AI Trust & Secure Execution Engineer

EY

Phoenix (AZ)

Hybrid

USD 107,000 - 177,000

Full time

17 hours ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Hybrid work model
Medical & dental coverage
Pension and 401(k)

Job summary

EY seeks an AI Systems Engineer to own the security and trust fabric of EY's AI-native platform, spanning identity, secrets, cryptographic, and attestation layers across cloud, on-prem, edge, and air-gapped environments.

You will ensure workloads are identity-bound, secrets protected, nodes trusted, and deployments attestable and auditable, forming EY's strategic platform differentiator in regulated industries.

Qualifications

  • Bachelor’s or Master’s degree in Computer Science, Security, or related field, or equivalent experience.
  • 8+ years in security engineering, identity/PKI, or trust infrastructure, with hands-on production ownership.
  • Deep, hands-on expertise with workload identity (SPIRE/SPIFFE), IAM (Keycloak/Entra ID), and secrets management (OpenBao/Vault).
  • Strong grounding in PKI, X.509 certificate lifecycle (cert-manager), key management, and transit encryption.
  • Working experience with confidential compute and hardware attestation (TDX, SEV-SNP, SGX, NVIDIA CC, or equivalents) and secure boot (Intel TXT).
  • Experience delivering identity and secrets consistently across multi-tenant, multi-environment (cloud/on-prem/edge/air-gapped) platforms.
  • Proven track record operating under compliance, security, or regulatory constraints with audit-grade evidence requirements.
  • Ability to define clean ownership boundaries and consumption contracts with platform, data, and runtime teams.

Responsibilities

  • Own workload identity and secrets management across environments (SPIRE/ODIS, Keycloak/Entr a ID, OpenBao, cert-manager, PKI).
  • Build confidential compute environments (TEE, secure boot, secure DPU) for isolated, attestable workloads.
  • Establish platform-wide identity model for verifiable identity across telemetry and policy enforcement.
  • Own cryptographic lifecycle: issuance, rotation, revocation, expiry of certificates and keys.
  • Enforce attestation policy for nodes, enclaves, and workloads with audit-ready evidence.
  • Collaborate with Enterprise Security / Cloud Platform / SRE for audit readiness and compliance.

Skills

workload identity
secrets management
PKI
confidential compute
auditability
communication
cloud/on-prem/edge

Education

Bachelor’s or Master’s in CS/Security
8+ years security engineering

Tools

SPIRE/SPIFFE
Keycloak/Entra ID
OpenBao/Vault
cert-manager
TDX/SEV-SNP/SGX
NVIDIA DOCA

Job description

EY seeks an AI Systems Engineer to own the security and trust fabric of EY's AI-native platform, spanning identity, secrets, cryptographic, and attestation layers across cloud, on-prem, edge, and air-gapped environments.

You will ensure workloads are identity-bound, secrets protected, nodes trusted, and deployments attestable and auditable, forming EY's strategic platform differentiator in regulated industries.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior AI Security & Trust Engineer - Secure Execution
Senior AI Security & Trust Engineer - Secure Execution

EY • Seattle (WA)

Hybrid
USD 107,000 - 177,000
Hybrid work model
Total rewards package
Paid time off
AI Trust & Secure Execution Systems Engineer
AI Trust & Secure Execution Systems Engineer

EY • Tampa (FL)

Hybrid
USD 107,000 - 177,000
Hybrid work model
Total rewards package
Paid time off
AI Trust & Secure Execution Systems Engineer
AI Trust & Secure Execution Systems Engineer

EY • Cincinnati (OH)

On-site
USD 107,000 - 177,000
Hybrid/remote work possible
Total rewards package
Paid time off
Senior AI Trust & Secure Execution Engineer
Senior AI Trust & Secure Execution Engineer

EY • Kansas City (MO)

Hybrid
USD 107,000 - 177,000
Hybrid work model
Total Rewards package (medical, dental
401(k) and paid time off
AI Systems Security & Trust Engineer
AI Systems Security & Trust Engineer

EY • Richmond (VA)

Hybrid
USD 107,000 - 177,000
Hybrid work model
Salary and benefits
Paid time off
+1
AI Systems Engineer – Secure Execution & Trust
AI Systems Engineer – Secure Execution & Trust

EY • Birmingham (AL)

Hybrid
USD 107,000 - 177,000
Medical and dental coverage
Pension and 401(k) plans
Paid time off
AI Systems Engineer: Secure Execution & Trust
AI Systems Engineer: Secure Execution & Trust

EY • McLean (VA)

Hybrid
USD 107,000 - 177,000
Hybrid work model
Total rewards package (medical/dental,
Flexible vacation policy
AI Security Engineer: Trusted Execution & Identity
AI Security Engineer: Trusted Execution & Identity

EY • Louisville (KY)

Hybrid
USD 107,000 - 177,000
Hybrid work model
Medical and dental coverage
Pension and 401(k) plans
+1
Senior AI Trust & Security Systems Engineer
Senior AI Trust & Security Systems Engineer

EY • Minneapolis (MN)

Hybrid
USD 107,000 - 177,000
Hybrid work model
Medical and dental coverage
Pension and 401(k)
+1
Senior AI Security & Trust Systems Engineer
Senior AI Security & Trust Systems Engineer

EY • Jericho (NY)

Hybrid
USD 107,000 - 177,000
Hybrid work model
Total Rewards package with medical and
Dental coverage