Lead AI Security Engineer - Senior Manager
$150.7k - $251.2kJobleads-US
Location: Anywhere in Country
At EY, we’re all in to shape your future with confidence.
We’ll help you succeed in a globally connected powerhouse of diverse teams and take your career wherever you want it to go. Join EY and help to build a better working world.
The opportunity
We are seeking an AI Security Engineer to own the security posture of EY’s Agentic AI platform end to end.
Agentic AI breaks the assumptions most enterprise security programs are built on. Systems now generate and execute their own code, invoke tools and external APIs autonomously, act on behalf of human principals across long delegation chains, and can be manipulated through the same channel that carries legitimate instructions. Perimeter controls, static code review, and human-in-the-loop approval do not contain any of this on their own.
This role exists to make EY’s agentic platform defensible in the most highly regulated client environments in the world, including tax, financial services, audit, and risk. It is the security engineering and assurance authority spanning the whole stack: from silicon-level attestation and Kubernetes hardening, through supply-chain integrity and sandboxed execution, to prompt-injection defense, agent authority containment, and audit-grade evidence.
This is a deliberately broad mandate. It is ideal for a principal security engineer who has genuine depth in cloud-native and platform security, who has moved decisively into AI and agentic threat models, and who is equally comfortable writing a threat model, breaking a system in a red-team exercise, defining policy-as-code, and defending the resulting engineering to a client’s CISO or a regulator.
Your key responsibilities
Own the platform threat model : covering agent autonomy, tool invocation, delegated authority, model and data supply chain, multi-tenancy, and every deployment target from cloud to air-gapped, and keep it current as the platform evolves through each build phase.
Define the security engineering and control set for every platform layer: infrastructure and boot chain, Kubernetes and cluster fabric, identity and secrets, secure execution and sandboxing, gateway and egress, data and state, delivery pipeline, and telemetry.
Set the secure-by-default contract so that platform capabilities arrive hardened, including agent templates, Helm charts, sandbox profiles, and network policy ship with correct controls rather than requiring teams to add them.
Own defense against agentic threat classes including direct and indirect prompt injection, jailbreak and instruction hijacking, excessive agency, confused-deputy and authority-escalation attacks, tool and function-call abuse, memory and context poisoning, and retrieval-augmented data exfiltration.
Work with the architecture team to help define the agent authority model : delegated and on-behalf-of authority, scope and delegation-depth limits, consent boundaries, and the non-escalation invariant that an agent never exceeds the authority of its initiating principal at any hop.
Own the sandboxing security standard for agent-generated code execution: isolation boundaries, filesystem and credential scope, egress restriction, resource containment, and the escape-test suite that proves the boundary holds.
Secure the model and knowledge supply chain: model provenance and integrity, upstream registry governance, poisoning and backdoor risk, embedding and vector-store integrity.
Secure agent-to-agent and tool protocols including MCP and A2A surfaces: discovery trust, tool registration and approval, schema validation, and authorization of inter-agent calls.
Lead AI red teaming and adversarial testing: build the offensive capability and the recurring exercise cadence that tests guardrails, sandboxes, and authority boundaries before adversaries and auditors do.
Own supply-chain integrity end to end: artifact signing and verification (Sigstore/Cosign, Notation), SBOM generation and attestation, provenance and SLSA-aligned build integrity, CVE management, dependency and license governance.
Own admission and runtime policy: policy-as-code across Kyverno and OPA, signature-verification enforcement, Pod Security Standards, and the guardrails that make non-compliant workloads unschedulable rather than merely reported.
Define Kubernetes and infrastructure hardening baselines: CIS-aligned cluster configuration, network default-deny and segmentation, node and boot-chain integrity, GPU and DPU isolation, and secrets-handling standards.
Own tenant isolation assurance: the security definition of a tenant boundary across compute, network, storage, secrets, telemetry, and evidence, and the testing that proves cross-tenant leakage is not possible.
Serve as the security authority in client engagements: lead security engineering reviews, respond to client CISO and regulator scrutiny, and produce the assurance artefacts that unblock deployment into regulated environments.
Drive security detection and response for the platform: detection engineering for agentic misbehavior, security telemetry requirements, alerting, incident response playbooks, and post-incident review.
Skills and attributes for success
Deep cloud-native security expertise: Kubernetes, container, and infrastructure security at production scale, with real operational experience rather than assessment-only exposure.
Genuine command of AI and agentic threat models, with the judgement to distinguish novel risk from familiar risk wearing new vocabulary.
Strong zero-trust and workload-identity foundations: SPIFFE/SPIRE, PKI and certificate lifecycle, secrets management, and delegated authorization patterns.
