AI Systems Engineer: Secure Execution & Trust

EY

McLean (VA)

Hybrid

USD 107,000 - 177,000

Full time

18 hours ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Hybrid work model
Total rewards package (medical/dental,
Flexible vacation policy

Job summary

EY is seeking an AI Systems Engineer to own the security and trust fabric of EY's AI-native platform, spanning identity, secrets, attestation, and cryptographic lifecycle across cloud, on-prem, edge, and air-gapped environments.

You will own workload identity, manage confidential compute, and enforce attestation while partnering with security, platform, and SRE teams to ensure audit readiness in regulated client contexts. This is a hybrid, nationwide US role.

Qualifications

  • Bachelor’s or Master’s degree in Computer Science, Security, or related field, or equivalent experience.
  • 8+ years in security engineering, identity/PKI, or trust infrastructure with hands-on production ownership.
  • Hands-on expertise with workload identity (SPIRE/SPIFFE), IAM (Keycloak/Entra ID), and secrets management (OpenBao/Vault).
  • Strong grounding in PKI, X.509 certificate lifecycle (cert-manager), key management, and transit encryption.
  • Experience with confidential compute and hardware attestation (TDX, SEV-SNP, SGX, NVIDIA CC, or equivalents) and secure boot (Intel TXT).
  • Experience delivering identity and secrets across multi-tenant, multi-environment platforms.
  • Proven track record under compliance/audit constraints with evidence requirements.
  • Ability to define ownership boundaries and consumption contracts with platform, data, and runtime teams.

Responsibilities

  • Own workload identity and secrets management across SPIRE, ODIS, IAM, OpenBao, and cert-manager in multi-tenant environments.
  • Build confidential compute environments with TEE, hardware attestation, and secure boot.
  • Define platform-wide identity model for verifiable, propagating identity across telemetry and policy enforcement.
  • Manage cryptographic lifecycle: issuance, rotation, revocation, expiry of certificates and keys.
  • Enforce attestation policy for nodes, enclaves, and workloads; capture evidence for audit.
  • Collaborate with Enterprise Security / Cloud Platform / SRE for audits and compliance in regulated contexts.

Skills

Workload identity
PKI
Confidential compute
Attestation
Audit readiness
Communication
Regulatory compliance

Education

Bachelor’s or Master’s degree in CS/Security

Tools

SPIRE
Keycloak/Entra ID
OpenBao/Vault
cert-manager
TEE/TPM hardware attestation

Job description

EY is seeking an AI Systems Engineer to own the security and trust fabric of EY's AI-native platform, spanning identity, secrets, attestation, and cryptographic lifecycle across cloud, on-prem, edge, and air-gapped environments.

You will own workload identity, manage confidential compute, and enforce attestation while partnering with security, platform, and SRE teams to ensure audit readiness in regulated client contexts. This is a hybrid, nationwide US role.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

AI Systems Engineer: Secure Execution & Trust
AI Systems Engineer: Secure Execution & Trust

EY • Jacksonville (FL)

Hybrid
USD 107,000 - 177,000
Hybrid work model
Medical and dental coverage
401(k) / pension and generous PTO
AI Systems Engineer: Secure Execution & Identity Trust
AI Systems Engineer: Secure Execution & Identity Trust

EY • Southfield (MI)

Hybrid
USD 107,000 - 177,000
Hybrid work model
Medical and dental coverage
Pension and 401(k)
+2
AI Systems Engineer: Secure Execution & Identity Trust
AI Systems Engineer: Secure Execution & Identity Trust

EY • Austin (TX)

Hybrid
USD 107,000 - 177,000
Hybrid work model
Flexible vacation policy
Competitive compensation
AI Systems Engineer – Secure Execution & Trust
AI Systems Engineer – Secure Execution & Trust

EY • Birmingham (AL)

Hybrid
USD 107,000 - 177,000
Medical and dental coverage
Pension and 401(k) plans
Paid time off
AI Systems Security & Trust Engineer
AI Systems Security & Trust Engineer

EY • Richmond (VA)

Hybrid
USD 107,000 - 177,000
Hybrid work model
Salary and benefits
Paid time off
+1
AI Trust & Secure Execution Engineer
AI Trust & Secure Execution Engineer

EY • Phoenix (AZ)

Hybrid
USD 107,000 - 177,000
Hybrid work model
Medical & dental coverage
Pension and 401(k)
AI Trust & Secure Execution Systems Engineer
AI Trust & Secure Execution Systems Engineer

EY • Tampa (FL)

Hybrid
USD 107,000 - 177,000
Hybrid work model
Total rewards package
Paid time off
AI Systems Engineer: Secure Execution & Trust Fabric
AI Systems Engineer: Secure Execution & Trust Fabric

EY • City of Albany (NY)

Hybrid
USD 107,000 - 177,000
AI Systems Engineer: Secure Execution & Trust Fabric
AI Systems Engineer: Secure Execution & Trust Fabric

EY • St. Louis (MO)

Hybrid
USD 107,000 - 177,000
Hybrid work model
Healthcare and pension benefits
Generous paid time off
AI Systems Engineer - Secure Execution & Trust Platform
AI Systems Engineer - Secure Execution & Trust Platform

EY • Cleveland (OH)

On-site
USD 107,000 - 177,000
Total Rewards package
Flexible vacation policy