Lead AI Security Engineer - Senior Manager
$125.5k - $261.6kEY
Location: Anywhere in Country
At EY, we’re all in to shape your future with confidence.
We’ll help you succeed in a globally connected powerhouse of diverse teams and take your career wherever you want it to go. Join EY and help to build a better working world.
The opportunity
We are seeking an AI Security Engineer to own the security posture of EY’s Agentic AI platform end to end.
Agentic AI breaks the assumptions most enterprise security programs are built on. Systems now generate and execute their own code, invoke tools and external APIs autonomously, act on behalf of human principals across long delegation chains, and can be manipulated through the same channel that carries legitimate instructions. Perimeter controls, static code review, and human-in-the-loop approval do not contain any of this on their own.
This role exists to make EY’s agentic platform defensible in the most highly regulated client environments in the world, including tax, financial services, audit, and risk. It is the security engineering and assurance authority spanning the whole stack: from silicon-level attestation and Kubernetes hardening, through supply-chain integrity and sandboxed execution, to prompt-injection defense, agent authority containment, and audit-grade evidence.
This is a deliberately broad mandate. It is ideal for a principal security engineer who has genuine depth in cloud-native and platform security, who has moved decisively into AI and agentic threat models, and who is equally comfortable writing a threat model, breaking a system in a red-team exercise, defining policy-as-code, and defending the resulting engineering to a client’s CISO or a regulator.
Your key responsibilities
- Own the platform threat model : covering agent autonomy, tool invocation, delegated authority, model and data supply chain, multi-tenancy, and every deployment target from cloud to air-gapped, and keep it current as the platform evolves through each build phase.
- Define the security engineering and control set for every platform layer: infrastructure and boot chain, Kubernetes and cluster fabric, identity and secrets, secure execution and sandboxing, gateway and egress, data and state, delivery pipeline, and telemetry.
- Set the secure-by-default contract so that platform capabilities arrive hardened, including agent templates, Helm charts, sandbox profiles, and network policy ship with correct controls rather than requiring teams to add them.
- Own defense against agentic threat classes including direct and indirect prompt injection, jailbreak and instruction hijacking, excessive agency, confused-deputy and authority-escalation attacks, tool and function-call abuse, memory and context poisoning, and retrieval-augmented data exfiltration.
- Work with the architecture team to help define the agent authority model : delegated and on-behalf-of authority, scope and delegation-depth limits, consent boundaries, and the non-escalation invariant that an agent never exceeds the authority of its initiating principal at any hop.
- Own the sandboxing security standard for agent-generated code execution: isolation boundaries, filesystem and credential scope, egress restriction, resource containment, and the escape-test suite that proves the boundary holds.
- Secure the model and knowledge supply chain: model provenance and integrity, upstream registry governance, poisoning and backdoor risk, embedding and vector-store integrity.
- Secure agent-to-agent and tool protocols including MCP and A2A surfaces: discovery trust, tool registration and approval, schema validation, and authorization of inter-agent calls.
- Lead AI red teaming and adversarial testing: build the offensive capability and the recurring exercise cadence that tests guardrails, sandboxes, and authority boundaries before adversaries and auditors do.
- Own supply-chain integrity end to end: artifact signing and verification (Sigstore/Cosign, Notation), SBOM generation and attestation, provenance and SLSA-aligned build integrity, CVE management, dependency and license governance.
- Own admission and runtime policy: policy-as-code across Kyverno and OPA, signature-verification enforcement, Pod Security Standards, and the guardrails that make non-compliant workloads unschedulable rather than merely reported.
- Define Kubernetes and infrastructure hardening baselines: CIS-aligned cluster configuration, network default-deny and segmentation, node and boot-chain integrity, GPU and DPU isolation, and secrets-handling standards.
- Own tenant isolation assurance: the security definition of a tenant boundary across compute, network, storage, secrets, telemetry, and evidence, and the testing that proves cross-tenant leakage is not possible.
- Serve as the security authority in client engagements: lead security engineering reviews, respond to client CISO and regulator scrutiny, and produce the assurance artefacts that unblock deployment into regulated environments.
- Drive security detection and response for the platform: detection engineering for agentic misbehavior, security telemetry requirements, alerting, incident response playbooks, and post-incident review.
Skills and attributes for success
- Deep cloud-native security expertise: Kubernetes, container, and infrastructure security at production scale, with real operational experience rather than assessment-only exposure.
- Genuine command of AI and agentic threat models, with the judgement to distinguish novel risk from familiar risk wearing new vocabulary.
- Strong zero-trust and workload-identity foundations: SPIFFE/SPIRE, PKI and certificate lifecycle, secrets management, and delegated authorization patterns.
- Fluency in policy-as-code, with the instinct to encode controls as enforced policy rather than documented expectation.
