Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Lead AI Security Engineer - Senior Manager

$150.7k - $251.2k

Jobleads-US

Location: Anywhere in Country

At EY, we’re all in to shape your future with confidence.

We’ll help you succeed in a globally connected powerhouse of diverse teams and take your career wherever you want it to go. Join EY and help to build a better working world.

The opportunity

We are seeking an AI Security Engineer to own the security posture of EY’s Agentic AI platform end to end.

Agentic AI breaks the assumptions most enterprise security programs are built on. Systems now generate and execute their own code, invoke tools and external APIs autonomously, act on behalf of human principals across long delegation chains, and can be manipulated through the same channel that carries legitimate instructions. Perimeter controls, static code review, and human-in-the-loop approval do not contain any of this on their own.

This role exists to make EY’s agentic platform defensible in the most highly regulated client environments in the world, including tax, financial services, audit, and risk. It is the security engineering and assurance authority spanning the whole stack: from silicon-level attestation and Kubernetes hardening, through supply-chain integrity and sandboxed execution, to prompt-injection defense, agent authority containment, and audit-grade evidence.

This is a deliberately broad mandate. It is ideal for a principal security engineer who has genuine depth in cloud-native and platform security, who has moved decisively into AI and agentic threat models, and who is equally comfortable writing a threat model, breaking a system in a red-team exercise, defining policy-as-code, and defending the resulting engineering to a client’s CISO or a regulator.

Your key responsibilities

  • Own the platform threat model : covering agent autonomy, tool invocation, delegated authority, model and data supply chain, multi-tenancy, and every deployment target from cloud to air-gapped, and keep it current as the platform evolves through each build phase.

  • Define the security engineering and control set for every platform layer: infrastructure and boot chain, Kubernetes and cluster fabric, identity and secrets, secure execution and sandboxing, gateway and egress, data and state, delivery pipeline, and telemetry.

  • Set the secure-by-default contract so that platform capabilities arrive hardened, including agent templates, Helm charts, sandbox profiles, and network policy ship with correct controls rather than requiring teams to add them.

  • Own defense against agentic threat classes including direct and indirect prompt injection, jailbreak and instruction hijacking, excessive agency, confused-deputy and authority-escalation attacks, tool and function-call abuse, memory and context poisoning, and retrieval-augmented data exfiltration.

  • Work with the architecture team to help define the agent authority model : delegated and on-behalf-of authority, scope and delegation-depth limits, consent boundaries, and the non-escalation invariant that an agent never exceeds the authority of its initiating principal at any hop.

  • Own the sandboxing security standard for agent-generated code execution: isolation boundaries, filesystem and credential scope, egress restriction, resource containment, and the escape-test suite that proves the boundary holds.

  • Secure the model and knowledge supply chain: model provenance and integrity, upstream registry governance, poisoning and backdoor risk, embedding and vector-store integrity.

  • Secure agent-to-agent and tool protocols including MCP and A2A surfaces: discovery trust, tool registration and approval, schema validation, and authorization of inter-agent calls.

  • Lead AI red teaming and adversarial testing: build the offensive capability and the recurring exercise cadence that tests guardrails, sandboxes, and authority boundaries before adversaries and auditors do.

  • Own supply-chain integrity end to end: artifact signing and verification (Sigstore/Cosign, Notation), SBOM generation and attestation, provenance and SLSA-aligned build integrity, CVE management, dependency and license governance.

  • Own admission and runtime policy: policy-as-code across Kyverno and OPA, signature-verification enforcement, Pod Security Standards, and the guardrails that make non-compliant workloads unschedulable rather than merely reported.

  • Define Kubernetes and infrastructure hardening baselines: CIS-aligned cluster configuration, network default-deny and segmentation, node and boot-chain integrity, GPU and DPU isolation, and secrets-handling standards.

  • Own tenant isolation assurance: the security definition of a tenant boundary across compute, network, storage, secrets, telemetry, and evidence, and the testing that proves cross-tenant leakage is not possible.

  • Serve as the security authority in client engagements: lead security engineering reviews, respond to client CISO and regulator scrutiny, and produce the assurance artefacts that unblock deployment into regulated environments.

  • Drive security detection and response for the platform: detection engineering for agentic misbehavior, security telemetry requirements, alerting, incident response playbooks, and post-incident review.

Skills and attributes for success

  • Deep cloud-native security expertise: Kubernetes, container, and infrastructure security at production scale, with real operational experience rather than assessment-only exposure.

