All open roles
+ [REQ] SeniorPipeline Building

AI Security Engineering Manager

JohannesburgIndependent Contractor AgreementSeniorIn-Office

This position is responsible for designing, building, and operating the security controls that protect Artificial Intelligence (AI) and Large Language Model (LLM) systems. The role is hands-on and engineering-focused, covering the development and integration of AI security control components such as policy engines, guardrails, input/output filters, AI firewalls, and secure API/AI gateway configurations. The position translates assurance, threat, and architecture findings into practical controls by engineering protective guardrails, authoring and tuning policy-as-code, and embedding security into AI/LLM pipelines and platforms. While assurance functions test and verify, this position builds and hardens the underlying controls.

Responsibilities

  • Design and build security controls across the AI/LLM estate, including guardrails, policy engines, input/output filtering, content moderation, and AI firewalls
  • Develop and maintain policy-as-code and policy engines (e.g., OPA/Rego or equivalent) governing model access, data handling, tool/plugin invocation, and output controls
  • Configure, tune, and continuously improve LLM guardrails to balance security and safety against usability and false-positive rates
  • Engineer secure API and AI gateway configurations, including authentication, authorisation, rate limiting, schema validation, and prompt/response inspection
  • Build secure-by-design patterns and reusable control libraries for AI/LLM solutions, such as secure RAG, secrets management, and sandboxing of agent tools and plugins
  • Integrate AI security controls into CI/CD and MLOps pipelines, enabling DevSecOps practices for AI so that controls are deployed and managed as code
  • Implement detection, logging, and telemetry for AI systems, including prompt/response logging, abuse detection, and model monitoring
  • Develop automation to deploy, version, and manage guardrails and policies at scale across multiple markets
  • Partner with the AI Security Assurance function to remediate findings and harden controls based on red-team and assurance results
  • Maintain and continuously uplift the AI security control baseline in alignment with the OWASP LLM Top 10, MITRE ATLAS mitigations, and NIST AI RMF, within a Zero Trust architecture
  • Provide engineering guidance and technical support to solution teams implementing AI security controls
  • Track and report on control effectiveness metrics, including guardrail block rates, false-positive rates, and reduction in AI-related security incidents
  • Manage and resolve escalations relating to AI security control failures, guardrail bypasses, and policy-engine incidents
  • Report periodically to function leadership on progress against defined metrics, and on an ad hoc basis for specific projects
  • Support planning and management of budgets for AI security control tooling, guardrail platforms, and policy-engine platforms

Experience and education

Education

  • Bachelor's or Master's degree in Computer Science, Software Engineering, Information Security, or a related field
  • Relevant professional certification, accreditation, or body membership as required

Certifications (preferred)

  • Cloud security or engineering certification (Azure, AWS, or GCP Security)
  • AI/ML security certification or secure-AI engineering training
  • Secure coding or DevSecOps certification
  • CISSP, CSSLP, or equivalent

Experience

  • 8–10 years of experience in security engineering or software engineering, including at least 5 years building and operating security controls
  • Strong software and automation engineering ability, with Python preferred
  • Demonstrable experience building guardrails, policy engines, content filtering, or API security controls
  • Experience with policy-as-code frameworks (OPA/Rego or similar) and authorisation engines
  • Experience integrating with LLM/AI platforms, AI firewalls, API gateways, and MLOps pipelines
  • Experience designing secure data pipelines, including encryption at rest and in transit, tokenisation, and data masking
  • Working knowledge of regulatory frameworks such as PSD2, GDPR, PCI DSS, POPIA, and emerging AI regulation (e.g., the EU AI Act)
Ready to build with global clients?
Join the Scrums.com talent network. No fees, no subscription.
Apply for this role →