AI Systems Engineer - Secure Execution - Senior
About the role
We are seeking AI Systems Engineers to own the security and trust fabric of EY’s AI-native platform. This role is crucial for deploying AI workloads in regulated industries and ensuring their security, economic bounds, and audit-readiness.
Responsibilities
- Own workload identity and secrets management: SPIRE/ODIS, Keycloak/Entra ID (IAM), OpenBao (secrets store), cert-manager (X.509 lifecycle), PKI issuers/roots, and transit encryption.
- Build confidential compute environments: TEE (TDX/SEV-SNP/SGX/TrustZone/CCA/NVIDIA CC), Intel TXT boot security, and secure DPU architecture (DOCA).
- Establish the platform-wide identity model so every workload, agent, and service carries a verifiable, propagated identity.
- Own the cryptographic lifecycle: issuance, rotation, revocation, and expiry of certificates, keys, and roots.
- Enforce attestation policy: trust at boot and runtime, and capture attestation evidence for audit.
- Partner on a dotted-line basis with Enterprise Security / Cloud Platform / SRE to ensure independent review, alignment to enterprise trust standards, and audit readiness in regulated client contexts.
Requirements
- Deep expertise in workload identity, secrets management, PKI, and cryptographic lifecycle at production scale across multiple environments.
- Strong understanding of confidential compute, trusted execution environments, hardware roots of trust, and remote attestation.
- Security-first mindset: thinking in terms of provable trust, blast radius, least privilege, and cryptographic attribution.
- Comfortable operating across cloud, on-prem, edge, and air-gapped environments with consistent identity and trust mechanisms.
- Strong communicator able to explain trust, identity, and attestation tradeoffs to engineers, architects, auditors, and leadership.
- Orientation toward auditability and evidence: able to translate regulatory expectations into technical controls and demonstrable proof.
Qualifications
- Bachelor’s or Master’s degree in Computer Science, Security, or related technical field, or equivalent experience.
- 8+ years in security engineering, identity/PKI, or trust infrastructure, with hands-on production ownership.
- Deep, hands-on expertise with workload identity (SPIRE/SPIFFE), IAM (Keycloak/Entra ID), and secrets management (OpenBao/Vault).
- Strong grounding in PKI, X.509 certificate lifecycle (cert-manager), key management, and transit encryption.
- Working experience with confidential compute and hardware attestation (TDX, SEV-SNP, SGX, NVIDIA CC, or equivalents) and secure boot (Intel TXT).
- Experience delivering identity and secrets consistently across multi-tenant, multi-environment (cloud/on-prem/edge/air-gapped) platforms.
- Proven track record operating under compliance, security, or regulatory constraints with audit-grade evidence requirements.
- Ability to define clean ownership boundaries and consumption contracts with platform, data, and runtime teams.
- Familiarity with secure DPU architectures (DOCA) and hardware root-of-trust / boot-chain designs.
- Experience integrating identity and attestation into service mesh, policy engines (OPA), and API gateways.
- Exposure to AI/ML workloads and the specific trust challenges of confidential AI inference (models/secrets inside enclaves).
- Experience producing attestation and compliance evidence for external auditors or regulators.
- Relevant certifications (e.g., CISSP, cloud security specialties) or demonstrable equivalent depth.
- Exposure to regulated industries (financial services, tax, healthcare, risk).
Skills
- Deep expertise in workload identity, secrets management, PKI, and cryptographic lifecycle at production scale across multiple environments.
- Strong understanding of confidential compute, trusted execution environments, hardware roots of trust, and remote attestation.
- Security-first mindset: thinking in terms of provable trust, blast radius, least privilege, and cryptographic attribution.
- Comfortable operating across cloud, on-prem, edge, and air-gapped environments with consistent identity and trust mechanisms.
- Strong communicator able to explain trust, identity, and attestation tradeoffs to engineers, architects, auditors, and leadership.
- Orientation toward auditability and evidence: able to translate regulatory expectations into technical controls and demonstrable proof.
Benefits
The platform offers a comprehensive compensation and benefits package, including medical and dental coverage, pension and 401(k) plans, and a wide range of paid time off options.
Pay
$106,900 to $176,500 base salary range for the US, and $128,400 to $200,600 for the New York City Metro Area, Washington State, and California (excluding Sacramento).
Schedule
Our expectation is for most people in external, client serving roles to work together in person 40-60% of the time over the course of an engagement, project or year.
Application Instructions
EY accepts applications for this position on an on-going basis. For those living in California, please click here for additional information.
Equal Opportunity Employer
EY is committed to providing reasonable accommodation to qualified individuals with disabilities including veterans with disabilities. If you have a disability and either need assistance applying online or need to request an accommodation during any part of the application process, please call 1-800-EY-HELP3, select Option 2 for candidate related inquiries, then select Option 1 for candidate queries and finally select Option 2 for candidates with an inquiry which will route you to EY’s Talent Shared Services Team (TSS) or email the TSS at ssc.customersupport@ey.com.