×
Register Here to Apply for Jobs or Post Jobs. X

AI Systems Engineer - Secure Execution - Senior

Job in Wichita, Sedgwick County, Kansas, 67232, USA
Listing for: EY
Full Time position
Listed on 2026-09-01
Job specializations:
  • IT/Tech
    Cybersecurity, Security Management & Operations, Information Security & Data Protection
Salary/Wage Range or Industry Benchmark: 107000 - 177000 USD Yearly USD 107000.00 177000.00 YEAR
Job Description & How to Apply Below

Location:

Anywhere in Country

At EY, we’re all in to shape your future with confidence.

We’ll help you succeed in a globally connected powerhouse of diverse teams and take your career wherever you want it to go. Join EY and help to build a better working world.

The opportunity

We are seeking AI Systems Engineers to own the security and trust fabric of EY’s AI-native platform, comprising the identity, secrets, cryptographic, and attestation layer that makes agentic AI workloads deployable in highly regulated environments. This role owns the enforcement mechanisms that allow EY to prove every workload is identity-bound, every secret is protected, every node is trusted, and every deployment is at testable and audit-ready.

This is the strategic differentiator of the platform. The ability to deploy AI workloads in regulated industries and prove they are secure, economically bounded, and auditable depends on the trust fabric this role builds. It is the technical enforcement layer behind the AI Integrity / Security control authority and much of the platform’s governance capabilities, spanning consistently across cloud, on‑prem, edge, and air‑gapped environments.

Your

Key Responsibilities
  • Own workload identity and secrets management: SPIRE/ODIS, Keycloak/Entra  (IAM), Open Bao (secrets store), cert‑manager (X.509 lifecycle), PKI issuers/roots, and transit encryption — propagated consistently across every environment and tenant.
  • Build confidential compute environments: TEE (TDX/SEV‑SNP/SGX/Trust Zone/CCA/NVIDIA CC), Intel TXT boot security, and secure DPU architecture (DOCA), so environments are isolated, at testable, and audit-ready.
  • Establish the platform‑wide identity model so every workload, agent, and service carries a verifiable, propagated identity that flows through telemetry, cost attribution, and policy enforcement end‑to‑end.
  • Own the cryptographic lifecycle: issuance, rotation, revocation, and expiry of certificates, keys, and roots, with zero manual, untracked secrets and no long‑lived credential sprawl across tenants.
  • Enforce attestation policy: which nodes, enclaves, and workloads are trusted, how trust is proven at boot and at runtime, and how attestation evidence is captured for audit.
  • Partner on a dotted‑line basis with Enterprise Security / Cloud Platform / SRE to ensure independent review, alignment to enterprise trust standards, and audit readiness in regulated client contexts.
Skills And Attributes For Success
  • Deep expertise in workload identity, secrets management, PKI, and cryptographic lifecycle at production scale across multiple environments.
  • Strong understanding of confidential compute, trusted execution environments, hardware roots of trust, and remote attestation.
  • A security‑first mindset: thinking in terms of provable trust, blast radius, least privilege, and cryptographic attribution rather than perimeter or convenience.
  • Ability to encode trust and compliance directly into infrastructure so that security is enforced by the platform, not by manual review.
  • Comfortable operating across cloud, on‑prem, edge, and air‑gapped environments with consistent identity and trust mechanisms.
  • Strong communicator able to explain trust, identity, and attestation tradeoffs to engineers, architects, auditors, and leadership.
  • Orientation toward auditability and evidence: able to translate regulatory expectations into technical controls and demonstrable proof.
To qualify you must have
  • Bachelor’s or Master’s degree in Computer Science, Security, or related technical field, or equivalent experience.
  • 8+ years in security engineering, identity/PKI, or trust infrastructure, with hands‑on production ownership.
  • Deep, hands‑on expertise with workload identity (SPIRE/SPIFFE), IAM (Keycloak/Entra ), and secrets management (Open Bao/Vault).
  • Strong grounding in PKI, X.509 certificate lifecycle (cert‑manager), key management, and transit encryption.
  • Working experience with confidential compute and hardware attestation (TDX, SEV‑SNP, SGX, NVIDIA CC, or equivalents) and secure boot (Intel TXT).
  • Experience delivering identity and secrets consistently across multi‑tenant, multi‑environment (cloud/on‑prem/edge/air‑gapped) platforms.
  • Pro…
Position Requirements
10+ Years work experience
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary