AI Engineer

XPT Software Australia Pty Ltd

Sydney, City of Melbourne

On-site

AUD 180,000 - 240,000

Full time

40 hours ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

XPT Software Australia Pty Ltd is seeking a Senior AI/Software Engineer to design and implement the AI/agentic layer atop SAST/SCA pipelines. You'll build custom automation using OpenAI or similar LLM APIs and architect agentic patterns to reduce triage effort and speed up remediation.

Responsibilities include integrating GitLab findings via API/webhooks, developing LLM-based triage, guardrails, and audit logging, plus ensuring data governance and security compliance in regulated telco

Qualifications

  • 8+ years software/AI engineering experience, with 1–2 years hands-on building production LLM-based or agentic systems.
  • AppSec domain experience is a strong plus.
  • Hands-on experience with LLM APIs (OpenAI, Anthropic, or equivalent) including function calling and tool use.
  • Experience designing agentic systems with multi-step reasoning and human-in-the-loop checkpoints.
  • Strong software engineering skills to build integration pipelines (GitLab API/webhooks, CI/CD).
  • Understanding of prompt engineering best practices and evaluation methodology.
  • Knowledge of data governance/privacy implications of sending code and vulnerability data to third-party LLM APIs.

Responsibilities

  • Design and build integrations that pull SAST/SCA findings from GitLab into an external AI pipeline.
  • Develop LLM-based triage: false-positive scoring, plain-language explanations, remediation suggestions.
  • Create agentic workflows that relate dependencies CVEs to code usage and draft remediation MR.
  • Own prompt engineering, guardrails, approval gates, and audit logging for AI decisions.

Skills

LLM APIs
Agentic design
Software engineering
Prompt engineering
AppSec concepts
GitLab API/webhooks
Data governance

Job description

XPT Software Australia Pty Ltd | Contract

Sydney, Melbourne, Australia | Posted on 09/22/2026

  • XPT SoftwareAustralia PTY Ltd, incorporated in 2016, is a Software Services company
  • XPT works with topclients across Australia in Banking, Insurance, Telecom,Retail, Energy, Mining and Manufacturingdomains.
  • We have 120+technocrats in Australia working at our clientlocations.
  • XPT SoftwareAustralia is part of group companies which has globalpresence across India & Europe.
  • We have served100+ clients globally, fulfilling their onsite-offshoreneeds.
Job Description
Role Purpose

Build the AI/agentic layer on top of the SAST/SCAcapability . GitLab's own Duo/agentic features are out of scope for thisprogramme, so this role is responsible for designing and building customautomation using OpenAI (or equivalent LLM APIs) and agentic patterns to reducetriage effort, cut false-positive noise, and speed up remediation

KeyResponsibilities

Designand build integrations that pull SAST/SCA findings out of GitLab (viaAPI/webhooks) into an external pipeline for AI-assisted processing.

BuildLLM-based triage assistance: false-positive likelihood scoring, vulnerabilityexplanation in plain language, and contextual remediation suggestions generatedagainst the actual code diff/repo context.

Designagentic workflows (multi-step, tool-using LLM agents) that can, for example,correlate a dependency CVE with actual usage in code, check for available safeupgrade paths, and draft a remediation MR for human review.

Ownprompt engineering, evaluation, and guardrails for these agents — includinghallucination checks, human-in-the-loop approval gates before anyauto-generated fix reaches a merge request, and audit logging for everyAI-assisted decision.

Selectand integrate the LLM provider/stack (OpenAI API, or alternatives) factoring indata residency and confidentiality constraints — telco source code andvulnerability data leaving the environment via a third-party API is agovernance concern requiring explicit sign-off.

Buildfeedback loops so agent outputs (false-positive calls, fix suggestions) are measuredagainst actual analyst/developer decisions to improve accuracy over time.

Workwith the SME to ensure the AI layer complements rather than duplicates nativeGitLab scanning logic, and with the BA to translate desired outcomes (reducedMTTR, lower false-positive rate) into technical automation targets.

Documentarchitecture, data flows, and model usage for security/compliance review —critical in a regulated telco environment where any AI system touching sourcecode or vulnerability data will likely need a formal risk assessment.

ExperienceLevel

Senior, 8+ years software/AI engineering experience,with at least 1–2 years hands-on building production LLM-based or agenticsystems. AppSec domain experience is a strong plus.

RequiredKnowledge & Skills

Hands-onexperience with LLM APIs (OpenAI, Anthropic, or equivalent) — functioncalling/tool use, structured outputs, and context management at productionscale.

Practicalexperience designing agentic systems — multi-step reasoning, tool-useorchestration, and building in human-approval checkpoints rather than fullyautonomous action.

Strongsoftware engineering skills — able to build and maintain integration pipelines(GitLab API/webhooks, CI/CD hooks) rather than just prototyping in a notebook.

Understandingof prompt engineering best practices and evaluation methodology (how to measurewhether an AI triage decision is actually good, not just plausible-sounding).

Workingknowledge of AppSec concepts (SAST/SCA findings, CVE/CWE, vulnerabilityseverity) sufficient to build meaningful automation.

Awarenessof data governance/privacy implications of sending code and vulnerability datato third-party LLM APIs, and experience implementing controls (redaction,on-prem/private deployment options, data retention policies).

Familiaritywith GitLab's API and webhook model for building external integrations.

Nice to Have

Experiencewith self-hosted/open-weight LLMs as an alternative to external APIs, for dataresidency-sensitive use cases.

Priorexperience building AI tooling specifically in a security or DevSecOps context(vulnerability triage, code review automation).

Exposureto evaluation frameworks/observability tooling for LLM systems in production(tracing, guardrail testing, drift monitoring).

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

AI Engineer
AI Engineer

XPT Software • Sydney

On-site
AUD 120,000 - 180,000
AI Engineer
AI Engineer

XPT Software • City of Melbourne

On-site
AUD 150,000 - 210,000
Senior AI Engineer
Senior AI Engineer

Blackbook.AI • City of Melbourne

On-site
AUD 150,000 - 230,000
Security Engineer, Application
Security Engineer, Application

United States Digital Space LLC • Sydney

On-site
AUD 150,000 - 210,000
Senior AI Engineer (LLM /GenAI)
Senior AI Engineer (LLM /GenAI)

Excolo. • Sydney

Hybrid
AUD 160,000 - 200,000
AI Solutions Architect
AI Solutions Architect

XPT Software Australia Pty Ltd • Council of the City of Sydney

On-site
AUD 180,000 - 240,000
GenAI & AI Strategy Consultant
GenAI & AI Strategy Consultant

XPT Software Australia Pty Ltd • Sydney

On-site
AUD 120,000 - 210,000
Senior AI Security Engineer
Senior AI Security Engineer

Talenza • Sydney

On-site
AUD 180,000 - 240,000
AI specialist / Generative AI design
AI specialist / Generative AI design

XPT Software Australia Pty Ltd • Council of the City of Sydney

On-site
AUD 140,000 - 190,000
AI programmer/ Engineer
AI programmer/ Engineer

Trellis Data • South Canberra

Hybrid
AUD 120,000 - 170,000