AI Security Engineer: Trusted Execution & Identity

EY

Louisville (KY)

Hybrid

USD 107,000 - 177,000

Full time

36 hours ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Hybrid work model
Medical and dental coverage
Pension and 401(k) plans
Paid time off

Job summary

EY seeks AI Systems Engineers to own the security and trust fabric of EY's AI-native platform, ensuring identity-bound workloads, protected secrets, trusted nodes, and attestable deployments across cloud, on-prem, edge, and air-gapped environments.

You will drive platform-wide identity models, cryptographic lifecycle, and attestation policies while collaborating with Enterprise Security, Cloud Platform, and SRE for audit readiness in regulated contexts.

Qualifications

  • Bachelor’s or Master’s degree in Computer Science, Security, or related field, or equivalent experience.
  • 8+ years in security engineering, identity/PKI, or trust infrastructure, with hands-on production ownership.
  • Hands-on expertise with workload identity (SPIRE/SPIFFE), IAM (Keycloak/Entra ID), and secrets management (OpenBao/Vault).
  • Strong grounding in PKI, X.509 certificate lifecycle (cert-manager), key management, and transit encryption.
  • Experience with confidential compute and hardware attestation (TDX, SEV-SNP, SGX, NVIDIA CC) and secure boot (Intel TXT).
  • Experience delivering identity and secrets across multi-tenant, multi-environment (cloud/on-prem/edge/air-gapped) platforms.
  • Proven track record operating under compliance, security, or regulatory constraints with audit-grade evidence requirements.
  • Ability to define clean ownership boundaries and consumption contracts with platform, data, and runtime teams.

Responsibilities

  • Own workload identity and secrets management: SPIRE/ODIS, Keycloak/Entra ID (IAM), OpenBao (secrets store), cert-manager (X.509 lifecycle).
  • Build confidential compute environments: TEE (TDX/SEV-SNP/SGX/TrustZone/CCA/NVIDIA CC), Intel TXT boot security, secure DPU architecture (DOCA).
  • Establish the platform-wide identity model so every workload, agent, and service carries a verifiable identity.
  • Own the cryptographic lifecycle: issuance, rotation, revocation, and expiry of certificates, keys, and roots.
  • Enforce attestation policy: which nodes, enclaves, and workloads are trusted, and how evidence is captured for audit.
  • Partner on a dotted-line basis with Enterprise Security / Cloud Platform / SRE for audit readiness in regulated contexts.

Skills

Workload identity
Secrets management
PKI & X.509
Confidential compute
Attestation

Education

Bachelor’s or Master’s in CS/Security

Job description

EY seeks AI Systems Engineers to own the security and trust fabric of EY's AI-native platform, ensuring identity-bound workloads, protected secrets, trusted nodes, and attestable deployments across cloud, on-prem, edge, and air-gapped environments.

You will drive platform-wide identity models, cryptographic lifecycle, and attestation policies while collaborating with Enterprise Security, Cloud Platform, and SRE for audit readiness in regulated contexts.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

AI Security & Identity Systems Engineer
AI Security & Identity Systems Engineer

EY • Dallas (TX)

Hybrid
USD 107,000 - 177,000
Medical and dental coverage
401(k) and pension plan
Paid time off and holidays
AI Systems Engineer: Secure Execution & Identity Trust
AI Systems Engineer: Secure Execution & Identity Trust

EY • Austin (TX)

Hybrid
USD 107,000 - 177,000
Hybrid work model
Flexible vacation policy
Competitive compensation
AI Systems Engineer: Secure Execution & Identity Trust
AI Systems Engineer: Secure Execution & Identity Trust

EY • Southfield (MI)

Hybrid
USD 107,000 - 177,000
Hybrid work model
Medical and dental coverage
Pension and 401(k)
+2
AI Systems Security & Trust Engineer
AI Systems Security & Trust Engineer

EY • Richmond (VA)

Hybrid
USD 107,000 - 177,000
Hybrid work model
Salary and benefits
Paid time off
+1
Senior AI Security Systems Engineer: Trusted Execution
Senior AI Security Systems Engineer: Trusted Execution

EY • Huntsville (AL)

On-site
USD 107,000 - 177,000
Medical benefits
Dental coverage
401(k) plan
+1
AI Security Engineer: Trusted Execution for Regulated AI
AI Security Engineer: Trusted Execution for Regulated AI

EY • Tallahassee (FL)

Hybrid
USD 107,000 - 177,000
Hybrid work model
Healthcare and 401(k)
Paid time off
Senior AI Security Systems Engineer — Trusted Execution
Senior AI Security Systems Engineer — Trusted Execution

EY • New Brunswick (NJ)

Hybrid
USD 107,000 - 177,000
Hybrid work model
Total Rewards package
Flexible vacation policy
AI Security & Trust Platform Engineer
AI Security & Trust Platform Engineer

EY • Secaucus (NJ)

Hybrid
USD 107,000 - 177,000
Hybrid work model
Total Rewards package including health
Senior AI Trust & Secure Execution Engineer
Senior AI Trust & Secure Execution Engineer

EY • Kansas City (MO)

Hybrid
USD 107,000 - 177,000
Hybrid work model
Total Rewards package (medical, dental
401(k) and paid time off
AI Systems Security Engineer - Trust & Identity
AI Systems Security Engineer - Trust & Identity

EY • Miami (FL)

Hybrid
USD 107,000 - 177,000
Hybrid work model
Medical and dental coverage
Pension and 401(k) plans
+2