798,808open jobs
51,006companies
125,723added this week
Browse all
Salary
$107k – $177k per year
Location
Hybrid (United States)
Seniority
Senior · 8+ years exp

Confirmed on the employer's own hiring board on Sep 26, 2026. First seen by Alion on Sep 25, 2026.

Overview
Company
Impact
Profile match
Headquartered in London, United Kingdom, EY (Ernst & Young) is a multinational professional services network and one of the "Big Four" accounting firms. The organization provides financial assurance and auditing, tax advisory, management and technology consulting, and strategy and transactions advisory through its EY-Parthenon arm. Operating across more than 150 countries, it delivers risk management, digital transformation, data analytics, and regulatory compliance solutions to multinational corporations, financial institutions, and government entities worldwide.

Location: Anywhere in Country

At EY, we’re all in to shape your future with confidence.

We’ll help you succeed in a globally connected powerhouse of diverse teams and take your career wherever you want it to go. Join EY and help to build a better working world.

The opportunity

We are seeking AI Systems Engineers to own the security and trust fabric of EY’s AI-native platform, comprising the identity, secrets, cryptographic, and attestation layer that makes agentic AI workloads deployable in highly regulated environments. This role owns the enforcement mechanisms that allow EY to prove every workload is identity-bound, every secret is protected, every node is trusted, and every deployment is attestable and audit-ready.

This is the strategic differentiator of the platform. The ability to deploy AI workloads in regulated industries and prove they are secure, economically bounded, and auditable depends on the trust fabric this role builds. It is the technical enforcement layer behind the AI Integrity / Security control authority and much of the platform’s governance capabilities, spanning consistently across cloud, on-prem, edge, and air-gapped environments.

Your key responsibilities

  • Own workload identity and secrets management: SPIRE/ODIS, Keycloak/Entra ID (IAM), OpenBao (secrets store), cert-manager (X.509 lifecycle), PKI issuers/roots, and transit encryption - propagated consistently across every environment and tenant.
  • Build confidential compute environments: TEE (TDX/SEV-SNP/SGX/TrustZone/CCA/NVIDIA CC), Intel TXT boot security, and secure DPU architecture (DOCA), so environments are isolated, attestable, and audit-ready.
  • Establish the platform-wide identity model so every workload, agent, and service carries a verifiable, propagated identity that flows through telemetry, cost attribution, and policy enforcement end-to-end.
  • Own the cryptographic lifecycle: issuance, rotation, revocation, and expiry of certificates, keys, and roots, with zero manual, untracked secrets and no long-lived credential sprawl across tenants.
  • Enforce attestation policy: which nodes, enclaves, and workloads are trusted, how trust is proven at boot and at runtime, and how attestation evidence is captured for audit.
  • Partner on a dotted-line basis with Enterprise Security / Cloud Platform / SRE to ensure independent review, alignment to enterprise trust standards, and audit readiness in regulated client contexts.

Skills and attributes for success

  • Deep expertise in workload identity, secrets management, PKI, and cryptographic lifecycle at production scale across multiple environments.
  • Strong understanding of confidential compute, trusted execution environments, hardware roots of trust, and remote attestation.
  • A security-first mindset: thinking in terms of provable trust, blast radius, least privilege, and cryptographic attribution rather than perimeter or convenience.
  • Ability to encode trust and compliance directly into infrastructure so that security is enforced by the platform, not by manual review.
  • Comfortable operating across cloud, on-prem, edge, and air-gapped environments with consistent identity and trust mechanisms.
  • Strong communicator able to explain trust, identity, and attestation tradeoffs to engineers, architects, auditors, and leadership.
  • Orientation toward auditability and evidence: able to translate regulatory expectations into technical controls and demonstrable proof.

To qualify you must have

  • Bachelor’s or Master’s degree in Computer Science, Security, or related technical field, or equivalent experience.
  • 8+ years in security engineering, identity/PKI, or trust infrastructure, with hands-on production ownership.
  • Deep, hands-on expertise with workload identity (SPIRE/SPIFFE), IAM (Keycloak/Entra ID), and secrets management (OpenBao/Vault).
  • Strong grounding in PKI, X.509 certificate lifecycle (cert-manager), key management, and transit encryption.
  • Working experience with confidential compute and hardware attestation (TDX, SEV-SNP, SGX, NVIDIA CC, or equivalents) and secure boot (Intel TXT).
  • Experience delivering identity and secrets consistently across multi-tenant, multi-environment (cloud/on-prem/edge/air-gapped) platforms.
  • Proven track record operating under compliance, security, or regulatory constraints with audit-grade evidence requirements.
  • Ability to define clean ownership boundaries and consumption contracts with platform, data, and runtime teams.

