AI Systems Engineer: Secure Execution & Trust Platform

EY

City of Rochester (NY)

On-site

USD 107,000 - 177,000

Full time

16 hours ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

EY is seeking AI Systems Engineers to own the security and trust fabric of EY's AI-native platform, spanning cloud, on-prem, edge, and air-gapped environments. You will manage workload identity, secrets, PKI, attestation, and cryptographic lifecycle to enable auditable, trusted AI workloads across regulated contexts.

The role interfaces with Enterprise Security, Cloud Platform, and SRE to align with enterprise trust standards and governance, while delivering verifiable identity and secure boot

Qualifications

  • Bachelor’s or Master’s degree in Computer Science, Security, or related field, or equivalent experience.
  • 8+ years in security engineering, identity/PKI, or trust infrastructure, with hands-on production ownership.
  • Hands-on expertise with workload identity (SPIRE/SPIFFE), IAM (Keycloak/Entra ID), and secrets management (OpenBao/Vault).
  • Strong grounding in PKI, X.509 certificate lifecycle (cert-manager), key management, and transit encryption.
  • Experience with confidential compute and hardware attestation (TDX, SEV-SNP, SGX, NVIDIA CC, or equivalents) and secure boot (Intel TXT).
  • Experience delivering identity and secrets across multi-tenant, multi-environment platforms.
  • Proven track record under compliance/audit constraints with evidence requirements.
  • Ability to define ownership boundaries with platform, data, and runtime teams.

Responsibilities

  • Own workload identity and secrets management across environments.
  • Build confidential compute environments to ensure isolation, attestability, and audit-readiness.
  • Define platform-wide identity model for verifiable identities across telemetry and policy enforcement.
  • Manage cryptographic lifecycle: issuance, rotation, revocation, expiry; prevent secret sprawl.
  • Enforce attestation policy for nodes, enclaves, and workloads with audit evidence.
  • Collaborate with Enterprise Security / Cloud Platform / SRE for audit readiness in regulated contexts.

Skills

Workload identity
Secrets management
PKI
Confidential compute
Hardware attestation
Audit readiness
Multi-tenant environments
Compliance & regulation

Education

Bachelor’s or Master’s degree in Computer Science, Security, or related field

Tools

SPIRE/SPIFFE
Keycloak/Entra ID
OpenBao/Vault
cert-manager
DOCA/TEE platforms
TDX/SEV-SNP/SGX/TrustZone

Job description

EY is seeking AI Systems Engineers to own the security and trust fabric of EY's AI-native platform, spanning cloud, on-prem, edge, and air-gapped environments. You will manage workload identity, secrets, PKI, attestation, and cryptographic lifecycle to enable auditable, trusted AI workloads across regulated contexts.

The role interfaces with Enterprise Security, Cloud Platform, and SRE to align with enterprise trust standards and governance, while delivering verifiable identity and secure boot

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

AI Systems Engineer: Secure Execution & Trust
AI Systems Engineer: Secure Execution & Trust

EY • Philadelphia

Hybrid
USD 107,000 - 177,000
Hybrid work model
Medical and dental coverage
Pension and 401(k)
+1
AI Systems Engineer: Secure Execution & Trust
AI Systems Engineer: Secure Execution & Trust

EY • Irvine (CA)

Hybrid
USD 128,000 - 201,000
Hybrid work model
Competitive compensation
Paid time off
AI Systems Engineer: Secure Execution & Trust
AI Systems Engineer: Secure Execution & Trust

EY • Jacksonville (FL)

Hybrid
USD 107,000 - 177,000
Hybrid work model
Medical and dental coverage
401(k) / pension and generous PTO
AI Systems Engineer: Secure Execution & Trust
AI Systems Engineer: Secure Execution & Trust

EY • McLean (VA)

Hybrid
USD 107,000 - 177,000
Hybrid work model
Total rewards package (medical/dental,
Flexible vacation policy
AI Systems Engineer: Secure Execution & Identity Trust
AI Systems Engineer: Secure Execution & Identity Trust

EY • Austin (TX)

Hybrid
USD 107,000 - 177,000
Hybrid work model
Flexible vacation policy
Competitive compensation
AI Systems Engineer – Secure Execution & Trust
AI Systems Engineer – Secure Execution & Trust

EY • Birmingham (AL)

Hybrid
USD 107,000 - 177,000
Medical and dental coverage
Pension and 401(k) plans
Paid time off
AI Systems Engineer: Secure Execution & Identity Trust
AI Systems Engineer: Secure Execution & Identity Trust

EY • Southfield (MI)

Hybrid
USD 107,000 - 177,000
Hybrid work model
Medical and dental coverage
Pension and 401(k)
+2
AI Systems Engineer: Secure Execution & Trust Fabric
AI Systems Engineer: Secure Execution & Trust Fabric

EY • City of Albany (NY)

Hybrid
USD 107,000 - 177,000
AI Systems Security & Trust Engineer
AI Systems Security & Trust Engineer

EY • Stamford (CT)

On-site
USD 107,000 - 177,000
Hybrid work model
Medical and dental coverage
Pension and 401(k)
+1
AI Systems Security & Trust Engineer
AI Systems Security & Trust Engineer

EY • Richmond (VA)

Hybrid
USD 107,000 - 177,000
Hybrid work model
Salary and benefits
Paid time off
+1