  • Genuine command of AI and agentic threat models, with the judgement to distinguish novel risk from familiar risk wearing new vocabulary.

  • Strong zero-trust and workload-identity foundations: SPIFFE/SPIRE, PKI and certificate lifecycle, secrets management, and delegated authorization patterns.

  • Fluency in policy-as-code, with the instinct to encode controls as enforced policy rather than documented expectation.

  • Software supply-chain security depth: signing, provenance, SBOM, and build integrity.

  • Offensive-security instinct: able to think like an attacker against systems that generate their own code and act autonomously.

  • Pragmatism about risk: able to distinguish controls that must exist before the first client workload from those that can follow, and to defend both decisions.

  • Exceptional communication: able to move between a deep technical design review, an executive risk conversation, and a regulator or client CISO discussion without losing precision.

  • Security-as-enablement mindset: measured by how much safe delivery velocity the controls unlock, not by how much they prevent.

To qualify you must have

  • Bachelor’s or Master’s degree in Computer Science, Security, or a related technical field, or demonstrably equivalent depth.

  • 10+ years in security engineering, security engineering, or offensive security, including hands-on production ownership.

  • Demonstrable depth in cloud-native and Kubernetes security: admission control, network policy, workload isolation, and runtime security in production.

  • Hands-on experience with workload identity and secrets management (SPIFFE/SPIRE, Vault/OpenBao or equivalents) and with PKI and certificate lifecycle.

  • Practical experience securing AI or ML systems in production, including familiarity with LLM and agentic attack surfaces, such as prompt injection, tool abuse, excessive agency, and model or data supply-chain risk.

  • Threat modelling capability applied to real systems, with evidence that the resulting controls were built and verified.

  • A track record delivering under compliance, security, or regulatory constraint with audit-grade evidence requirements.

  • Experience defining ownership boundaries and control contracts with platform, data, runtime, and delivery teams.

Ideally, you'll also have

  • Software supply-chain security experience: artifact signing, SBOM, provenance, and vulnerability management embedded in delivery pipelines.

  • Policy-as-code experience with OPA, Kyverno, or equivalent admission and authorisation engines.

  • Experience building or leading an AI red team, or running adversarial testing against LLM and agentic systems.

  • Familiarity with confidential computing and hardware attestation (Intel TDX, AMD SEV-SNP, SGX, NVIDIA CC) and secure boot / measured boot designs.

  • Working knowledge of the OWASP Top 10 for LLM Applications, MITRE ATLAS, NIST AI RMF, and the EU AI Act as applied to real engineering.

  • Experience with LLM guardrail and defense tooling (NeMo Guardrails, LLM Guard, LlamaFirewall, Guardrails AI, or equivalents) in production paths.

  • Experience securing multi-tenant platforms across cloud, on-prem, edge, client-managed, and air-gapped deployment modes.

  • Detection engineering and incident response experience, particularly for novel or behavioral threat classes.

  • Client-facing or consulting background, with credibility in front of CISOs, auditors, and regulators.

  • Relevant certifications (CISSP, OSCP, GIAC, cloud security specialties) or demonstrable equivalent depth.

  • Exposure to regulated industries: financial services, tax, audit, healthcare, or public sector.

  • Contribution to open-source security tooling, research, or public standards work in AI security.

What we offer you

At EY, we harness our collective strength to empower you to shape your future with confidence through professional growth, personal fulfillment and an inclusive culture. Learn more at ey.com/us/careers.

  • We offer a comprehensive compensation and benefits package where you’ll be rewarded based on your performance and recognized for the value you bring to the business. The base salary range for this job is:

  • New York City, Boston, and Washington DC Metro Areas, Washington State, and Southern California offices – $150,700 to $251,200

  • Bay Area California offices – $157,100 to $261,600

  • All other offices locations in the US, including Sacramento – $125,500 to $230,200

  • Individual salaries within these ranges are determined through a wide variety of factors including but not limited to education, experience, knowledge, skills and geography. In addition, our Total Rewards package includes medical and dental coverage, pension and 401(k) plans, and a wide range of paid time off options.

  • Under our flexible vacation policy, you’ll decide how much vacation time you need based on your own personal circumstances. You’ll also be granted time off for designated EY Paid Holidays, Winter/Summer breaks, Personal/Family Care, and other leaves of absence when needed to support your physical, financial, and emotional well-being.

