At EY, we're all in to shape your future with confidence.
We'll help you succeed in a globally connected powerhouse of diverse teams and take your career wherever you want it to go. Join EY and help to build a better working world.
Today's world is fueled by vast amounts of information. Data is more valuable than ever before. Protecting data and information systems is central to doing business, and everyone in EY Information Security has a critical role to play. Join a global team of over 900 people who collaborate to support the business of EY by protecting EY and client information assets! Our Information Security professionals enable EY to work securely and deliver secure products and services, as well as detect and quickly respond to security events as they happen. Together, the efforts of our dedicated team help protect the EY brand and build client trust.
Within Information Security we blend risk strategy, digital identity, cyber defense, application security and technology solutions as we consider the entire security lifecycle. You will join a team of hardworking, security-focused individuals dedicated to supporting, protecting, and enabling the business through innovative, secure solutions that provide speed to market and business value.
The opportunity
Security Technology Services (STS), part of Information Security, enables more than 390,000 people across 150+ countries to access systems and information securely. As a member of the STS team, the Principal Architect for AI & Security will lead AI protection architecture across AI agents, agentic AI platforms, copilots, automation workflows, application development, and data products. The successful candidate will translate business and technology needs into scalable AI security architectures, define protection patterns and control requirements, lead proof-of-value efforts, guide technology selection, and ensure solutions align with EY's enterprise architecture, Zero Trust, risk, compliance, and security objectives.
Key Responsibilities
Lead AI protection architecture for AI agents, agentic AI, MCP, A2A, copilots, automation platforms, GenAI applications, and data-driven AI products.
Act as a senior architecture lead for AI protection, driving strategy, target-state architecture, and security design decisions independently.
Establish and govern application standards across GRC, risk management, business continuity, Security Certification, and cybersecurity platforms to ensure consistency, scalability, and alignment with enterprise objectives.
Define UX/UI, workflow, and integration standards across strategic platforms, ensuring consistent user experience, standardized business processes, and secure API-driven interoperability.
Define secure-by-design, Zero Trust, identity, data protection, monitoring, and guardrail controls for AI platforms and agent ecosystems.
Lead architecture reviews, threat modeling, control mapping, and risk assessments for AI-enabled solutions, workflows, applications, and data products.
Partner with EY Fabric, engineering, product, application development, data, and platform teams to embed AI protection into delivery processes.
Design and govern AI protection capabilities across Microsoft Security, Purview, Defender, Sentinel, Entra ID, Zscaler AI Guard, ZIA/ZPA, Wiz, and related enterprise security platforms.
Develop AI protection standards, reference architectures, reusable patterns, decision records, and implementation roadmaps.
Present AI protection strategy, architecture recommendations, risks, dependencies, and mitigation plans to senior leadership and governance forums.
Skills & Attributes for Success
Deep expertise in AI protection, AI security architecture, agentic AI, MCP, A2A, AI governance, and AI risk management.
Hands-on experience protecting AI agents, copilot, Foundry, Custom Agents, LLM-based applications, automation workflows, and AI-enabled business platforms.
Advanced knowledge of Microsoft Security, Entra ID, Purview, Defender, Sentinel, Zscaler AI Guard, ZIA/ZPA, Wiz, and cloud-native security capabilities.
Strong background in Zero Trust, identity security, data protection, cloud security, application security, and secure software delivery.
Experience with Azure, APIs, microservices, GitHub, DevOps, data platforms, and enterprise-scale integration architectures.
Skilled in AI threat modeling, control design, security architecture, risk assessment, compliance mapping, and remediation planning.
Proven ability to lead independently, influence senior stakeholders, and build partnerships across AI, development, security, product, data, and technology teams.
Excellent communication, executive storytelling, and architecture presentation skills with a strong consulting mindset.
To qualify for the role, you must have
Degree in Computer Science, Cybersecurity, Engineering, Artificial Intelligence, Data Technology, or equivalent work experience.
15+ years of experience in Information Technology, cybersecurity, application development, data platforms, AI platforms, or related technology domains.
7+ years of architecture experience, including solution architecture for enterprise-scale platforms and security capabilities.
5+ years of experience in AI related development including security architecture, application security, data security, cloud security, secure AI, or AI protection solution design.
Experience leading architecture strategy, proof-of-value efforts, technology evaluations, or implementation planning for complex security initiatives.
Ideally, you'll also have
Security certification such as CISSP, CISM, CCSP, or equivalent.
Architecture certification or framework knowledge such as TOGAF, SABSA, or similar.
Experience with AI governance, responsible AI, data protection, privacy, or model risk management frameworks.
Experience with Microsoft Security, Zscaler, Wiz, GitHub security, Azure AI, or enterprise AI platform protection.
What we look for
Experience developing detailed AI protection, security, application, data, cloud, and infrastructure architectures.
Working knowledge of secure software development, GitHub, DevOps, data architecture, AI security, data security, and cloud technology.
Strong understanding of AI protection patterns, secure-by-design principles, Zero Trust, CISSP domains, and common Information Security practices.
Ability to lead architecture direction, shape security strategy, and influence the speed, direction, and quality of complex initiatives.
Ability to evaluate multiple solution options and recommend a practical approach by balancing business value, security risk, complexity, scalability, and delivery impact.
Delivery-focused mindset with the ability to support speed to market while maintaining AI protection, security, compliance, and architectural quality.
Ability to think broadly across AI platforms, agents, applications, workflows, data products, and enterprise dependencies while adapting to changing priorities.
Ability to research and quickly build expertise in emerging AI protection, security, data, and automation technologies.
Ability to build trusted relationships across complex global technology landscapes and collaborate effectively with senior stakeholders at multiple levels.
Strong critical thinking skills with an analytical and systematic approach to problem solving.
Excellent written and verbal communication skills, including preparation and delivery of senior-level architecture presentations.
Sound judgment, tact, and decision-making ability.
Ability to manage ambiguity, prioritize effectively, and meet objectives in a fast-changing AI and security environment.
What we offer you
The compensation ranges below are provided in order to comply with United States pay transparency laws. Other geographies will follow their local salary guidelines, which