Fluency in policy-as-code, with the instinct to encode controls as enforced policy rather than documented expectation.
Software supply-chain security depth: signing, provenance, SBOM, and build integrity.
Offensive-security instinct: able to think like an attacker against systems that generate their own code and act autonomously.
Pragmatism about risk: able to distinguish controls that must exist before the first client workload from those that can follow, and to defend both decisions.
Exceptional communication: able to move between a deep technical design review, an executive risk conversation, and a regulator or client CISO discussion without losing precision.
Security-as-enablement mindset: measured by how much safe delivery velocity the controls unlock, not by how much they prevent.
To qualify you must have
Bachelor’s or Master’s degree in Computer Science, Security, or a related technical field, or demonstrably equivalent depth.
10+ years in security engineering, security engineering, or offensive security, including hands-on production ownership.
Demonstrable depth in cloud-native and Kubernetes security: admission control, network policy, workload isolation, and runtime security in production.
Hands-on experience with workload identity and secrets management (SPIFFE/SPIRE, Vault/OpenBao or equivalents) and with PKI and certificate lifecycle.
Practical experience securing AI or ML systems in production, including familiarity with LLM and agentic attack surfaces, such as prompt injection, tool abuse, excessive agency, and model or data supply-chain risk.
Threat modelling capability applied to real systems, with evidence that the resulting controls were built and verified.
A track record delivering under compliance, security, or regulatory constraint with audit-grade evidence requirements.
Experience defining ownership boundaries and control contracts with platform, data, runtime, and delivery teams.
Ideally, you'll also have
Software supply-chain security experience: artifact signing, SBOM, provenance, and vulnerability management embedded in delivery pipelines.
Policy-as-code experience with OPA, Kyverno, or equivalent admission and authorisation engines.
Experience building or leading an AI red team, or running adversarial testing against LLM and agentic systems.
Familiarity with confidential computing and hardware attestation (Intel TDX, AMD SEV-SNP, SGX, NVIDIA CC) and secure boot / measured boot designs.
Working knowledge of the OWASP Top 10 for LLM Applications, MITRE ATLAS, NIST AI RMF, and the EU AI Act as applied to real engineering.
Experience with LLM guardrail and defense tooling (NeMo Guardrails, LLM Guard, LlamaFirewall, Guardrails AI, or equivalents) in production paths.
Experience securing multi-tenant platforms across cloud, on-prem, edge, client-managed, and air-gapped deployment modes.
Detection engineering and incident response experience, particularly for novel or behavioral threat classes.
Client-facing or consulting background, with credibility in front of CISOs, auditors, and regulators.
Relevant certifications (CISSP, OSCP, GIAC, cloud security specialties) or demonstrable equivalent depth.
Exposure to regulated industries: financial services, tax, audit, healthcare, or public sector.
Contribution to open-source security tooling, research, or public standards work in AI security.
What we offer you
At EY, we harness our collective strength to empower you to shape your future with confidence through professional growth, personal fulfillment and an inclusive culture. Learn more at ey.com/us/careers.
We offer a comprehensive compensation and benefits package where you’ll be rewarded based on your performance and recognized for the value you bring to the business. The base salary range for this job is:
New York City, Boston, and Washington DC Metro Areas, Washington State, and Southern California offices – $150,700 to $251,200
Bay Area California offices – $157,100 to $261,600
All other offices locations in the US, including Sacramento – $125,500 to $230,200
Individual salaries within these ranges are determined through a wide variety of factors including but not limited to education, experience, knowledge, skills and geography. In addition, our Total Rewards package includes medical and dental coverage, pension and 401(k) plans, and a wide range of paid time off options.
Under our flexible vacation policy, you’ll decide how much vacation time you need based on your own personal circumstances. You’ll also be granted time off for designated EY Paid Holidays, Winter/Summer breaks, Personal/Family Care, and other leaves of absence when needed to support your physical, financial, and emotional well-being.
EY | Building a better working world
EY is building a better working world by creating new value for clients, people, society and the planet, while building trust in capital markets.
Enabled by data, AI and advanced technology, EY teams help clients shape the future with confidence and develop answers for the most pressing issues of today and tomorrow.
EY teams work across a full spectrum of services in assurance, consulting, tax, strategy and transactions. Fueled by sector insights, a globally connected, multi-disciplinary network and diverse ecosystem partners, EY teams can provide services in more than 150 countries and territories.
All in to shape the future with confidence.
EY provides equal employment opportunities to applicants and employees without regard to race, color, religion, age, sex, sexual orientation, gender identity/expression, pregnancy, genetic information, national origin, protected veteran status, disability status, or any other legally protected basis, including arrest and conviction records, in accordance with applicable law.