EY | Building a better working world

EY is building a better working world by creating new value for clients, people, society and the planet, while building trust in capital markets.

Enabled by data, AI and advanced technology, EY teams help clients shape the future with confidence and develop answers for the most pressing issues of today and tomorrow.

EY teams work across a full spectrum of services in assurance, consulting, tax, strategy and transactions. Fueled by sector insights, a globally connected, multi-disciplinary network and diverse ecosystem partners, EY teams can provide services in more than 150 countries and territories.

All in to shape the future with confidence.

EY provides equal employment opportunities to applicants and employees without regard to race, color, religion, age, sex, sexual orientation, gender identity/expression, pregnancy, genetic information, national origin, protected veteran status, disability status, or any other legally protected basis, including arrest and conviction records, in accordance with applicable law.

EY is committed to providing reasonable accommodation to qualified individuals with disabilities including veterans with disabilities. If you have a disability and either need assistance applying online or need to request an accommodation during any part of the application process, please call 1-800-EY-HELP3, select Option 2 for candidate related inquiries, then select Option 1 for candidate queries and finally select Option 2 for candidates with an inquiry which will route you to EY’s Talent Shared Services Team (TSS) or email the TSS at View email address on click.appcast.io .

#J-18808-Ljbffr Jobleads-US
Vacancy posted 2 days ago
Similar jobs that could be interesting for youBased on the Lead AI Security Engineer - Senior Manager in Charlotte, NC vacancy
  •  ...Key Responsibilities AI Security Leadership Lead the AI Security function, including development and...  ...with Cybersecurity Architects and Engineers, IT Infrastructure Engineers, and Application...  ...Partner with Project and Program Management to ensure that we’re executing the... 
    Suggested
    Full time
    Shift work
    Night shift
    Weekend work

    CRC Group

    Charlotte, NC
    4 days ago
  • $210k

    AI SECURITY ENGINEER LEADTHE TEAM YOU WILL BE JOININGJoin a growing Security...  ...agentic technology. Serve as the senior AI Security SME within a...  ...Step into a newly created Lead-level individual contributor...  ...path without requiring people management. Compensation up to... 
    Suggested

    AccruePartners

    Charlotte, NC
    2 days ago
  • $124k - $280k

     ...OpportunityAs an AML and Sanctions- AI Engineer- Senior Manager, you will leverage data and analytics...  ...team effectiveness.Responsibilities- Leading the development and implementation of...  ...factors thoughtfully to establish a secure and trusted workplace for all.SummaryLocation... 
    Senior
    Full time
    H1b

    PwC

    Charlotte, NC
    4 days ago
  • We AreAccenture Security helps organizations prepare, protect...  ...security, and managed service solutions to rethink...  ...Forward Deployed Engineer is a production engineer...  ...engineering teams—to make AI systems secure, governed...  ...(AWS, Azure, or GCP)Lead AI governance framework... 
    Senior
    Full time
    Work experience placement
    Live in
    Work at office
    Local area

    Accenture

    Charlotte, NC
    2 days ago
  •  ...cost-out, strategic category management, and procurement operations.You...  ...clients shift to the New using leading-edge technologies on the most...  ...satisfaction, and community impact.As a Senior Manager, you will be...  ...leadership in cloud, data and AI with unmatched industry experience... 
    Senior
    Full time
    Work experience placement
    Live in
    Work at office
    Local area
    Shift work

    Accenture

    Charlotte, NC
    3 days ago
  •  ...Realign Llc in Charlotte, NC seeks a highly technical Senior Engineer to lead AI security/platform modernization and developer productivity initiatives...  ...of AI capabilities, establish an AI vulnerability-management roadmap, accelerate modernization, and enable rapid releases... 
    Senior

    Jobleads-US

    Charlotte, NC
    3 days ago
  •  ...following job description:Leads an IAM AuthN/AuthZ-focused engineering, automation, and...  ..., and delivering AI-enabled automation,...  ..., architecture, security, risk, and compliance...  ...evidence retention.Manages, develops, and...  ...measurable outcomes to senior leaders and partner... 
    Senior
    Permanent employment
    Full time
    Part time
    Work experience placement
    H1b
    Work visa
    Shift work
    Day shift

    Truist

    Charlotte, NC
    4 days ago
  •  ...building out practitioners within our Song - Sales practice: AI Forward Deployed Engineers who embed directly with clients to design, prototype, and...  ...$141,100 to $337,000About AccentureAccenture is a leading global professional services company that helps the world’... 
    Senior
    Full time
    Live in
    Work at office
    Local area

