AI Systems Engineer - Secure Execution - Senior
$106.9k - $200.6kErnst & Young
Location: Anywhere in Country
At EY, we’re all in to shape your future with confidence.
We’ll help you succeed in a globally connected powerhouse of diverse teams and take your career wherever you want it to go. Join EY and help to build a better working world.
The opportunity
We are seeking AI Systems Engineers to own the security and trust fabric of EY’s AI-native platform, comprising the identity, secrets, cryptographic, and attestation layer that makes agentic AI workloads deployable in highly regulated environments. This role owns the enforcement mechanisms that allow EY to prove every workload is identity-bound, every secret is protected, every node is trusted, and every deployment is attestable and audit-ready.
This is the strategic differentiator of the platform. The ability to deploy AI workloads in regulated industries and prove they are secure, economically bounded, and auditable depends on the trust fabric this role builds. It is the technical enforcement layer behind the AI Integrity / Security control authority and much of the platform’s governance capabilities, spanning consistently across cloud, on-prem, edge, and air-gapped environments.
Your key responsibilities
- Own workload identity and secrets management: SPIRE/ODIS, Keycloak/Entra ID (IAM), OpenBao (secrets store), cert-manager (X.509 lifecycle), PKI issuers/roots, and transit encryption — propagated consistently across every environment and tenant.
- Build confidential compute environments: TEE (TDX/SEV-SNP/SGX/TrustZone/CCA/NVIDIA CC), Intel TXT boot security, and secure DPU architecture (DOCA), so environments are isolated, attestable, and audit-ready.
- Establish the platform-wide identity model so every workload, agent, and service carries a verifiable, propagated identity that flows through telemetry, cost attribution, and policy enforcement end-to-end.
- Own the cryptographic lifecycle: issuance, rotation, revocation, and expiry of certificates, keys, and roots, with zero manual, untracked secrets and no long-lived credential sprawl across tenants.
- Enforce attestation policy: which nodes, enclaves, and workloads are trusted, how trust is proven at boot and at runtime, and how attestation evidence is captured for audit.
- Partner on a dotted-line basis with Enterprise Security / Cloud Platform / SRE to ensure independent review, alignment to enterprise trust standards, and audit readiness in regulated client contexts.
Skills and attributes for success
- Deep expertise in workload identity, secrets management, PKI, and cryptographic lifecycle at production scale across multiple environments.
- Strong understanding of confidential compute, trusted execution environments, hardware roots of trust, and remote attestation.
- A security-first mindset: thinking in terms of provable trust, blast radius, least privilege, and cryptographic attribution rather than perimeter or convenience.
- Ability to encode trust and compliance directly into infrastructure so that security is enforced by the platform, not by manual review.
- Comfortable operating across cloud, on-prem, edge, and air-gapped environments with consistent identity and trust mechanisms.
- Strong communicator able to explain trust, identity, and attestation tradeoffs to engineers, architects, auditors, and leadership.
- Orientation toward auditability and evidence: able to translate regulatory expectations into technical controls and demonstrable proof.
To qualify you must have
- Bachelor’s or Master’s degree in Computer Science, Security, or related technical field, or equivalent experience.
- 8+ years in security engineering, identity/PKI, or trust infrastructure, with hands-on production ownership.
- Deep, hands-on expertise with workload identity (SPIRE/SPIFFE), IAM (Keycloak/Entra ID), and secrets management (OpenBao/Vault).
- Strong grounding in PKI, X.509 certificate lifecycle (cert-manager), key management, and transit encryption.
- Working experience with confidential compute and hardware attestation (TDX, SEV-SNP, SGX, NVIDIA CC, or equivalents) and secure boot (Intel TXT).
- Experience delivering identity and secrets consistently across multi-tenant, multi-environment (cloud/on-prem/edge/air-gapped) platforms.
- Proven track record operating under compliance, security, or regulatory constraints with audit-grade evidence requirements.
- Ability to define clean ownership boundaries and consumption contracts with platform, data, and runtime teams.
Ideally, you’ll also have
- Familiarity with secure DPU architectures (DOCA) and hardware root-of-trust / boot-chain designs.
