
AI Systems Engineer - Secure Execution - Senior
Ernst and Young1 hour ago
Base Salary
$107k - $201k/yr
Responsibilities
- Own workload identity and secrets management using SPIRE/ODIS, Keycloak/Entra ID, OpenBao, cert-manager, PKI issuers and roots, and transit encryption.
- Build confidential computing environments using trusted execution environments, secure boot, hardware attestation, and secure DPU architecture.
- Establish a platform-wide identity model for workloads, agents, and services across telemetry, cost attribution, and policy enforcement.
- Own certificate, key, and root issuance, rotation, revocation, and expiry while eliminating untracked and long-lived secrets.
- Define and enforce attestation policies for trusted nodes, enclaves, and workloads and capture evidence for audits.
- Partner with Enterprise Security, Cloud Platform, and SRE on independent review, trust standards, and audit readiness.
- Translate regulatory expectations into enforceable technical controls and demonstrable evidence across multi-tenant environments.
Requirements
- Bachelor’s or Master’s degree in Computer Science, Security, or a related technical field, or equivalent experience.
- 8+ years of experience in security engineering, identity/PKI, or trust infrastructure with hands-on production ownership.
- Deep expertise in workload identity, including SPIRE/SPIFFE, IAM, Keycloak/Entra ID, and secrets management with OpenBao/Vault.
- Strong grounding in PKI, X.509 certificate lifecycle, cert-manager, key management, and transit encryption.
- Experience with confidential compute, trusted execution environments, hardware attestation, and secure boot.
- Experience delivering identity and secrets across multi-tenant, multi-environment cloud, on-premises, edge, and air-gapped platforms.
- Experience operating under compliance, security, or regulatory constraints with audit-grade evidence requirements.
- Ability to define ownership boundaries and consumption contracts with platform, data, and runtime teams.
- Preferred familiarity with DOCA, hardware roots of trust, boot-chain designs, service meshes, OPA, API gateways, confidential AI inference, external audit evidence, relevant security certifications, and regulated industries.
Benefits
- Base salary ranges from $106,900 to $176,500 in most US locations and from $128,400 to $200,600 in New York City Metro Area, Washington State, and California excluding Sacramento.
- Medical and dental coverage, pension and 401(k) plans, and paid time off options are offered.
- The role follows a flexible hybrid model, with most external client-serving employees expected to work in person 40–60% of the time during an engagement, project, or year.
- Benefits include flexible vacation, EY paid holidays, winter and summer breaks, personal and family care time, and other leaves of absence.
- Applications are accepted on an ongoing basis.
Tech Stack
Vault