AI Security Architect – Agentic Platform Defense

EY

Palo Alto (CA)

On-site

USD 157,000 - 262,000

Full time

2 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

EY is seeking an AI Security Engineer to own the security posture of EY’s Agentic AI platform end to end. You will shape threat models, deploy secure-by-default controls, and lead red teaming across cloud-native environments. This role requires deep AI security expertise, zero-trust foundations, and strong communication with clients and regulators.

You will define policy-as-code, secure the supply chain, and drive incident response and assurance artifacts for regulated deployments.

Qualifications

  • Bachelor’s or Master’s degree in Computer Science, Security, or a related field or demonstrably equivalent depth.
  • 10+ years in security engineering with hands-on production ownership.
  • Deep cloud-native and Kubernetes security experience in production.
  • Hands-on workload identity and secrets management expertise.
  • Practical experience securing AI or ML systems in production with agentic risk.

Responsibilities

  • Own platform threat model covering agent autonomy, tool invocation, and multi- tenancy.
  • Define security controls for all platform layers: infra, Kubernetes, identity, and data.
  • Set secure-by-default contracts with templates, charts, and network policy.
  • Lead defense against agentic threat classes and prompt injection risks.
  • Define agent authority model with delegation limits and non-escalation invariants.
  • Own sandboxing standards for agent-generated code execution and isolation.
  • Secure model and knowledge supply chain with provenance and attestation.
  • Secure agent-to-agent and tool protocols with trust and authorization.
  • Lead AI red teaming, adversarial testing, and guardrails validation.
  • Own end-to-end supply-chain integrity: Sigstore/Cosign, SBOM, attestation.
  • Own admission and runtime policy using Kyverno and OPA; enforce guards.
  • Define Kubernetes hardening baselines and network controls.
  • Ensure tenant isolation and cross-tenant leakage prevention.
  • Serve as security lead in client engagements with CISOs/regulators.
  • Drive detection and response for platform misbehavior and incidents.

Skills

Cloud-native security
Kubernetes security
AI and agentic threat models
Zero-trust / workload identity
Policy-as-code
Software supply-chain security
Threat modelling
Communication with execs/regulators

Education

Bachelor’s or Master’s degree in Computer Science, Security, or a related technical field

Tools

SPIFFE/SPIRE
PKI / certificate lifecycle
Sigstore / Cosign
Kyverno / OPA
Kuberenetes security tooling
SBOM / provenance tooling

Job description

EY is seeking an AI Security Engineer to own the security posture of EY’s Agentic AI platform end to end. You will shape threat models, deploy secure-by-default controls, and lead red teaming across cloud-native environments. This role requires deep AI security expertise, zero-trust foundations, and strong communication with clients and regulators.

You will define policy-as-code, secure the supply chain, and drive incident response and assurance artifacts for regulated deployments.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior AI Security Engineer — Platform & Agentic Defense
Senior AI Security Engineer — Platform & Agentic Defense

EY • Kansas City (MO)

Hybrid
USD 126,000 - 262,000
Medical and dental coverage
Pension and 401(k)
Flexible vacation policy
+1
Senior AI Security Engineer: Agentic Platform Defense
Senior AI Security Engineer: Agentic Platform Defense

EY • Jacksonville (FL)

On-site
USD 170,000 - 250,000
Medical and dental coverage
Pension and 401(k)
Paid time off
Senior AI Security Engineer - Platform Defense & Threats
Senior AI Security Engineer - Platform Defense & Threats

EY • Tampa (FL)

On-site
USD 125,000 - 231,000
Senior AI Security Architect for Agentic Platforms
Senior AI Security Architect for Agentic Platforms

EY • Houston (TX)

On-site
USD 126,000 - 230,000
Medical and dental coverage
Pension and 401(k) plans
Paid time off
Senior AI Security Engineer - Agentic Platform Defenses
Senior AI Security Engineer - Agentic Platform Defenses

EY • Milwaukee (WI)

On-site
USD 126,000 - 230,000
Medical and dental coverage
401(k)
Paid time off
+1
Remote AI Security Engineer – Agentic Platform Defense
Remote AI Security Engineer – Agentic Platform Defense

EY • Indianapolis (IN)

On-site
USD 126,000 - 230,000
Total rewards package
Healthcare and retirement plans
Flexible vacation policy
+1
AI Security Platform Architect
AI Security Platform Architect

EY • Buffalo (NY)

Remote
USD 126,000 - 230,000
Medical & dental coverage
401(k) plan
Flexible vacation policy
Senior AI Security Engineer - Platform & Threat Defense
Senior AI Security Engineer - Platform & Threat Defense

EY • Pittsburgh

On-site
USD 151,000 - 251,000
Competitive compensation
Medical and dental coverage
Paid time off
+1
Lead AI Security Engineer — Platform Threat Defense
Lead AI Security Engineer — Platform Threat Defense

EY • Portland (OR)

Remote
USD 126,000 - 251,000
Medical and dental coverage
401(k) plan
Flexible vacation policy
Lead AI Security Engineer: Defend the Agentic AI Platform
Lead AI Security Engineer: Defend the Agentic AI Platform

EY • Denver (CO)

On-site
USD 126,000 - 230,000
Medical and dental coverage
401(k) with company match
Flexible vacation policy