Stand out for this role — generate a tailored resume and cover letter in about a minute.
XPT Software Australia Pty Ltd is seeking a Senior AI/Software Engineer to design and implement the AI/agentic layer atop SAST/SCA pipelines. You'll build custom automation using OpenAI or similar LLM APIs and architect agentic patterns to reduce triage effort and speed up remediation.
Responsibilities include integrating GitLab findings via API/webhooks, developing LLM-based triage, guardrails, and audit logging, plus ensuring data governance and security compliance in regulated telco
XPT Software Australia Pty Ltd | Contract
Sydney, Melbourne, Australia | Posted on 09/22/2026
Build the AI/agentic layer on top of the SAST/SCAcapability . GitLab's own Duo/agentic features are out of scope for thisprogramme, so this role is responsible for designing and building customautomation using OpenAI (or equivalent LLM APIs) and agentic patterns to reducetriage effort, cut false-positive noise, and speed up remediation
Designand build integrations that pull SAST/SCA findings out of GitLab (viaAPI/webhooks) into an external pipeline for AI-assisted processing.
BuildLLM-based triage assistance: false-positive likelihood scoring, vulnerabilityexplanation in plain language, and contextual remediation suggestions generatedagainst the actual code diff/repo context.
Designagentic workflows (multi-step, tool-using LLM agents) that can, for example,correlate a dependency CVE with actual usage in code, check for available safeupgrade paths, and draft a remediation MR for human review.
Ownprompt engineering, evaluation, and guardrails for these agents — includinghallucination checks, human-in-the-loop approval gates before anyauto-generated fix reaches a merge request, and audit logging for everyAI-assisted decision.
Selectand integrate the LLM provider/stack (OpenAI API, or alternatives) factoring indata residency and confidentiality constraints — telco source code andvulnerability data leaving the environment via a third-party API is agovernance concern requiring explicit sign-off.
Buildfeedback loops so agent outputs (false-positive calls, fix suggestions) are measuredagainst actual analyst/developer decisions to improve accuracy over time.
Workwith the SME to ensure the AI layer complements rather than duplicates nativeGitLab scanning logic, and with the BA to translate desired outcomes (reducedMTTR, lower false-positive rate) into technical automation targets.
Documentarchitecture, data flows, and model usage for security/compliance review —critical in a regulated telco environment where any AI system touching sourcecode or vulnerability data will likely need a formal risk assessment.
Senior, 8+ years software/AI engineering experience,with at least 1–2 years hands-on building production LLM-based or agenticsystems. AppSec domain experience is a strong plus.
Hands-onexperience with LLM APIs (OpenAI, Anthropic, or equivalent) — functioncalling/tool use, structured outputs, and context management at productionscale.
Practicalexperience designing agentic systems — multi-step reasoning, tool-useorchestration, and building in human-approval checkpoints rather than fullyautonomous action.
Strongsoftware engineering skills — able to build and maintain integration pipelines(GitLab API/webhooks, CI/CD hooks) rather than just prototyping in a notebook.
Understandingof prompt engineering best practices and evaluation methodology (how to measurewhether an AI triage decision is actually good, not just plausible-sounding).
Workingknowledge of AppSec concepts (SAST/SCA findings, CVE/CWE, vulnerabilityseverity) sufficient to build meaningful automation.
Awarenessof data governance/privacy implications of sending code and vulnerability datato third-party LLM APIs, and experience implementing controls (redaction,on-prem/private deployment options, data retention policies).
Familiaritywith GitLab's API and webhook model for building external integrations.
Experiencewith self-hosted/open-weight LLMs as an alternative to external APIs, for dataresidency-sensitive use cases.
Priorexperience building AI tooling specifically in a security or DevSecOps context(vulnerability triage, code review automation).
Exposureto evaluation frameworks/observability tooling for LLM systems in production(tracing, guardrail testing, drift monitoring).