AI Security & Trust Platform Engineer

EY

Secaucus (NJ)

Hybrid

USD 107,000 - 177,000

Full time

13 days ago
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Hybrid work model
Total Rewards package including health

Job summary

EY is seeking AI Systems Engineers to own the security and trust fabric of EY’s AI-native platform, spanning identity, secrets, cryptography, and attestation across cloud, on‑prem, edge, and air‑gapped environments.

You will implement workload identity, manage cryptographic lifecycles, enforce attestation policies, and collaborate with Enterprise Security and SRE to ensure auditability in regulated client contexts.

EY offers hybrid work, a strong Total Rewards package, and ongoing development.

Qualifications

  • Bachelor’s or Master’s degree in Computer Science, Security, or related technical field, or equivalent experience.
  • 8+ years in security engineering, identity/PKI, or trust infrastructure with hands‑on production ownership.
  • Deep hands‑on expertise with workload identity (SPIRE/SPIFFE), IAM (Keycloak/Entra ID), and secrets management (OpenBao/Vault).
  • Strong grounding in PKI, X.509 certificate lifecycle (cert‑manager), key management, and transit encryption.
  • Working experience with confidential compute and hardware attestation (TDX, SEV‑SNP, SGX, NVIDIA CC, or equivalents) and secure boot (Intel TXT).
  • Experience delivering identity and secrets consistently across multi‑tenant, multi‑environment (cloud/on‑prem/edge/air‑gapped) platforms.
  • Proven track record operating under compliance, security, or regulatory constraints with audit‑grade evidence requirements.
  • Ability to define clean ownership boundaries and consumption contracts with platform, data, and runtime teams.

Responsibilities

  • Own workload identity and secrets management: SPIRE/ODIS, Keycloak/Entra ID (IAM), OpenBao (secrets store), cert‑manager (X.509 lifecycle), PKI issuers/roots, and transit encryption across every environment and tenant.
  • Build confidential compute environments: TEE (TDX/SEV‑SNP/SGX/TrustZone/CCA/NVIDIA CC), Intel TXT boot security, and secure DPU architecture (DOCA), so environments are isolated, attestable, and audit-ready.
  • Establish the platform‑wide identity model so every workload, agent, and service carries a verifiable, propagated identity through telemetry, cost attribution, and policy enforcement end‑to‑end.
  • Own the cryptographic lifecycle: issuance, rotation, revocation, and expiry of certificates, keys, and roots, with zero manual secrets and no long‑lived credential sprawl across tenants.
  • Enforce attestation policy: which nodes, enclaves, and workloads are trusted, how trust is proven at boot and runtime, and how attestation evidence is captured for audit.
  • Partner on a dotted‑line basis with Enterprise Security / Cloud Platform / SRE to ensure independent review, alignment to enterprise trust standards, and audit readiness in regulated client contexts.

Skills

Workload identity & secrets mgmt
PKI & crypto lifecycle
Confidential compute & TEEs
Attestation & remote attestation
Multi‑env architectures (cloud/on‑prem

Education

Bachelor’s or Master’s in CS/Security or related field

Tools

SPIRE/SPIFFE
Keycloak/Entra ID
OpenBao
cert-manager
X.509 lifecycle

Job description

EY is seeking AI Systems Engineers to own the security and trust fabric of EY’s AI-native platform, spanning identity, secrets, cryptography, and attestation across cloud, on‑prem, edge, and air‑gapped environments.

You will implement workload identity, manage cryptographic lifecycles, enforce attestation policies, and collaborate with Enterprise Security and SRE to ensure auditability in regulated client contexts.

EY offers hybrid work, a strong Total Rewards package, and ongoing development.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

AI Systems Security & Trust Engineer
AI Systems Security & Trust Engineer

EY • Richmond (VA)

Hybrid
USD 107,000 - 177,000
Hybrid work model
Salary and benefits
Paid time off
+1
AI Security Systems Engineer: Trust & Attestation
AI Security Systems Engineer: Trust & Attestation

EY • Woodbridge Township (NJ)

Hybrid
USD 107,000 - 177,000
Hybrid work model
Total Rewards package (health, pension
Generous leave
Senior AI Security & Trust Systems Engineer
Senior AI Security & Trust Systems Engineer

EY • Jericho (NY)

Hybrid
USD 107,000 - 177,000
Hybrid work model
Total Rewards package with medical and
Dental coverage
AI Security Engineer — Trust & Attestation Platform
AI Security Engineer — Trust & Attestation Platform

EY • Westlake Village (CA)

On-site
USD 128,000 - 201,000
Hybrid work model
Competitive compensation
Paid time off
AI Security & Identity Systems Engineer
AI Security & Identity Systems Engineer

EY • Dallas (TX)

Hybrid
USD 107,000 - 177,000
Medical and dental coverage
401(k) and pension plan
Paid time off and holidays
Senior AI Trust & Security Systems Engineer
Senior AI Trust & Security Systems Engineer

EY • Minneapolis (MN)

Hybrid
USD 107,000 - 177,000
Hybrid work model
Medical and dental coverage
Pension and 401(k)
+1
AI Security Engineer: Trusted Execution & Identity
AI Security Engineer: Trusted Execution & Identity

EY • Louisville (KY)

Hybrid
USD 107,000 - 177,000
Hybrid work model
Medical and dental coverage
Pension and 401(k) plans
+1
Senior AI Security & Trust Systems Engineer
Senior AI Security & Trust Systems Engineer

EY • Toledo (OH)

Hybrid
USD 107,000 - 177,000
Hybrid work model
Competitive pay and benefits
Total Rewards package
Senior AI Security & Trust Engineer
Senior AI Security & Trust Engineer

EY • Tulsa (OK)

On-site
USD 107,000 - 177,000
Hybrid/Remote flexible work options
Total Rewards package
Medical and dental coverage
+1
Senior AI Trust & Attestation Engineer
Senior AI Trust & Attestation Engineer

EY • Memphis (TN)

On-site
USD 107,000 - 177,000
Medical and dental coverage
401(k) plans
Paid time off
+1