EY - Ernst & Young logo
EY - Ernst & Young

Ernst & Young, or EY, is a global financial services company that provides a host of assurance, tax, transaction, and advisory services. A member of Ernst & Young Global Limited, E

Senior Network Security Architect

Location

United States

Posted

11 days ago

Salary

$170.6K - $390K / year

Seniority

Lead

Bachelor Degree

Job Description

Senior Network Security Architect

EY - Ernst & Young

Title: Cybersecurity Engineering - Network Security Architect - Senior Manager - Consulting - Location Open Location: Anywhere in Country The opportunity The Senior Network Security Architect is a strategic and hands‑on technical leader responsible for designing, implementing, and governing secure network architectures across the enterprise. This role ensures that network security controls align with business objectives, risk tolerance, and regulatory requirements while enabling scalability, performance, and resilience. The architect serves as the authority on network security design, providing thought leadership across on‑premises, cloud, and hybrid environments, and partnering closely with infrastructure, cloud, application, and security operations teams. Join our dynamic team as a Senior Manager in Cybersecurity Engineering, where you will play a pivotal role in developing, managing, and integrating cutting-edge cybersecurity solutions. Protect sensitive data against a myriad of threats while leading cross-departmental initiatives that align security measures with business goals and technical specifications. This is your chance to be part of a revenue-generating team that values innovation and quality in safeguarding our digital landscape. Your key responsibilities As a Senior Manager, you will be at the forefront of designing and managing security infrastructure systems, monitoring for intrusions, and ensuring data integrity. You'll collaborate across departments to meet security, business, and operational needs, leading complex project delivery with a focus on quality and risk management. Additionally, you will control budgets, establish client relations, identify sales opportunities, and manage resources for project success. Expect regular travel to meet client needs and daily interactions with external clients to foster and manage relationships. - Design and manage security infrastructure systems - Monitor and protect against intrusions and data breaches - Collaborate interdepartmentally to align security with business objectives Skills and attributes for success To thrive in this role, you must possess a deep understanding of cybersecurity and privacy concepts, coupled with the technical expertise in deploying and managing security solutions. Change management, system administration, and technical writing are part of your arsenal, along with threat hunting and vulnerability management. Your business competencies will include relationship-building, critical thinking, negotiation, and communication skills, enabling you to lead and manage teams effectively. - Deep technical experience in Zero Trust and Network security - Develop and maintain enterprise network security architecture encompassing LAN, WAN, cloud, data center, edge, and remote access environments - Design secure solutions using zero trust principles, defense‑in‑depth, and least privilege access - Define standards for firewalls, segmentation, VPNs, secure routing, IDS/IPS, DDoS protection, NAC, and secure network services - Review and approve network and security designs for new initiatives and changes - Expertise in broad cybersecurity concepts - Proficiency in change management and organizational impact - Strong skills in technical writing and people management - Exceptional relationship-building and critical thinking abilities - Effective communication and team leadership skills To qualify for the role, you must have - A bachelor's degree, with a master's degree preferred - A minimum of 5-7 years of relevant experience in the cybersecurity field { - Change Management skills - Expertise in Cybersecurity and Privacy Concepts, Principles, and Solutions - Experience with Digital Transformation - Script Writing/Coding abilities - Proficiency in Security Solution Deployment, Integration, Configuration, and Debugging - Experience with Cisco, Palo Alto Networks, Zscaler, Cloudflare, Netskope Ideally, you’ll also have - Knowledge of the complexity of deploying technology to branch-connected networks - Cloud network security expertise (AWS, Azure, GCP) - Experience with SASE / SSE platforms - Automation and Infrastructure‑as‑Code exposure (e.g., Terraform, ARM, CloudFormation) - Security architecture certifications such as: - CISSP - CCSP - CCIE Security - GIAC certifications - Experience in regulated industries or large global enterprises - Strong Business Skills including Building and Managing Relationships, Communicating with Impact, Complex Problem-Solving, Critical Thinking, and Negotiation and Influencing What we look for We seek top performers who demonstrate a keen understanding of the importance of cybersecurity in today's digital world. Candidates should exhibit a proactive approach to problem-solving, an eagerness to learn and adapt to new technologies, and the ability to lead with integrity and inspire trust among team members and clients. and risk management. What we offer you At EY, we’ll develop you with future-focused skills and equip you with world-class experiences. We’ll empower you in a flexible environment, and fuel you and your extraordinary talents in a diverse and inclusive culture of globally connected teams. Learn more. - We offer a comprehensive compensation and benefits package where you’ll be rewarded based on your performance and recognized for the value you bring to the business. The base salary range for this job in all geographic locations in the US is $170,600 to $390,000. The base salary range for New York City Metro Area, Washington State and California (excluding Sacramento) is $204,800 to $443,200. Individual salaries within those ranges are determined through a wide variety of factors including but not limited to education, experience, knowledge, skills and geography. In addition, our Total Rewards package includes medical and dental coverage, pension and 401(k) plans, and a wide range of paid time off options. - Join us in our team-led and leader-enabled hybrid model. Our expectation is for most people in external, client serving roles to work together in person 40-60% of the time over the course of an engagement, project or year. - Under our flexible vacation policy, you’ll decide how much vacation time you need based on your own personal circumstances. You’ll also be granted time off for designated EY Paid Holidays, Winter/Summer breaks, Personal/Family Care, and other leaves of absence when needed to support your physical, financial, and emotional well-being.

