This position is responsible for designing, building, and operating the security controls that protect Artificial Intelligence (AI) and Large Language Model (LLM) systems. The role is hands-on and engineering-focused, covering the development and integration of AI security control components such as policy engines, guardrails, input/output filters, AI firewalls, and secure API/AI gateway configurations. The position translates assurance, threat, and architecture findings into practical controls by engineering protective guardrails, authoring and tuning policy-as-code, and embedding security into AI/LLM pipelines and platforms. While assurance functions test and verify, this position builds and hardens the underlying controls.
Responsibilities
- Design and build security controls across the AI/LLM estate, including guardrails, policy engines, input/output filtering, content moderation, and AI firewalls
- Develop and maintain policy-as-code and policy engines (e.g., OPA/Rego or equivalent) governing model access, data handling, tool/plugin invocation, and output controls
- Configure, tune, and continuously improve LLM guardrails to balance security and safety against usability and false-positive rates
- Engineer secure API and AI gateway configurations, including authentication, authorisation, rate limiting, schema validation, and prompt/response inspection
- Build secure-by-design patterns and reusable control libraries for AI/LLM solutions, such as secure RAG, secrets management, and sandboxing of agent tools and plugins
- Integrate AI security controls into CI/CD and MLOps pipelines, enabling DevSecOps practices for AI so that controls are deployed and managed as code
- Implement detection, logging, and telemetry for AI systems, including prompt/response logging, abuse detection, and model monitoring
- Develop automation to deploy, version, and manage guardrails and policies at scale across multiple markets
- Partner with the AI Security Assurance function to remediate findings and harden controls based on red-team and assurance results
- Maintain and continuously uplift the AI security control baseline in alignment with the OWASP LLM Top 10, MITRE ATLAS mitigations, and NIST AI RMF, within a Zero Trust architecture
- Provide engineering guidance and technical support to solution teams implementing AI security controls
- Track and report on control effectiveness metrics, including guardrail block rates, false-positive rates, and reduction in AI-related security incidents
- Manage and resolve escalations relating to AI security control failures, guardrail bypasses, and policy-engine incidents
- Report periodically to function leadership on progress against defined metrics, and on an ad hoc basis for specific projects
- Support planning and management of budgets for AI security control tooling, guardrail platforms, and policy-engine platforms
Experience and education
Education
- Bachelor's or Master's degree in Computer Science, Software Engineering, Information Security, or a related field
- Relevant professional certification, accreditation, or body membership as required
Certifications (preferred)
- Cloud security or engineering certification (Azure, AWS, or GCP Security)
- AI/ML security certification or secure-AI engineering training
- Secure coding or DevSecOps certification
- CISSP, CSSLP, or equivalent
Experience
- 8–10 years of experience in security engineering or software engineering, including at least 5 years building and operating security controls
- Strong software and automation engineering ability, with Python preferred
- Demonstrable experience building guardrails, policy engines, content filtering, or API security controls
- Experience with policy-as-code frameworks (OPA/Rego or similar) and authorisation engines
- Experience integrating with LLM/AI platforms, AI firewalls, API gateways, and MLOps pipelines
- Experience designing secure data pipelines, including encryption at rest and in transit, tokenisation, and data masking
- Working knowledge of regulatory frameworks such as PSD2, GDPR, PCI DSS, POPIA, and emerging AI regulation (e.g., the EU AI Act)