EY-Cyber Security- Senior AI Engineer – IAM & Cybersecurity
At EY, you’ll have the chance to build a career as unique as you are, with the global scale, support, inclusive culture and technology to become the best version of you. Join us and build an exceptional experience for yourself, and a better working world for all.
About Global Delivery Services
Global Delivery Services refers to EY's worldwide network of service delivery centers. The GDS team plays an important role in EY’s strategy by ensuring effective support to EY’s growth agenda. Our journey started in 2002 with approximately 200 people. Today we stand at 80,000+ professionals in ten locations around the world, operating in Argentina, China, Hungary, India, Philippines, Poland, Sri Lanka, Mexico, Spain and the United Kingdom. Client service is focused on providing Consulting, Assurance, Tax, Strategy & Transactions, and Knowledge support to our clients around the world.
The Opportunity
EY Global Delivery Services (GDS) is seeking a Senior AI Engineer to support the design and delivery of AI‑led solutions across Identity and Access Management and Cybersecurity domains. This role will help shape how AI capabilities are applied to modern IAM challenges such as identity governance, access management, privileged access, directory services and non‑human identity security.
As a senior profile, the candidate will work closely with IAM, Cyber, cloud and business stakeholders to understand client problems, identify practical AI opportunities and convert them into working solutions, prototypes and scalable delivery assets. The focus is not only on technology implementation, but also on improving identity risk visibility, access decisioning, governance efficiency and operational effectiveness.
Your Key Responsibilities
- Design, develop and operationalize AI solutions for IAM and Cybersecurity use cases across SSO, MFA, Conditional Access, IGA, PAM, AD/Entra ID and NHI domains.
- Build hands‑on AI/ML capabilities using Python, PowerShell, LLM/SLM APIs, embeddings, RAG, LangChain, LangGraph, MCP, ADKs and AI orchestration engines.
- Develop agentic AI workflows, copilots and automation frameworks for access requests, certification campaigns, provisioning, privileged access, remediation and identity operations.
- Integrate AI solutions with SailPoint, Saviynt, CyberArk, Microsoft Entra ID, Active Directory, Azure, AWS, Microsoft Graph API, SIEM/SOAR, Splunk, Microsoft Sentinel, Microsoft Defender, CrowdStrike and XDR platforms.
- Analyze identity, access, privilege, vault, directory, activity and security logs to identify risk patterns, anomalies, access recommendations, role mining opportunities and policy gaps.
- Support AI‑driven IAM governance including risk‑based authentication, risk‑based provisioning, access reviews, compliance checks, SOD, identity lifecycle orchestration and audit‑ready reporting.
- Apply ML, classification, optimization, time‑series analysis, pattern recognition, NLP, UEBA, anomaly detection and predictive risk scoring for identity and access intelligence.
- Work on Non‑Human Identity use cases including service accounts, managed identities, service principals, enterprise applications, API‑based identities, workload identities, agent identities, token misuse and agent overreach controls.
- Contribute to PAM analytics and automation across CyberArk, Privilege Cloud, EPM, EPV, CPM, PSM, JIT/JEA, password rotation, secret lifecycle management, session monitoring and vault log analytics.
- Create dashboards and insights using Power BI, Tableau and identity analytics views to explain access risk, compliance posture, user activity trends and remediation priorities.
- Collaborate with business, cyber and IAM stakeholders to convert problem statements into working prototypes, scalable solutions and executive‑ready recommendations.
Qualifications
Required Skills
- 5+ years of hands‑on experience in AI engineering, software development, data science, automation, cybersecurity analytics or IAM technology delivery.
- Practical experience building AI applications using LLM/SLM APIs, RAG, embeddings, prompt engineering, agentic AI, AI agents, copilots and multi‑agent workflows.
- Strong programming and automation experience in Python, PowerShell, APIs, SQL basics and Microsoft Graph API; exposure to HTML, CSS and JavaScript is preferred.
- Hands‑on exposure to Azure AI, OpenAI, AWS, Python‑based AI/ML frameworks, ML models, classification, optimization, NLP, pattern recognition, time‑series analysis and anomaly detection.
- Working knowledge of IAM concepts including SSO, MFA, Conditional Access, SAML, OAuth, OIDC with PKCE, authentication, authorization, federation, certificate management and key management.
- Working knowledge of Microsoft Entra ID, Active Directory, Entra Connect, Cloud Sync, Directory Services, DNS, Global Catalog, GPO, OU, Domains/Forests, FSMO roles and Sites and Services.
- Experience or strong exposure to IGA platforms and concepts such as SailPoint, Saviynt, identity lifecycle, access reviews, certification campaigns, role mining, SOD, access risk and policy compliance.
- Experience or strong exposure to PAM concepts and tools including CyberArk, Privilege Cloud, EPM, EPV, CPM, PSM, JIT/JEA, password rotation, secrets, session monitoring and vault logs.
- Understanding of NHI and AI identity security including service accounts, managed identities, service principals, enterprise applications, API‑based identities, workload identities, agent identities and token controls.
- Experience with security monitoring or analytics platforms such as SIEM, SOAR, UEBA, Splunk, Microsoft Sentinel, Microsoft Defender, CrowdStrike, XDR and Identity Protection.
- Strong consulting mindset with the ability to communicate AI, IAM and Cybersecurity topics clearly to technical teams and leadership stakeholders.
Nice to Have
- Experience identifying AI use cases for IAM transformation, identity analytics, access recommendations, privileged access recommendations, NHI governance and automated remediation.
- Experience with data pipelines, identity and privilege analytics pipelines, model monitoring, observability, MLOps and scalable deployment of enterprise AI solutions.
- Experience with Power BI, Tableau, dashboards and data storytelling for access risk, compliance posture and identity operations.
- Exposure to SOX, GDPR, HIPAA, ISO 27001, CISSP, CISM, SailPoint, Saviynt, CyberArk, Azure AI or Google ML certifications is preferred.
- Prior experience in a consulting, professional services or large enterprise environment is a plus.
What we offer you
At EY, we’ll develop you with future‑focused skills and equip you with world‑class experiences. We’ll empower you in a flexible environment, and fuel you and your extraordinary talents in a diverse and inclusive culture of globally connected teams.
Benefits
Premium benefits, including health and wellness packages, rewards, and cutting‑edge learning opportunities that empower you to continually grow and excel in your professional and personal development.
Commitment to Diversity, Equity & Inclusion
We are an equal‑opportunity employer and are committed to Diversity, Equity & Inclusion. We persistently endeavour to embody our values, fulfil our purpose, and champion inclusiveness.
Application Process
Apply by completing our user‑friendly form with personal and professional information and providing consent to data privacy. Successful candidates advance to a competency‑based interview and, if mutual interest persists, a job offer awaits.
#J-18808-Ljbffr