Ideally, you’ll also have

  • Familiarity with secure DPU architectures (DOCA) and hardware root-of-trust / boot-chain designs.
  • Experience integrating identity and attestation into service mesh, policy engines (OPA), and API gateways.
  • Exposure to AI/ML workloads and the specific trust challenges of confidential AI inference (models/secrets inside enclaves).
  • Experience producing attestation and compliance evidence for external auditors or regulators.
  • Relevant certifications (e.g., CISSP, cloud security specialties) or demonstrable equivalent depth.
  • Exposure to regulated industries (financial services, tax, healthcare, risk).

What we offer you

At EY, we’ll develop you with future-focused skills and equip you with world-class experiences. We’ll empower you in a flexible environment, and fuel you and your extraordinary talents in a diverse and inclusive culture of globally connected teams. Learn more.

  • We offer a comprehensive compensation and benefits package where you’ll be rewarded based on your performance and recognized for the value you bring to the business. The base salary range for this job in all geographic locations in the US is $106,900 to $176,500. The base salary range for New York City Metro Area, Washington State and California (excluding Sacramento) is $128,400 to $200,600. Individual salaries within those ranges are determined through a wide variety of factors including but not limited to education, experience, knowledge, skills and geography. In addition, our Total Rewards package includes medical and dental coverage, pension and 401(k) plans, and a wide range of paid time off options.
  • Join us in our team-led and leader-enabled hybrid model. Our expectation is for most people in external, client serving roles to work together in person 40-60% of the time over the course of an engagement, project or year.
  • Under our flexible vacation policy, you’ll decide how much vacation time you need based on your own personal circumstances. You’ll also be granted time off for designated EY Paid Holidays, Winter/Summer breaks, Personal/Family Care, and other leaves of absence when needed to support your physical, financial, and emotional well-being.

Are you ready to shape your future with confidence? Apply today.

EY accepts applications for this position on an on-going basis.

For those living in California, please click here for additional information.

EY focuses on high-ethical standards and integrity among its employees and expects all candidates to demonstrate these qualities.

EY | Building a better working world

EY is building a better working world by creating new value for clients, people, society and the planet, while building trust in capital markets.

Enabled by data, AI and advanced technology, EY teams help clients shape the future with confidence and develop answers for the most pressing issues of today and tomorrow.

EY teams work across a full spectrum of services in assurance, consulting, tax, strategy and transactions. Fueled by sector insights, a globally connected, multi-disciplinary network and diverse ecosystem partners, EY teams can provide services in more than 150 countries and territories.

EY provides equal employment opportunities to applicants and employees without regard to race, color, religion, age, sex, sexual orientation, gender identity/expression, pregnancy, genetic information, national origin, protected veteran status, disability status, or any other legally protected basis, including arrest and conviction records, in accordance with applicable law.

EY is committed to providing reasonable accommodation to qualified individuals with disabilities including veterans with disabilities. If you have a disability and either need assistance applying online or need to request an accommodation during any part of the application process, please call 1-800-EY-HELP3, select Option 2 for candidate related inquiries, then select Option 1 for candidate queries and finally select Option 2 for candidates with an inquiry which will route you to EY’s Talent Shared Services Team (TSS) or email the TSS at [email protected].

