Senior Secure AI Platform Engineer — Identity & Attestation

Ernst & Young Oman

Salem (OR)

On-site

USD 107,000 - 177,000

Full time

14 days+
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Hybrid work/Remote-friendly policy
Total rewards package including health
Paid time off

Job summary

EY is seeking AI Systems Engineers to own the security and trust fabric of EY’s AI-native platform, spanning identity, secrets, cryptography, and attestation across cloud, on‑prem, edge, and air‑gapped environments.

You will own the enforcement mechanisms to prove workloads are identity‑bound, secrets protected, and deployments auditable, enabling regulated client contexts and secure, auditable AI workloads.

Qualifications

  • Bachelor’s or Master’s degree in Computer Science, Security, or related technical field, or equivalent experience.
  • 8+ years in security engineering, identity/PKI, or trust infrastructure with hands-on production ownership.
  • Deep, hands-on expertise with workload identity (SPIRE/SPIFFE), IAM (Keycloak/Entra ID), and secrets management (OpenBao/Vault).
  • Strong grounding in PKI, X.509 certificate lifecycle (cert-manager), key management, and transit encryption.
  • Working experience with confidential compute and hardware attestation (TDX, SEV-SNP, SGX, NVIDIA CC, or equivalents) and secure boot (Intel TXT).
  • Experience delivering identity and secrets consistently across multi-tenant, multi-environment (cloud/on-prem/edge/air-gapped) platforms.
  • Proven track record operating under compliance, security, or regulatory constraints with audit-grade evidence requirements.
  • Ability to define clean ownership boundaries and consumption contracts with platform, data, and runtime teams.

Responsibilities

  • Own workload identity and secrets management across environments (SPIRE/ODIS, Keycloak/Entra ID, OpenBao, cert-manager).
  • Build confidential compute environments (TEE, Intel TXT) to keep workloads isolated, attestable and auditable.
  • Define platform-wide identity model for verifiable workloads through telemetry and policy enforcement.
  • Manage cryptographic lifecycle: certificates, keys, and roots with zero manual secrets sprawl.
  • Enforce attestation policy for nodes, enclaves, and workloads with evidence capture for audit.
  • Collaborate with Enterprise Security, Cloud Platform, and SRE for audit readiness in regulated contexts.

Skills

Workload identity
Secrets management
PKI
Cryptographic lifecycle
Confidential compute
Auditability & compliance

Education

Bachelor’s or Master’s degree in Computer Science, Security, or related field

Tools

SPIRE/SPIFFE
Keycloak/Entra ID
OpenBao/Vault
cert-manager (X.509 lifecycle)
TDX/SEV-SNP/SGX/TrustZone
NVIDIA DOCA

Job description

EY is seeking AI Systems Engineers to own the security and trust fabric of EY’s AI-native platform, spanning identity, secrets, cryptography, and attestation across cloud, on‑prem, edge, and air‑gapped environments.

You will own the enforcement mechanisms to prove workloads are identity‑bound, secrets protected, and deployments auditable, enabling regulated client contexts and secure, auditable AI workloads.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior AI Security Systems Engineer — Trust & Attestation
Senior AI Security Systems Engineer — Trust & Attestation

EY • Hartford (CT)

Hybrid
USD 107,000 - 177,000
Hybrid work model
Total rewards package
Competitive compensation & benefits
Senior AI Security Systems Engineer - Trust & Attestation
Senior AI Security Systems Engineer - Trust & Attestation

EY • Salt Lake City (UT)

On-site
USD 107,000 - 177,000
Medical and dental coverage
Pension and 401(k)
Paid time off
Senior AI Security & Attestation Engineer
Senior AI Security & Attestation Engineer

EY • Portland (OR)

Hybrid
USD 107,000 - 177,000
Hybrid work model
Total rewards package
Paid time off
Senior AI Security Systems Engineer - Trust & Attestation
Senior AI Security Systems Engineer - Trust & Attestation

EY • San Francisco (CA)

On-site
USD 107,000 - 177,000
Hybrid work model
Total Rewards package
401(k) and pensions
+1
Senior AI Trust & Attestation Engineer
Senior AI Trust & Attestation Engineer

EY • Memphis (TN)

On-site
USD 107,000 - 177,000
Medical and dental coverage
401(k) plans
Paid time off
+1
Senior AI Security Systems Engineer - Trust & Attestation
Senior AI Security Systems Engineer - Trust & Attestation

EY • San Jose (CA)

Hybrid
USD 107,000 - 177,000
Hybrid work model
Total Rewards package
Paid time off
Senior AI Security & Trust Engineer - Secure Execution
Senior AI Security & Trust Engineer - Secure Execution

EY • Seattle (WA)

Hybrid
USD 107,000 - 177,000
Hybrid work model
Total rewards package
Paid time off
Senior AI Security Engineer – Trust & Attestation
Senior AI Security Engineer – Trust & Attestation

EY • Indianapolis (IN)

On-site
USD 107,000 - 177,000
Hybrid work model
Medical & dental coverage
Pension & 401(k)
+1
Senior AI Systems Engineer – Secure Execution & Trust
Senior AI Systems Engineer – Secure Execution & Trust

EY • Houston (TX)

Hybrid
USD 107,000 - 177,000
Hybrid work model
Medical and dental coverage
Pension and 401(k) plans
+1
Senior AI Trust & Security Systems Engineer
Senior AI Trust & Security Systems Engineer

EY • Minneapolis (MN)

Hybrid
USD 107,000 - 177,000
Hybrid work model
Medical and dental coverage
Pension and 401(k)
+1