Senior AI Security Architect: Platform Defense

EY

Sacramento (CA)

On-site

USD 126,000 - 230,000

Full time

2 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Benefits offered by this job

Medical and dental coverage
Pension and 401(k) plans
Paid time off
Flexible vacation policy

Job summary

EY is seeking an AI Security Engineer to own the security posture of EY’s Agentic AI platform end to end. The role spans cloud-native security, tooling, and risk governance, including threat modelling, containment, and audit-grade evidence for regulated environments.

The ideal candidate brings 10+ years in security engineering, hands-on AI security experience, and a pragmatic approach to incident response, identity management, and SBOM governance.

Qualifications

  • Bachelor’s or Master’s degree in Computer Science, Security, or related field.
  • 10+ years in security engineering, security engineering, or offensive security, including hands-on production ownership.
  • Practical experience securing AI or ML systems in production, including familiarity with prompt injection, tool abuse, excessive agency, and model or data supply-chain risk.

Responsibilities

  • Own the platform threat model: covering agent autonomy, tool invocation, delegated authority, model and data supply chain, multi-tenancy, and every deployment target from cloud to air-gapped, and keep it current as the platform evolves through each build phase.
  • Define the security engineering and control set for every platform layer: infrastructure and boot chain, Kubernetes and cluster fabric, identity and secrets, secure execution and sandboxing, gateway and egress, data and state, delivery pipeline, and telemetry.
  • Set the secure-by-default contract so that platform capabilities arrive hardened, including agent templates, Helm charts, sandbox profiles, and network policy ship with correct controls rather than requiring teams to add them.
  • Own defense against agentic threat classes including direct and indirect prompt injection, jailbreak and instruction hijacking, excessive agency, confused-deputy and authority-escalation attacks, tool and function-call abuse, memory and context poisoning, and retrieval-augmented data exfiltration.
  • Work with the architecture team to help define the agent authority model: delegated and on-behalf-of authority, scope and delegation-depth limits, consent boundaries, and the non-escalation invariant that an agent never exceeds the authority of its initiating principal at any hop.
  • Own the sandboxing security standard for agent-generated code execution: isolation boundaries, filesystem and credential scope, egress restriction, resource containment, and the escape-test suite that proves the boundary holds.

Skills

Cloud-native security
AI/agentic threat models
Zero-trust architecture
Policy-as-code
Threat modelling
Incident response

Education

Bachelor’s or Master’s degree in Computer Science, Security, or related field

Tools

SPIFFE/SPIRE
PKI & certificate lifecycle
Sigstore/Cosign
SBOM and supply-chain tooling

Job description

EY is seeking an AI Security Engineer to own the security posture of EY’s Agentic AI platform end to end. The role spans cloud-native security, tooling, and risk governance, including threat modelling, containment, and audit-grade evidence for regulated environments.

The ideal candidate brings 10+ years in security engineering, hands-on AI security experience, and a pragmatic approach to incident response, identity management, and SBOM governance.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior AI Security Engineer: Agentic Platform Defense
Senior AI Security Engineer: Agentic Platform Defense

EY • Jacksonville (FL)

On-site
USD 170,000 - 250,000
Medical and dental coverage
Pension and 401(k)
Paid time off
Senior AI Security Architect: Defend Autonomous Platforms
Senior AI Security Architect: Defend Autonomous Platforms

EY • McLean (VA)

On-site
USD 126,000 - 262,000
Medical and dental coverage
Pension and 401(k) plans
Flexible vacation policy
Senior AI Security Architect for Agentic Platform
Senior AI Security Architect for Agentic Platform

EY • Hoboken (NJ)

On-site
USD 126,000 - 251,000
Medical & dental coverage
401(k) plan with match
Flexible vacation policy
Senior AI Security Engineer - Platform Threat & Defense
Senior AI Security Engineer - Platform Threat & Defense

EY • Philadelphia

Remote
USD 126,000 - 262,000
Senior AI Security Architect
Senior AI Security Architect

EY • Hartford (CT)

Remote
USD 150,000 - 230,000
Medical and dental coverage
Total Rewards package
Flexible vacation policy
Senior AI Security Engineer: Platform Threat Defense
Senior AI Security Engineer: Platform Threat Defense

EY • Cincinnati (OH)

Remote
USD 126,000 - 230,000
Competitive compensation
Comprehensive benefits package
Flexible vacation
Senior AI Security Architect for Agentic Platform
Senior AI Security Architect for Agentic Platform

EY • New Brunswick (NJ)

Remote
USD 126,000 - 251,000
Senior AI Security Engineer — Platform & Agentic Defense
Senior AI Security Engineer — Platform & Agentic Defense

EY • Kansas City (MO)

Hybrid
USD 126,000 - 262,000
Medical and dental coverage
Pension and 401(k)
Flexible vacation policy
+1
Senior AI Security Engineer - Platform Defense & Threats
Senior AI Security Engineer - Platform Defense & Threats

EY • Tampa (FL)

On-site
USD 125,000 - 231,000
Senior AI Security Engineer – Agentic Platform Defense
Senior AI Security Engineer – Agentic Platform Defense

EY • Oklahoma City (OK)

Remote
USD 126,000 - 230,000