- Experience integrating identity and attestation into service mesh, policy engines (OPA), and API gateways.
- Exposure to AI/ML workloads and the specific trust challenges of confidential AI inference (models/secrets inside enclaves).
- Experience producing attestation and compliance evidence for external auditors or regulators.
- Relevant certifications (e.g., CISSP, cloud security specialties) or demonstrable equivalent depth.
- Exposure to regulated industries (financial services, tax, healthcare, risk).
What we offer you
At EY, we’ll develop you with future-focused skills and equip you with world-class experiences. We’ll empower you in a flexible environment, and fuel you and your extraordinary talents in a diverse and inclusive culture of globally connected teams. Learn more.
- We offer a comprehensive compensation and benefits package where you’ll be rewarded based on your performance and recognized for the value you bring to the business. The base salary range for this job in all geographic locations in the US is $106,900 to $176,500. The base salary range for New York City Metro Area, Washington State and California (excluding Sacramento) is $128,400 to $200,600. Individual salaries within those ranges are determined through a wide variety of factors including but not limited to education, experience, knowledge, skills and geography. In addition, our Total Rewards package includes medical and dental coverage, pension and 401(k) plans, and a wide range of paid time off options.
- Join us in our team-led and leader-enabled hybrid model. Our expectation is for most people in external, client serving roles to work together in person 40-60% of the time over the course of an engagement, project or year.
- Under our flexible vacation policy, you’ll decide how much vacation time you need based on your own personal circumstances. You’ll also be granted time off for designated EY Paid Holidays, Winter/Summer breaks, Personal/Family Care, and other leaves of absence when needed to support your physical, financial, and emotional well-being.
Are you ready to shape your future with confidence? Apply today.
EY accepts applications for this position on an on-going basis.
For those living in California, please click here for additional information.
EY focuses on high-ethical standards and integrity among its employees and expects all candidates to demonstrate these qualities.
EY | Building a better working world
EY is building a better working world by creating new value for clients, people, society and the planet, while building trust in capital markets.
Enabled by data, AI and advanced technology, EY teams help clients shape the future with confidence and develop answers for the most pressing issues of today and tomorrow.
EY teams work across a full spectrum of services in assurance, consulting, tax, strategy and transactions. Fueled by sector insights, a globally connected, multi-disciplinary network and diverse ecosystem partners, EY teams can provide services in more than 150 countries and territories.
EY provides equal employment opportunities to applicants and employees without regard to race, color, religion, age, sex, sexual orientation, gender identity/expression, pregnancy, genetic information, national origin, protected veteran status, disability status, or any other legally protected basis, including arrest and conviction records, in accordance with applicable law.
EY is committed to providing reasonable accommodation to qualified individuals with disabilities including veterans with disabilities. If you have a disability and either need assistance applying online or need to request an accommodation during any part of the application process, please call 1-800-EY-HELP3, select Option 2 for candidate related inquiries, then select Option 1 for candidate queries and finally select Option 2 for candidates with an inquiry which will route you to EY’s Talent Shared Services Team (TSS) or email the TSS at View email address on aiapply.co.
$106.9k - $200.6k
...opportunity We are seeking an AI Systems Engineer to own the delivery, model-... ...and deployed, how models execute, how requests are routed to... ...environments. Works with senior engineers to test and develop... ...pipelines that ship AI workloads, secure model execution, semantic...SeniorFull timeSummer holidayFlexible hours$106.9k - $200.6k
...working world. The opportunity We are seeking an AI Systems Engineer to own the stateful backbone of EY’s AI-native platform, including... ...track record operating data systems under compliance, security, or regulatory constraints, including data-at-rest and in-transit...SeniorFull timeSummer holidayFlexible hours- ...Description The Product Security team is responsible... ...throughout the System Development Life Cycle... ...background in systems engineering, coupled with a demonstrated... ...proposals and drive execution while proactively communicating... ...Pragmatic adoption of AI/LLM toolchains for...SeniorTemporary workRelocation package
- ...technology support to our Executive Leadership. You will... ..., more resilient systems and leveraging automation... ...through automation and AI, ensuring our... ...marketing, publishing, security, and player experience... ...white-glove service and engineering excellence. You thrive...SeniorFull timeLocal areaRemote workWorldwide
$190k - $250k
...beyond . About the Role: As a Senior Software Engineer - Security at Skydio, you will partner closely... ...teams to design, review, and build systems that secure our multi-tenant cloud and... ...a role that spans both strategy and execution Nice to have: Experience...SeniorFull timeLocal areaRelocation package- ...the best practices for engineering across the company.... ...Build tools that leverage AI and improve engineer... ...efficiency. Develop systems to automate mundane... ...LLMs for bug detection, security vulnerability assessment... ...-moving and highly execution-oriented team. Follow...SeniorTemporary workRelocation package
$134.41k - $181.84k
...innovation or solution engineering, our team members... ...skilled and innovative Senior Agentic AI Engineer to join the... ...autonomous multi-agent systems. The position plays a... ...and A2A for secure agent-to-agent coordination... ...Integrate secure tool execution environments, utilizing...SeniorLocal areaFlexible hours- ...Senior Systems Engineer Under the general supervision of the Manager, End User Computing and IAM... ...Provide concierge support to VIP/Executive personnel as needed Classification... ...Process and deployment Use client security (antivirus, encryption), remote support...SeniorWork experience placementRemote workFlexible hours
$125.5k - $261.6k
...The opportunity We are seeking AI Systems Engineers to build and operate the foundational... ...Management, so downstream runtime, data, and execution services can run safely and... ...capacity per tenant and engagement. Own secure execution and inference: Ray Serve, vLLM...Full timeContract workSummer holidayFlexible hours$144k - $374k
...opportunity We are seeking a senior, hands-on Distinguished Engineer to lead the delivery of AI-native systems into highly regulated... ...Engineering, Systems Design, Security, Compute, Data, Networking,... ...transform field observations into executive-ready recommendations,...SeniorFull timeTemporary workSummer holidayImmediate startFlexible hours- ...this new era, we seek AI-native thinkers... ...your role isn't just to execute a function, but to help... ...the power of AI. As a Senior Applied AI Engineer on our Cortex AI... ...measures and improves AI systems in production.... ...and optimization in secure, large-scale production...SeniorFull time
$147k - $184.8k
...location. Position Summary: The AI Security Engineer will be a key member of the "Structure... ...cybersecurity, experience with AI/ML systems, and expertise in cloud security, particularly... ...and data breaches. Develop and execute incident response plans specific to AI...Contract workWork at officeRemote work- ...Job Title: Senior AI Engineer Work Location: San Mateo, CA 94401 Contract duration: 06 Months Detailed Job Description o Design... ...integrations with ClientP for agent to tool integration and A2A for secure agent to agent coordination and task delegation. o...SeniorContract work
$205.2k - $360.8k
...Be the one building AI-powered experiences where... ...platform connects people, systems, data and AI to help... ...a Principal Software Engineer with deep, hands-on Genesys... ...invoke tools and APIs, execute business processes, and... ...including security, reliability, observability...SeniorWork from homeWorldwideFlexible hours$170k - $185k
...Senior Systems Engineer San Mateo, CA Mendaera is developing technology that will enable all healthcare providers to do more for their... ...specifications and KPIs; lead system level prioritization and execution. The position reports to Mendaera's Systems Engineering...Senior- ...Senior AI Application Engineer Working with Us Challenging. Meaningful. Life-changing... ...responsible for building secure cloud-hosted applications... ...integrate LLM APIs, retrieval systems, workflow engines, and... ...internal enterprise systems. Execute AI Accelerator cycles of...Senior
- ...life-changing impact to ZS. AI Engineer We are seeking an AI... ...performance and reliability of our systems. What You will Do: • Take... ...requirements • Own technical execution, ensuring code quality, adherence... ...and experience with security best practices and compliance...SeniorWork experience placementWork at officeLocal areaRemote workWork from homeWorldwideFlexible hours2 days per week3 days per week
$190k - $250k
...seeking a highly motivated, hands-on AI Engineer to spearhead the end-to-end... ...implementing and scaling production-ready AI systems that add business value by solving... ...capable of complex reasoning, secure tool usage, and autonomous execution of multi-step business workflows....Full timeContract workTemporary workRelocation package$326.06k - $385.05k
...everyone. As a Principal Security Software Engineer on the Production IAM team... ...Roblox Platform, mentor senior and staff engineers, and personally... ...hardest parts of these systems. As AI agents become first-class... ...for both engineers and executives, and you build alignment...Full timeWork experience placementH1bWork at officeLocal areaVisa sponsorshipMonday to Friday$216.68k - $269.17k
...experiences for everyone. Be a part of Roblox Corporation as a Senior Security Software Engineer in Vulnerability Management. Join our dedicated team to... ...through tools and services. Design and build automated systems to highlight security issues to owners and make...SeniorFull timeWork experience placementH1bWork at officeLocal areaVisa sponsorshipMonday to Friday- ...client, a rapidly growing AI infrastructure company,... ...seeking multiple AI Engineers (Enterprise) to help... ...into scalable production systems while collaborating with... .... Scope and execute proof-of-concept (POC)... ...through infrastructure, security, and compliance considerations...Full timeRemote workFlexible hours
- ...a passionate software engineer to help develop and advance... ...performant operating system that powers several... ...application Familiarity with security software: PKI, secure... ...fast-moving and highly execution-oriented team.... ...artificial intelligence (AI) tools to support parts...SeniorTemporary workRelocation package
- ...looking for a Staff Product Security Engineer to define and drive the long-... ...physical, safety-critical robotic system. In this role, you will:... ...of a fast-moving and highly execution-oriented team. Follow us... ...use artificial intelligence (AI) tools to support parts of the...SeniorTemporary workRelocation package
$100k - $150k
...practice integrates strategy, data, and AI to deliver scalable, technology-enabled... ...within our portfolio. As an AI Engineer / Senior AI Engineer , you will work across Blue... ...functional client-facing teams, develop and execute project plans to support initiatives that...SeniorFull timeTemporary workImmediate startFlexible hours- ...Networking team connects and secures these services,... ...infrastructure. We are executing on Cloud Bursting, a... ...network stack. Act as a senior voice on the team, mentoring junior engineers and promoting best... ...experience in distributed systems, with strong expertise...SeniorFull time
$269.17k - $326.06k
...experiences for everyone.The Security organization at... ...for designing and engineering secure systems from inception through... ...security solutions.As a Senior Security Software... ...controls for agentic and AI-assisted workflows,... ...one-off fixesHighly execution-focused and drive outcomes...SeniorFull timeWork experience placementH1bWork at officeLocal areaVisa sponsorshipMonday to Friday- ...this new era, we seek AI-native thinkers across... ...your role isn't just to execute a function, but to help... .... As a Staff AI Engineer on Cortex Code Quality... ...building the agentic systems and methodology that... ...’s confidentiality and security standards for handling...Full time
$245.14k - $302.82k
...results. Our people-first approach to AI eliminates friction, making employees... ...Description This role is the lead execution and strategic engine of the customer experience... ...championing Customer Success strategies that secure lasting adoption. The role does not manage...SeniorFlexible hours- ...We are looking for a Senior Software Engineer to lead the development... ..., scalable, and secure healthcare technology... ...scalable, high-performance systems using event-driven... ...Kibana).System Design & Execution System Design &... ...technologies (e.g., AI/ML integration, real-...SeniorRemote jobFull timeLocal area
- ...highly motivated, hands-on Lead AI Engineer to spearhead the end-to-end... ...enforcing identity-aware security, that transform operations across... ...(RBAC/ABAC) for agentic systems and establish observability... ...of a fast-moving and highly execution-oriented team. Follow us...Contract workTemporary workRelocation package
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to AI Systems Engineer - Secure Execution - Senior. Be the first to apply!
- ai engineer San Mateo, CA
- ai developer San Mateo, CA
- healthcare systems engineer San Mateo, CA
- mission system engineer San Mateo, CA
- senior linux systems engineer San Mateo, CA
- senior staff systems engineer San Mateo, CA
- systems engineer San Mateo, CA
- software system engineer San Mateo, CA
- digital communications systems engineer San Mateo, CA
- computer system validation engineer San Mateo, CA



