All open roles
+ [REQ] SeniorPipeline Building

Senior AI Security Assurance Manager

JohannesburgIndependent Contractor AgreementSeniorIn-Office

The role provides independent, evidence-based security assurance across the end-to-end Artificial Intelligence (AI) and Large Language Model (LLM) estate. This is a testing and assurance-focused position responsible for adversarially testing (red-teaming) AI/LLM systems, validating that security controls operate as designed, and providing technical verification to architecture and governance forums that AI solutions are safe to deploy and operate. The role covers the full AI stack, from the underlying models through to surrounding architectural components such as AI firewalls, API gateways, retrieval augmented generation (RAG) pipelines and inference endpoints, and delivers independent verification rather than building the controls itself.

Responsibilities

 

  • Define and execute the AI/LLM security assurance and testing strategy across the AI estate
  • Design and conduct adversarial testing (red-teaming) of LLMs and AI systems, covering prompt injection, jailbreaks, prompt and data leakage, training-data and model poisoning, model extraction, membership inference and evasion, aligned to the OWASP Top 10 for LLM Applications and MITRE ATLAS
  • Test the full AI stack end-to-end, including models, AI firewalls, API gateways, guardrails, RAG/retrieval components, plugins, agent tools and supporting infrastructure
  • Validate that AI security controls (input/output filtering, guardrails, content moderation, rate limiting, and authentication/authorisation at the API and AI gateway) function as designed and meet defined control objectives
  • Assess model robustness, safety, bias and resilience, benchmarking solutions against recognised frameworks including OWASP LLM Top 10, MITRE ATLAS, NIST AI RMF, ISO/IEC 42001 and 23894
  • Perform security testing of AI/LLM API integrations and gateways, including authentication, authorisation, schema and payload validation, rate limiting, token/secret handling and abuse protection, in line with the OWASP API Security Top 10
  • Conduct AI supply-chain and model-provenance assurance, including review of model cards, dataset lineage, and third-party/foundation-model risk
  • Produce assurance reports and prioritised remediation recommendations, and track closure of AI security defects with engineering teams
  • Provide independent security-readiness input and sign-off to change advisory and architecture review forums for AI solutions
  • Develop and maintain AI security test cases, tooling and automated assurance pipelines to support continuous AI red-teaming
  • Monitor the evolving AI threat landscape and translate emerging attack techniques into updated test coverage
  • Manage escalations relating to AI/LLM security assurance findings, unresolved high-risk vulnerabilities and disputes over deployment readiness
  • Report periodically to leadership on progress against defined metrics, and provide ad hoc reporting on specific projects as required
  • Support planning and management of the budget for AI security assurance and testing tooling and platforms

Experience and education

  • Bachelor's or Master's degree in Computer Science, Information Security, or a related field
  • Relevant professional certification, accreditation or membership as required
  • Preferred certifications: offensive security/penetration testing (e.g. OSCP, OSEP, GPEN, CRTO); AI/ML security or adversarial ML training; CISSP, CEH or equivalent; cloud security certification (Azure, AWS or GCP)
  • Minimum 8 to 10 years of experience in cybersecurity, including at least 5 years focused on security testing, penetration testing or red-teaming
  • Demonstrable experience testing AI/ML or LLM systems, including adversarial ML, prompt injection, jailbreak and data-leakage testing
  • Experience testing API security and API gateways (e.g. Apigee, Kong, AWS API Gateway, Azure API Management)
  • Hands-on experience with AI firewalls, LLM gateways and content-filtering/guardrail technologies
  • Familiarity with securing data pipelines, including encryption at rest and in transit, tokenisation and data masking
  • Working knowledge of AI security frameworks: OWASP LLM Top 10, MITRE ATLAS, NIST AI RMF and ISO/IEC 42001
  • Understanding of compliance requirements including PSD2, GDPR, PCI DSS, POPIA and emerging AI regulation such as the EU AI Act
  • Understanding of Agile and DevSecOps delivery methods (Scrum, Kanban preferable)
Ready to build with global clients?
Join the Scrums.com talent network. No fees, no subscription.
Apply for this role →