AI Systems Engineer: Secure Execution & Trust Fabric

EY

St. Louis (MO)

Hybrid

USD 107,000 - 177,000

Full time

34 hours ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Hybrid work model
Healthcare and pension benefits
Generous paid time off

Job summary

EY is seeking AI Systems Engineers to own the security fabric for its AI-native platform, spanning identity, secrets, attestation and PKI across cloud, on-prem, edge, and air-gapped environments.

You will drive workload identity, cryptographic lifecycle, and attestation policies, partnering with security and platform teams to ensure auditable, compliant workloads in regulated industries.

Qualifications

  • Bachelor’s or Master’s degree in Computer Science, Security, or related field, or equivalent experience.
  • 8+ years in security engineering, identity/PKI, or trust infrastructure with hands-on ownership.
  • Hands-on expertise with workload identity (SPIRE/SPIFFE), IAM (Keycloak/Entra ID), and secrets management (OpenBao/Vault).
  • Strong grounding in PKI, X.509 lifecycle, key management, and transit encryption.
  • Experience with confidential compute and hardware attestation (TDX/SEV-SNP/SGX/NVIDIA CC) and secure boot (Intel TXT).
  • Experience delivering identity and secrets across multi-tenant, multi-environment platforms.
  • Proven track record operating under compliance with audit-grade evidence.
  • Ability to define clean ownership boundaries with platform, data, and runtime teams.

Responsibilities

  • Own workload identity and secrets management across environments (SPIRE/ODIS, IAM, Secrets store).
  • Build confidential compute environments to keep workloads isolated, attestable, and audit-ready.
  • Establish a platform-wide identity model for verifiable identities across telemetry and policy enforcement.
  • Own the cryptographic lifecycle: certificates, keys, and roots with zero manual secrets.
  • Enforce attestation policy for nodes, enclaves, and workloads with boot and runtime proofs.
  • Partner with Enterprise Security / Cloud Platform / SRE for audit readiness in regulated contexts.

Skills

Workload identity
Secrets management
PKI
Cryptographic lifecycle
Confidential compute
Trustworthy hardware roots
Auditability
Cross-environment security

Education

Bachelor’s or Master’s in CS/Security/related field

Tools

SPIRE/SPIFFE
Keycloak/Entra ID
OpenBao
cert-manager
DOCA/TDX/SEV-SNP

Job description

EY is seeking AI Systems Engineers to own the security fabric for its AI-native platform, spanning identity, secrets, attestation and PKI across cloud, on-prem, edge, and air-gapped environments.

You will drive workload identity, cryptographic lifecycle, and attestation policies, partnering with security and platform teams to ensure auditable, compliant workloads in regulated industries.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

AI Systems Engineer: Secure Execution & Identity Trust
AI Systems Engineer: Secure Execution & Identity Trust

EY • Southfield (MI)

Hybrid
USD 107,000 - 177,000
Hybrid work model
Medical and dental coverage
Pension and 401(k)
+2
AI Systems Engineer: Secure Execution & Identity Trust
AI Systems Engineer: Secure Execution & Identity Trust

EY • Austin (TX)

Hybrid
USD 107,000 - 177,000
Hybrid work model
Flexible vacation policy
Competitive compensation
AI Systems Engineer: Secure Execution & Trust
AI Systems Engineer: Secure Execution & Trust

EY • Jacksonville (FL)

Hybrid
USD 107,000 - 177,000
Hybrid work model
Medical and dental coverage
401(k) / pension and generous PTO
AI Trust & Secure Execution Systems Engineer
AI Trust & Secure Execution Systems Engineer

EY • Cincinnati (OH)

On-site
USD 107,000 - 177,000
Hybrid/remote work possible
Total rewards package
Paid time off
AI Systems Security & Trust Engineer
AI Systems Security & Trust Engineer

EY • Richmond (VA)

Hybrid
USD 107,000 - 177,000
Hybrid work model
Salary and benefits
Paid time off
+1
AI Security Engineer: Trusted Execution & Identity
AI Security Engineer: Trusted Execution & Identity

EY • Louisville (KY)

Hybrid
USD 107,000 - 177,000
Hybrid work model
Medical and dental coverage
Pension and 401(k) plans
+1
Senior AI Security Systems Engineer: Trusted Execution
Senior AI Security Systems Engineer: Trusted Execution

EY • Huntsville (AL)

On-site
USD 107,000 - 177,000
Medical benefits
Dental coverage
401(k) plan
+1
Senior AI Trust & Secure Execution Engineer
Senior AI Trust & Secure Execution Engineer

EY • Kansas City (MO)

Hybrid
USD 107,000 - 177,000
Hybrid work model
Total Rewards package (medical, dental
401(k) and paid time off
Senior AI Security & Trust Engineer - Secure Execution
Senior AI Security & Trust Engineer - Secure Execution

EY • Seattle (WA)

Hybrid
USD 107,000 - 177,000
Hybrid work model
Total rewards package
Paid time off
AI Systems Engineer: Secure Identity & Attestation
AI Systems Engineer: Secure Identity & Attestation

EY • Columbus (OH)

Hybrid
USD 107,000 - 177,000
Hybrid work model
Competitive compensation
401(k) and pension
+2