AI Systems Engineer - Secure Execution - Senior

Ernst & Young LLP
Madison, WI, United States
2 days ago
Apply on www.techcareers.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
8 years minimum
Compensation
$106,900.0 - $176,500.0
Working hours
Regular working hours

Tech stack

Artificial Intelligence Cloud Computing Security Data Auditing Identity and Access Management Key Management Public Key Infrastructure X.509 Cloud Platform System Okta Istio Information Technology U-Boot
+1 more
Api Gateway

Job description

  • Own workload identity and secrets management: SPIRE/ODIS, Keycloak/Entra ID (IAM), OpenBao (secrets store), cert-manager (X.509 lifecycle), PKI issuers/roots, and transit encryption - propagated consistently across every environment and tenant.
  • Build confidential compute environments: TEE (TDX/SEV-SNP/SGX/TrustZone/CCA/NVIDIA CC), Intel TXT boot security, and secure DPU architecture (DOCA), so environments are isolated, attestable, and audit-ready.
  • Establish the platform-wide identity model so every workload, agent, and service carries a verifiable, propagated identity that flows through telemetry, cost attribution, and policy enforcement end-to-end.
  • Own the cryptographic lifecycle: issuance, rotation, revocation, and expiry of certificates, keys, and roots, with zero manual, untracked secrets and no long-lived credential sprawl across tenants.
  • Enforce attestation policy: which nodes, enclaves, and workloads are trusted, how trust is proven at boot and at runtime, and how attestation evidence is captured for audit.
  • Partner on a dotted-line basis with Enterprise Security / Cloud Platform / SRE to ensure independent review, alignment to enterprise trust standards, and audit readiness in regulated client contexts.

Requirements

  • Deep expertise in workload identity, secrets management, PKI, and cryptographic lifecycle at production scale across multiple environments.
  • Strong understanding of confidential compute, trusted execution environments, hardware roots of trust, and remote attestation.
  • A security-first mindset: thinking in terms of provable trust, blast radius, least privilege, and cryptographic attribution rather than perimeter or convenience.
  • Ability to encode trust and compliance directly into infrastructure so that security is enforced by the platform, not by manual review.
  • Comfortable operating across cloud, on-prem, edge, and air-gapped environments with consistent identity and trust mechanisms.
  • Strong communicator able to explain trust, identity, and attestation tradeoffs to engineers, architects, auditors, and leadership.
  • Orientation toward auditability and evidence: able to translate regulatory expectations into technical controls and demonstrable proof.

To qualify you must have

  • Bachelor’s or Master’s degree in Computer Science, Security, or related technical field, or equivalent experience.
  • 8+ years in security engineering, identity/PKI, or trust infrastructure, with hands-on production ownership.
  • Deep, hands-on expertise with workload identity (SPIRE/SPIFFE), IAM (Keycloak/Entra ID), and secrets management (OpenBao/Vault).
  • Strong grounding in PKI, X.509 certificate lifecycle (cert-manager), key management, and transit encryption.
  • Working experience with confidential compute and hardware attestation (TDX, SEV-SNP, SGX, NVIDIA CC, or equivalents) and secure boot (Intel TXT).
  • Experience delivering identity and secrets consistently across multi-tenant, multi-environment (cloud/on-prem/edge/air-gapped) platforms.
  • Proven track record operating under compliance, security, or regulatory constraints with audit-grade evidence requirements.
  • Ability to define clean ownership boundaries and consumption contracts with platform, data, and runtime teams.

Ideally, you’ll also have

  • Familiarity with secure DPU architectures (DOCA) and hardware root-of-trust / boot-chain designs.
  • Experience integrating identity and attestation into service mesh, policy engines (OPA), and API gateways.
  • Exposure to AI/ML workloads and the specific trust challenges of confidential AI inference (models/secrets inside enclaves).
  • Experience producing attestation and compliance evidence for external auditors or regulators.
  • Relevant certifications (e.g., CISSP, cloud security specialties) or demonstrable equivalent depth.
  • Exposure to regulated industries (financial services, tax, healthcare, risk).

Benefits & conditions

At EY, we’ll develop you with future-focused skills and equip you with world-class experiences. We’ll empower you in a flexible environment, and fuel you and your extraordinary talents in a diverse and inclusive culture of globally connected teams. Learn more .

  • We offer a comprehensive compensation and benefits package where you’ll be rewarded based on your performance and recognized for the value you bring to the business. The base salary range for this job in all geographic locations in the US is $106,900 to $176,500. The base salary range for New York City Metro Area, Washington State and California (excluding Sacramento) is $128,400 to $200,600. Individual salaries within those ranges are determined through a wide variety of factors including but not limited to education, experience, knowledge, skills and geography. In addition, our Total Rewards package includes medical and dental coverage, pension and 401(k) plans, and a wide range of paid time off options.
  • Join us in our team-led and leader-enabled hybrid model. Our expectation is for most people in external, client serving roles to work together in person 40-60% of the time over the course of an engagement, project or year.
  • Under our flexible vacation policy, you’ll decide how much vacation time you need based on your own personal circumstances. You’ll also be granted time off for designated EY Paid Holidays, Winter/Summer breaks, Personal/Family Care, and other leaves of absence when needed to support your physical, financial, and emotional well-being.

About the company

We’ll help you succeed in a globally connected powerhouse of diverse teams and take your career wherever you want it to go. Join EY and help to build a better working world., EY focuses on high-ethical standards and integrity among its employees and expects all candidates to demonstrate these qualities.

EY Building a better working world

EY is building a better working world by creating new value for clients, people, society and the planet, while building trust in capital markets.

Enabled by data, AI and advanced technology, EY teams help clients shape the future with confidence and develop answers for the most pressing issues of today and tomorrow.

EY teams work across a full spectrum of services in assurance, consulting, tax, strategy and transactions. Fueled by sector insights, a globally connected, multi-disciplinary network and diverse ecosystem partners, EY teams can provide services in more than 150 countries and territories.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.techcareers.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:28 min

Requirements for deploying secure AI systems in public sectors

Isha Salania Isha Salania · World Congress 2026 Europe

2:33 min

Introduction to security advocacy and automation testing

Chris Heilmann +2 · LIVE

2:53 min

Configuring dynamic proxy updates with Istio Pilot

Jan Mensch Jan Mensch · World Congress 2026 Europe

4:37 min

Architecting single sign-on flows across multiple application domains

Gift Egwuenu · World Congress 2023

7:15 min

Installing Istio programmatically with bash scripts

Thomas Südbröcker · LIVE

1:20 min

Identifying multi-disciplinary talent for developer experience engineering roles

Hazal Mestci +1 · Coffee With Developers

Videos

See all

Related articles

See all