Related Categories

Related Job Pages

More Security Engineer Jobs

Stefanini LATAM logo

Ingeniero de Seguridad

Stefanini LATAM

Co-creating solutions for a better future

Full TimeRemoteTeam 10,001+Since 1987H1B No Sponsor

• Implementar controles de seguridad, respuesta a incidentes y revisión de cumplimiento normativo. • Desarrollar funcionalidades complejas y ejecutar proyectos de mayor envergadura. • Optimizar tiempo, mantener la productividad y asumir nuevas asignaciones.

Mexico
Excellus BlueCross BlueShield logo

Principal AI Security Engineer

Excellus BlueCross BlueShield

UPSTARS – продуктова IT-компанія, з якою злітають і люди, і бренди. Наш основний фокус – технологічні рішення та B2B-послуги для міжнародних клієнтів.

Full TimeRemoteTeam 2-10H1B No Sponsor

Role Description The Principal Artificial Intelligence (AI) Security Engineer serves as the technical lead for securing machine learning (ML), generative artificial intelligence (GenAI), and agentic systems in production, with emphasis on healthcare and other regulated environments. This role creates security architecture, threat modeling, control design, and detection strategy across the AI lifecycle. - Data ingestion - Feature engineering - Training and fine-tuning - Evaluation - Model serving - Retrieval-augmented generation (RAG) pipelines - Agent frameworks - Application programming interface (API) mediation - Post-deployment monitoring The Principal AI Security Engineer leads and partners throughout the organization to build enforceable guardrails for: - Protected health information and electronic protected health information handling - Identity and access control - Secrets isolation - Model and dataset provenance - Output safety - Evidence collection for audits and investigations Qualifications - Ten (10) years of hands-on security engineering experience spanning application security, cloud security, security architecture, detection and response, platform security, or infrastructure security. - Bachelor's degree in computer science, information technology, or relevant field. In lieu of degree, six (6) cumulative years of related experience required. - Demonstrated experience securing production AI/ML systems, including large language model (LLM) applications, model serving stacks, retrieval-augmented generation architecture, or agent frameworks. - CISA, CISM, CCSP, HCISPP, GIAC and or CISSP certifications preferred. - Demonstrated advanced expertise in AI threat modeling and adversarial testing. - Strong implementation knowledge of secure software development lifecycle (SDLC), continuous integration/continuous delivery (CI/CD) security, and cloud-native telemetry pipelines. - Experience designing or reviewing controls for secure machine learning operations (MLOps). - Experience instrumenting detections and response workflows using logs, traces, metrics. - Advanced working knowledge of RAG security and evaluation harnesses for safety, security, and regulated-data compliance. - Prior experience in healthcare, payer, provider or similarly regulated environments with PHI/ePHI safeguards preferred. - Advanced ability to write engineering standards, design docs, threat models, and control requirements. - Hands-on familiarity with model gateways and AI observability tooling. - Working knowledge of static/dynamic application security testing and dependency-risk management. - Experience with AI red teaming platforms and automated release gates for model or prompt changes. - Familiarity with Sarbanes Oxley, HIPAA, OCR, AI RFM, HCFA, PCI/DSS, NIST and other regulations impacting security preferred. Requirements - Ability to work prolonged periods sitting and/or standing at a workstation and working on a computer. - Ability to travel across the Health Plan service region for meetings and/or trainings as needed. - Ability to work in a home office for continuous periods of time for business continuity. Benefits - Participation in group health and/or dental insurance - Retirement plan - Wellness program - Paid time away from work - Paid holidays Compensation Range(s) Minimum: $123,304 - Maximum: $221,948 The salary range indicated in this posting represents the minimum and maximum of the salary range for this position. Actual salary will vary depending on factors including, but not limited to, budget available, prior experience, knowledge, skill and education as they relate to the position’s minimum qualifications, in addition to internal equity. The posted salary range reflects just one component of our total rewards package. Please note: There may be opportunity for remote work within all jobs posted by the Excellus Talent Acquisition team. This decision is made on a case-by-case basis. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran.

