Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
Scoutfield Logo

See all jobs on Scoutfield

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
EY

Lead AI Security Engineer – Senior Manager

EY

. Own the end-to-end threat model for EY’s Agentic AI platform .

Posted 9/25/2026full-timeAtlanta • United StatesSenior💰 $125,500 - $230,200 per yearWebsite

Tech Stack

Tools & technologies
CloudKubernetesNode.jsVault

About the role

Key responsibilities & impact
  • Own the end-to-end threat model for EY’s Agentic AI platform
  • Define security engineering controls across infrastructure, boot chain, Kubernetes, identity, secrets, sandboxing, gateways, data, delivery pipelines, and telemetry
  • Establish secure-by-default controls for agent templates, Helm charts, sandbox profiles, and network policies
  • Defend against agentic threats including prompt injection, jailbreaks, excessive agency, authority escalation, tool abuse, memory poisoning, and data exfiltration
  • Define the agent authority model, delegation limits, consent boundaries, and non-escalation invariant
  • Own sandboxing standards and escape-test suites for agent-generated code execution
  • Secure model, knowledge, embedding, vector-store, and software supply chains
  • Secure MCP and A2A agent-to-agent and tool protocols
  • Lead AI red teaming and recurring adversarial testing
  • Own artifact signing, verification, SBOMs, attestations, provenance, CVE management, dependencies, and license governance
  • Own admission and runtime policy using Kyverno, OPA, signature verification, and Pod Security Standards
  • Define Kubernetes and infrastructure hardening baselines, network segmentation, node and boot-chain integrity, GPU/DPU isolation, and secrets handling
  • Own tenant-isolation assurance and cross-tenant leakage testing
  • Serve as security authority in client engagements and respond to CISO and regulator scrutiny
  • Drive security detection, telemetry, alerting, incident response playbooks, and post-incident reviews

Requirements

What you’ll need
  • Bachelor’s or Master’s degree in Computer Science, Security, or a related technical field, or demonstrably equivalent depth
  • 10+ years in security engineering or offensive security, including hands-on production ownership
  • Production-scale cloud-native and Kubernetes security experience, including admission control, network policy, workload isolation, and runtime security
  • Hands-on workload identity and secrets management experience, including SPIFFE/SPIRE, Vault/OpenBao or equivalents
  • PKI and certificate lifecycle experience
  • Practical experience securing AI or ML systems in production
  • Familiarity with LLM and agentic attack surfaces, including prompt injection, tool abuse, excessive agency, and model or data supply-chain risk
  • Threat modelling capability applied to real systems, with evidence that resulting controls were built and verified
  • Track record delivering under compliance, security, or regulatory constraints with audit-grade evidence requirements
  • Experience defining ownership boundaries and control contracts with platform, data, runtime, and delivery teams
  • Software supply-chain security experience, including artifact signing, SBOM, provenance, and vulnerability management
  • Policy-as-code experience with OPA, Kyverno, or equivalent engines
  • Experience building or leading an AI red team or running adversarial testing against LLM and agentic systems
  • Familiarity with confidential computing, hardware attestation, secure boot, and measured boot designs
  • Working knowledge of OWASP Top 10 for LLM Applications, MITRE ATLAS, NIST AI RMF, and EU AI Act
  • Experience with LLM guardrail and defense tooling in production
  • Experience securing multi-tenant platforms across cloud, on-prem, edge, client-managed, and air-gapped deployment modes
  • Detection engineering and incident response experience
  • Client-facing or consulting background with credibility in front of CISOs, auditors, and regulators
  • Relevant certifications such as CISSP, OSCP, GIAC, or cloud security specialties, or demonstrable equivalent depth
  • Exposure to regulated industries such as financial services, tax, audit, healthcare, or public sector

Benefits

Comp & perks
  • Medical and dental coverage
  • Pension and 401(k) plans
  • Flexible vacation policy
  • EY Paid Holidays
  • Winter/Summer breaks
  • Personal/Family Care leave
  • Other leaves of absence
  • Professional growth opportunities
  • Inclusive culture
  • Reasonable accommodation for qualified individuals with disabilities