    Accenture

    Charlotte, NC
    4 days ago
  •  ...us! Seeking a highly technical, hands-on Senior Engineer with deep Systems Engineering expertise to lead AI security, platform modernization, and developer productivity...  ..., establish the roadmap for AI vulnerability management (including Mythos remediation), accelerate... 
    Senior
    Work at office
    Flexible hours
    Shift work
    Day shift

    Bank of America Corporation

    Charlotte, NC
    19 days ago
  • $153k - $297k

     ...seeking an Associate Director, AI Security Frontier Engineering to join our Enterprise...  ...record of independently leading technical initiatives end-...  ...engineering teams and non-technical senior stakeholdersApplicants...  ...judgment, effectively manage stress and work safely and... 
    H1b
    Local area

    KPMG

    Charlotte, NC
    1 day ago
  • $112k - $216k

     ...search for talented visionaries and your search for important and impactful work lead to the same place.As a member of the Global Client Growth team, the Market Development Senior Manager will have responsibility for developing and executing marketing and business development... 
    Senior
    Full time
    Temporary work
    Work at office
    Local area
    Remote work
    Shift work

    K&L Gates

    Charlotte, NC
    3 days ago
  • About this role:Wells Fargo is seeking a Senior Lead Business Execution Consultant to serve as the Branch Customer Intelligence & Insights subject-matter expert within Branch Channel Management.This role serves as the primary research and insights partner supporting the... 
    Senior
    Full time
    Work experience placement
    Work at office
    Shift work

    Wells Fargo

    Charlotte, NC
    15 hours ago
  • $139k - $239k

    About this role:The Wealth & Investment Management (WIM) Chief Product Office (CPO) is seeking a Senior Lead Product Manager supporting Client Management. This role provides product leadership across key capabilities, including Leads and Referrals, New Associate, ServiceNow... 
    Senior
    Full time
    Work experience placement
    Work at office

    Wells Fargo

    Charlotte, NC
    2 days ago
  •  ...company at the forefront of AI-native innovation. We...  ...-powered workflows engineered to scale in real-world...  ...Deployed AI EngineerSr Manager who thrives at the intersection...  ...for responsible, secure, and scalable AI deployment...  ..., including leading technical discussions,... 
    Senior
    Full time
    Work experience placement
    Live in
    Work at office
    Local area

    Accenture

    Charlotte, NC
    3 days ago
  •  ...client success by designing and leading expertly tailored solutions....  ...have come to rely on us to manage their most vital transformation...  ..., Quality, Regulatory, Engineering, Finance, Information Technology...  ...information for site teams and senior leadership. · Ability to... 
    Senior
    Full time
    Contract work
    Local area

    Blue Skies Consulting

    Charlotte, NC
    4 days ago
  •  ...Responsible for the design, implementation, and management of a defined Digital, Client Experience,...  .... Act as an authority and primary lead to manage engagements on behalf of DCXM and...  ...DCXM for review and engagement with DCXM Senior Leadership Team and key first, second,... 
    Senior
    Full time
    Part time
    Shift work
    Day shift

    Truist

    Charlotte, NC
    3 days ago
  • We Are:Accenture is a leading solutions and services company that helps...  ...and unleashing the power of AI to create value at speed...  ..., data, analytics, AI, change management, talent and sustainability capabilities...  ...working on a priority. At a Senior Manager level, it could... 
    Senior
    Full time
    Live in
    Work at office
    Local area

    Accenture

    Charlotte, NC
    4 days ago
  •  ...SecurityAccenture Security delivers continuous...  ..., security and managed services.Accenture...  ...proposal response etc.)Leads large/ complex...  ...interaction with senior leadership at a client...  ..., infrastructure engineering, software...  ...knowledge on usage of AI (demonstrate AI fluency... 
    Senior
    Full time
    Work experience placement
    Live in
    Work at office
    Local area

    Accenture

    Charlotte, NC
    3 days ago
  •  ...of America)Please review the following job description:The AI Security Engineer is responsible for implementing, validating, and supporting...  ...controls including identity protections, access controls, secrets management, logging, monitoring, and deployment safeguards.Assist... 
    Full time
    Part time
    Shift work
    Day shift