United States
$123.3K - $221.9K / year
CrowdStrike logo

Detection Focused Senior Cloud Security Consultant

CrowdStrike

CrowdStrike has redefined security with the world’s most advanced cloud-native platform that protects and enables the people, processes and technologies that drive modern enterprise. Tested and proven, the world's largest organizations trust CrowdStrike to stop breaches with unparalleled protection against the most sophisticated cyberattacks. The CrowdStrike culture has been built upon our Core Values since the day we began. We are Fanatical About the Customer, Relentlessly Focused on Innovation and believe that our Limitless Passion drives Unlimited Potential for every CrowdStriker. As a purpose-built remote-first company, we believe cultivating a connected culture for every employee, no matter where they are in the world, is a key ingredient in building a high-performing, diverse team. We don’t have a mission statement. We’re on a mission—to stop breaches. Ready to join a mission that matters?

Full TimeRemoteTeam 5,001-10,000Since 2011H1B Sponsor

Role Description CrowdStrike is looking for a technically strong, self-directed cloud security professional to join our Professional Services team in the JAPAC region. This is a hands-on role for someone with genuine curiosity about cloud attack techniques and a drive to build the detection and defensive capability to counter them. You'll work with complex, high-profile organisations across the region, helping them understand where they're exposed, sharpen their detection capabilities, and close the gaps that adversaries look for. The work demands both technical depth and client credibility, so you'll need to be effective at both. What You'll Do - Conduct cloud security assessments across a range of environments, focusing primarily on AWS and Azure: reviewing configurations, identity architectures, network exposure, and attack paths to surface the risks that actually matter. - Design and build detection logic and alerting for cloud control plane activity, identity-based threats, and misconfiguration-driven exposure across cloud-native and third-party security platforms. - Write automation to speed up assessment work, extract and correlate data across large datasets, and turn repeatable analysis into something the team can use again. - Partner with our Red Team during Purple Team exercises: testing customer detection and response capabilities and translating the gaps into concrete recommendations. - Collaborate with internal delivery teams to help turn assessment findings into detection content that's ready to deploy. - Produce clear, high-quality reports and presentations for technical and executive audiences. - Run client engagements from scoping through delivery, keeping stakeholders well-informed throughout. - Help push our service offerings forward through methodology development, tooling contributions, and public-facing thought leadership. Qualifications - Strong practical experience with AWS and Azure, including identity, compute, networking, storage, serverless, and logging and monitoring services. - A solid grasp of cloud architecture patterns and where security assumptions tend to break down in practice. - GCP experience is a plus, but not a requirement. - Experience building detection content that works: writing queries, developing alerting logic, and cutting through noise in cloud-native and third-party SIEM/XDR environments. - A working knowledge of how threat actors operate in cloud environments, and the ability to translate that into detections that actually fire on the right things. - Experience tracing how misconfigurations chain together into realistic attack paths — analysis that tells a coherent story rather than producing a list of isolated findings. - Familiarity with common cloud attack patterns: privilege escalation, lateral movement, persistence, and data exfiltration. - Solid scripting ability in Python or equivalent, comfortable building tools to automate assessment tasks, work with large datasets, and extend existing frameworks. - Experience writing queries across platforms such as KQL, SPL, or cloud-native query engines. - Strong written and verbal communication in English. - Able to adapt your approach across different business cultures. - Additional language proficiency is a strong advantage, particularly Mandarin, Japanese, Hindi, or Thai. Requirements - Detection engineering experience in traditional enterprise environments: on-premises Active Directory, Windows endpoint telemetry, and classic Wintel infrastructure. - Cloud incident response experience (AWS, Azure, or M365). - Kubernetes and container security. - CI/CD pipeline security and DevSecOps practices. Benefits - Market leader in compensation and equity awards. - Comprehensive physical and mental wellness programs. - Competitive vacation and holidays for recharge. - Paid parental and adoption leaves. - Professional development opportunities for all employees regardless of level or role. - Employee Networks, geographic neighborhood groups, and volunteer opportunities to build connections. - Vibrant office culture with world class amenities. - Great Place to Work Certified™ across the globe.

Asia + 4 moreAll locations: Asia | South-eastern Asia | Australia and New Zealand | Eastern Asia | Southern Asia
Job Closed
ONE logo

Corporate Security Engineer – IAC & Automation

ONE

Helping people save and grow their money.

Full TimeRemoteTeam 201-500H1B Sponsor

• Lead the design, implementation, and optimization of our corporate security infrastructure. • Enhance security controls, align goals with business objectives, and drive automation and self-service capabilities. • Work with IaC tools like Terraform to ensure enterprise configurations are steady, change-managed, and machine-readable. • Design and deploy endpoint security measures aligned with industry standards, including vulnerability management. • Ensure a strong security posture for corporate SaaS applications by configuring vendor capabilities or building automations to meet OnePay standards. • Mature and manage data protection controls, including Data Loss Prevention (DLP) tools and secure data handling processes. • Build secure methods for sharing data with internal teams and external partners. • Collaborate with IT, Infrastructure, and Security teams to implement security measures, maintain critical corporate systems, and drive process improvement through automation. • Develop and run incident response and disaster recovery plans, including tabletop exercises.

United States
$140K - $165K / year