electrical Security System Engineer Location: Huntsville, AL Employment Type: Full-Time Salary Range: $135,000-$167,000 Position Summary RPI Group, Inc. is looking for a Senior Electronic Security System (ESS) Engineer to support... 
    Senior
    Full time
    Contract work
    For subcontractor

    RPI Group Inc

    Huntsville, AL
    19 days ago
  • $148k - $168k

     ...SECURITY CLEARANCE REQUIREMENT: TS, WITH SCI ELIGIBILITY ***POSITION...  ...areas of Cybersecurity and Management to improve the Information...  ...: We are seeking a Senior Level ISSE to carry out the...  ...support Information System Engineering performed by the Information... 
    Senior
    Full time
    Contract work

    RedTrace Technologies Inc

    Huntsville, AL
    10 days ago
  •  ...Job Description Job Description DC Team Lead Reporting To: DC Manager  Direct Reports: Yes Status: Full-Time  Exempt/Non-Exempt: Non-Exempt Division: Distribution and Logistics    Job Purpose: The Distribution Center (DC) Team Lead oversees and... 
    Senior
    Full time
    Immediate start
    Shift work

    TPH Holdings LLC

    Birmingham, AL
    2 days ago
  •  ...professional business and information management services. STI-TEC offers...  ...protect and enhance national security. Join us and be part of...  ...secure. The ideal Lead Specialty Integration Manager...  ...the integration of specialty engineering disciplines—such as cybersecurity... 
    Contract work
    Temporary work
    For contractors
    Flexible hours

    Solutions Through Innovative Technologies, Inc

    Huntsville, AL
    a month ago
  •  ...support for Model-Based Systems Engineering (MBSE) to enhance the...  ...systems for PAE Fires. The Lead Senior Enterprise Architect drives...  ...technical stakeholders (Program Managers, CPE leadership) can understand...  ..., infrastructure, and security into a unified technology strategy... 
    Senior
    Contract work

    Technology, Automation, and Management, Inc.

    Huntsville, AL
    23 days ago
  •  ...Austal USA is a ship manufacturer with facilities in Mobile, Alabama, San Diego, Singapore, and Charlottesville. The Contracts Manager will oversee all contract administration for assigned programs, draft and negotiate contracts, and coordinate with multiple departments... 
    Senior
    Contract work

    Austal

    Mobile, AL
    1 day ago
  •  ...in Huntsville, AL Summary The Private Client Relationship Manager will provide business depository, treasury management, and...  ...adhere to all risk and control policies, regulatory guidelines and security measures Performs all other duties as assigned.   QUALIFICATIONS... 
    Senior
    Full time
    Temporary work
    Work experience placement
    Local area

    First Horizon Bank

    Huntsville, AL
    13 days ago
  •  ...Thompson CAT in Birmingham, AL seeks a Human Resources Benefits Manager to lead the direction and administration of employee health and wellness benefits and total rewards programs. This role serves as the SME and primary spokesperson for benefits, reporting to the Director... 
    Senior

    Thompson CAT

    Birmingham, AL
    4 days ago
  •  ...A leading consulting firm is seeking a Construction Project Manager to oversee diverse construction projects from start to finish. This role involves managing schedules...  ...should possess a Bachelor's degree in Engineering and extensive related experience, preferably with... 
    Senior
    For subcontractor

    4P Consulting Inc

    Calera, AL
    2 days ago
  • A leading electrical contracting firm is seeking a Foreman Electrician for multiple job sites across the southeastern United States. The ideal candidate should have 7-10 years of experience in electrical construction, showcasing leadership and mentorship skills. Responsibilities... 
    Senior
    Local area

    Comfort Systems USA

    Newton, AL
    4 days ago
  •  ...Chugach Government Solutions (CGS) is seeking a Labor Relations Manager to serve as the enterprise operational lead for labor-management relations. You will partner with Operations, site HR, Payroll, Benefits, unions, and Legal Counsel to administer CBAs, resolve disputes... 
    Senior

    Chugach Alaska

    Huntsville, AL
    4 days ago
  • RaceTrac in Huntsville, Alabama, is looking for a driven Co-Manager to support the General Manager and lead a team focused on exceptional guest experiences. In this dynamic role, you'll cultivate a welcoming culture while driving sales and operational excellence. The ideal... 

    RaceTrac

    Huntsville, AL
    3 days ago
  • A leading electrical contractor is seeking a Foreman Electrician to oversee installation and repair of electrical systems across various...  ...standards. Responsibilities include leading crew members, managing projects effectively, and ensuring all work adheres to local regulations... 
    Senior
    For contractors
    Local area

    Comfort Systems USA

    Birmingham, AL
    4 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Lead AI Security Engineer - Senior Manager. Be the first to apply!