AI Systems Security & Trust Engineer

EY

Richmond (VA)

Hybrid

USD 107,000 - 177,000

Full time

38 hours ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Hybrid work model
Salary and benefits
Paid time off
Medical & dental

Job summary

EY is seeking AI Systems Engineers to own the security and trust fabric of EY's AI-native platform, spanning identity, secrets, cryptographic layers, and attestation across cloud, on-prem, edge, and air-gapped environments.

Responsibilities include workload identity and secrets management, confidential compute, and platform-wide identity modelling. You will coordinate with security and platform teams to ensure audit-ready governance and regulatory compliance.

Qualifications

  • Bachelor's or Master’s degree in Computer Science, Security, or related technical field, or equivalent experience.
  • 8+ years in security engineering, identity/PKI, or trust infrastructure, with hands-on production ownership.
  • Deep, hands-on expertise with workload identity (SPIRE/SPIFFE), IAM (Keycloak/Entra ID), and secrets management (OpenBao/Vault).
  • Strong grounding in PKI, X.509 certificate lifecycle (cert-manager), key management, and transit encryption.
  • Working experience with confidential compute and hardware attestation (TDX, SEV-SNP, SGX, NVIDIA CC, or equivalents) and secure boot (Intel TXT).
  • Experience delivering identity and secrets consistently across multi-tenant, multi-environment (cloud/on-prem/edge/air-gapped) platforms.
  • Proven track record operating under compliance, security, or regulatory constraints with audit-grade evidence requirements.
  • Ability to define clean ownership boundaries and consumption contracts with platform, data, and runtime teams.

Responsibilities

  • Own workload identity and secrets management across multiple environments.
  • Build confidential compute environments and secure boot capabilities to enable attestable platforms.
  • Define a unified platform-wide identity model for verifiable workload identities.
  • Oversee cryptographic lifecycle: issuance, rotation, revocation of certificates and keys.
  • Enforce attestation policy for trusted nodes and workloads with audit-ready evidence.
  • Collaborate with Enterprise Security / Cloud Platform / SRE to ensure regulatory compliance.

Skills

Workload identity
Secrets management
PKI
Cryptographic lifecycle
Confidential compute
Trusted execution environments
Hardware roots of trust
Remote attestation
Security-first mindset
Auditability
Multi-environment platforms

Education

Bachelor's or Master’s degree in Computer Science / Security / related field

Tools

SPIRE/SPIFFE
Keycloak/Entra ID
OpenBao/Vault
cert-manager
X.509 lifecycle
TDX / SEV-SNP / SGX / TrustZone
NVIDIA DOCA

Job description

EY is seeking AI Systems Engineers to own the security and trust fabric of EY's AI-native platform, spanning identity, secrets, cryptographic layers, and attestation across cloud, on-prem, edge, and air-gapped environments.

Responsibilities include workload identity and secrets management, confidential compute, and platform-wide identity modelling. You will coordinate with security and platform teams to ensure audit-ready governance and regulatory compliance.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

AI Systems Security Engineer - Trust & Identity
AI Systems Security Engineer - Trust & Identity

EY • Miami (FL)

Hybrid
USD 107,000 - 177,000
Hybrid work model
Medical and dental coverage
Pension and 401(k) plans
+2
AI Systems Engineer: Secure Execution & Identity Trust
AI Systems Engineer: Secure Execution & Identity Trust

EY • Southfield (MI)

Hybrid
USD 107,000 - 177,000
Hybrid work model
Medical and dental coverage
Pension and 401(k)
+2
AI Systems Engineer: Secure Execution & Identity Trust
AI Systems Engineer: Secure Execution & Identity Trust

EY • Austin (TX)

Hybrid
USD 107,000 - 177,000
Hybrid work model
Flexible vacation policy
Competitive compensation
AI Security & Identity Systems Engineer
AI Security & Identity Systems Engineer

EY • Dallas (TX)

Hybrid
USD 107,000 - 177,000
Medical and dental coverage
401(k) and pension plan
Paid time off and holidays
AI Security & Trust Platform Engineer
AI Security & Trust Platform Engineer

EY • Secaucus (NJ)

Hybrid
USD 107,000 - 177,000
Hybrid work model
Total Rewards package including health
Senior AI Trust & Security Systems Engineer
Senior AI Trust & Security Systems Engineer

EY • Minneapolis (MN)

Hybrid
USD 107,000 - 177,000
Hybrid work model
Medical and dental coverage
Pension and 401(k)
+1
AI Security Engineer: Trusted Execution & Identity
AI Security Engineer: Trusted Execution & Identity

EY • Louisville (KY)

Hybrid
USD 107,000 - 177,000
Hybrid work model
Medical and dental coverage
Pension and 401(k) plans
+1
Senior AI Security & Trust Systems Engineer
Senior AI Security & Trust Systems Engineer

EY • Jericho (NY)

Hybrid
USD 107,000 - 177,000
Hybrid work model
Total Rewards package with medical and
Dental coverage
Senior AI Security & Trust Systems Engineer
Senior AI Security & Trust Systems Engineer

EY • Toledo (OH)

Hybrid
USD 107,000 - 177,000
Hybrid work model
Competitive pay and benefits
Total Rewards package
Senior AI Trust & Secrets Systems Engineer
Senior AI Trust & Secrets Systems Engineer

EY • Charleston (WV)

On-site
USD 107,000 - 177,000
Hybrid work model
Medical and dental coverage
Total Rewards package