AI Systems Engineer - Secure Execution - Senior
$106.9k - $200.6kErnst & Young
Location: Anywhere in Country
At EY, we’re all in to shape your future with confidence.
We’ll help you succeed in a globally connected powerhouse of diverse teams and take your career wherever you want it to go. Join EY and help to build a better working world.
The opportunity
We are seeking AI Systems Engineers to own the security and trust fabric of EY’s AI-native platform, comprising the identity, secrets, cryptographic, and attestation layer that makes agentic AI workloads deployable in highly regulated environments. This role owns the enforcement mechanisms that allow EY to prove every workload is identity-bound, every secret is protected, every node is trusted, and every deployment is attestable and audit-ready.
This is the strategic differentiator of the platform. The ability to deploy AI workloads in regulated industries and prove they are secure, economically bounded, and auditable depends on the trust fabric this role builds. It is the technical enforcement layer behind the AI Integrity / Security control authority and much of the platform’s governance capabilities, spanning consistently across cloud, on-prem, edge, and air-gapped environments.
Your key responsibilities
- Own workload identity and secrets management: SPIRE/ODIS, Keycloak/Entra ID (IAM), OpenBao (secrets store), cert-manager (X.509 lifecycle), PKI issuers/roots, and transit encryption — propagated consistently across every environment and tenant.
- Build confidential compute environments: TEE (TDX/SEV-SNP/SGX/TrustZone/CCA/NVIDIA CC), Intel TXT boot security, and secure DPU architecture (DOCA), so environments are isolated, attestable, and audit-ready.
- Establish the platform-wide identity model so every workload, agent, and service carries a verifiable, propagated identity that flows through telemetry, cost attribution, and policy enforcement end-to-end.
- Own the cryptographic lifecycle: issuance, rotation, revocation, and expiry of certificates, keys, and roots, with zero manual, untracked secrets and no long-lived credential sprawl across tenants.
- Enforce attestation policy: which nodes, enclaves, and workloads are trusted, how trust is proven at boot and at runtime, and how attestation evidence is captured for audit.
- Partner on a dotted-line basis with Enterprise Security / Cloud Platform / SRE to ensure independent review, alignment to enterprise trust standards, and audit readiness in regulated client contexts.
Skills and attributes for success
- Deep expertise in workload identity, secrets management, PKI, and cryptographic lifecycle at production scale across multiple environments.
- Strong understanding of confidential compute, trusted execution environments, hardware roots of trust, and remote attestation.
- A security-first mindset: thinking in terms of provable trust, blast radius, least privilege, and cryptographic attribution rather than perimeter or convenience.
- Ability to encode trust and compliance directly into infrastructure so that security is enforced by the platform, not by manual review.
- Comfortable operating across cloud, on-prem, edge, and air-gapped environments with consistent identity and trust mechanisms.
- Strong communicator able to explain trust, identity, and attestation tradeoffs to engineers, architects, auditors, and leadership.
- Orientation toward auditability and evidence: able to translate regulatory expectations into technical controls and demonstrable proof.
To qualify you must have
- Bachelor’s or Master’s degree in Computer Science, Security, or related technical field, or equivalent experience.
- 8+ years in security engineering, identity/PKI, or trust infrastructure, with hands-on production ownership.
- Deep, hands-on expertise with workload identity (SPIRE/SPIFFE), IAM (Keycloak/Entra ID), and secrets management (OpenBao/Vault).
- Strong grounding in PKI, X.509 certificate lifecycle (cert-manager), key management, and transit encryption.
- Working experience with confidential compute and hardware attestation (TDX, SEV-SNP, SGX, NVIDIA CC, or equivalents) and secure boot (Intel TXT).
- Experience delivering identity and secrets consistently across multi-tenant, multi-environment (cloud/on-prem/edge/air-gapped) platforms.
- Proven track record operating under compliance, security, or regulatory constraints with audit-grade evidence requirements.
- Ability to define clean ownership boundaries and consumption contracts with platform, data, and runtime teams.
Ideally, you’ll also have
- Familiarity with secure DPU architectures (DOCA) and hardware root-of-trust / boot-chain designs.
