Senior AI Security & Trust Engineer

Ernst & Young Oman

Dallas (TX)

On-site

USD 107,000 - 177,000

Full time

14 days+
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Benefits offered by this job

Hybrid work model
Medical and dental coverage
Pension and 401(k)
Paid time off

Job summary

EY is seeking an AI Systems Engineer to own the security and trust fabric of EY's AI-native platform, spanning identity, secrets, cryptographic, and attestation layers across cloud, on-prem, edge, and air-gapped environments.

You will enforce attestation, manage workload identity and cryptographic lifecycle, and collaborate with Enterprise Security, Cloud Platform, and SRE to ensure audit readiness in regulated client contexts.

Qualifications

  • Bachelor's or Master's degree in Computer Science, Security, or related technical field, or equivalent experience.
  • 8+ years in security engineering, identity/PKI, or trust infrastructure, with hands-on production ownership.
  • Deep, hands-on expertise with workload identity (SPIRE/SPIFFE), IAM (Keycloak/Entra ID), and secrets management (OpenBao/Vault).
  • Strong grounding in PKI, X.509 certificate lifecycle (cert-manager), key management, and transit encryption.
  • Working experience with confidential compute and hardware attestation (TDX, SEV-SNP, SGX, NVIDIA CC, or equivalents) and secure boot (Intel TXT).
  • Experience delivering identity and secrets consistently across multi-tenant, multi-environment (cloud/on-prem/edge/air-gapped) platforms.
  • Proven track record operating under compliance, security, or regulatory constraints with audit-grade evidence requirements.
  • Ability to define clean ownership boundaries and consumption contracts with platform, data, and runtime teams.

Responsibilities

  • Own workload identity and secrets management: SPIRE/ODIS, Keycloak/Entra ID (IAM), OpenBao (secrets store), cert-manager (X.509 lifecycle), PKI issuers/roots, and transit encryption across environments.
  • Build confidential compute environments: TEE (TDX/SEV-SNP/SGX/TrustZone/CCA/NVIDIA CC), Intel TXT boot security, and secure DPU architecture (DOCA) for isolation and audit-readiness.
  • Establish the platform-wide identity model so every workload, agent, and service carries a verifiable identity flowing through telemetry, cost attribution, and policy enforcement.
  • Own the cryptographic lifecycle: issuance, rotation, revocation, and expiry of certificates, keys, and roots with zero manual secrets sprawl across tenants.
  • Enforce attestation policy: which nodes, enclaves, and workloads are trusted and how attestation evidence is captured for audit.
  • Partner on a dotted-line basis with Enterprise Security / Cloud Platform / SRE to ensure review and audit readiness in regulated client contexts.

Skills

Workload identity
Secrets management
PKI
Cryptographic lifecycle

Education

Bachelor's or Master's degree

Tools

SPIRE/SPIFFE
Keycloak/Entra ID
OpenBao/Vault
cert-manager
DOCA/TEE hardware

Job description

EY is seeking an AI Systems Engineer to own the security and trust fabric of EY's AI-native platform, spanning identity, secrets, cryptographic, and attestation layers across cloud, on-prem, edge, and air-gapped environments.

You will enforce attestation, manage workload identity and cryptographic lifecycle, and collaborate with Enterprise Security, Cloud Platform, and SRE to ensure audit readiness in regulated client contexts.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior AI Security & Trust Systems Engineer
Senior AI Security & Trust Systems Engineer

EY • Jericho (NY)

Hybrid
USD 107,000 - 177,000
Hybrid work model
Total Rewards package with medical and
Dental coverage
Senior AI Security & Trust Engineer
Senior AI Security & Trust Engineer

EY • Tulsa (OK)

On-site
USD 107,000 - 177,000
Hybrid/Remote flexible work options
Total Rewards package
Medical and dental coverage
+1
Senior AI Security & Identity Engineer
Senior AI Security & Identity Engineer

Ernst & Young Oman • Trenton (NJ)

Hybrid
USD 107,000 - 177,000
Hybrid work model
Paid time off
Senior AI Security & Attestation Engineer
Senior AI Security & Attestation Engineer

EY • Portland (OR)

Hybrid
USD 107,000 - 177,000
Hybrid work model
Total rewards package
Paid time off
Senior AI Security & Trust Systems Engineer
Senior AI Security & Trust Systems Engineer

EY • Toledo (OH)

Hybrid
USD 107,000 - 177,000
Hybrid work model
Competitive pay and benefits
Total Rewards package
Senior AI Security Systems Engineer - Trust & Attestation
Senior AI Security Systems Engineer - Trust & Attestation

EY • San Jose (CA)

Hybrid
USD 107,000 - 177,000
Hybrid work model
Total Rewards package
Paid time off
Senior AI Security Systems Engineer - Trust & Attestation
Senior AI Security Systems Engineer - Trust & Attestation

EY • Orlando (FL)

Hybrid
USD 107,000 - 177,000
Senior AI Security & Trust Architect
Senior AI Security & Trust Architect

EY • Nashville (TN)

On-site
USD 107,000 - 177,000
Total rewards package
Hybrid work model
Generous PTO
Senior AI Security Systems Engineer - Trust & Attestation
Senior AI Security Systems Engineer - Trust & Attestation

EY • Salt Lake City (UT)

On-site
USD 107,000 - 177,000
Medical and dental coverage
Pension and 401(k)
Paid time off
Senior AI Security & Trust Engineer: Identity & Attestation
Senior AI Security & Trust Engineer: Identity & Attestation

EY • Las Vegas (NV)

On-site
USD 107,000 - 177,000
Hybrid work model
Medical and dental coverage
Pension and 401(k)