EY is committed to providing reasonable accommodation to qualified individuals with disabilities including veterans with disabilities. If you have a disability and either need assistance applying online or need to request an accommodation during any part of the application process, please call 1-800-EY-HELP3, select Option 2 for candidate related inquiries, then select Option 1 for candidate queries and finally select Option 2 for candidates with an inquiry which will route you to EY’s Talent Shared Services Team (TSS) or email the TSS at View email address on click.appcast.io .
#J-18808-Ljbffr Jobleads-US- ...EY is seeking an AI Security Engineer to own the security posture of the Agentic AI platform end to end. You will drive threat modeling, zero-... ...default policies across cloud and edge deployments. You will lead red teaming, supply-chain integrity, and policy-based...Suggested
- ...healthier and more financially secure workforce by unifying the... ...wellbeing, navigation, and absence management.Our BenefitsWith a... ...currently seeking an experienced AI engineer who will collaborate closely... ...outcomes.Key ResponsibilitiesAs a senior AI/ML engineer, you will be...SeniorFor contractorsWork at officeLocal areaRemote workWork from homeWorldwideFlexible hours
$112.5k - $202.5k
...help improve the security of the company?... ...collaborate with industry-leading security experts?... ...of Security Engineering. You will have the... ...the best As a Senior Security Engineer... ...Leveraging emerging AI capabilities to enhance... ...or intrusion management Show experience...SeniorWork experience placementWork at officeWorldwide- ...Statewide Pretrial Services (OSPS) is seeking a Sr. Network Security Engineer to join the Springfield, IL on-site team and protect the agency... ...data and network from cyber threats. You will deploy and manage firewalls, IDS/IPS, VPNs, and security patches; perform vulnerability...SeniorWork at office
$149k - $198k
...seeking a motivated and experienced Security Sales Engineer to join our dynamic enterprise... ...Work closely with the product management and engineering teams to relay... ...Datadog: Datadog is the leading observability and security platform for the AI era, providing businesses with...SeniorWork at office- ...delivers real business value with AI. What You’ll Do We are looking for a Senior Manager – AI Platform to lead the development and... ...multidisciplinary team of engineers and data scientists, collaborating... ..., observability, and security. Manage, mentor, and grow...SeniorPermanent employmentFlexible hours
- ...Teradata is seeking a Senior Manager – AI Platform to lead development of the next-generation AI Platform powering autonomous agents. You will supervise a diverse team of engineers and data scientists, guiding architecture, pipelines, and tool orchestration while aligning...Senior
- ...Responsibilities:Provide operational support of the Reyes Holdings global IP LAN/WAN IP infrastructures specifically for the network security systems (firewalls, Zscaler), supporting 170+ global locations and 3 major contact centersOversight of Security policies, best...SeniorRemote work
- ...comprehensive suite of originations, servicing, and managed servicing solutions together with... ...Fiserv. Position Purpose: The Senior Client Executive assumes the leadership... ...client’s Account Plan, develop a plan to secure timely Service Agreement Renewals. Monitor...SeniorWork experience placementFlexible hours
- ...Honeywell International, Inc. is seeking a Senior Technical Sales Representative to drive growth for industrial... ...or related components, with the ability to engage engineers and decision-makers, develop territories, and manage the full sales cycle. Travel is expected to be...Senior
- ...Tarlton Corporation, a leading contractor, is hiring for project managers to lead civil construction projects across Central Illinois and Southern Iowa. The successful candidate will manage project teams, budgets, and schedules while fostering strong client relationships...SeniorFor contractorsWork at office
$129.3k - $258.7k
...AffairsIndustry: HealthcarePosted: 2026-10-04 Senior Manager Specimen Bank Working at Abbott At... ...as the Principal Investigator and leads daily operations for the internal biospecimen... ...wellness benefits, which provide the security to help you and your family live full...SeniorContract workWorldwide$78k - $156k
...-10-04 Position Overview The Sr. AI/ML Engineer guides the architecture, technical... ...repositories, and scientific systems using secure, supported platform patterns. ~... ...and comply with the company’s Quality Management System policies and procedures. ~...SeniorNight shift$140k - $180k
...Infrastructure We’re seeking a qualified Project Manager to lead roadway construction projects from... ...software Bachelor’s degree in Civil Engineering, Construction Management, or related... ...01(k) plan with company contributions Seniority level Mid-Senior level Employment type...SeniorFull timeFor subcontractorWork at office- ...firm specializing in data strategy, data engineering, and data analytics. Our clients span... ...performance, reliability, reusability, and security. Support Medicaid analytics and... ...of people and data. If you're ready to lead meaningful projects, collaborate with passionate...SeniorPermanent employment
