All open roles
+ [REQ] SeniorPipeline Building

Senior Information Security – AI

JohannesburgIndependent Contractor AgreementSeniorIn-Office

The role is responsible for supporting the security of Artificial Intelligence (AI) across the organisation's Fintech division and helping safeguard the implementation of the enterprise's policy for safe, secure, and responsible AI. Reporting to the Senior Manager: Information Security (AI), the position supports the design and operation of AI security controls, standards, and assurance activities across Generative AI (GenAI), classical Machine Learning (ML), data pipelines, and AI-enabled products, ensuring that innovation scales securely, remains compliant, and is resilient to adversarial manipulation. Working closely with Information Security, product, platform and engineering teams, and cloud security partners, the role acts as a hands-on custodian of AI security discipline and a trusted technical partner to engineering, data science, and product teams.

Responsibilities

AI Security Governance

  • Support the AI security mandate and operating model, embedding enterprise AI policy requirements into standards, procedures, and product gates
  • Contribute to relevant governance forums and coordinate with Risk, Legal, Privacy, and Procurement on policy, third-party, and contract controls
  • Maintain AI control objectives, assurance plans, and attestation mechanisms aligned to enterprise information security policy

AI Security Strategy and Architecture

  • Implement AI security standards aligned to the group cyber reference architecture and recognised industry principles, including Zero Trust, cloud security, secure Software Development Life Cycle (SDLC), and Identity and Access Management (IAM)
  • Apply secure architecture standards for AI platforms, MLOps stacks, and model-serving patterns, embedding security-by-design across the full AI lifecycle

Generative AI and LLM Security

  • Operationalise policy guardrails including prompt security, input/output filtering, data loss prevention, access control, usage monitoring, and secure Large Language Model (LLM) architecture patterns
  • Support approval workflows for model access, use cases, and sensitive data handling, and implement usage analytics and model egress controls to prevent data leakage

Adversarial ML Defence and AI Red Teaming

  • Apply AI threat-modelling methodology and support adversarial robustness testing, including poisoning, evasion, prompt injection, and API exploitation
  • Help define secure model deployment controls and post-deployment behavioural drift monitoring for manipulation detection

Secure MLOps and Data Security

  • Apply secure MLOps standards including CI/CD for models, integrated security testing, hardened model registries and artifact stores, and pipeline authentication and authorisation
  • Protect training and validation datasets by enforcing secure data ingestion, sensitive data minimisation, and prevention of training data leakage

AI Security Monitoring and Incident Response

  • Integrate AI platforms, data pipelines, and model-serving endpoints with the enterprise SIEM/SOC for continuous monitoring and anomaly detection
  • Extend cyber incident response playbooks to AI scenarios, including containment of compromised models, forensic acquisition of model artifacts, and post-incident model integrity verification

Risk, Compliance and Policy Alignment

  • Map AI security controls to enterprise and industry policy frameworks, aligning with POPIA, GDPR, ISO/IEC 27001, ISO/IEC 27701, ISO/IEC 42001, and the NIST AI Risk Management Framework
  • Support model risk management across first and second lines of defence, including risk taxonomy, criticality tiers, control baselines, and assurance reporting
  • Support third-party and cloud AI risk activities, including vendor due diligence and contract clauses covering data, intellectual property, and security service levels

Platform and Product Enablement

  • Partner with product, platform, and GenAI adoption teams to embed design-time controls, privacy-by-design, and production guardrails into AI-enabled services
  • Provide reference architectures and secure patterns for common use cases such as Retrieval-Augmented Generation (RAG), copilots, and fraud analytics

Capability Uplift, Reporting and Tooling

  • Support training and awareness initiatives for engineers, data scientists, and product teams on secure GenAI usage and adversarial ML
  • Track and report key performance indicators such as AI use cases cleared through governance gates, time-to-approve models, adversarial test coverage, model drift mean time to repair, and reduction in AI security incidents
  • Support administration of AI security tooling, including secrets scanning for ML, model provenance and attestation, content safety, and AI Security Posture Management

Experience and education

Education

  • Bachelor's degree in Computer Science, Engineering, Mathematics, or a related field
  • Honours degree advantageous
  • Relevant security certifications such as CISSP or CCSP; cloud AI specialisations or ML engineering credentials advantageous

Experience

  • 5+ years of experience across cybersecurity or platform security, including 2 to 3+ years securing AI/ML platforms, GenAI/LLM ecosystems, or data-intensive analytics at enterprise scale
  • Experience contributing to security operating models or Centres of Excellence, and supporting group-wide policy adoption within complex, multi-country organisations, preferably within telecommunications or financial services
  • Hands-on exposure to cloud-native AI stacks (particularly Azure), MLOps toolchains, and embedding security controls within agile product delivery
  • Experience integrating AI systems into SOC/SIEM environments, supporting AI incident response, and conducting AI red teaming and robustness testing
Ready to build with global clients?
Join the Scrums.com talent network. No fees, no subscription.
Apply for this role →