Senior AI Security Engineer for Agentic Platform

EY

Tallahassee (FL)

On-site

USD 126,000 - 230,000

Full time

9 hours ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Benefits offered by this job

Medical and dental coverage
401(k) plan
Flexible vacation policy
Paid holidays
Work-life balance

Job summary

EY is seeking an AI Security Engineer to own the security posture of EY’s Agentic AI platform end to end. You’ll craft threat models, implement security controls, and lead red teaming across cloud, Kubernetes, and data pipelines to defend against agentic threats.

The role requires deep cloud-native security expertise, experience with AI security in production, and the ability to communicate with clients and regulators at executive levels.

Qualifications

  • Bachelor’s or Master’s degree in Computer Science, Security, or a related technical field, or demonstrably equivalent depth.
  • 10+ years in security engineering, security engineering, or offensive security, including hands-on production ownership.
  • Demonstrable depth in cloud-native and Kubernetes security: admission control, network policy, workload isolation, and runtime security in production.
  • Hands-on experience with workload identity and secrets management (SPIFFE/SPIRE, Vault/OpenBao or equivalents) and with PKI and certificate lifecycle.
  • Practical experience securing AI or ML systems in production, including familiarity with LLM and agentic attack surfaces, such as prompt injection, tool abuse, excessive agency, and model or data supply-chain risk.
  • Threat modelling capability applied to real systems, with evidence that the resulting controls were built and verified.
  • A track record delivering under compliance, security, or regulatory constraint with audit-grade evidence requirements.
  • Experience defining ownership boundaries and control contracts with platform, data, runtime, and delivery teams.

Responsibilities

  • Own the platform threat model: covering agent autonomy, tool invocation, delegated authority, model and data supply chain, multi-tenancy, and every deployment target from cloud to air-gapped, and keep it current as the platform evolves.
  • Define the security engineering and control set for every platform layer: infrastructure and boot chain, Kubernetes and cluster fabric, identity and secrets, secure execution and sandboxing, gateway and egress, data and state, delivery pipeline, and telemetry.
  • Set the secure-by-default contract so that platform capabilities arrive hardened, including agent templates, Helm charts, sandbox profiles, and network policy ship with correct controls rather than requiring teams to add them.
  • Own defense against agentic threat classes including direct and indirect prompt injection, jailbreak and instruction hijacking, excessive agency, confused-deputy and authority-escalation attacks, tool and function-call abuse, memory and context poisoning, and retrieval-augmented data exfiltration.
  • Work with the architecture team to help define the agent authority model: delegated and on-behalf-of authority, scope and delegation-depth limits, consent boundaries, and the non-escalation invariant that an agent never exceeds the authority of its initiating principal at any hop.
  • Own the sandboxing security standard for agent-generated code execution: isolation boundaries, filesystem and credential scope, egress restriction, resource containment, and the escape-test suite that proves the boundary holds.
  • Secure the model and knowledge supply chain: model provenance and integrity, upstream registry governance, poisoning and backdoor risk, embedding and vector-store integrity.
  • Secure agent-to-agent and tool protocols including MCP and A2A surfaces: discovery trust, tool registration and approval, schema validation, and authorization of inter-agent calls.
  • Lead AI red teaming and adversarial testing: build the offensive capability and the recurring exercise cadence that tests guardrails, sandboxes, and authority boundaries before adversaries and auditors do.
  • Own supply-chain integrity end to end: artifact signing and verification (Sigstore/Cosign, Notation), SBOM generation and attestation, provenance and SLSA-aligned build integrity, CVE management, dependency and license governance.
  • Own admission and runtime policy: policy-as-code across Kyverno and OPA, signature-verification enforcement, Pod Security Standards, and the guardrails that make non-compliant workloads unschedulable rather than merely reported.
  • Define Kubernetes and infrastructure hardening baselines: CIS-aligned cluster configuration, network default-deny and segmentation, node and boot-chain integrity, GPU and DPU isolation, and secrets-handling standards.
  • Own tenant isolation assurance: the security definition of a tenant boundary across compute, network, storage, secrets, telemetry, and evidence, and the testing that proves cross-tenant leakage is not possible.
  • Serve as the security authority in client engagements: lead security engineering reviews, respond to client CISO and regulator scrutiny, and produce the assurance artefacts that unblock deployment into regulated environments.
  • Drive security detection and response for the platform: detection engineering for agentic misbehavior, security telemetry requirements, alerting, incident response playbooks, and post-incident review.

Skills

Cloud-native security
AI security
Zero-trust
Policy-as-code
Threat modelling
Communication with stakeholders

Education

Bachelor’s or Master’s degree in Computer Science, Security, or related field

Tools

SPIFFE/SPIRE
Sigstore/Cosign
Notation
Kyverno
OPA

Job description

EY is seeking an AI Security Engineer to own the security posture of EY’s Agentic AI platform end to end. You’ll craft threat models, implement security controls, and lead red teaming across cloud, Kubernetes, and data pipelines to defend against agentic threats.

The role requires deep cloud-native security expertise, experience with AI security in production, and the ability to communicate with clients and regulators at executive levels.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior AI Security Architect for Agentic Platforms
Senior AI Security Architect for Agentic Platforms

EY • Houston (TX)

On-site
USD 126,000 - 230,000
Medical and dental coverage
Pension and 401(k) plans
Paid time off
Senior AI Security Architect for Agentic Platform
Senior AI Security Architect for Agentic Platform

EY • Boca Raton (FL)

Remote
USD 125,000 - 230,000
Medical and dental coverage
401(k) with company match
Flexible vacation policy
Senior AI Security Engineer — Platform & Agentic Defense
Senior AI Security Engineer — Platform & Agentic Defense

EY • Kansas City (MO)

Hybrid
USD 126,000 - 262,000
Medical and dental coverage
Pension and 401(k)
Flexible vacation policy
+1
Principal AI Security Engineer for Agentic Platform
Principal AI Security Engineer for Agentic Platform

EY • Las Vegas (NV)

Remote
USD 126,000 - 230,000
Medical and dental coverage
Pension and 401(k)
Paid time off
+1
Principal AI Security Architect for Agentic Platform
Principal AI Security Architect for Agentic Platform

EY • Nashville (TN)

Remote
USD 125,000 - 230,000
Medical and dental coverage
Pension/401(k)
Paid time off
+1
Senior AI Security Engineer - Agentic Platform Defenses
Senior AI Security Engineer - Agentic Platform Defenses

EY • Milwaukee (WI)

On-site
USD 126,000 - 230,000
Medical and dental coverage
401(k)
Paid time off
+1
Senior AI Security Engineer - Platform Defense & Threats
Senior AI Security Engineer - Platform Defense & Threats

EY • Tampa (FL)

On-site
USD 125,000 - 231,000
Senior AI Security Engineer: Agentic Platform Defense
Senior AI Security Engineer: Agentic Platform Defense

EY • Jacksonville (FL)

On-site
USD 170,000 - 250,000
Medical and dental coverage
Pension and 401(k)
Paid time off
Senior AI Security Architect for Agentic Platform
Senior AI Security Architect for Agentic Platform

EY • New Brunswick (NJ)

Remote
USD 126,000 - 251,000
AI Security Architect – Agentic Platform Defense
AI Security Architect – Agentic Platform Defense

EY • Palo Alto (CA)

On-site
USD 157,000 - 262,000