Senior AI Security Systems Engineer - Trust & Attestation

Ernst & Young Oman

Tucson (AZ)

Hybrid

USD 107,000 - 177,000

Full time

3 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Medical and dental coverage
Pension and 401(k)
Paid time off
Hybrid work model

Job summary

EY is seeking an AI Systems Engineer to own security fabric across EY's AI-native platform, spanning identity, secrets, attestation, and cryptographic lifecycle. You will enable trusted workloads in cloud, on-prem, edge, and air-gapped environments, ensuring verifiable identities, zero-sprawl credentials, and auditable deployments.

You'll partner with Enterprise Security, Cloud Platform, and SRE to meet compliance and enterprise trust standards, contributing to a secure, regulated workload

Qualifications

  • Bachelor's or Master's degree in Computer Science, Security, or related field, or equivalent experience.
  • 8+ years in security engineering, identity/PKI, or trust infrastructure, with hands-on production ownership.
  • Deep, hands-on expertise with workload identity (SPIRE/SPIFFE), IAM (Keycloak/Entra ID), and secrets management (OpenBao/Vault).
  • Strong grounding in PKI, X.509 certificate lifecycle (cert-manager), key management, and transit encryption.
  • Working experience with confidential compute and hardware attestation (TDX, SEV-SNP, SGX, NVIDIA CC, or equivalents) and secure boot (Intel TXT).
  • Experience delivering identity and secrets consistently across multi-tenant, multi-environment (cloud/on-prem/edge/air-gapped) platforms.
  • Proven track record operating under compliance, security, or regulatory constraints with audit-grade evidence requirements.
  • Ability to define clean ownership boundaries and consumption contracts with platform, data, and runtime teams.

Responsibilities

  • Own workload identity and secrets management across environments.
  • Build confidential compute environments with TEEs and secure boot.
  • Establish platform-wide identity model for verifiable identities across telemetry and policy enforcement.
  • Own the cryptographic lifecycle: issuance, rotation, revocation, and expiry with no credential sprawl.
  • Enforce attestation policy for trusted nodes, enclaves, and workloads, with audit evidence.
  • Partner with Enterprise Security / Cloud Platform / SRE for enterprise trust standards and audit readiness.

Skills

Workload identity
Secrets management
PKI
Cryptographic lifecycle
Confidential compute
Attestation
Audit readiness
Cross-environment deployment
Communication
Regulatory compliance

Education

Bachelor's/Master's in CS/Security

Tools

SPIRE/SPIFFE
Keycloak/Entra ID
OpenBao
cert-manager
TDX/SEV-SNP/SGX/TrustZone
NVIDIA DOCA

Job description

EY is seeking an AI Systems Engineer to own security fabric across EY's AI-native platform, spanning identity, secrets, attestation, and cryptographic lifecycle. You will enable trusted workloads in cloud, on-prem, edge, and air-gapped environments, ensuring verifiable identities, zero-sprawl credentials, and auditable deployments.

You'll partner with Enterprise Security, Cloud Platform, and SRE to meet compliance and enterprise trust standards, contributing to a secure, regulated workload

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior AI Security & Trust Engineer
Senior AI Security & Trust Engineer

Ernst & Young Oman • Rogers (AR)

Hybrid
USD 107,000 - 177,000
Hybrid work model
Total Rewards package (medical/dental,
Senior AI Trust & Secure Execution Engineer
Senior AI Trust & Secure Execution Engineer

Ernst & Young Oman • McLean (VA)

Hybrid
USD 107,000 - 177,000
Hybrid work model
Total Rewards package
Generous vacation policy
AI Security Platform Engineer: Trust & Attestation
AI Security Platform Engineer: Trust & Attestation

Ernst & Young Oman • Little Rock (AR)

Hybrid
USD 107,000 - 177,000
Hybrid work model
Medical and dental coverage
Paid time off
Senior AI Security Engineer: Trusted Execution & Identities
Senior AI Security Engineer: Trusted Execution & Identities

Ernst & Young Oman • Toledo (OH)

Hybrid
USD 107,000 - 177,000
Hybrid work model
Medical and dental coverage
Pension and 401(k)
+1
Senior AI Security Engineer: Trust & Attestation Architect
Senior AI Security Engineer: Trust & Attestation Architect

Ernst & Young Advisory Services Sdn Bhd • Atlanta (GA)

Hybrid
USD 107,000 - 177,000
Total rewards package
Hybrid work model
Generous PTO
Senior AI Systems Architect for Regulated Enterprise
Senior AI Systems Architect for Regulated Enterprise

Ernst & Young Advisory Services Sdn Bhd • Atlanta (GA)

Hybrid
USD 144,000 - 329,000
Hybrid work model
Competitive compensation package
Senior AI Platform Infrastructure Engineer
Senior AI Platform Infrastructure Engineer

Ernst & Young Advisory Services Sdn Bhd • Atlanta (GA)

Hybrid
USD 126,000 - 262,000
Hybrid work model
Competitive compensation
Total Rewards package (medical, dental
+1
Senior AI Data & State Infrastructure Engineer
Senior AI Data & State Infrastructure Engineer

Ernst & Young Oman • Toledo (OH)

On-site
USD 107,000 - 177,000
Senior Cloud & AI Security Consultant
Senior Cloud & AI Security Consultant

Ernst and Young • Atlanta (GA)

Hybrid
USD 128,000 - 240,000
Hybrid work model
Medical and dental coverage
401(k) plan
Senior AI Data & State Platform Engineer
Senior AI Data & State Platform Engineer

Ernst & Young Oman • Rogers (AR)

Hybrid
USD 107,000 - 177,000
Hybrid work model
Medical and dental coverage
Pension and 401(k) plans
+1