AI Security Engineer: Trusted Execution for Regulated AI

EY

Tallahassee (FL)

Hybrid

USD 107,000 - 177,000

Full time

20 hours ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Hybrid work model
Healthcare and 401(k)
Paid time off

Job summary

EY is seeking AI Systems Engineers to own the security and trust fabric of EY's AI-native platform across cloud, on-prem, edge, and air-gapped environments. The role enforces identity, secrets, attestation, and cryptographic controls to enable auditable, trusted AI workloads.

You will collaborate with Enterprise Security, Cloud Platform, and SRE to ensure compliance with regulated client contexts, while supporting a hybrid, client-facing model and a broad total rewards package.

Qualifications

  • Bachelor's or Master's degree in Computer Science, Security, or related technical field, or equivalent experience.
  • 8+ years in security engineering, identity/PKI, or trust infrastructure, with hands-on production ownership.
  • Deep, hands-on expertise with workload identity (SPIRE/SPIFFE), IAM (Keycloak/Entra ID), and secrets management (OpenBao/Vault).
  • Strong grounding in PKI, X.509 certificate lifecycle (cert-manager), key management, and transit encryption.
  • Working experience with confidential compute and hardware attestation (TDX, SEV-SNP, SGX, NVIDIA CC, or equivalents) and secure boot (Intel TXT).
  • Experience delivering identity and secrets consistently across multi-tenant, multi-environment (cloud/on-prem/edge/air-gapped) platforms.
  • Proven track record operating under compliance, security, or regulatory constraints with audit-grade evidence requirements.
  • Ability to define clean ownership boundaries and consumption contracts with platform, data, and runtime teams.

Responsibilities

  • Own workload identity and secrets management across environments (SPIRE/ODIS, Keycloak/Entra ID, OpenBao, cert-manager).
  • Build confidential compute environments (TEE, secure boot, secure DPU architecture) for audited, isolated workloads.
  • Establish a platform-wide identity model for verifiable identities across telemetry and policy enforcement.
  • Manage the cryptographic lifecycle: issuance, rotation, revocation, expiry of certificates and keys.
  • Enforce attestation policy across nodes, enclaves, and workloads with audit-ready evidence.
  • Partner with Enterprise Security / Cloud Platform / SRE for enterprise trust alignment and audit readiness.

Skills

Workload identity
Secrets management
PKI
Cryptography

Education

Bachelor's/Master's degree

Tools

SPIRE/SPIFFE
Keycloak/Entra ID
OpenBao/Vault
cert-manager

Job description

EY is seeking AI Systems Engineers to own the security and trust fabric of EY's AI-native platform across cloud, on-prem, edge, and air-gapped environments. The role enforces identity, secrets, attestation, and cryptographic controls to enable auditable, trusted AI workloads.

You will collaborate with Enterprise Security, Cloud Platform, and SRE to ensure compliance with regulated client contexts, while supporting a hybrid, client-facing model and a broad total rewards package.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

AI Security Engineer: Trusted Execution & Identity
AI Security Engineer: Trusted Execution & Identity

EY • Louisville (KY)

Hybrid
USD 107,000 - 177,000
Hybrid work model
Medical and dental coverage
Pension and 401(k) plans
+1
Senior AI Security & Trust Engineer
Senior AI Security & Trust Engineer

EY • Tulsa (OK)

On-site
USD 107,000 - 177,000
Hybrid/Remote flexible work options
Total Rewards package
Medical and dental coverage
+1
AI Security & Identity Systems Engineer
AI Security & Identity Systems Engineer

EY • Dallas (TX)

Hybrid
USD 107,000 - 177,000
Medical and dental coverage
401(k) and pension plan
Paid time off and holidays
Senior AI Security Systems Engineer: Trusted Execution
Senior AI Security Systems Engineer: Trusted Execution

EY • Huntsville (AL)

On-site
USD 107,000 - 177,000
Medical benefits
Dental coverage
401(k) plan
+1
Senior AI Trust & Secure Execution Engineer
Senior AI Trust & Secure Execution Engineer

EY • Kansas City (MO)

Hybrid
USD 107,000 - 177,000
Hybrid work model
Total Rewards package (medical, dental
401(k) and paid time off
Senior AI Security & Trust Systems Engineer
Senior AI Security & Trust Systems Engineer

EY • Toledo (OH)

Hybrid
USD 107,000 - 177,000
Hybrid work model
Competitive pay and benefits
Total Rewards package
AI Systems Security & Trust Engineer
AI Systems Security & Trust Engineer

EY • Richmond (VA)

Hybrid
USD 107,000 - 177,000
Hybrid work model
Salary and benefits
Paid time off
+1
Senior AI Security & Trust Engineer - Secure Execution
Senior AI Security & Trust Engineer - Secure Execution

EY • Seattle (WA)

Hybrid
USD 107,000 - 177,000
Hybrid work model
Total rewards package
Paid time off
AI Systems Engineer: Secure Execution & Identity Trust
AI Systems Engineer: Secure Execution & Identity Trust

EY • Southfield (MI)

Hybrid
USD 107,000 - 177,000
Hybrid work model
Medical and dental coverage
Pension and 401(k)
+2
Senior AI Security & Trust Architect
Senior AI Security & Trust Architect

EY • Nashville (TN)

On-site
USD 107,000 - 177,000
Total rewards package
Hybrid work model
Generous PTO