- Software supply-chain security depth: signing, provenance, SBOM, and build integrity.
- Offensive-security instinct: able to think like an attacker against systems that generate their own code and act autonomously.
- Pragmatism about risk: able to distinguish controls that must exist before the first client workload from those that can follow, and to defend both decisions.
- Exceptional communication: able to move between a deep technical design review, an executive risk conversation, and a regulator or client CISO discussion without losing precision.
- Security-as-enablement mindset: measured by how much safe delivery velocity the controls unlock, not by how much they prevent.
To qualify you must have
- Bachelor’s or Master’s degree in Computer Science, Security, or a related technical field, or demonstrably equivalent depth.
- 10+ years in security engineering, security engineering, or offensive security, including hands-on production ownership.
- Demonstrable depth in cloud-native and Kubernetes security: admission control, network policy, workload isolation, and runtime security in production.
- Hands-on experience with workload identity and secrets management (SPIFFE/SPIRE, Vault/OpenBao or equivalents) and with PKI and certificate lifecycle.
- Practical experience securing AI or ML systems in production, including familiarity with LLM and agentic attack surfaces, such as prompt injection, tool abuse, excessive agency, and model or data supply-chain risk.
- Threat modelling capability applied to real systems, with evidence that the resulting controls were built and verified.
- A track record delivering under compliance, security, or regulatory constraint with audit-grade evidence requirements.
- Experience defining ownership boundaries and control contracts with platform, data, runtime, and delivery teams.
Ideally, you'll also have
- Software supply-chain security experience: artifact signing, SBOM, provenance, and vulnerability management embedded in delivery pipelines.
- Policy-as-code experience with OPA, Kyverno, or equivalent admission and authorisation engines.
- Experience building or leading an AI red team, or running adversarial testing against LLM and agentic systems.
- Familiarity with confidential computing and hardware attestation (Intel TDX, AMD SEV-SNP, SGX, NVIDIA CC) and secure boot / measured boot designs.
- Working knowledge of the OWASP Top 10 for LLM Applications, MITRE ATLAS, NIST AI RMF, and the EU AI Act as applied to real engineering.
- Experience with LLM guardrail and defense tooling (NeMo Guardrails, LLM Guard, LlamaFirewall, Guardrails AI, or equivalents) in production paths.
- Experience securing multi-tenant platforms across cloud, on-prem, edge, client-managed, and air-gapped deployment modes.
- Detection engineering and incident response experience, particularly for novel or behavioral threat classes.
- Client-facing or consulting background, with credibility in front of CISOs, auditors, and regulators.
- Relevant certifications (CISSP, OSCP, GIAC, cloud security specialties) or demonstrable equivalent depth.
- Exposure to regulated industries: financial services, tax, audit, healthcare, or public sector.
- Contribution to open-source security tooling, research, or public standards work in AI security.
What we offer you
At EY, we harness our collective strength to empower you to shape your future with confidence through professional growth, personal fulfillment and an inclusive culture. Learn more at ey.com/us/careers.
- We offer a comprehensive compensation and benefits package where you’ll be rewarded based on your performance and recognized for the value you bring to the business. The base salary range for this job is:
-
- New York City, Boston, and Washington DC Metro Areas, Washington State, and Southern California offices – $150,700 to $251,200
- Bay Area California offices – $157,100 to $261,600
- All other offices locations in the US, including Sacramento – $125,500 to $230,200
- Individual salaries within these ranges are determined through a wide variety of factors including but not limited to education, experience, knowledge, skills and geography. In addition, our Total Rewards package includes medical and dental coverage, pension and 401(k) plans, and a wide range of paid time off options.
- Under our flexible vacation policy, you’ll decide how much vacation time you need based on your own personal circumstances. You’ll also be granted time off for designated EY Paid Holidays, Winter/Summer breaks, Personal/Family Care, and other leaves of absence when needed to support your physical, financial, and emotional well-being.
Are you ready to shape your future with confidence? Apply today.
- To make the most of your application experience, please limit yourself to two applications within a six-month period.
- EY accepts applications for this position on an on-going basis.
- For those living in California, please click here for additional information.
- At EY, our values set the foundation for how we work and the behaviors we expect of our people. Any misrepresentation or falsification of information or lack of integrity at any point in the recruiting process may result in withdrawal of your candidacy, revocation of an offer or immediate termination of employment.
EY | Building a better working world
EY is building a better working world by creating new value for clients, people, society and the planet, while building trust in capital markets.
Enabled by data, AI and advanced technology, EY teams help clients shape the future with confidence and develop answers for the most pressing issues of today and tomorrow.
EY teams work across a full spectrum of services in assurance, consulting, tax, strategy and transactions. Fueled by sector insights, a globally connected, multi-disciplinary network and diverse ecosystem partners, EY teams can provide services in more than 150 countries and territories.
