GDS Cyber - Frontier AI Layered Defense - Senior Manager
Job description
At EY, you’ll have the chance to build a career as unique as you are, with the global scale, support, inclusive culture and technology to become the best version of you. And we’re counting on your unique voice and perspective to help EY become even better, too. Join us and build an exceptional experience for yourself, and a better working world for all.
Job Title: EY – Frontier AI Security Lead / Layered Defence Lead – Technology Consulting – Senior Manager
About the Role:
EY is seeking a Senior Manager – Frontier AI Security Lead / Layered Defence Lead to shape, scale, and lead the firm’s capabilities for securing frontier AI systems, generative AI platforms, LLM-powered applications, and agentic or multi-agent architectures. The role will focus on enabling trusted enterprise adoption of advanced AI by designing layered defence strategies that address risks across governance, data, model, agent, application, identity, runtime, and infrastructure layers.
This leader will define AI security strategy, reference architectures, control patterns, and delivery methodologies that help clients manage emerging risks such as prompt injection, indirect prompt injection, jailbreaks, data leakage, model and RAG poisoning, excessive agency, autonomous tool misuse, system prompt exposure, AI supply chain compromise, and unsafe model or agent behaviour.
The successful candidate will serve as a trusted advisor to senior client stakeholders and internal leadership, translating frontier AI risk into actionable security programmes, scalable managed capabilities, and market-relevant offerings. The role will also contribute to go-to-market strategy, sales pursuits, solution shaping, and the growth of EY’s AI Security practice.
The ideal candidate will combine deep cybersecurity, AI, cloud, architecture, and consulting experience with the ability to lead multidisciplinary teams, influence senior stakeholders, and build differentiated capabilities for securing AI at enterprise scale.
Layered Defence Scope:
The role will establish and mature layered defence patterns across the following AI security domains: governance and policy; data, knowledge, and retrieval pipelines; model access and prompt controls; agent planning, memory, tool use, and orchestration; application, API, and integration security; identity, access, secrets, and permissioning; runtime monitoring, telemetry, detection, and response; cloud, platform, infrastructure, and AI supply chain security.
Key Responsibilities:
Strategy and Practice Leadership
- Define and drive EY’s Frontier AI Security and Layered Defence strategy across client and enterprise environments.
- Build and scale AI security offerings, delivery methods, reusable assets, accelerators, reference architectures, and control frameworks.
- Lead go-to-market development, sales pursuits, RFP responses, proposals, solution shaping, and commercial growth for AI security engagements.
- Establish a strong AI Security capability and community of practice, including talent development, enablement, knowledge sharing, and innovation priorities.
Frontier AI Security Architecture
- Architect secure AI systems across LLM applications, RAG pipelines, AI agents, multi-agent systems, model integrations, APIs, and enterprise platforms.
- Define defence-in-depth patterns across data, model, prompt, agent, application, identity, runtime, and infrastructure layers.
- Embed security into AI engineering lifecycles, including design reviews, threat modelling, secure build standards, MLOps, GenAIOps, DevSecOps, testing, deployment, and continuous monitoring.
- Advise clients on secure adoption of frontier AI capabilities, including high-risk use cases, autonomous workflows, and AI-enabled decision support.
AI Risk, Red Teaming, and Control Design
- Lead AI threat modelling and risk assessments for frontier AI use cases, including LLMs, agentic workflows, RAG systems, model providers, and third-party AI components.
- Establish AI red teaming and adversarial testing approaches covering prompt injection, jailbreaks, data exfiltration, model manipulation, tool abuse, excessive agency, and unsafe agent behaviour.
- Define and implement guardrails, policy enforcement, input and output validation, content safety controls, human-in-the-loop checkpoints, permission boundaries, and runtime response mechanisms.
- Align AI security controls to recognised industry frameworks and emerging regulatory expectations, including AI governance, privacy, cybersecurity, and responsible AI requirements.
Client Advisory and Delivery Leadership
- Lead large-scale client engagements and advise CxOs, technology leaders, cyber leaders, and risk stakeholders on AI security strategy and operating models.