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
798,808 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account Continue with Google
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

AI/ML
Similar stack
Same company
In your city
$450k per year • In office • Full-Time • San Francisco
Apply
≈ $162k – $294k per year (Estimated) • In office • Full-Time • 3+ years exp • Master's Degree • San Jose
AI/ML
Reinforcement Learning
Multimodal AI
Diffusion Models
Computer Vision
AI Agents
World Models
Embodied AI
Machine Learning
Apply
≈ $145k – $281k per year (Estimated) • In office • Full-Time • 3+ years exp • San Jose
Python
C++
AI/ML
Diffusion Models
Computer Vision
GAN
Robotics
Localization
Apply
≈ $135k – $262k per year (Estimated) • In office • Full-Time • 3+ years exp • Bachelor's Degree • Seattle
Python
Java
Ruby
C++
Scala
MATLAB
AI/ML
Machine Learning
Apply
≈ $155k – $282k per year (Estimated) • In office • Full-Time • 3+ years exp • Bachelor's Degree • San Jose
AI/ML
NLP
Recommender Systems
Machine Learning
Apply
≈ $42k – $87k per year (Estimated) • Hybrid • Full-Time • 15+ years exp • Bachelor's Degree • Hyderabad
Python
Java
Scala
Databases
Snowflake
AI/ML
Spark
dbt
AI Agents
LLM
RAG
Feature Store
Machine Learning
DevOps
Terraform
CloudFormation
Azure
CI/CD
Git
AWS
Docker
Kubernetes
Cybersecurity
GDPR
Analytics
Power BI
ETL/ELT
Management
Agile
Apply
ML/AI Engineer 1 day ago
$96k – $107k per year • Hybrid • Confidential • Full-Time • PhD • Manchester
Python
Databases
Google BigQuery
BigQuery
AI/ML
LangGraph
LangChain
Model Context Protocol
CUDA Toolkit
MLFlow
Vertex AI
RLHF
AI Agents
TensorRT
Kubeflow
Google ADK
Ray
CUDA
Triton
TorchServe
Feature Store
Human-in-the-Loop
Machine Learning
DevOps
GCP
Helm
Dynatrace
Prometheus
CI/CD
GitOps
Git
Docker
Kubernetes
Grafana
Service Mesh
Google GKE
Google Cloud Run
Progressive Delivery
Apply
≈ $34k – $66k per year (Estimated) • In office • Internship • Bachelor's Degree • Singapore
AI/ML
AI Agents
Apply
In office • Bengaluru
Python
JavaScript
Python
FastAPI
Django
AI/ML
LangChain
LlamaIndex
Prompt Engineering
AI Agents
RAG
DevOps
Rest API
Apply
≈ $21k – $43k per year (Estimated) • Hybrid • Full-Time • Moscow
AI/ML
AI Agents
LLM
LLM Guardrails
Apply
$144k – $329k per year • Hybrid • 10+ years exp • Westlake
Python
Java
Rust
TypeScript
AI/ML
Cursor
Claude Code
AI Agents
Federated Learning
Post-training
Multi-Agent Systems
DevOps
Azure DevOps
Azure
CI/CD
AWS
GitHub
GitLab
Apply
$126k – $230k per year • Hybrid • Bachelor's Degree • Des Moines
AI/ML
AI Agents
LLM
Apply
$126k – $230k per year • Hybrid • 5+ years exp • San Antonio
Python
Java
Rust
AI/ML
Cursor
Claude Code
LoRA
Fine-tuning
AI Agents
PEFT
Transformers
RAG
SFT
Post-training
Multi-Agent Systems
DevOps
Azure DevOps
Azure
CI/CD
AWS
GitHub
GitLab
Apply
$107k – $177k per year • Hybrid • Bachelor's Degree • Fort Worth
Databases
Apache Kafka
AI/ML
Ray Serve
vLLM
MLFlow
Langfuse
LangSmith
LLM
Ray
Triton
Hugging Face
DevOps
GitHub Actions
Jaeger
Loki
OpenTelemetry
Prometheus
GitLab CI
CI/CD
GitOps
ArgoCD
Kubernetes
Grafana
Harbor
Platform Engineering
Mimir
JFrog Artifactory
FinOps
SLI/SLO/SLA
Cybersecurity
Trivy
CVE
SBOM
Apply
$144k – $329k per year • Hybrid • 10+ years exp • Philadelphia
Python
Java
Rust
AI/ML
Cursor
Claude Code
LoRA
Fine-tuning
AI Agents
PEFT
Transformers
RAG
SFT
Post-training
Multi-Agent Systems
DevOps
Azure DevOps
Azure
CI/CD
AWS
GitHub
GitLab
Apply
See all jobs
This is one of many
798,808 more open roles from verified company boards, updated every day.