- ...seeking a Shift Leader to oversee shift operations, guide team members, and ensure high standards of service and food quality. You will lead by example, train staff, and maintain a positive team environment while meeting performance goals. The role emphasizes supervising...Shift work
$78k - $156k
...changing technologies spans the spectrum of healthcare, with leading businesses and products in diagnostics, medical devices,... ...leading, exists to move that mission forward. The Senior Integration Manager leads the planning, execution, management, and maintenance...SeniorWork at officeLocal areaNight shift$19 - $19.25 per hour
...Discount, College Scholarship Award. All Bonuses, Awards and Benefits subject to qualifications and eligibility.The Assistant Store Manager is responsible for establishing and maintaining Guest Services. The Assistant Manager is responsible for supporting the Store...SeniorHourly payLocal area$130k - $165k
...for an experienced Construction Project Manager to plan and supervise a wide range of construction... .... RESPONSIBILITIES: Collaborate with engineers, architects etc. to determine the... ...equivalent certification will be an advantage Seniority level Mid-Senior level Employment type...SeniorFull timeFor contractors- ...Do you have a passion for working with Seniors? The Senior Living Sales Director is responsible for leading the sales and occupancy strategy for Park Plaza Senior Living by managing the complete prospect journey from initial inquiry through move-in and successful transition...Senior
- ...transmission systems, our industry-recognized engineers and scientists have been at the... ...MN, MO, ND, NE, SD, WI, and WY).As a Senior Project Manager, you are an experienced leader and contributor... ..., networking, client relations and lead developmentTravel on average 10-20% of...SeniorWork at office
- ...is partnering with a respected, employee-owned engineering and geospatial consulting firm seeking a Survey Project Manager to support the continued growth of its... ...geospatial surveying principles ~ Experience leading and coordinating field and office teams ~ Excellent...SeniorWork at officeRemote workFlexible hours
- ...sales channels, and market applications. Lead, inspire, and develop a high-performing... ..., succession planning, and change management initiatives. Build and maintain strong... ...University degree in Business Administration, Engineering, or a related discipline; a Master's...SeniorLocal areaRemote work
- ...Arora and Associates, PC is seeking an experienced Senior Civil Engineer in Illinois to lead the planning and design of roadway projects. The role requires... ...guiding studies, plans, specs, and estimates and managing a team of engineers and planners. You will coordinate...Senior
- ...startups, and over 80% of unicorns, choose to launch on AWS.As a Senior Startup Investor Manager within AWS, you will work with venture capital firms to... ...of cloud and emerging technologies, such as generative AI, with business acumen to identify opportunities and ensure...SeniorWorldwide
- ...Citi Trends is seeking a Store Manager to lead all aspects of store performance, people leadership, and daily operations. You will oversee sales, profitability, and customer experience while coaching a high-performing team. This role suits experienced retail leaders who...
- ...EY is seeking a senior Salesforce Technology leader to drive program delivery and client leadership across multiple engagements. You will oversee architecture, manage teams, and grow accounts while ensuring high-quality solutions for clients in a dynamic, global consulting...Senior
- ...Project Manager Systems Integration & Development (SID) is an award-winning IT solutions provider headquartered in McLean, VA seeking... ...a relevant field such as business, information technology, or engineering. 10+ years of project management experience, preferably in IT...SeniorFull time
$296.3k
...Description We are seeking an experienced and technically strong Senior Engineering Manager - AI/ML Engineering for the Data Foundations organization of... ...and Zero Congestion and we embrace the responsibility to lead the change that will make our world better, safer and more...SeniorFull timeLocal areaRemote workWork from homeRelocationRelocation packageFlexible hours- ...WITH PHARMA EXPERIENCE PREFERRED*** Position Overview: The Senior Project Manager is responsible for driving all inputs for exhibit and... ...Project scopes involve all aspects of architectural design, engineering, fabrication, and installation. The Senior Project Manager...SeniorContract workWork at office
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Lead AI Security Engineer - Senior Manager. Be the first to apply!
- ai developer Springfield, IL
- ai engineer Springfield, IL
- senior cloud security engineer Springfield, IL
- aws cloud security engineer Springfield, IL
- sr information security engineer Springfield, IL
- network security engineer Springfield, IL
- information technology security engineer Springfield, IL
- security engineer Springfield, IL
- IT security engineer Springfield, IL
- senior mulesoft developer Springfield, IL



