> Markdown version of [/jobs/ext/3106488-lead-ai-security-engineer-senior-manager](https://www.wearedevelopers.com/jobs/ext/3106488-lead-ai-security-engineer-senior-manager). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Lead AI Security Engineer - Senior Manager - **Company:** Ernst & Young LLP - **Location:** Phoenix, AZ, United States (Remote available) - **Experience:** Expert - **Salary:** $150,700.0 - $251,200.0 - **Contract:** Permanent contract - **Skills:** Kubernetes Security, Test Suite, Artificial Intelligence, Cloud Computing Security, Cloud Engineering, Computer Networks, Intrusion Detection and Prevention, Key Management, Node.Js, Open Source Technology, Open Web Application Security, Public Key Infrastructure, Red Team (Cyber Security), Zero Trust Network Access, Runbook, Software Vulnerability Management, Policy as Code, Delivery Pipeline, Large Language Models, Multi-Agent Systems, Kubernetes Helm Charts, Kubernetes, Information Technology, Machine Learning Operations - **Published:** September 27, 2026 - **Apply:** https://dejobs.org/x/x/031B2DD998054764A5476F081C88B7AB/job/ ## About the Role * Deep cloud-native security expertise: Kubernetes, container, and infrastructure security at production scale, with real operational experience rather than assessment-only exposure. * Genuine command of AI and agentic threat models, with the judgement to distinguish novel risk from familiar risk wearing new vocabulary. * Strong zero-trust and workload-identity foundations: SPIFFE/SPIRE, PKI and certificate lifecycle, secrets management, and delegated authorization patterns. * Fluency in policy-as-code, with the instinct to encode controls as enforced policy rather than documented expectation. * Software supply-chain security depth: signing, provenance, SBOM, and build integrity. * Offensive-security instinct: able to think like an attacker against systems that generate their own code and act autonomously. * Pragmatism about risk: able to distinguish controls that must exist before the first client workload from those that can follow, and to defend both decisions. * Exceptional communication: able to move between a deep technical design review, an executive risk conversation, and a regulator or client CISO discussion without losing precision. * Security-as-enablement mindset: measured by how much safe delivery velocity the controls unlock, not by how much they prevent. To qualify you must have * Bachelor's or Master's degree in Computer Science, Security, or a related technical field, or demonstrably equivalent depth. * 10+ years in security engineering, security engineering, or offensive security, including hands-on production ownership. * Demonstrable depth in cloud-native and Kubernetes security: admission control, network policy, workload isolation, and runtime security in production. * Hands-on experience with workload identity and secrets management (SPIFFE/SPIRE, Vault/OpenBao or equivalents) and with PKI and certificate lifecycle. * Practical experience securing AI or ML systems in production, including familiarity with LLM and agentic attack surfaces, such as prompt injection, tool abuse, excessive agency, and model or data supply-chain risk. * Threat modelling capability applied to real systems, with evidence that the resulting controls were built and verified. * A track record delivering under compliance, security, or regulatory constraint with audit-grade evidence requirements. * Experience defining ownership boundaries and control contracts with platform, data, runtime, and delivery teams. Ideally, you'll also have * Software supply-chain security experience: artifact signing, SBOM, provenance, and vulnerability management embedded in delivery pipelines. * Policy-as-code experience with OPA, Kyverno, or equivalent admission and authorisation engines. * Experience building or leading an AI red team, or running adversarial testing against LLM and agentic systems. * Familiarity with confidential computing and hardware attestation (Intel TDX, AMD SEV-SNP, SGX, NVIDIA CC) and secure boot / measured boot designs. * Working knowledge of the OWASP Top 10 for LLM Applications, MITRE ATLAS, NIST AI RMF, and the EU AI Act as applied to real engineering. * Experience with LLM guardrail and defense tooling (NeMo Guardrails, LLM Guard, LlamaFirewall, Guardrails AI, or equivalents) in production paths. * Experience securing multi-tenant platforms across cloud, on-prem, edge, client-managed, and air-gapped deployment modes. * Detection engineering and incident response experience, particularly for novel or behavioral threat classes. * Client-facing or consulting background, with credibility in front of CISOs, auditors, and regulators. * Relevant certifications (CISSP, OSCP, GIAC, cloud security specialties) or demonstrable equivalent depth. * Exposure to regulated industries: financial services, tax, audit, healthcare, or public sector. * Contribution to open-source security tooling, research, or public standards work in AI security. ## Description * Own the platform threat model : covering agent autonomy, tool invocation, delegated authority, model and data supply chain, multi-tenancy, and every deployment target from cloud to air-gapped, and keep it