Ernst & Young

Cyber - AI Security - Senior - Consulting

Ernst & Young$125K — $209K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's or graduate degree in Cybersecurity, Computer Science, Information Systems, Engineering, or a related field.
  • 3-5 years of relevant experience, including 1-2 years in AI or ML security.
  • Experience in AI security assessments, AI-SPM, or AI model risk evaluations.
  • Familiarity with AI security frameworks and guidance like NIST AI RMF and OWASP for LLMs.
  • Strong working knowledge of foundational cybersecurity frameworks such as NIST CSF and ISO 27001.

Responsibilities

  • Conduct AI security assessments and evaluate AI/ML pipelines.
  • Identify vulnerabilities in AI systems and develop remediation strategies.
  • Architect and implement AI Security Posture Management solutions.
  • Create governance frameworks and policies for AI aligned with regulatory requirements.
  • Develop technical architecture documentation and client presentations.

Benefits

  • Professional growth and personal fulfillment opportunities.
  • Inclusive workplace culture.
  • Medical and dental coverage.
  • Pension and 401(k) plans.
  • Wide range of paid time off options.
Full Job Description
Location: Anywhere in Country

The Opportunity

Artificial Intelligence (AI) is rapidly transforming how organizations operate, and with that transformation comes an entirely new frontier of security, governance, and risk management challenges. Organizations are grappling with securing AI pipelines, managing model-level risks, operationalizing AI governance programs, and navigating an evolving regulatory landscape specific to AI technologies. As a Senior Consultant within EY's Cyber practice focused on AI Security, you will work with clients to assess AI risk postures, architect AI security controls, and develop governance frameworks that enable organizations to adopt and scale AI responsibly and securely. This role offers the opportunity to combine hands-on technical implementation work with strategic advisory and architecture engagements across diverse industries.

Your Key Responsibilities

As a Senior Consultant in AI Security, you will play an active and technically engaged role in delivering AI security, AI Security Posture Management (AI-SPM), and AI governance engagements while collaborating closely with clients and EY engagement teams. You will conduct AI security assessments, evaluate AI/ML pipelines and model infrastructure, identify vulnerabilities inherent to AI systems, and develop practical, prioritized remediation strategies. You will architect and support the implementation of AI-SPM solutions, configure AI security tooling-including platforms and harnesses-and help clients operationalize continuous monitoring and governance controls across their AI workloads.

In addition, as a Senior Consultant, you will develop AI governance frameworks, policies, and standards aligned to emerging regulatory requirements and industry guidance. You will assist clients in designing AI risk management programs, performing AI model risk assessments, and building AI security roadmaps that balance innovation with responsible AI principles. You will prepare client deliverables, technical architecture documentation, and executive-level presentations that communicate complex AI security concepts to both technical and non-technical audiences. You will collaborate with multidisciplinary teams to deliver high-quality work products, support project planning and management activities, mentor junior team members, and contribute to business development initiatives, thought leadership, and practice-building efforts within EY's growing AI security capability.

Skills and Attributes for Success
  • Strong understanding of AI/ML systems, architectures, and deployment patterns, including large language models (LLMs), generative AI, and MLOps pipelines.
  • Hands-on experience with AI Security Posture Management (AI-SPM) tools, platforms, and methodologies.
  • Ability to identify and assess security risks specific to AI systems, including prompt injection, model poisoning, data exfiltration, supply chain vulnerabilities, and adversarial attacks.
  • Experience configuring and operationalizing AI security and DevSecOps tooling, including platforms and harnesses, to enforce security controls within AI development and deployment pipelines.
  • Knowledge of AI governance frameworks, responsible AI principles, and emerging AI-specific regulatory requirements.
  • Strong critical thinking, analytical, and problem-solving skills applied to complex AI security and risk challenges.
  • Ability to communicate technical AI security concepts effectively to both engineering teams and executive stakeholders.
  • Experience developing technical architecture documentation, executive presentations, and client-facing deliverables.
  • Strong verbal and written communication skills.
  • Ability to manage competing priorities in a fast-paced consulting environment.
  • Strong attention to detail and commitment to high-quality client service.
  • Ability to build relationships and collaborate effectively across multidisciplinary teams and client organizations.
  • Demonstrated initiative, adaptability, and a commitment to staying current with the rapidly evolving AI security landscape.


