Lead AI Security Engineer - Senior Manager

Ernst & Young Oman

Stamford (CT)

Remote

USD 150,000 - 190,000

Full time

10 days ago
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Ernst & Young Oman is seeking an AI Security Engineer to own the end-to-end security posture of EY's Agentic AI platform. The role focuses on threat modeling, secure-by-default contracts, and defense against agentic threats across cloud-native environments.

You will lead red teaming, define policy-as-code, and defend the platform against sophisticated attacks while communicating with CISOs and regulators. This is a senior, platform-wide security leadership role.

Qualifications

  • Experience in cloud-native security architectures and threat modeling.
  • Ability to design and defend agentic AI platforms against advanced attacker capabilities.
  • Hands-on security engineering across platform layers, from silicon-level attestation to telemetry.

Responsibilities

  • Own the platform threat model covering agent autonomy, tool invocation, delegated authority, and multi-tenant deployment.
  • Define the security engineering and control set for infrastructure, Kubernetes, identity, secrets, sandboxing, networking, data, and telemetry.
  • Set the secure-by-default contract with agent templates, Helm charts, sandbox profiles, and network policies.
  • Own defense against agentic threat classes including prompt injection, jailbreaks, excessive agency, and context manipulation.
  • Collaborate with architecture to define the agent authority model, boundaries, and non-escalation invariants.
  • Own the sandboxing security standard for agent-generated code execution, including isolation, filesystem scope, and egress restrictions.
  • Secure the model and knowledge supply chain: provenance, governance, poisoning risks, and integrity of embeddings/vector stores.
  • Secure agent-to-agent and tool protocols: discovery trust, tool registration, schema validation, and inter-agent authorization.
  • Lead AI red teaming and adversarial testing to build offensive capabilities and defense mechanisms.

Tools

Kubernetes

Job description

Location: Anywhere in Country

At EY, we're all in to shape your future with confidence.

We'll help you succeed in a globally connected powerhouse of diverse teams and take your career wherever you want it to go. Join EY and help to build a better working world.

The opportunity

We are seeking an AI Security Engineer to own the security posture of EY's Agentic AI platform end to end.

Agentic AI breaks the assumptions most enterprise security programs are built on. Systems now generate and execute their own code, invoke tools and external APIs autonomously, act on behalf of human principals across long delegation chains, and can be manipulated through the same channel that carries legitimate instructions. Perimeter controls, static code review, and human-in-the-loop approval do not contain any of this on their own.

This role exists to make EY's agentic platform defensible in the most highly regulated client environments in the world, including tax, financial services, audit, and risk. It is the security engineering and assurance authority spanning the whole stack: from silicon-level attestation and Kubernetes hardening, through supply-chain integrity and sandboxed execution, to prompt-injection defense, agent authority containment, and audit-grade evidence.

This is a deliberately broad mandate. It is ideal for a principal security engineer who has genuine depth in cloud-native and platform security, who has moved decisively into AI and agentic threat models, and who is equally comfortable writing a threat model, breaking a system in a red-team exercise, defining policy-as-code, and defending the resulting engineering to a client's CISO or a regulator.

Your key responsibilities
  • Own the platform threat model : covering agent autonomy, tool invocation, delegated authority, model and data supply chain, multi-tenancy, and every deployment target from cloud to air-gapped, and keep it current as the platform evolves through each build phase.

  • Define the security engineering and control set for every platform layer: infrastructure and boot chain, Kubernetes and cluster fabric, identity and secrets, secure execution and sandboxing, gateway and egress, data and state, delivery pipeline, and telemetry.

  • Set the secure-by-default contract so that platform capabilities arrive hardened, including agent templates, Helm charts, sandbox profiles, and network policy ship with correct controls rather than requiring teams to add them.

  • Own defense against agentic threat classes including direct and indirect prompt injection, jailbreak and instruction hijacking, excessive agency, confused-deputy and authority-escalation attacks, tool and function-call abuse, memory and context poisoning, and retrieval-augmented data exfiltration.

  • Work with the architecture team to help define the agent authority model : delegated and on-behalf-of authority, scope and delegation-depth limits, consent boundaries, and the non-escalation invariant that an agent never exceeds the authority of its initiating principal at any hop.

  • Own the sandboxing security standard for agent-generated code execution: isolation boundaries, filesystem and credential scope, egress restriction, resource containment, and the escape-test suite that proves the boundary holds.

  • Secure the model and knowledge supply chain : model provenance and integrity, upstream registry governance, poisoning and backdoor risk, embedding and vector-store integrity.

  • Secure agent-to-agent and tool protocols including MCP and A2A surfaces: discovery trust, tool registration and approval, schema validation, and authorization of inter-agent calls.

  • Lead AI red teaming and adversarial testing : build the offensive capability and the

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Lead AI Security Engineer - Senior Manager
Lead AI Security Engineer - Senior Manager

Ernst & Young Oman • San Mateo (CA)

Remote
USD 140,000 - 190,000
Lead AI Security Engineer - Senior Manager
Lead AI Security Engineer - Senior Manager

Ernst & Young Oman • Chantilly (VA)

On-site
USD 130,000 - 180,000
Lead AI Security Engineer - Senior Manager
Lead AI Security Engineer - Senior Manager

Ernst & Young Oman • Cleveland (OH)

Remote
USD 150,000 - 190,000
Lead AI Security Engineer - Senior Manager
Lead AI Security Engineer - Senior Manager

Ernst & Young Oman • City of Rochester (NY)

On-site
USD 130,000 - 180,000
Lead AI Security Engineer - Senior Manager
Lead AI Security Engineer - Senior Manager

Ernst & Young Oman • San Jose (CA)

Remote
USD 140,000 - 190,000
Lead AI Security Engineer - Senior Manager
Lead AI Security Engineer - Senior Manager

Ernst & Young Oman • Milwaukee (WI)

Remote
USD 140,000 - 190,000
Lead AI Security Engineer - Senior Manager
Lead AI Security Engineer - Senior Manager

Ernst & Young Oman • Palo Alto (CA)

Remote
USD 150,000 - 190,000
Lead AI Security Engineer - Senior Manager
Lead AI Security Engineer - Senior Manager

Ernst & Young Oman • St. Louis (MO)

Remote
USD 140,000 - 190,000
Lead AI Security Engineer - Senior Manager
Lead AI Security Engineer - Senior Manager

Ernst & Young Oman • Columbus (OH)

Remote
USD 150,000 - 210,000
Lead AI Security Engineer - Senior Manager
Lead AI Security Engineer - Senior Manager

Ernst & Young Oman • Hartford (CT)

Remote
USD 140,000 - 210,000