- Experience integrating identity and attestation into service mesh, policy engines (OPA), and API gateways.
- Exposure to AI/ML workloads and the specific trust challenges of confidential AI inference (models/secrets inside enclaves).
- Experience producing attestation and compliance evidence for external auditors or regulators.
- Relevant certifications (e.g., CISSP, cloud security specialties) or demonstrable equivalent depth.
- Exposure to regulated industries (financial services, tax, healthcare, risk).
What we offer you
At EY, we’ll develop you with future-focused skills and equip you with world-class experiences. We’ll empower you in a flexible environment, and fuel you and your extraordinary talents in a diverse and inclusive culture of globally connected teams. Learn more.
- We offer a comprehensive compensation and benefits package where you’ll be rewarded based on your performance and recognized for the value you bring to the business. The base salary range for this job in all geographic locations in the US is $106,900 to $176,500. The base salary range for New York City Metro Area, Washington State and California (excluding Sacramento) is $128,400 to $200,600. Individual salaries within those ranges are determined through a wide variety of factors including but not limited to education, experience, knowledge, skills and geography. In addition, our Total Rewards package includes medical and dental coverage, pension and 401(k) plans, and a wide range of paid time off options.
- Join us in our team-led and leader-enabled hybrid model. Our expectation is for most people in external, client serving roles to work together in person 40-60% of the time over the course of an engagement, project or year.
- Under our flexible vacation policy, you’ll decide how much vacation time you need based on your own personal circumstances. You’ll also be granted time off for designated EY Paid Holidays, Winter/Summer breaks, Personal/Family Care, and other leaves of absence when needed to support your physical, financial, and emotional well-being.
Are you ready to shape your future with confidence? Apply today.
EY accepts applications for this position on an on-going basis.
For those living in California, please click here for additional information.
EY focuses on high-ethical standards and integrity among its employees and expects all candidates to demonstrate these qualities.
EY | Building a better working world
EY is building a better working world by creating new value for clients, people, society and the planet, while building trust in capital markets.
Enabled by data, AI and advanced technology, EY teams help clients shape the future with confidence and develop answers for the most pressing issues of today and tomorrow.
EY teams work across a full spectrum of services in assurance, consulting, tax, strategy and transactions. Fueled by sector insights, a globally connected, multi-disciplinary network and diverse ecosystem partners, EY teams can provide services in more than 150 countries and territories.
EY provides equal employment opportunities to applicants and employees without regard to race, color, religion, age, sex, sexual orientation, gender identity/expression, pregnancy, genetic information, national origin, protected veteran status, disability status, or any other legally protected basis, including arrest and conviction records, in accordance with applicable law.
EY is committed to providing reasonable accommodation to qualified individuals with disabilities including veterans with disabilities. If you have a disability and either need assistance applying online or need to request an accommodation during any part of the application process, please call 1-800-EY-HELP3, select Option 2 for candidate related inquiries, then select Option 1 for candidate queries and finally select Option 2 for candidates with an inquiry which will route you to EY’s Talent Shared Services Team (TSS) or email the TSS at View email address on aiapply.co.