To Qualify for the Role, You Must Have
  • A bachelor's degree in Cybersecurity, Computer Science, Information Systems, Engineering, or a related field, and approximately 3-5 years of relevant experience, including at least 1-2 years in AI or machine learning security; or a graduate degree and 2-4 years of relevant experience.
  • Experience in one or more of the following areas:
    • AI security assessments, AI-SPM, or AI model risk evaluations
    • AI/ML pipeline security, model security, and MLOps security practices
    • AI governance, responsible AI policy development, and AI risk management frameworks
    • DevSecOps and CI/CD security, including hands-on experience with platforms and harnesses
    • Cloud security with specific experience securing AI workloads on platforms such as AWS, Azure, or GCP
    • AI regulatory compliance and emerging AI-specific standards and guidance
    • Cybersecurity architecture, risk management, and security controls design
  • Familiarity with AI security frameworks and guidance, including NIST AI RMF, OWASP Top 10 for LLMs, and MITRE ATLAS.
  • Working knowledge of foundational cybersecurity frameworks-including NIST CSF, NIST 800-53, and ISO 27001/27002-as applied within AI-enabled environments.
  • Strong Microsoft PowerPoint, Excel, and Word skills.
  • Willingness to travel based on client and business needs; travel estimated at 25-50%.


Ideally, You'll Also Have
  • Professional certifications in cybersecurity (e.g., CISSP, CCSP, CISM) or emerging AI/ML security credentials.
  • Hands-on experience with AI-SPM platforms, MLOps tooling, and AI security automation technologies.
  • Experience with CI/CD orchestration and integrated security tooling, including harnesses, to enforce automated security gates within AI development pipelines.
  • Knowledge of adversarial machine learning techniques, model explainability requirements, and AI supply chain risk management.
  • Exposure to AI-related regulatory developments, including the EU AI Act, NIST AI RMF, and sector-specific AI guidance applicable to financial services, healthcare, or critical infrastructure.
  • Experience facilitating client workshops, technical design sessions, and AI security architecture reviews.
  • Background in software development, data engineering, or ML engineering that informs deep technical AI security expertise.
  • Experience within a consulting, professional services, or advisory environment.


What We Look For

We are seeking professionals who are deeply curious about the intersection of artificial intelligence and cybersecurity, with the hands-on technical capabilities to assess and architect secure AI systems alongside the advisory acumen to guide organizational AI governance strategies. Successful candidates combine technical depth in AI security with strong business judgment and can engage confidently with both engineering teams and executive stakeholders. The ideal candidate is motivated by the challenge of securing transformative and rapidly evolving technologies, committed to delivering exceptional client outcomes, and eager to help shape and grow EY's Cyber practice.

What we offer you
At EY, we harness our collective strength to empower you to shape your future with confidence through professional growth, personal fulfillment and an inclusive culture. Learn more at ey.com/us/careers.

  • The salary range for this job is:
    • New York City, Boston, and Washington DC Metro Areas, Washington State, and Southern California offices - $125,800 to $209,700
    • Bay Area California offices - $131,100 to $218,500
    • All other offices locations in the US, including Sacramento - $104,800 to $192,200
  • Individual salaries within these ranges are determined through a wide variety of factors including but not limited to education, experience, knowledge, skills and geography. In addition, our Total Rewards package includes medical and dental coverage, pension and 401(k) plans, and a wide range of paid time off options.


Are you ready to shape your future with confidence? Apply today.
  • To make the most of your application experience, please limit yourself to two applications within a six-month period.
  • EY accepts applications for this position on an on-going basis.
  • For those living in California, please click here for additional information.
  • At EY, our values set the foundation for how we work and the behaviors we expect of our people. Any misrepresentation or falsification of information or lack of integrity at any point in the recruiting process may result in withdrawal of your candidacy, revocation of an offer or immediate termination of employment.

About Ernst & Young

Ernst & Young (EY) is a multinational professional services firm that provides audit, tax, consulting, and advisory services to clients in a wide range of industries. The firm was founded in 1989 through the merger of Ernst & Whinney and Arthur Young & Co., and has since grown to become one of the largest professional services firms in the world. EY is committed to building a better working world by helping its clients solve their toughest challenges, and by creating a positive impact on the communities it serves.
Learn more about Ernst & Young
Size
300,000 employees
Industry
Founded
1989

Similar Jobs

More Jobs at Ernst & Young

More Information Technology Jobs

Find similar Cyber - AI Security - Senior - Consulting jobs: