We are looking for an AI Security / Cybersecurity professional to support the secure adoption of AI and Generative AI technologies across the organisation.
This role focuses on applying cybersecurity, risk management, security architecture and secure-by-design principles to AI/GenAI solutions, from initial design through production.
Key Responsibilities
- Support and review AI/GenAI use cases from design through production.
- Define and assess security requirements for AI platforms, APIs, agents, tool use and integrations.
- Perform security architecture reviews, threat modelling and risk assessments for AI solutions.
- Validate AI integrations and deployments against security, privacy, logging, monitoring and auditability requirements.
- Identify, assess and mitigate AI-specific risks, including:
- Prompt injection and jailbreaks.
- Sensitive information disclosure and data leakage.
- Unsafe tool use and excessive agentic autonomy.
- Abusive or unbounded resource consumption.
- Insecure integrations and poisoned or untrusted inputs.
- Define practical guardrails for the use of sensitive, personal, confidential and regulated data.
- Ensure appropriate logging, monitoring, audit trails and evidence of control effectiveness.
- Contribute to AI security governance, standards, policies and secure-by-design patterns.
- Collaborate closely with Cybersecurity, Engineering, Product, Cloud and Data teams to challenge implementations and ensure effective security controls.
Required Experience
- Professional background in Cybersecurity, ideally in Application Security, Product Security, Cloud Security or Security Architecture.
- Good understanding of GenAI/LLM-based solutions from a security and risk perspective.
- Experience performing security reviews, architecture reviews and threat modelling.
- Experience defining and validating technical security controls.
- Strong knowledge of IAM, API security, secrets management, logging, monitoring and auditability.
- Knowledge of data protection, privacy, data minimisation and secure handling of sensitive or regulated data.
- Ability to critically challenge technical implementations and verify that security controls are effectively implemented.
Preferred Experience
- Experience with AWS and/or Azure, particularly in the context of AI workloads.
- Exposure to platforms such as AWS Bedrock, Azure OpenAI, Azure AI Foundry or similar GenAI services, particularly:
- Guardrails and content controls.
- IAM and least privilege.
- Logging, observability and auditability.
- Data protection and sensitive-data handling.
- Familiarity with Databricks from a security perspective, including:
- Access control and data permissions.
- Workspaces, jobs, pipelines and notebooks.
- Secrets management and networking.
- Data governance.
AI Security Knowledge
Familiarity with relevant AI security frameworks, standards and emerging technologies, including:
- OWASP Top 10 for LLM Applications / Agentic AI.
- SAIF (Secure AI Framework).
- Model Context Protocol (MCP) and agent-to-tool security considerations.
- Agent-to-Agent (A2A) architectures and agentic trust boundaries.
- Emerging AI security risk taxonomies, including MCP-38.
- DevSecOps and/or MLOps environments as a collaboration context.
Core Skills
- Ability to translate AI security risks into clear, practical and enforceable technical requirements.
- Strong risk identification, prioritisation and decision-making skills.
- Ability to challenge technical designs and validate whether controls are actually effective.
- Strong communication and collaboration skills across Security, Product, Engineering and Data teams.
- Pragmatic approach focused on secure-by-design, measurable and auditable controls.
Role Focus
This is fundamentally a Cybersecurity role applied to AI/GenAI.
The position is not primarily focused on model development, data engineering, ML platform operations, or ownership of pipelines, notebooks or ML platforms. The focus is on security architecture, risk, governance and technical control validation for AI-enabled solutions.