AI Systems Engineer - Secure Execution - Senior
EY · Baton Rouge, LA · 2 days ago
Hybrid$107k–$177k/yrFull-time
About the role
We are seeking AI Systems Engineers to own the security and trust fabric of EY's AI-native platform.
Responsibilities
- Own workload identity and secrets management: SPIRE/ODIS, Keycloak/Entra ID (IAM), OpenBao (secrets store), cert-manager (X.509 lifecycle), PKI issuers/roots, and transit encryption — propagated consistently across every environment and tenant.
- Build confidential compute environments: TEE (TDX/SEV-SNP/SGX/TrustZone/CCA/NVIDIA CC), Intel TXT boot security, and secure DPU architecture (DOCA), so environments are isolated, attestable, and audit-ready.
- Establish the platform-wide identity model so every workload, agent, and service carries a verifiable, propagated identity that flows through telemetry, cost attribution, and policy enforcement end-to-end.
- Own the cryptographic lifecycle: issuance, rotation, revocation, and expiry of certificates, keys, and roots, with zero manual, untracked secrets and no long-lived credential sprawl across tenants.
- Enforce attestation policy: which nodes, enclaves, and workloads are trusted, how trust is proven at boot and at runtime, and how attestation evidence is captured for audit.
- Partner on a dotted-line basis with Enterprise Security / Cloud Platform / SRE to ensure independent review, alignment to enterprise trust standards, and audit readiness in regulated client contexts.
Requirements
- Deep expertise in workload identity, secrets management, PKI, and cryptographic lifecycle at production scale across multiple environments.
- Strong understanding of confidential compute, trusted execution environments, hardware roots of trust, and remote attestation.
- Security-first mindset: thinking in terms of provable trust, blast radius, least privilege, and cryptographic attribution rather than perimeter or convenience.
- Ability to encode trust and compliance directly into infrastructure so that security is enforced by the platform, not by manual review.
- Comfortable operating across cloud, on-prem, edge, and air-gapped environments with consistent identity and trust mechanisms.
- Strong communicator able to explain trust, identity, and attestation tradeoffs to engineers, architects, auditors, and leadership.
- Orientation toward auditability and evidence: able to translate regulatory expectations into technical controls and demonstrable proof.
Attributes for Success
- Deep, hands-on expertise with workload identity (SPIRE/SPIFFE), IAM (Keycloak/Entra ID), and secrets management (OpenBao/Vault).
- Strong grounding in PKI, X.509 certificate lifecycle (cert-manager), key management, and transit encryption.
- Working experience with confidential compute and hardware attestation (TDX, SEV-SNP, SGX, NVIDIA CC, or equivalents) and secure boot (Intel TXT).
- Experience delivering identity and secrets consistently across multi-tenant, multi-environment (cloud/on-prem/edge/air-gapped) platforms.
- Proven track record operating under compliance, security, or regulatory constraints with audit-grade evidence requirements.
- Ability to define clean ownership boundaries and consumption contracts with platform, data, and runtime teams.
- Familiarity with secure DPU architectures (DOCA) and hardware root-of-trust / boot-chain designs.
- Experience integrating identity and attestation into service mesh, policy engines (OPA), and API gateways.
- Exposure to AI/ML workloads and the specific trust challenges of confidential AI inference (models/secrets inside enclaves).
- Experience producing attestation and compliance evidence for external auditors or regulators.
- Relevant certifications (e.g., CISSP, cloud security specialties) or demonstrable equivalent depth.
- Exposure to regulated industries (financial services, tax, healthcare, risk).
What We Offer
- Cumulative compensation and benefits package where you'll be rewarded based on your performance and recognized for the value you bring to the business.
- Base salary range for this job in all geographic locations in the US is $106,900 to $176,500.
- Base salary range for New York City Metro Area, Washington State and California (excluding Sacramento) is $128,400 to $200,600.
- Individual salaries within those ranges are determined through a wide variety of factors including but not limited to education, experience, knowledge, skills and geography.
- Total Rewards package includes medical and dental coverage, pension and 401(k) plans, and a wide range of paid time off options.
- Flexible vacation policy where you'll decide how much vacation time you need based on your own personal circumstances.
- Time off for designated EY Paid Holidays, Winter/Summer breaks, Personal/Family Care, and other leaves of absence when needed to support your physical, financial, and emotional well-being.