- Translate complex AI security risks into board-ready narratives, practical control roadmaps, investment priorities, and measurable transformation outcomes.
- Build trusted relationships with clients, partners, ecosystem providers, and internal stakeholders to drive collaboration and business growth.
- Mentor high-performing teams and foster a culture of innovation, automation, responsible AI adoption, and continuous learning.
Technical Skills and Expertise:
- Deep expertise in AI security, cybersecurity architecture, cloud security, application security, data protection, privacy, identity, and incident response.
- Strong understanding of frontier AI systems, LLMs, multimodal models, RAG, vector databases, agentic AI, multi-agent orchestration, model context protocols, and AI-enabled automation workflows.
- Proven experience designing layered security architectures for AI systems across governance, data, model, prompt, agent, application, API, identity, runtime, and infrastructure layers.
- Practical knowledge of AI-specific threats including prompt injection, indirect prompt injection, jailbreaks, sensitive information disclosure, system prompt leakage, data and model poisoning, vector and embedding weaknesses, excessive agency, insecure tool use, model theft, and AI supply chain risks.
- Experience with AI red teaming, adversarial testing, safety and security evaluations, model/system documentation, secure RAG assessments, guardrail validation, and control effectiveness testing.
- Hands-on familiarity with Python, SQL, APIs, secure software engineering, MLOps, GenAIOps, CI/CD, observability, telemetry, logging, detection engineering, and response automation.
- Experience with cloud platforms such as Azure, AWS, and GCP, including deployment and protection of AI workloads, model endpoints, data pipelines, secrets, identities, containers, and infrastructure.
- Familiarity with AI engineering frameworks and platforms such as LangChain, LangGraph, AutoGen, semantic orchestration frameworks, vector stores, model gateways, guardrail platforms, and enterprise AI services.
- Ability to align AI security programmes with cybersecurity, technology risk, privacy, responsible AI, and compliance expectations while maintaining practical delivery focus.
- Strong consulting, executive communication, stakeholder management, and large programme leadership skills.
Skills and Attributes for Success:
- Proven leadership experience in building and scaling AI security, cybersecurity, cloud security, or emerging technology practices.
- Strategic thinker with strong commercial acumen and the ability to convert frontier AI risks into differentiated market offerings.
- Excellent communication and executive presence, with the ability to engage business, technology, cyber, risk, legal, and compliance stakeholders.
- Ability to operate in fast-moving and ambiguous environments where frontier AI risks, technologies, and regulations continue to evolve.
- Collaborative leadership style with experience working across multidisciplinary teams, geographies, vendors, and alliance ecosystems.
- Strong passion for innovation, responsible AI adoption, automation, continuous learning, and practical security outcomes.
Qualifications:
- Bachelor’s degree in Computer Science, Engineering, Cybersecurity, Information Security, Data Science, AI/ML, or a related field; advanced degree such as MBA, MS, or PhD preferred.
- Minimum 15 years of professional experience, including significant leadership experience across cybersecurity, AI, cloud, architecture, technology consulting, or digital transformation.
- Demonstrated success in AI security architecture, secure AI adoption, solution development, client advisory, and practice leadership.
- Relevant security certifications such as CISSP, CCSP, CCSK, CISM, GIAC, or cloud security certifications are highly desirable.
- AI, machine learning, data science, responsible AI, or AI governance certifications are desirable, particularly where combined with practical AI security delivery experience.
What We Offer:
- Opportunity to lead a high-growth Frontier AI Security and Layered Defence capability within a global, multidisciplinary consulting environment.
- Exposure to complex, transformative AI security programmes across industries, platforms, and emerging AI operating models.
- Supportive environment for leadership growth, coaching, innovation, thought leadership, and continuous professional development.
- Flexible work arrangements and a culture that values collaboration, inclusion, responsible innovation, and measurable client impact.
EY | Building a better working world
EY exists to build a better working world, helping to create long-term value for clients, people and society and build trust in the capital markets.
Enabled by data and technology, diverse EY teams in over 150 countries provide trust through assurance and help clients grow, transform and operate.
Working across assurance, consulting, law, strategy, tax and transactions, EY teams ask better questions to find new answers for the complex issues facing our world today.