current as the platform evolves through each build phase. * Define the security engineering and control set for every platform layer: infrastructure and boot chain, Kubernetes and cluster fabric, identity and secrets, secure execution and sandboxing, gateway and egress, data and state, delivery pipeline, and telemetry. * Set the secure-by-default contract so that platform capabilities arrive hardened, including agent templates, Helm charts, sandbox profiles, and network policy ship with correct controls rather than requiring teams to add them. * Own defense against agentic threat classes including direct and indirect prompt injection, jailbreak and instruction hijacking, excessive agency, confused-deputy and authority-escalation attacks, tool and function-call abuse, memory and context poisoning, and retrieval-augmented data exfiltration. * Work with the architecture team to help define the agent authority model : delegated and on-behalf-of authority, scope and delegation-depth limits, consent boundaries, and the non-escalation invariant that an agent never exceeds the authority of its initiating principal at any hop. * Own the sandboxing security standard for agent-generated code execution: isolation boundaries, filesystem and credential scope, egress restriction, resource containment, and the escape-test suite that proves the boundary holds. * Secure the model and knowledge supply chain: model provenance and integrity, upstream registry governance, poisoning and backdoor risk, embedding and vector-store integrity. * Secure agent-to-agent and tool protocols including MCP and A2A surfaces: discovery trust, tool registration and approval, schema validation, and authorization of inter-agent calls. * Lead AI red teaming and adversarial testing: build the offensive capability and the recurring exercise cadence that tests guardrails, sandboxes, and authority boundaries before adversaries and auditors do. * Own supply-chain integrity end to end: artifact signing and verification (Sigstore/Cosign, Notation), SBOM generation and attestation, provenance and SLSA-aligned build integrity, CVE management, dependency and license governance. * Own admission and runtime policy: policy-as-code across Kyverno and OPA, signature-verification enforcement, Pod Security Standards, and the guardrails that make non-compliant workloads unschedulable rather than merely reported. * Define Kubernetes and infrastructure hardening baselines: CIS-aligned cluster configuration, network default-deny and segmentation, node and boot-chain integrity, GPU and DPU isolation, and secrets-handling standards. * Own tenant isolation assurance: the security definition of a tenant boundary across compute, network, storage, secrets, telemetry, and evidence, and the testing that proves cross-tenant leakage is not possible. * Serve as the security authority in client engagements: lead security engineering reviews, respond to client CISO and regulator scrutiny, and produce the assurance artefacts that unblock deployment into regulated environments. * Drive security detection and response for the platform: detection engineering for agentic misbehavior, security telemetry requirements, alerting, incident response playbooks, and post-incident review. ## Related Videos - [The New AI Security Stack: Observe, Detect, Protect](https://www.wearedevelopers.com/videos/100302-the-new-ai-security-stack-observe-detect-protect) - [Technical Documentation - How Can I Write Them Better and Why Should I Care?](https://www.wearedevelopers.com/videos/681-technical-documentation-how-can-i-write-them-better-and-why-should-i-care) - [How To Test A Ball of Mud](https://www.wearedevelopers.com/videos/173-how-to-test-a-ball-of-mud) - [Stop using Node.js like in 2020! What changed and what you can do today with Node.js](https://www.wearedevelopers.com/videos/100011-stop-using-node-js-like-in-2020-what-changed-and-what-you-can-do-today-with-node-js) - [Tackling the Risks of AI - With AI](https://www.wearedevelopers.com/videos/1690-tackling-the-risks-of-ai-with-ai) - [Bridging AI and Nomad: a Go-based MCP Server for Cluster Control](https://www.wearedevelopers.com/videos/2063-bridging-ai-and-nomad-a-go-based-mcp-server-for-cluster-control) ## Related Articles - [Got AI ideas but no money? Here are 10 free ways to level up your AI skills with Google Cloud](https://www.wearedevelopers.com/magazine/600-got-ai-ideas-but-no-money-here-are-10-free-ways-to-level-up-your-ai-skills-with-google-cloud) - [How to Become an AI Engineer](https://www.wearedevelopers.com/magazine/331-how-to-become-an-ai-engineer) - [Trustworthy AI Starts at Deployment: 5 Checks Before You Ship](https://www.wearedevelopers.com/magazine/753-trustworthy-ai-starts-at-deployment-5-checks-before-you-ship) - [Navigating the AI Shift](https://www.wearedevelopers.com/magazine/629-navigating-the-ai-shift) - [Best US AI Conferences for CTOs in 2026: Build vs. Buy, Vendor Evaluation, and Peer Intelligence](https://www.wearedevelopers.com/magazine/736-best-us-ai-conferences-for-ctos-in-2026-build-vs-buy-vendor-evaluation-and-peer-intelligence) - [What is Software Engineering in the Age of AI?](https://www.wearedevelopers.com/magazine/640-what-is-software-engineering-in-the-age-of-ai)