    Truist

    Charlotte, NC
    4 days ago
  •  ...team uses automated API security tools like Akamai, Salt...  ...in running APIs.• This Senior Security Engineer will be experienced...  ...change from time to time.Lead the enterprise vulnerability management program for automated API...  ...traceability for AI systems. Working knowledge... 
    Senior
    Full time
    Part time
    Shift work
    Day shift

    Truist

    Charlotte, NC
    1 day ago
  •  ...services, including banking, leasing, securities, credit cards, and consumer finance....  ...Leasing Co., Ltd. JOB SUMMARY As an AI Security Engineer, you will help secure the...  ...web applications, identity and access management, authentication, privileged access controls... 
    Work at office
    Local area
    Work from home
    Worldwide

    SMBC Group

    Charlotte, NC
    2 days ago
  • $120k - $135k

    *****NO C2C OR THIRD PARTY INQUIRIES***** Senior Security Engineer Location: Charlotte, NC – Full time Onsite 5 days per week Salary Range: $120k - $135k The Professional Services Consultant (SASE) is an expert with a strong understanding of network security... 
    Senior
    Full time
    Remote work
    Weekend work

    Secur-Serv

    Charlotte, NC
    2 days ago
  • Charlotte, North CarolinaHybridFull Time$120k - $160kSenior AI/ML Engineer (Python)Onsite — Wilmington, NC Our client, a fintech company building...  ...-world assets, and financial instruments, is looking for a Senior AI/ML Engineer with strong Python skills to join their... 
    Senior
    Full time

    Motion Recruitment

    Charlotte, NC
    5 days ago
  • $122k - $240.5k

     ...Summary Agentic AI is moving from experimentation...  ...'re growing a team of engineers who want to work at the...  ...complex engagements. Manage day-to-day interactions...  ...Ability to lead projects or workstreamsAbility...  ...entry-level employees to senior leaders, we believe... 
    Senior
    Work at office
    Local area
    Visa sponsorship
    Shift work

    Deloitte

    Charlotte, NC
    3 days ago
  •  ...review the following job description:The Senior AI Agentic Engineer is a hands-on software engineer...  ...integrations. The engineer develops scalable, secure, and reliable solutions that combine...  ...human-in-the-loop controls, session management, and safe fallback mechanisms.Develop... 
    Senior
    Full time
    Part time
    Shift work
    Day shift

    Truist

    Charlotte, NC
    3 days ago
  • We are: A leading partner to the world’s major...  ...in cloud change management; and cloud-ready operating...  ...by design — with security, data privacy,...  ...and product engine of the Accenture Google...  ...move to Agentic AI and Product-Led Operating...  ...AI Delivery Senior Engineer, you are... 
    Senior
    Full time
    Work experience placement
    Live in
    Work at office
    Local area
    Shift work

    Accenture

    Charlotte, NC
    4 days ago
  •  ...We are seeking an experienced AI Lead/Architect to drive the design,...  ...capabilities to define AI strategy, mentor engineering teams, and deliver innovative...  ..., governance, and lifecycle management. Ensure AI solutions comply with security, privacy, responsible AI, and... 
    Full time

    Synechron

    Charlotte, NC
    2 days ago
  • $70 per hour

     ...Job Title: Senior SAP Basis & Security Engineer Location: Charlotte, NC 28217 (Fully On-Site) Job Type...  ...Responsibilities SAP Security & Role Design: Lead the design, maintenance, and...  ...ARM, BRM, and EAM/Firefighter) and manage complex MSMP workflows. Transport... 
    Senior
    Weekly pay
    Full time
    Contract work
    Monday to Friday

    swipejobs

    Charlotte, NC
    4 days ago
  •  ...turn ideas into reality.We are Secure, Responsible AI & Data Protection professionals...  ...AreManagers are the hands-on delivery engine of the Secure AI practice. They lead day-to-day execution of client...  ...capable practitioners. Each Manager hire will be expected to operate... 
    Full time
    Work experience placement
    Live in
    Work at office
    Local area

    Accenture

    Charlotte, NC
    4 days ago
  •  ...Application Security Contract Charlotte, NC (Hybrid) Full-Time Must have : App Security...  ...), driving a security-first culture. •Lead application security reviews, threat...  ...enforce security standards and policies. •Manage and track application security... 
    Senior
    Full time
    Contract work

    Arkhya Tech Inc.

    Charlotte, NC
    1 day ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Lead AI Security Engineer - Senior Manager. Be the first to apply!