Senior AI Security Engineer: Trusted Execution & Identity

Ernst & Young Oman

Tulsa (OK)

Hybrid

USD 107,000 - 177,000

Full time

3 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Hybrid work model
Total Rewards package
Paid time off

Job summary

EY seeks AI Systems Engineers to own the security and trust fabric of EY's AI-native platform across cloud, on-prem, edge, and air-gapped environments. This role drives identity, secrets, attestation, and cryptographic controls to ensure workloads are verifiably secure and auditable.

Collaborate with Enterprise Security, Cloud Platform, and SRE to maintain enterprise trust standards and regulatory compliance in client contexts.

Qualifications

  • Bachelor’s or Master’s degree in Computer Science, Security, or related field, or equivalent experience.
  • 8+ years in security engineering, identity/PKI, or trust infrastructure with hands-on ownership.
  • Hands-on with workload identity and secrets management at production scale across multi-tenant environments.
  • Deep PKI knowledge including X.509 lifecycle and transit encryption.

Responsibilities

  • Own workload identity and secrets management across environments.
  • Build confidential compute environments with trusted execution and secure boot.
  • Establish platform-wide identity model for verifiable identity propagation.
  • Own the cryptographic lifecycle: certificates, keys, and roots rotation/expiry.
  • Enforce attestation policy for trusted nodes and workloads.
  • Collaborate with Enterprise Security / Cloud Platform / SRE for audit readiness.

Skills

Workload identity
Secrets management
PKI
Confidential compute
Auditability
Communication
Trust enforcement

Education

Bachelor's or Master's in CS/Security

Tools

SPIRE/SPIFFE
Keycloak/Entra ID
OpenBao
cert-manager

Job description

EY seeks AI Systems Engineers to own the security and trust fabric of EY's AI-native platform across cloud, on-prem, edge, and air-gapped environments. This role drives identity, secrets, attestation, and cryptographic controls to ensure workloads are verifiably secure and auditable.

Collaborate with Enterprise Security, Cloud Platform, and SRE to maintain enterprise trust standards and regulatory compliance in client contexts.

Get your free, confidential resume review.
or drag and drop your file here.