waypointjobs

Ernst & Young Oman

Lead AI Security Engineer - Senior Manager

workfromhome, AR

Check who can apply and the requirements below before continuing.

About this opportunity

Ernst & Young Oman lists this Lead AI Security Engineer - Senior Manager opportunity in workfromhome, Arkansas. Review the employer’s description below for duties, qualifications and application requirements.

Job description

Location: Anywhere in Country

At EY, we're all in to shape your future with confidence.

We'll help you succeed in a globally connected powerhouse of diverse teams and take your career wherever you want it to go. Join EY and help to build a better working world.

The opportunity

We are seeking an AI Security Engineer to own the security posture of EY's Agentic AI platform end to end.

Agentic AI breaks the assumptions most enterprise security programs are built on. Systems now generate and execute their own code, invoke tools and external APIs autonomously, act on behalf of human principals across long delegation chains, and can be manipulated through the same channel that carries legitimate instructions. Perimeter controls, static code review, and human-in-the-loop approval do not contain any of this on their own.

This role exists to make EY's agentic platform defensible in the most highly regulated client environments in the world, including tax, financial services, audit, and risk. It is the security engineering and assurance authority spanning the whole stack: from silicon-level attestation and Kubernetes hardening, through supply-chain integrity and sandboxed execution, to prompt-injection defense, agent authority containment, and audit-grade evidence.

This is a deliberately broad mandate. It is ideal for a principal security engineer who has genuine depth in cloud-native and platform security, who has moved decisively into AI and agentic threat models, and who is equally comfortable writing a threat model, breaking a system in a red-team exercise, defining policy-as-code, and defending the resulting engineering to a client's CISO or a regulator.

Your key responsibilities

Own the platform threat model : covering agent autonomy, tool invocation, delegated authority, model and data supply chain, multi-tenancy, and every deployment target from cloud to air-gapped, and keep it current as the platform evolves through each build phase.

Define the security engineering and control set for every platform layer: infrastructure and boot chain, Kubernetes and cluster fabric, identity and secrets, secure execution and sandboxing, gateway and egress, data and state, delivery pipeline, and telemetry.

Set the secure-by-default contract so that platform capabilities arrive hardened, including agent templates, Helm charts, sandbox profiles, and network policy ship with correct controls rather than requiring teams to add them.

Own defense against agentic threat classes including direct and indirect prompt injection, jailbreak and instruction hijacking, excessive agency, confused-deputy and authority-escalation attacks, tool and function-call abuse, memory and context poisoning, and retrieval-augmented data exfiltration.

Work with the architecture team to help define the agent authority model : delegated and on-behalf-of authority, scope and delegation-depth limits, consent boundaries, and the non-escalation invariant that an agent never exceeds the authority of its initiating principal at any hop.

Own the sandboxing security standard for agent-generated code execution: isolation boundaries, filesystem and credential scope, egress restriction, resource containment, and the escape-test suite that proves the boundary holds.

Secure the model and knowledge supply chain : model provenance and integrity, upstream registry governance, poisoning and backdoor risk, embedding and vector-store integrity.

Secure agent-to-agent and tool protocols including MCP and A2A surfaces: discovery trust, tool registration and approval, schema validation, and authorization of inter-agent calls.

Lead AI red teaming and adversarial testing : build the offensive capability and the

#J-18808-Ljbffr

Worksite address

workfromhome, AR, 72208, US

Who can apply

Review the original listing for work authorization, qualifications and employer requirements.

Ready for your next step?Apply on the official website
Apply on WhatJobs ↗

Explore related searches

Current related jobs

OSI Engineering

WhatJobs

PC Test Engineer

mountain view, CA

See pay details in description

This range is provided by OSI Engineering. Your actual pay will be based on your skills and experience — talk with your recruiter to learn more. …

Last received from source 2026-10-08View job

Convergenz

WhatJobs

Exchange Engineer

workfromhome, DC

$110,000.00/yr - $140,000.00/yr

This range is provided by Convergenz. Your actual pay will be based on your skills and experience — talk with your recruiter to learn more. Bas…

Last received from source 2026-10-08View job

Pyramid Consulting, Inc

WhatJobs

Application Performance & Network Support Engineer

honolulu, HI

See pay details in description

Application Performance & Network Support Engineer 3 days ago Be among the first 25 applicants Pyramid Consulting, Inc provided pay range T…

Last received from source 2026-10-08View job