Ernst and Young

Lead AI Security Engineer - Senior Manager

Ernst and Young
Apply
4 days ago
Atlanta, GA, USAStaff+
H1B sponsor

Base Salary

$126k - $262k/yr

Responsibilities

  • Own and continuously update the platform threat model for agent autonomy, tool invocation, delegated authority, supply chains, multi-tenancy, and all deployment targets.
  • Define security controls across infrastructure, boot chains, Kubernetes, identity, secrets, sandboxing, gateways, data, delivery pipelines, and telemetry.
  • Establish secure-by-default controls for agent templates, Helm charts, sandbox profiles, network policies, and platform capabilities.
  • Defend against prompt injection, jailbreaks, excessive agency, authority escalation, tool abuse, memory poisoning, and retrieval-augmented data exfiltration.
  • Define agent authority, delegation-depth, consent, and non-escalation controls with the architecture team.
  • Own sandbox security standards and escape-test suites for agent-generated code execution.
  • Secure model, knowledge, embedding, vector-store, artifact, and software supply chains.
  • Secure MCP and A2A agent-to-agent and tool protocols, including discovery, registration, schema validation, and authorization.
  • Lead AI red teaming and adversarial testing of guardrails, sandboxes, and authority boundaries.
  • Own artifact signing, verification, SBOMs, provenance, SLSA-aligned build integrity, CVE management, and dependency governance.
  • Enforce admission and runtime policy using policy-as-code, signature verification, and Pod Security Standards.
  • Define Kubernetes, infrastructure, node, boot-chain, GPU, DPU, secrets-handling, and network-hardening baselines.
  • Own tenant-isolation assurance across compute, network, storage, secrets, telemetry, and evidence.
  • Lead client security reviews and respond to CISO, auditor, and regulator scrutiny.
  • Drive detection engineering, security telemetry, alerting, incident response playbooks, and post-incident reviews.

Requirements

  • Bachelor’s or Master’s degree in Computer Science, Security, or a related technical field, or demonstrably equivalent depth.
  • 10+ years of hands-on security engineering or offensive-security experience with production ownership.
  • Production-scale cloud-native and Kubernetes security experience, including admission control, network policy, workload isolation, and runtime security.
  • Hands-on workload identity, secrets management, PKI, and certificate-lifecycle experience, including SPIFFE/SPIRE, Vault/OpenBao, or equivalents.
  • Practical experience securing AI or ML systems in production and understanding LLM and agentic attack surfaces.
  • Experience applying threat modeling to real systems and building and verifying the resulting controls.
  • Track record delivering under compliance, security, or regulatory constraints with audit-grade evidence.
  • Experience defining ownership boundaries and control contracts with platform, data, runtime, and delivery teams.
  • Preferred software supply-chain security experience covering signing, SBOMs, provenance, and vulnerability management.
  • Preferred policy-as-code experience with OPA, Kyverno, or equivalent authorization and admission engines.
  • Preferred experience building or leading AI red teams or adversarial testing of LLM and agentic systems.
  • Preferred familiarity with confidential computing, hardware attestation, secure boot, and measured boot.
  • Working knowledge of OWASP Top 10 for LLM Applications, MITRE ATLAS, NIST AI RMF, and the EU AI Act.
  • Preferred production experience with LLM guardrail and defense tooling such as NeMo Guardrails, LLM Guard, LlamaFirewall, or Guardrails AI.
  • Experience securing multi-tenant platforms across cloud, on-premises, edge, client-managed, and air-gapped environments.
  • Detection engineering and incident response experience for behavioral or novel threat classes.
  • Client-facing or consulting experience with credibility before CISOs, auditors, and regulators.
  • Relevant certifications such as CISSP, OSCP, GIAC, or cloud-security certifications, or demonstrable equivalent depth.
  • Exposure to regulated industries and contribution to open-source security tooling, research, or public standards work are advantageous.

Benefits

  • Base salary ranges from $125,500 to $230,200 in most US locations, with higher ranges for specified metropolitan and California offices.
  • Medical and dental coverage, pension and 401(k) plans, and paid time off are provided.
  • Flexible vacation, EY-paid holidays, winter and summer breaks, personal and family care leave, and other leave options are available.
  • The position is open to applicants anywhere in the country and applications are accepted on an ongoing basis.

Tech Stack

HelmKubernetesVault

Categories

Ernst and Young

About Ernst and Young

10,000+ employees

Ernst & Young (EY) provides audit/assurance, tax, consulting, strategy and transactions services to enterprises, financial institutions, and public‑sector clients. Structured as a global network of partner‑owned member firms, it sells professional services on a fee basis, including a dedicated Financial Services Organization for banking, insurance, and capital markets. Headquartered in London, EY was formed in 1989 from the merger of Ernst & Whinney and Arthur Young, and operates in 150+ countries.

Contact me