AI Systems Security & Trust Engineer

EY

Stamford (CT)

On-site

USD 107,000 - 177,000

Full time

2 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Hybrid work model
Medical and dental coverage
Pension and 401(k)
Generous paid time off

Job summary

EY seeks an AI Systems Engineer to own the security and trust fabric of EY's AI-native platform across cloud, on-prem, edge, and air-gapped environments. The role focuses on workload identity, secrets management, cryptographic lifecycle, and attestation to enable regulated, auditable AI workloads.

The position requires deep expertise in production-scale identity and cryptography, with experience across SPIRE, IAM, PKI, confidential compute, and secure boot.

Qualifications

  • Bachelor’s or Master’s degree in Computer Science, Security, or related technical field, or equivalent experience.
  • 8+ years in security engineering, identity/PKI, or trust infrastructure, with hands-on production ownership.
  • Deep, hands-on expertise with workload identity (SPIRE/SPIFFE), IAM (Keycloak/Entra ID), and secrets management (OpenBao/Vault).
  • Strong grounding in PKI, X.509 certificate lifecycle (cert-manager), key management, and transit encryption.
  • Working experience with confidential compute and hardware attestation (TDX, SEV-SNP, SGX, NVIDIA CC, or equivalents) and secure boot (Intel TXT).
  • Experience delivering identity and secrets consistently across multi-tenant, multi-environment (cloud/on-prem/edge/air-gapped) platforms.
  • Proven track record operating under compliance, security, or regulatory constraints with audit-grade evidence requirements.
  • Ability to define clean ownership boundaries and consumption contracts with platform, data, and runtime teams.

Responsibilities

  • Own workload identity and secrets management across multiple environments and tenants.
  • Build confidential compute environments to ensure isolation, attestability, and audit-readiness.
  • Establish the platform-wide identity model for verifiable, propagated identity across telemetry and policy enforcement.
  • Own the cryptographic lifecycle: issuance, rotation, revocation, and expiry of certificates and keys.
  • Enforce attestation policy for nodes, enclaves, and workloads with audit-ready evidence.
  • Partner with Enterprise Security / Cloud Platform / SRE for enterprise trust standards and audits.

Skills

Workload identity
Secrets management
PKI
Confidential compute
Auditability

Education

Bachelor’s or Master’s in Computer Science/Security or related field

Tools

SPIRE/SPIFFE
Keycloak/Entra ID
OpenBao/Vault
cert-manager (X.509)
DOCA/TDX/SEV-SNP/SGX/NVIDIA CC

Job description

EY seeks an AI Systems Engineer to own the security and trust fabric of EY's AI-native platform across cloud, on-prem, edge, and air-gapped environments. The role focuses on workload identity, secrets management, cryptographic lifecycle, and attestation to enable regulated, auditable AI workloads.

The position requires deep expertise in production-scale identity and cryptography, with experience across SPIRE, IAM, PKI, confidential compute, and secure boot.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

AI Systems Engineer: Secure Execution & Trust Platform
AI Systems Engineer: Secure Execution & Trust Platform

EY • City of Rochester (NY)

On-site
USD 107,000 - 177,000
AI Security & Identity Systems Engineer
AI Security & Identity Systems Engineer

EY • Dallas (TX)

Hybrid
USD 107,000 - 177,000
Medical and dental coverage
401(k) and pension plan
Paid time off and holidays
AI Systems Security Engineer - Trust & Identity
AI Systems Security Engineer - Trust & Identity

EY • Miami (FL)

Hybrid
USD 107,000 - 177,000
Hybrid work model
Medical and dental coverage
Pension and 401(k) plans
+2
AI Systems Engineer: Secure Execution & Trust
AI Systems Engineer: Secure Execution & Trust

EY • Philadelphia

Hybrid
USD 107,000 - 177,000
Hybrid work model
Medical and dental coverage
Pension and 401(k)
+1
AI Systems Engineer: Secure Execution & Trust
AI Systems Engineer: Secure Execution & Trust

EY • McLean (VA)

Hybrid
USD 107,000 - 177,000
Hybrid work model
Total rewards package (medical/dental,
Flexible vacation policy
AI Systems Engineer – Secure Execution & Trust
AI Systems Engineer – Secure Execution & Trust

EY • Birmingham (AL)

Hybrid
USD 107,000 - 177,000
Medical and dental coverage
Pension and 401(k) plans
Paid time off
AI Trust & Secure Execution Engineer
AI Trust & Secure Execution Engineer

EY • Phoenix (AZ)

Hybrid
USD 107,000 - 177,000
Hybrid work model
Medical & dental coverage
Pension and 401(k)
Senior AI Security & Trust Engineer
Senior AI Security & Trust Engineer

Ernst & Young Oman • Dallas (TX)

On-site
USD 107,000 - 177,000
Hybrid work model
Medical and dental coverage
Pension and 401(k)
+1
Senior AI Security & Trust Systems Engineer
Senior AI Security & Trust Systems Engineer

EY • Jericho (NY)

Hybrid
USD 107,000 - 177,000
Hybrid work model
Total Rewards package with medical and
Dental coverage
AI Systems Engineer: Secure Execution & Identity Trust
AI Systems Engineer: Secure Execution & Identity Trust

EY • Austin (TX)

Hybrid
USD 107,000 - 177,000
Hybrid work model
Flexible vacation policy
Competitive compensation