- EY seeks AI Systems Engineers to own the security and trust fabric of EY’s AI-native platform, spanning identity, secrets, cryptography, and attestation. You will enforce workload identity, protect secrets, and ensure auditable, trusted deployments across cloud, on‑prem...Senior
- ...normalized" problem and the AI-native curiosity to create... ...01, 2026. Job Title: Senior Oracle Security and AI Engineer About the Role... ...Fusion environments, including executing scheduled environment refreshes... ...usage, and ensuring system configuration baselines....SeniorLocal area
$106.9k - $200.6k
...opportunity We are seeking an AI Systems Engineer to own the delivery, model-... ...and deployed, how models execute, how requests are routed to... ...environments. Works with senior engineers to test and develop... ...pipelines that ship AI workloads, secure model execution, semantic...SeniorFull timeSummer holidayFlexible hours$272k - $283k
...patented technology for secured credit provides an on-... ...customers to enter the credit system. Through PayJoy’s point... ..., and anti-fraud AI, we have served over 18... ...a specialized systems engineer focused on the heart of... ...and the TEE (Trusted Execution Environment) . In...SeniorFull timeLocal areaImmediate startHome office$167k - $223k
...sensing, autonomy, artificial intelligence (AI)/machine learning (ML), cybersecurity,... ...market opportunities. The ATO Systems Security Engineering Technical Leader is expected to provide... ...Experience in project leadership and execution. Experience working with U.S. Government...SeniorPermanent employmentContract workWork experience placementLocal areaRemote workRelocationRelocation package$106.9k - $200.6k
...working world. The opportunity We are seeking an AI Systems Engineer to own the stateful backbone of EY’s AI-native platform, including... ...track record operating data systems under compliance, security, or regulatory constraints, including data-at-rest and in-transit...SeniorFull timeSummer holidayFlexible hours$159.2k - $301.6k
The Opportunity We are looking for a Senior AI Systems Engineer with deep C++ expertise to help build... ...AI useful, reliable, observable, and secure. What You’ll Do AI-Native Systems Architecture... ...model-backed workflows. Define clean execution interfaces, schemas, validation...SeniorFull timeTemporary workLocal areaRemote workWorldwide$250k - $300k
...com, we are building the AI Search Infrastructure that powers modern AI systems. Our goal is to create... .... Our team includes engineers, researchers, product... ...with non-technical and executive stakeholders. What we... ...will provide the Social Security Administration (SSA)...SeniorFull timeImmediate startRemote workWork from homeFlexible hours- Cacheflow is seeking a Majors Account Executive to drive new business and strengthen existing relationships with large organizations regarding cloud security solutions. In this role, you will execute high-value sales engagements, working closely with security leaders and...SeniorFull time
- ...Capital One in San Francisco is seeking a Staff AI Engineer to build responsible AI systems, partnering with engineers, researchers, technical program managers, and product managers to deliver AI-powered products that transform how customers interact with Capital One....Senior
$200k - $300k
...Senior/Staff Applied AI Engineer, Agent Harness Company: Init Intelligence... ...coworkers for IT teams. Its security-focused product is an agent... ...never sees, and can operate systems it was never given an API... ...agent harness, including the execution loop, tool-use strategies,...SeniorFull timeContract workH1bWork at officeVisa sponsorshipMonday to Friday- Salesforce AI Research is looking for a Machine Learning Engineer to incubate next-generation agentic AI platform. You will work with research scientists, software... ...to design, implement and iterate agentic AI systems with customers. With your strong technical competence...Senior
$267k
...to protect, defend, and secure Uber's products, infrastructure... ...talented and experienced Senior Staff Software Engineer - (Agentic Systems) to lead our Enterprise... ...Roadmap: Define and execute the technical strategy and... ...Leverage automation and AI to transform enterprise defense...SeniorFull timeWork experience placementWork at officeRemote work$242.25k - $285k
...connected platform and AI-native ecosystem for... ...fragmented tools with a single system of record, Carta... ...’ll join Carta’s ML Engineering team, embedded in Carta... ...techniques. Execution: You have owned model... ...from unapproved domains to security@carta.com....SeniorFull timeContract work$143.2k - $243.4k
...It all started when engineer Fred Luddy wrote code that... ...Today, ServiceNow is the AI control tower for... ...Implementation: Design and build secure, performant... ...and customer enterprise systems including ServiceNow, Workday... ...to a customer's executive team. Customer-First...SeniorFull timeWork at officeImmediate startRemote workFlexible hoursDay shift- Senior Technical Expert Serves as a senior technical... ..., enterprise-wide engineering strategies for Al-enabled systems, computer hardware/... ...people. As an AI technical SME... ...federal mandates, executive orders, and/or other... ...data platforms, and secure computing infrastructures...Senior
