Senior AI Security Engineer - Platform Threat & Defense

EY

Philadelphia (Philadelphia County)

Remote

USD 126,000 - 262,000

Full time

34 hours ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

EY, the global professional services firm, is seeking an AI Security Engineer to own the security posture of EY’s Agentic AI platform end to end. You will tackle threat modelling, sandboxing, supply-chain integrity, and policy-as-code across cloud-native deployments, from cloud to air-gapped environments, working with architecture and client engagements.

This role demands deep security expertise, AI risk knowledge, and the ability to communicate with CISOs and regulators while delivering

Qualifications

  • Bachelor’s or Master’s degree in Computer Science, Security, or related field or demonstrably equivalent depth.
  • 10+ years in security engineering with production ownership.
  • Demonstrable depth in cloud-native and Kubernetes security.
  • Hands-on experience with workload identity and secrets management.
  • Practical experience securing AI/ML systems in production, including agentic attack surfaces.
  • Threat modelling applied to real systems with verified controls.
  • Track record delivering under compliance with audit-grade evidence requirements.
  • Experience defining ownership boundaries and control contracts with platform, data, runtime, and delivery teams.

Responsibilities

  • Own the platform threat model: covering agent autonomy, tool invocation, delegated authority, model and data supply chain, multi-tenancy, and deployment targets.
  • Define the security engineering and control set for every platform layer: infrastructure, Kubernetes, identity, secure execution, gateway, data, telemetry.
  • Set the secure-by-default contract with hardened capabilities, including agent templates, Helm charts, sandbox profiles, and network policy.
  • Own defense against agentic threat classes including prompt injection, jailbreak, excessive agency, and authority escalation.
  • Work with architecture to define the agent authority model: delegation depth, consent boundaries, and non-escalation invariants.
  • Own the sandboxing security standard for agent-generated code execution.
  • Secure the model and knowledge supply chain: provenance, SBOM, and attestation.
  • Secure agent-to-agent and tool protocols: trust, registration, validation, and authorization.
  • Lead AI red teaming and adversarial testing before client/auditor exposure.
  • Own supply-chain integrity end-to-end: signing, verification, SBOM, provenance, and license governance.
  • Own admission and runtime policy: policy-as-code across Kyverno and OPA, and Pod Security Standards.
  • Define Kubernetes hardening baselines: CIS-aligned config, default-deny networking, and secret handling standards.
  • Own tenant isolation assurance and cross-tenant leakage testing.
  • Serve as security authority in client engagements: reviews, regulator responses, and auditable artefacts.
  • Drive security detection and response for the platform: telemetry, alerts, and incident response playbooks.

Skills

Cloud-native security
AI threat models
Zero-trust
Policy as code
SBOM provenance
Offensive security
Risk management
Executive communication
Security enablement

Education

Bachelor’s or Master’s in CS/Security

Tools

SPIFFE/SPIRE
Vault/OpenBB (OpenBao)
Sigstore/Cosign
OPA/Kyverno

Job description

EY, the global professional services firm, is seeking an AI Security Engineer to own the security posture of EY’s Agentic AI platform end to end. You will tackle threat modelling, sandboxing, supply-chain integrity, and policy-as-code across cloud-native deployments, from cloud to air-gapped environments, working with architecture and client engagements.

This role demands deep security expertise, AI risk knowledge, and the ability to communicate with CISOs and regulators while delivering

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior AI Security Engineer - Platform Defense & Threats
Senior AI Security Engineer - Platform Defense & Threats

EY • Tampa (FL)

On-site
USD 125,000 - 231,000
Senior AI Security Engineer - Platform & Threat Defense
Senior AI Security Engineer - Platform & Threat Defense

EY • Pittsburgh

On-site
USD 151,000 - 251,000
Competitive compensation
Medical and dental coverage
Paid time off
+1
Senior AI Security Engineer — Platform & Agentic Defense
Senior AI Security Engineer — Platform & Agentic Defense

EY • Kansas City (MO)

Hybrid
USD 126,000 - 262,000
Medical and dental coverage
Pension and 401(k)
Flexible vacation policy
+1
Senior AI Security Engineer – Platform Threat Defense
Senior AI Security Engineer – Platform Threat Defense

EY • Atlanta (GA)

Remote
USD 126,000 - 230,000
Medical and dental coverage
Pension and 401(k) plans
Paid time off options
Senior AI Security Engineer - Agentic Platform Defenses
Senior AI Security Engineer - Agentic Platform Defenses

EY • Milwaukee (WI)

On-site
USD 126,000 - 230,000
Medical and dental coverage
401(k)
Paid time off
+1
Principal AI Security Engineer — Platform Defense
Principal AI Security Engineer — Platform Defense

EY • Rogers (AR)

Remote
USD 126,000 - 262,000
Medical and dental coverage
Pension and 401(k)
Flexible vacation policy
Senior AI Security Architect for Agentic Platforms
Senior AI Security Architect for Agentic Platforms

EY • Houston (TX)

On-site
USD 126,000 - 230,000
Medical and dental coverage
Pension and 401(k) plans
Paid time off
Senior AI Security Engineer: Platform Threat Defense
Senior AI Security Engineer: Platform Threat Defense

EY • Cincinnati (OH)

Remote
USD 126,000 - 230,000
Competitive compensation
Comprehensive benefits package
Flexible vacation
Senior AI Security Engineer: Agentic Platform Defense
Senior AI Security Engineer: Agentic Platform Defense

EY • Jacksonville (FL)

On-site
USD 170,000 - 250,000
Medical and dental coverage
Pension and 401(k)
Paid time off
Senior AI Security Architect: Defend Autonomous Platforms
Senior AI Security Architect: Defend Autonomous Platforms

EY • McLean (VA)

On-site
USD 126,000 - 262,000
Medical and dental coverage
Pension and 401(k) plans
Flexible vacation policy