Jobs · Kentucky

AI Systems Engineer - Secure Execution - Senior

EY · Louisville, KY · 2 days ago
Hybrid$107k–$177k/yrFull-time

About the role

We are seeking AI Systems Engineers to own the security and trust fabric of EY’s AI-native platform.

Responsibilities

  • Own workload identity and secrets management: SPIRE/ODIS, Keycloak/Entra ID (IAM), OpenBao (secrets store), cert-manager (X.509 lifecycle), PKI issuers/roots, and transit encryption — propagated consistently across every environment and tenant.
  • Build confidential compute environments: TEE (TDX/SEV-SNP/SGX/TrustZone/CCA/NVIDIA CC), Intel TXT boot security, and secure DPU architecture (DOCA), so environments are isolated, attestable, and audit-ready.
  • Establish the platform-wide identity model so every workload, agent, and service carries a verifiable, propagated identity that flows through telemetry, cost attribution, and policy enforcement end-to-end.
  • Own the cryptographic lifecycle: issuance, rotation, revocation, and expiry of certificates, keys, and roots, with zero manual, untracked secrets and no long-lived credential sprawl across tenants.
  • Enforce attestation policy: which nodes, enclaves, and workloads are trusted, how trust is proven at boot and at runtime, and how attestation evidence is captured for audit.
  • Partner on a dotted-line basis with Enterprise Security / Cloud Platform / SRE to ensure independent review, alignment to enterprise trust standards, and audit readiness in regulated client contexts.

Requirements

  • Deep expertise in workload identity, secrets management, PKI, and cryptographic lifecycle at production scale across multiple environments.
  • Strong understanding of confidential compute, trusted execution environments, hardware roots of trust, and remote attestation.
  • Security-first mindset: thinking in terms of provable trust, blast radius, least privilege, and cryptographic attribution rather than perimeter or convenience.
  • Ability to encode trust and compliance directly into infrastructure so that security is enforced by the platform, not by manual review.
  • Comfortable operating across cloud, on-prem, edge, and air-gapped environments with consistent identity and trust mechanisms.
  • Strong communicator able to explain trust, identity, and attestation tradeoffs to engineers, architects, auditors, and leadership.
  • Orientation toward auditability and evidence: able to translate regulatory expectations into technical controls and demonstrable proof.

Qualifications

  • Bachelor’s or Master’s degree in Computer Science, Security, or related technical field, or equivalent experience.
  • 8+ years in security engineering, identity/PKI, or trust infrastructure, with hands-on production ownership.
  • Deep, hands-on expertise with workload identity (SPIRE/SPIFFE), IAM (Keycloak/Entra ID), and secrets management (OpenBao/Vault).
  • Strong grounding in PKI, X.509 certificate lifecycle (cert-manager), key management, and transit encryption.
  • Working experience with confidential compute and hardware attestation (TDX, SEV-SNP, SGX, NVIDIA CC, or equivalents) and secure boot (Intel TXT).
  • Experience delivering identity and secrets consistently across multi-tenant, multi-environment (cloud/on-prem/edge/air-gapped) platforms.
  • Proven track record operating under compliance, security, or regulatory constraints with audit-grade evidence requirements.
  • Ability to define clean ownership boundaries and consumption contracts with platform, data, and runtime teams.
  • Idealist, familiarity with secure DPU architectures (DOCA) and hardware root-of-trust / boot-chain designs.
  • Experience integrating identity and attestation into service mesh, policy engines (OPA), and API gateways.
  • Exposure to AI/ML workloads and the specific trust challenges of confidential AI inference (models/secrets inside enclaves).
  • Experience producing attestation and compliance evidence for external auditors or regulators.
  • Relevant certifications (e.g., CISSP, cloud security specialties) or demonstrable equivalent depth.
  • Exposure to regulated industries (financial services, tax, healthcare, risk).

Skills

  • Deep expertise in workload identity, secrets management, PKI, and cryptographic lifecycle at production scale across multiple environments.
  • Strong understanding of confidential compute, trusted execution environments, hardware roots of trust, and remote attestation.
  • Security-first mindset: thinking in terms of provable trust, blast radius, least privilege, and cryptographic attribution rather than perimeter or convenience.
  • Ability to encode trust and compliance directly into infrastructure so that security is enforced by the platform, not by manual review.
  • Comfortable operating across cloud, on-prem, edge, and air-gapped environments with consistent identity and trust mechanisms.
  • Strong communicator able to explain trust, identity, and attestation tradeoffs to engineers, architects, auditors, and leadership.
  • Orientation toward auditability and evidence: able to translate regulatory expectations into technical controls and demonstrable proof.

Benefits

Comprehensive compensation and benefits package including medical and dental coverage, pension and 401(k) plans, and a wide range of paid time off options.

Pay

The base salary range for this job in all geographic locations in the US is $106,900 to $176,500. The base salary range for New York City Metro Area, Washington State and California (excluding Sacramento) is $128,400 to $200,600.

Schedule

Our expectation is for most people in external, client serving roles to work together in person 40-60% of the time over the course of an engagement, project or year.

Similar jobs