- ...touchpoint with the healthcare system—driving over $300B in... ...We’re looking for a Senior Backend or Full-Stack Software Engineer (5+ years experience)... ...devices in a reliable, secure way Work closely with... ...decisions that balanced execution speed, scalability, and...SeniorFull timeTemporary workWork at officeMonday to FridayMonday to ThursdayFlexible hours
$143.2k - $243.4k
...all started when engineer Fred Luddy wrote code... ...ServiceNow is the AI control tower for... ...Role : As a Senior AI Agent Engineer... ...Platform with enterprise systems (ITSM, HRIS,... ...compliant with federal security and data-handling... ...to a customer's executive team....SeniorPermanent employmentFull timeWork at officeImmediate startRemote workFlexible hours- Staff/Senior Agentic AI Engineers (Multiple roles) San Francisco, California As a... ...autonomous, intelligent agents to execute multi-step medical reasoning and data workflows securely and at scale. Whether you... ...production-grade agentic systems from scratch, directly translating...Senior
- ...Senior AI Application Engineer Working with Us Challenging. Meaningful. Life-changing... ...responsible for building secure cloud-hosted applications... ...integrate LLM APIs, retrieval systems, workflow engines, and... ...internal enterprise systems. Execute AI Accelerator cycles of...Senior
$230k - $385k
AI Systems Engineer - Codex Core Agents About The Team The Codex Core Agents team builds the agent... ...and interpreting model outputs, executing actions safely in real environments, and... ...users under demanding reliability and security constraints. Open-source infrastructure...$165k - $200k
...Senior Systems Engineer Crusoe is on a mission to accelerate the abundance of... ...only vertically integrated AI infrastructure company built... ...ensure systems are reliable, secure, and scalable to support Crusoe... ...efficiency Planning and executing application integrations (...SeniorTemporary work$152k
...the role We are seeking an experienced Senior Systems Engineer to own our macOS platform and drive... ...– endpoint management, identity, and security tooling – with a primary focus on macOS... ...worked tirelessly to out‑hustle and out‑execute competitors to bring our mission to life...SeniorFull timeWork at officeLocal areaRemote workShift work$190k - $230k
...Senior Systems Engineer Crusoe is on a mission to accelerate the abundance of... ...only vertically integrated AI infrastructure company built... ...Engineer to play a key role in executing Crusoe's 2026 Enterprise AI... ...environments Embedding security, data privacy, and compliance...SeniorTemporary work$135k - $145k
...is looking for an experienced Level 3 Engineer / Senior Systems Engineer to join our technical team.... ...Projects & Migrations Plan and execute client IT infrastructure projects... ...Teams, and OneDrive. Networking & Security Design and troubleshoot...SeniorCasual workWork at officeRemote workRelocation$125.5k - $261.6k
...The opportunity We are seeking AI Systems Engineers to build and operate the foundational... ...Management, so downstream runtime, data, and execution services can run safely and... ...capacity per tenant and engagement. Own secure execution and inference: Ray Serve, vLLM...Full timeContract workSummer holidayFlexible hours- ...startup (1-10 employees) building AI coworkers for IT teams: a security-focused product where an agent registers... ...for human approval, and drives systems it was never given an API for. Raised... ...the core agent harness (the execution loop, tool-use strategies, context...SeniorFull timeContract workH1bVisa sponsorship
$200k - $235k
...enabling our clients to securely navigate the digital... ...We are seeking a Senior Application Security Engineer to lead the technical execution of our product security... ...services, key management systems (KMS), and advanced data... ...next-generation AI-integrated applications...SeniorFull timeWork at officeWorldwide- ...Risk Technology - Sap Grc & Security - Senior ConsultantLocation: New York... ...SAP applications Ability to execute defined tasks independently while... ...science, information systems, information security, or a related... ...of emerging SAP technologies such as BTP, SAC, AI, or RPA...SeniorShift work
- ...We’re looking for a Senior AI engineer to build the core intelligence behind AI teammates for finance. You’ll develop systems that go beyond copilots and actually execute work, combining reasoning, context, and action inside real enterprise workflows. What you’ll do...SeniorFull time
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to AI Systems Engineer - Secure Execution - Senior. Be the first to apply!
- ai engineer San Francisco, CA
- ai research engineer San Francisco, CA
- ai engineer remote San Francisco, CA
- ai prompt engineer San Francisco, CA
- ai developer San Francisco, CA
- senior ai engineer San Francisco, CA
- machine learning ai engineer San Francisco, CA
- ai ml engineer San Francisco, CA
- healthcare systems engineer San Francisco, CA
- mission system engineer San Francisco, CA



