freehire launches on Product Hunt on 26 August.

Follow →

AI Security Engineer

Summary

Leads AI cybersecurity governance and controls for the Australian government’s ICT environment, designing frameworks for threat detection, risk mitigation, and compliance with frameworks like PSPF, ISM, and NIST. Focuses on Microsoft 365 tools (e.g., Purview, DLP) and emerging AI threats like prompt injection.

AI/Controls Engineer - Cyber Security (Artificial Intelligence Cyber Security and Controls Engineer)

Location

Canberra, ACT

Working Arrangement

Onsite - 5 days per week in the Canberra office.
Remote/interstate candidates may be considered if no suitable Canberra-based candidate is available. Ad-hoc flexible working arrangements may be reviewed on a case-by-case basis.

Clearance Required

Negative Vetting Level 1 (NV1) - candidates must have an existing active NV1 clearance.

Company Overview

The Department of Foreign Affairs and Trade (DFAT) is seeking an ICT labour-hire resource within its Cyber Sustainment Section, part of the Cyber Security, Cloud & Networks Branch within the Information Management and Technology Division.

The Cyber Sustainment Tools team is responsible for providing a hardened and secure technology environment to safeguard DFAT's ICT environment.

Job Description

DFAT is seeking an Artificial Intelligence Cyber Security and Controls Engineer to lead the strategic application of AI and associated security controls across the department.

The successful candidate will provide expert guidance on AI threat detection, risk mitigation and policy development, helping ensure DFAT remains resilient against emerging digital threats.

The role requires a senior technical expert with strong expertise across AI and cyber security, including experience applying AI-related security controls in complex or high-risk environments. The successful candidate will also need strong stakeholder engagement skills and the ability to translate complex technical concepts into practical controls within an enterprise ICT environment.

Duties and Responsibilities

AI Governance and Controls

  • Act as the AI Cyber Security Lead in developing, implementing and continuously improving AI governance frameworks.
  • Support the AI Accountable Authority in developing and implementing AI strategies to enhance cyber security capabilities.
  • Design and implement AI control frameworks aligned with cyber security, privacy, risk and compliance requirements.
  • Develop security standards and procedures governing the use of AI technologies.
  • Assess AI solutions against security, privacy, ethical and legislative requirements.
  • Establish accountability, transparency, monitoring and assurance processes for AI.
  • Conduct research and horizon scanning to identify emerging AI trends and their cyber security implications.

AI Risk Management

  • Conduct AI risk assessments and identify appropriate mitigations.
  • Evaluate AI use cases and provide recommendations for secure and responsible deployment.
  • Monitor emerging AI threats, including data leakage, prompt injection, model manipulation and unauthorised AI usage.
  • Support the management of AI-related risks within DFAT's broader cyber security risk framework.

Microsoft AI and Data Protection Controls

Design, document, implement and maintain AI-related controls within Microsoft 365 and associated platforms, including:

  • Microsoft Purview Data Security Posture Management (DSPM) for AI.
  • Microsoft Purview Data Loss Prevention (DLP).
  • Sensitivity Labels.
  • Information Protection.
  • Insider Risk Management.
  • Communication Compliance.
  • Microsoft Defender for Cloud Apps.
  • Copilot governance and data access controls.

Education/Certifications Required

Relevant certifications are highly desirable, including:

  • Microsoft SC-100.
  • Microsoft SC-401.
  • Microsoft SC-500.
  • Microsoft MS-102.
  • Equivalent certifications.

Postgraduate qualifications relevant to AI, cyber security, information security or a related discipline are also highly desirable.

Knowledge/Skills Required

Essential

  • Experience in AI governance, technology risk, cyber security governance or information security.
  • Experience implementing cyber security and compliance controls within Microsoft 365.
  • Experience implementing Microsoft Purview, DLP and information protection technologies in relation to AI governance.
  • Excellent stakeholder engagement skills, including collaboration with technical teams, policy makers and external partners.
  • Demonstrated understanding of:
    • AI governance frameworks.
    • Responsible AI principles.
    • Privacy and data protection requirements.
    • Risk management methodologies.
    • Cyber security controls.
  • Familiarity with Australian Government frameworks, including PSPF, ISM and Essential Eight, and international frameworks such as NIST.

SFIA-aligned capabilities

  • AI Governance and Assurance - Governance (GOVN), Level 4+.
  • AI Engineering/Operations - Security Operations (SCAD), Level 4+.
  • AI Change Enablement - Organisational Design and Enablement (ORDI), Level 4+.
  • Independent AI Audit and Oversight - Information and Data Compliance (PEDP), Level 4+.
  • Desirable
    • Experience with Microsoft Fabric, Azure AI Foundry, Power Platform and Copilot Studio.
    • Exposure to cloud-based AI and data solutions across multiple vendors, including AWS.
    • Experience with third-party generative AI platforms and large language models, such as Anthropic Claude and similar technologies.
    • Understanding of emerging AI, automation and low-code/no-code solutions within enterprise environments.
    • Government or critical infrastructure experience.

Employment Benefits / Contract Details

  • Initial contract:12 months.
  • Extensions:Up to two additional 12-month extensions.
  • Maximum hours:40 hours per week.
  • Estimated start date:26 October 2026.
  • Experience level:EL1 equivalent.
  • Engagement type:ICT Labour Hire - DMP2.
  • Contract:Simple contract.
  • Maximum candidates per seller:
  • DFAT contractor stand-down:Typically 4-6 weeks during December and January, at DFAT's discretion.

Diversity and Inclusion

We are committed to fostering a diverse and inclusive workplace. We welcome applications from candidates of all backgrounds and experiences.

Veterans

Defence and Federal Government industry experience is highly desirable. We strongly encourage veterans and individuals with Defence experience to apply. Your unique skills and background are highly valued, and we are committed to supporting your transition into this role.

About Cleared

At Cleared, we provide tailored recruitment solutions to individuals seeking their next opportunity and to organisations searching for talent within Defence Industry, Intelligence and National Security.

See also

Tailor your CV for this role?

We couldn't check your fit for this role — add a CV to your profile to see it next time.

A new version of freehire is available