Senior AI Security Systems Engineer: Trusted Execution

EY

Huntsville (AL)

On-site

USD 107,000 - 177,000

Full time

9 days ago
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Medical benefits
Dental coverage
401(k) plan
Paid time off

Job summary

EY is seeking AI Systems Engineers to own the security and trust fabric of EY’s AI-native platform, spanning identity, secrets, cryptographic and attestation layers across cloud, on‑prem, edge, and air‑gapped environments.

You will architect and enforce platform‑wide identity models, manage cryptographic lifecycles, and drive attestation policies to support auditable, regulated workloads with strong governance across multi‑tenant deployments.

Qualifications

  • Bachelor’s or Master’s degree in Computer Science, Security, or related technical field, or equivalent experience.
  • 8+ years in security engineering, identity/PKI, or trust infrastructure, with hands‑on production ownership.
  • Deep, hands‑on expertise with workload identity (SPIRE/SPIFFE), IAM (Keycloak/Entra ID), and secrets management (OpenBao/Vault).
  • Strong grounding in PKI, X.509 certificate lifecycle (cert-manager), key management, and transit encryption.
  • Working experience with confidential compute and hardware attestation (TDX, SEV‑SNP, SGX, NVIDIA CC, or equivalents) and secure boot (Intel TXT).
  • Experience delivering identity and secrets consistently across multi‑tenant, multi‑environment (cloud/on‑prem/edge/air‑gapped) platforms.
  • Proven track record operating under compliance, security, or regulatory constraints with audit‑grade evidence requirements.
  • Ability to define clean ownership boundaries and consumption contracts with platform, data, and runtime teams.

Responsibilities

  • Own workload identity and secrets management across environments (SPIRE/ODIS, Keycloak/Entra ID, OpenBao, cert‑manager, PKI).
  • Build confidential compute environments (TEE, secure boot, secure DPU architecture) for attestable, audit‑ready workloads.
  • Establish platform‑wide identity models for verifiable identity across telemetry, cost attribution, and policy enforcement.
  • Own issuance, rotation, revocation, and expiry of certificates, keys, and roots with no long‑lived secret sprawl.
  • Enforce attestation policy for nodes, enclaves, and workloads and capture evidence for audit.
  • Collaborate with Enterprise Security / Cloud Platform / SRE to ensure compliance and audit readiness for regulated clients.

Skills

Workload identity
Secrets management
PKI
Cryptographic lifecycle
Confidential compute
Attestation
Audit & compliance
Cross-environment operations

Education

Bachelor’s or Master’s degree in Computer Science or Security

Tools

SPIRE/SPIFFE
Keycloak/Entra ID
OpenBao/Vault
cert-manager
TDX/SEV-SNP/SGX/TrustZone
Intel TXT
DOCA
Service mesh / OPA

Job description

EY is seeking AI Systems Engineers to own the security and trust fabric of EY’s AI-native platform, spanning identity, secrets, cryptographic and attestation layers across cloud, on‑prem, edge, and air‑gapped environments.

You will architect and enforce platform‑wide identity models, manage cryptographic lifecycles, and drive attestation policies to support auditable, regulated workloads with strong governance across multi‑tenant deployments.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior AI Security Systems Engineer — Trusted Execution
Senior AI Security Systems Engineer — Trusted Execution

EY • New Brunswick (NJ)

Hybrid
USD 107,000 - 177,000
Hybrid work model
Total Rewards package
Flexible vacation policy
Senior AI Security & Trust Engineer - Secure Execution
Senior AI Security & Trust Engineer - Secure Execution

EY • Seattle (WA)

Hybrid
USD 107,000 - 177,000
Hybrid work model
Total rewards package
Paid time off
Senior AI Trust & Security Systems Engineer
Senior AI Trust & Security Systems Engineer

EY • Minneapolis (MN)

Hybrid
USD 107,000 - 177,000
Hybrid work model
Medical and dental coverage
Pension and 401(k)
+1
Senior AI Trust & Secure Execution Engineer
Senior AI Trust & Secure Execution Engineer

EY • Kansas City (MO)

Hybrid
USD 107,000 - 177,000
Hybrid work model
Total Rewards package (medical, dental
401(k) and paid time off
Senior AI Systems Engineer – Secure Execution & Trust
Senior AI Systems Engineer – Secure Execution & Trust

EY • Houston (TX)

Hybrid
USD 107,000 - 177,000
Hybrid work model
Medical and dental coverage
Pension and 401(k) plans
+1
Senior AI Security & Trust Systems Engineer
Senior AI Security & Trust Systems Engineer

EY • Jericho (NY)

Hybrid
USD 107,000 - 177,000
Hybrid work model
Total Rewards package with medical and
Dental coverage
Senior AI Security Systems Engineer — Trust & Attestation
Senior AI Security Systems Engineer — Trust & Attestation

EY • Hartford (CT)

Hybrid
USD 107,000 - 177,000
Hybrid work model
Total rewards package
Competitive compensation & benefits
Senior AI Security Systems Engineer - Trust & Attestation
Senior AI Security Systems Engineer - Trust & Attestation

EY • Salt Lake City (UT)

On-site
USD 107,000 - 177,000
Medical and dental coverage
Pension and 401(k)
Paid time off
Senior AI Security & Trust Systems Engineer
Senior AI Security & Trust Systems Engineer

EY • Toledo (OH)

Hybrid
USD 107,000 - 177,000
Hybrid work model
Competitive pay and benefits
Total Rewards package
Senior AI Security Systems Engineer - Trust & Attestation
Senior AI Security Systems Engineer - Trust & Attestation

EY • San Jose (CA)

Hybrid
USD 107,000 - 177,000
Hybrid work model
Total Rewards package
Paid time off