AI Engineer

XPT Software

Sydney

On-site

AUD 120,000 - 180,000

Full time

43 hours ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

XPT Software is seeking a Senior AI/Automation Engineer to design and build an AI-assisted layer on top of SAST/SCA capabilities. You will implement OpenAI or equivalent LLM integrations, agentic patterns, and guardrails to reduce triage effort and remediation time.

You will create multi-step, tool-using AI workflows, ensure data governance, and contribute to architecture documentation in a regulated telco environment. Experience with AppSec and security-focused automations is highly valued.

Qualifications

  • Hands-on experience with LLM APIs (OpenAI, Anthropic, or equivalent) at production scale.
  • Experience designing agentic systems with multi-step reasoning and tool orchestration.
  • Strong software engineering skills to build and maintain integration pipelines (GitLab API/webhooks, CI/CD hooks).
  • Understanding of prompt engineering best practices and evaluation methodology.
  • Working knowledge of AppSec concepts (SAST/SCA, CVE/CWE, vulnerability severity).
  • Awareness of data governance/privacy implications of sending code/vulnerability data to third-party LLM APIs and data-redaction/on-prem options.

Responsibilities

  • Design and build integrations that pull SAST/SCA findings from GitLab via API/webhooks into an external pipeline for AI processing.
  • Develop LLM-based triage with false-positive scoring, plain-language explanations, and remediation suggestions using code context.
  • Create agentic workflows that correlate dependencies with code usage and draft remediation MR for review.
  • Own prompt engineering, guardrails, and human-in-the-loop approval for generated fixes.
  • Select and integrate LLM provider stack with data residency considerations and governance sign-off.
  • Build feedback loops to measure agent outputs against analyst decisions for accuracy improvements.
  • Collaborate with SMEs and business analysts to align AI outcomes with security objectives.

Skills

LLM APIs
Agentic systems
Software integration
Prompt engineering
AppSec concepts
Data governance/privacy
GitLab API & Webhooks

Tools

GitLab API
CI/CD hooks

Job description

Role Purpose

Build the AI/agentic layer on top of the SAST/SCA capability . GitLab's own Duo/agentic features are out of scope for this programme, so this role is responsible for designing and building custom automation using OpenAI (or equivalent LLM APIs) and agentic patterns to reduce triage effort, cut false-positive noise, and speed up remediation

Build the AI/agentic layer on top of the SAST/SCA capability . GitLab's own Duo/agentic features are out of scope for this programme, so this role is responsible for designing and building custom automation using OpenAI (or equivalent LLM APIs) and agentic patterns to reduce triage effort, cut false-positive noise, and speed up remediation

Key Responsibilities
  • Design and build integrations that pull SAST/SCA findings out of GitLab (via API/webhooks) into an external pipeline for AI-assisted processing.
  • Build LLM-based triage assistance: false-positive likelihood scoring, vulnerability explanation in plain language, and contextual remediation suggestions generated against the actual code diff/repo context.
  • Design agentic workflows (multi-step, tool-using LLM agents) that can, for example, correlate a dependency CVE with actual usage in code, check for available safe upgrade paths, and draft a remediation MR for human review.
  • Own prompt engineering, evaluation, and guardrails for these agents — including hallucination checks, human-in-the-loop approval gates before any auto-generated fix reaches a merge request, and audit logging for every AI-assisted decision.
  • Select and integrate the LLM provider/stack (OpenAI API, or alternatives) factoring in data residency and confidentiality constraints — telco source code and vulnerability data leaving the environment via a third-party API is a governance concern requiring explicit sign-off.
  • Build feedback loops so agent outputs (false-positive calls, fix suggestions) are measured against actual analyst/developer decisions to improve accuracy over time.
  • Work with the SME to ensure the AI layer complements rather than duplicates native GitLab scanning logic, and with the BA to translate desired outcomes (reduced MTTR, lower false-positive rate) into technical automation targets.
  • Document architecture, data flows, and model usage for security/compliance review — critical in a regulated telco environment where any AI system touching source code or vulnerability data will likely need a formal risk assessment.
Experience Level

Senior, 8+ years software/AI engineering experience, with at least 1-2 years hands-on building production LLM-based or agentic systems. AppSec domain experience is a strong plus.

Required Knowledge & Skills
  • Hands-on experience with LLM APIs (OpenAI, Anthropic, or equivalent) — function calling/tool use, structured outputs, and context management at production scale.
  • Practical experience designing agentic systems — multi-step reasoning, tool-use orchestration, and building in human-approval checkpoints rather than fully autonomous action.
  • Strong software engineering skills — able to build and maintain integration pipelines (GitLab API/webhooks, CI/CD hooks) rather than just prototyping in a notebook.
  • Understanding of prompt engineering best practices and evaluation methodology (how to measure whether an AI triage decision is actually good, not just plausible-sounding).
  • Working knowledge of AppSec concepts (SAST/SCA findings, CVE/CWE, vulnerability severity) sufficient to build meaningful automation.
  • Awareness of data governance/privacy implications of sending code and vulnerability data to third-party LLM APIs, and experience implementing controls (redaction, on-prem/private deployment options, data retention policies).
  • Familiarity with GitLab's API and webhook model for building external integrations.
Nice to Have
  • Experience with self-hosted/open-weight LLMs as an alternative to external APIs, for data residency-sensitive use cases.
  • Prior experience building AI tooling specifically in a security or DevSecOps context (vulnerability triage, code review automation).
  • Exposure to evaluation frameworks/observability tooling for LLM systems in production (tracing, guardrail testing, drift monitoring).
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

AI Engineer
AI Engineer

XPT Software • City of Melbourne

On-site
AUD 150,000 - 210,000
AI Engineer
AI Engineer

XPT Software Australia Pty Ltd • Sydney, City of Melbourne

On-site
AUD 180,000 - 240,000
AI Engineer (Agentic Systems)
AI Engineer (Agentic Systems)

Chandler Holdings • Australia

On-site
AUD 120,000 - 180,000
Senior AI Security Engineer
Senior AI Security Engineer

Talenza • Sydney

On-site
AUD 180,000 - 240,000
Data Engineer
Data Engineer

N2S.Global • City of Melbourne

On-site
AUD 100,000 - 135,000
AI programmer/ Engineer
AI programmer/ Engineer

Trellis Data • South Canberra

Hybrid
AUD 120,000 - 170,000
Security Engineer, Application
Security Engineer, Application

Firmus Technologies • Sydney

On-site
AUD 180,000 - 240,000
N/A
Full Stack Engineer
Full Stack Engineer

Russell Tobin • Sydney

On-site
AUD 120,000 - 180,000
AI Engineer
AI Engineer

Preacta • Council of the City of Sydney

On-site
AUD 120,000 - 150,000
Senior AI Security Engineer
Senior AI Security Engineer

United States Digital Space LLC • Sydney

On-site
AUD 120,000 - 180,000