All in to shape the future with confidence.
EY provides equal employment opportunities to applicants and employees without regard to race, color, religion, age, sex, sexual orientation, gender identity/expression, pregnancy, genetic information, national origin, protected veteran status, disability status, or any other legally protected basis, including arrest and conviction records, in accordance with applicable law.
EY is committed to providing reasonable accommodation to qualified individuals with disabilities including veterans with disabilities. If you have a disability and either need assistance applying online or need to request an accommodation during any part of the application process, please call 1-800-EY-HELP3, select Option 2 for candidate related inquiries, then select Option 1 for candidate queries and finally select Option 2 for candidates with an inquiry which will route you to EY’s Talent Shared Services Team (TSS) or email the TSS at View email address on aiapply.co.
- ...Job Description Job Title: Sr. Manager, Medical Content Lead \n Contract Length: 12 months (w/potential... ...and compliance \n Serve as the senior content interface to TA Medical leadership... ..., content reuse strategies, and AI-enabled approaches while ensuring scientific...SeniorContract workLocal areaRemote work
- ...Senior Life Sciences Knowledge Engineer Company: Norstella Location: Remote, United States Date Posted... ...Norstella? Norstella unites market-leading companies that all have a shared goal... ...scientific domain expertise and applied AI development. This role will be...SeniorFull timeTemporary workWork at officeLocal areaRemote workFlexible hoursShift work
$93k - $115k
Job DescriptionECS is seeking a TS-cleared Senior Information Systems Security Engineer (ISSE) to support one of our mission critical programs for the Department... ...driving corrective-action closure.Responsibilities:Leads security engineering and/or assessment support for...SeniorContract work- ...tech company that deploys AI-assisted teams to build and secure mission-critical... .... We are seeking a Senior AI Software Engineer with deep hands-on experience... ...reasoning loops, state management, tool-use orchestration... ...AI execution. Lead rapid prototyping and continuous...SeniorPermanent employmentFull timeTemporary workRemote work
- ...productivity, and optimize time management. Our innovative... ...a highly hands-on Head of Security Engineering to lead and evolve the company's security... ...n This role serves as the senior-most dedicated security leader... ...\n Familiarity with AI security risks and emerging...SuggestedLocal areaRemote workWorldwide
- ...We're Hiring! \n \n We are looking for a strong AI Architect / Senior AI Engineer to help design and build a new generation of autonomous... ...influence decisions \n Long-term memory and context management \n Tool use and dynamic tool selection \n Browser...SeniorRemote work
- ...recruiting salesperson who knows how to build business from scratch. We're a growing agency focused primarily on advanced technical and engineering talent, and we’ve built the company around experienced people, a low-bureaucracy environment, and the expectation that good...SeniorRemote work
- Job Description We’re seeking an Account Executive who knows how to shepherd 6-figure deals through a multi-month sales cycle, build trust with stakeholders up to the C-suite and relentlessly make the case for a product that to many prospects will seem too good to be...Senior
- ...Go, Python, Node.js, AI-Assisted Software Development... ...We are looking for a Senior Manager, Full Stack... ...leadership across multiple engineering teams delivering complex... ...practice level \n Lead AWS infrastructure strategy... ...cost optimization, security governance, resilience...Senior
$78.8k - $157.5k
...collaborative Sec Ops Engineer looking to work for... ...’ll be joining the Security Engineering team... ...About the Role As a Senior Security Engineer, you help lead in designing,... ...tuning, and lifecycle management of core security... ...Championing adoption of AI-assisted...SeniorFull timeLocal area- ...technology solutions.\n \n \nThrough Mobilfy, you'll help businesses with T Mobile for Business Mobility, Business Internet, Managed IT, Cybersecurity, AI, Cloud Communications, IoT, and other strategic technology solutions. That means larger opportunities, deeper customer...SeniorTemporary work
- ...Job Description Senior Healthcare Infrastructure, Cloud & Security Engineer \n \n Position Summary \n United Theranostics... ...Infrastructure & Cloud Engineer to lead the design, implementation, security, and ongoing management of our enterprise technology infrastructure...Senior
- ...Senior Information Systems Security Engineer Clarksburg, WV Tygart is seeking a Senior Information Systems... ...practices, including the NIST Risk Management Framework (RMF) and NIST security... ...developers, and integrators Experience leading or co‑leading technology projects...SeniorWork at officeLocal area
- ...cybersecurity company redefining cloud security through a proactive,... ...approach. \n Backed by leading global investors, we are scaling... ...\n We are looking for a Senior Account Executive to drive enterprise... ...→ close → expansion)\n Manage complex deals and build...Senior
- ...Job Description New Business Account Manager — Social/Digital Media Advertising | Remote US \n Ready to own your book of business and build something from the ground up? A leading social media platform is looking for a hunter-mentality Account Executive to drive...SeniorContract workRemote work
$149.75k - $205.31k
...ll do: We are looking for an engineer who can turn ambiguous business problems into working AI solutions, and who recognizes... ...technology. Responsibilities ~ Lead discovery with business and... ...quality, cost, latency, security, and authorization constraints....SeniorFull timeLocal areaImmediate startFlexible hours$175k
...Job Description Senior Account Executive \n 100... ...focuses on hiring across Engineering, Product, Design, Sales... ...Tech fields such as AI, ML, and space technologies... ...role responsible for managing and growing a portfolio... ...space. This role includes leading the full sales cycle...SeniorFull timeRemote work$89.2k - $209.5k
Job Description Oracle Health is seeking a Senior AI Agent Engineer to build production AI agents and workflow automation capabilities that accelerate... ...future for all. Discover your potential at a company leading the way in AI and cloud solutions that impact billions of...SeniorTemporary workFlexible hours$170k - $230k
...equitable care. \n The Opportunity \n We’re hiring an AI Engineer with strong voice AI experience to help design and build the... ...maintain AI orchestration layers, including agent workflows, state management, and system handoffs \n Architect and improve workflows...SeniorRemote work$102.7k - $164.6k
...Highmark Health is seeking a Senior Security Engineer to join our Enterprise... ...scale in one of the nation's leading health and insurance organizations... ...process, including within AI-assisted development... ...security standards. Deploy and manage application security...SeniorFull timeFor contractorsWork at officeLocal areaShift work$50k
...There is no SDR pod feeding you meetings and no large marketing engine dripping inbound. This is the single most important requirement.... ...border, FX, and orchestration have all done well here. \n You use AI as a working tool. The strongest people here write their own...SeniorLocal area$10k - $35k
...and recruitment services for leading companies in the United States... ...seeking a high-performing Senior Account Executive to convert... ...Account Executive, you will manage a full-cycle sales process while... ...marketing, e-commerce, IT/security, and procurement divisions. Maintain...SeniorRemote work- ...About Dono \n Dono is an AI-powered property records platform... ...internally \n Use data to lead conversations, not respond to... ..., or technical account management in B2B SaaS or workflow software... ...functional fluency across product, engineering, and ops \n ~ Comfortable...SeniorContract workRemote work
- ...Job Description Senior Study Manager \n \n Description of Services \n \n \n Assists the SM Study Lead and study team with the operational conduct of clinical studies (e.g., CTT minutes, clinical supplies planning/tracking, lab specimen tracking, imaging...SeniorWork at office
- ...Job Description Senior Enterprise Account Executive - AI-Powered Security Operations \n Location:... ...with credibility. \n Lead complex, multi-threaded... ...Collaborate closely with Sales Engineering, Marketing, Product and... .... \n Confidence managing complex, multi-...SeniorRemote work
$90k - $120k
...and looking for an experienced Senior Account Executive to help... ...negotiation, and close \n Manage qualified inbound opportunities... ...leaders, procurement, IT, and security \n Maintain strong CRM discipline... ...feedback \n Use modern AI tools for research, outreach,...SeniorRemote work- ...THE OPPORTUNITY \n We are seeking a proven, results-driven Senior Sales Representative to build and develop a high-performing territory... ...aligned with Applied Biologics commercial objectives. \n • Manage all key accounts, including wound care centers, hospitals, SNFs,...SeniorRemote work
$5,000 per month
...criminal defense, family law, and more — generate high-quality leads, dominate search, and grow their practice. We're looking for a proven... ...$5K+ MRR net-new accounts and exceed monthly revenue targets. \n • Manage your full-cycle CRM activity and forecast your own book....SeniorRemote work$90k
...Job Description Role: Senior Business Development Manager/ Senior Account Executive \n Location: Remote (TX, CO, AZ, FL, VA, MA) \n Salary:... ...full potential. \n \n Your Mission: \n \n \n Lead from the front : Drive new business opportunities within...SeniorRemote workFlexible hours$250k - $350k
...Standard for the Human-AI Era, trusted by over 15... ...Identity Intelligence Engine, enabling companies to... ...marketing, commerce, and security platforms. \n \n CHEQ... .... \n \n Our Senior Enterprise Account Executive... ...\n Have superb time management skills with the ability...SeniorWork at officeRemote workWorldwide
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Lead AI Security Engineer - Senior Manager. Be the first to apply!
- lead engineer West Virginia
- ai developer West Virginia
- ai engineer West Virginia
- ai prompt engineer West Virginia
- senior cloud security engineer West Virginia
- cloud security engineer West Virginia
- aws cloud security engineer West Virginia
- security software engineer West Virginia
- sr information security engineer West Virginia
- network security engineer West Virginia




