Cybersecurity - AI Cybersecurity Architect & Engineer - Consulting - Location OPEN
EY
- Location
- Dallas, TX, US, 75219 +80 more…
- Work model
- On-Site
- Level
- Mid
Skills
About this role
Location: Anywhere in Country At EY, we’re all in to shape your future with confidence. We’ll help you succeed in a globally connected powerhouse of diverse teams and take your career wherever you want it to go. Join EY and help to build a better working world.
Securing Frontier AI, Agentic Systems & AI-Driven Cyber Defense Job Family: Cybersecurity | Level: Senior Manager / Principal | Location: Hybrid / Remote-Eligible | Travel: Up to 30% ROLE OVERVIEW The AI Cybersecurity Architect & Engineer is a hybrid technical leadership role responsible for designing, building, and defending AI systems as first-class assets — while simultaneously leveraging AI to deliver next-generation cyber defense capabilities. This individual sits at the intersection of cybersecurity engineering, machine learning, and agentic AI, protecting models, data pipelines, prompts, agents, integrations, and the infrastructure that hosts them, while also using AI offensively (from a defensive standpoint) to match the speed and sophistication of Frontier AI-enabled attacks. This role is critical as organizations face a fundamental shift in the threat landscape: Frontier AI models can now autonomously discover and weaponize zero-day vulnerabilities in hours, AI-generated polymorphic malware evades signature-based detection, and autonomous AI worms spread laterally adapting tactics per-target. Defenders need an equally capable AI-augmented security posture — built and operated by professionals who understand both domains deeply. KEY RESPONSIBILITIES A. AI Security Architecture & Design
Design end-to-end secure architectures for AI/ML systems, including LLM applications, agentic AI workflows, RAG pipelines, vector databases, and model serving infrastructure. Establish threat models for AI systems using MITRE ATLAS, OWASP Top 10 for LLM Applications, OWASP Agentic Security Initiative (ASI) Top 10, and CSA MAESTRO 7-layer framework. Define secure-by-design patterns for AI agent permissions, tool invocation, memory/context isolation, and inter-agent communication (Model Context Protocol, Agent2Agent). Architect zero-trust controls for AI training pipelines, model registries, embedding stores, and prompt template repositories. Develop reference architectures for integrating GenAI capabilities into enterprise security platforms (CrowdStrike NGSIEM, Microsoft Sentinel, ServiceNow SIR / Now Assist, Splunk).
B. AI-Driven Cyber Defense Engineering
Build and operationalize AI-augmented detection, triage, and response capabilities — including LLM-assisted alert enrichment, autonomous incident summarization, and AI-driven threat hunting. Engineer agentic SOC workflows that integrate ServiceNow AI Agents, NVIDIA NIM, OpenAI / Anthropic models, and custom ML models with SIEM / SOAR / XDR platforms. Develop detections for AI-specific TTPs: prompt injection, jailbreak, model extraction, training data poisoning, agent hijacking, MCP server tampering, and rogue agent behavior. Build behavioral baselines and anomaly detection for AI agent activity, API call patterns, and inter-agent communications. Design and deploy AI-specific deception (decoy MCP servers, poisoned data traps, decoy LLM-accessible resources).
C. Threat Defense Against Frontier AI Attacks
Lead red-team and adversarial testing of AI systems — prompt injection, jailbreaks, model extraction, membership inference, training data extraction, and adversarial examples. Defend against AI-generated polymorphic malware, deepfake vishing / social engineering, AI-orchestrated multi-stage attacks, and autonomous AI worms. Build defenses against AI-driven vulnerability discovery — including reachability / exploitability validation, compensating controls frameworks, and AI-speed patching workflows. Develop containment playbooks for rogue AI agents, compromised LLM integrations, and AI-driven cascading failures. Operate