AI Security Engineer
Summary
Leads AI cybersecurity governance and controls for the Australian government’s ICT environment, designing frameworks for threat detection, risk mitigation, and compliance with frameworks like PSPF, ISM, and NIST. Focuses on Microsoft 365 tools (e.g., Purview, DLP) and emerging AI threats like prompt injection.
AI/Controls Engineer - Cyber Security (Artificial Intelligence Cyber Security and Controls Engineer)
Location
Canberra, ACT
Working Arrangement
Onsite - 5 days per week in the Canberra office.
Remote/interstate candidates may be considered if no suitable Canberra-based candidate is available. Ad-hoc flexible working arrangements may be reviewed on a case-by-case basis.
Clearance Required
Negative Vetting Level 1 (NV1) - candidates must have an existing active NV1 clearance.
Company Overview
The Department of Foreign Affairs and Trade (DFAT) is seeking an ICT labour-hire resource within its Cyber Sustainment Section, part of the Cyber Security, Cloud & Networks Branch within the Information Management and Technology Division.
The Cyber Sustainment Tools team is responsible for providing a hardened and secure technology environment to safeguard DFAT's ICT environment.
Job Description
DFAT is seeking an Artificial Intelligence Cyber Security and Controls Engineer to lead the strategic application of AI and associated security controls across the department.
The successful candidate will provide expert guidance on AI threat detection, risk mitigation and policy development, helping ensure DFAT remains resilient against emerging digital threats.
The role requires a senior technical expert with strong expertise across AI and cyber security, including experience applying AI-related security controls in complex or high-risk environments. The successful candidate will also need strong stakeholder engagement skills and the ability to translate complex technical concepts into practical controls within an enterprise ICT environment.
Duties and Responsibilities
AI Governance and Controls
- Act as the AI Cyber Security Lead in developing, implementing and continuously improving AI governance frameworks.
- Support the AI Accountable Authority in developing and implementing AI strategies to enhance cyber security capabilities.
- Design and implement AI control frameworks aligned with cyber security, privacy, risk and compliance requirements.
- Develop security standards and procedures governing the use of AI technologies.
- Assess AI solutions against security, privacy, ethical and legislative requirements.
- Establish accountability, transparency, monitoring and assurance processes for AI.
- Conduct research and horizon scanning to identify emerging AI trends and their cyber security implications.
AI Risk Management
- Conduct AI risk assessments and identify appropriate mitigations.
- Evaluate AI use cases and provide recommendations for secure and responsible deployment.
- Monitor emerging AI threats, including data leakage, prompt injection, model manipulation and unauthorised AI usage.
- Support the management of AI-related risks within DFAT's broader cyber security risk framework.
Microsoft AI and Data Protection Controls
Design, document, implement and maintain AI-related controls within Microsoft 365 and associated platforms, including:
- Microsoft Purview Data Security Posture Management (DSPM) for AI.
- Microsoft Purview Data Loss Prevention (DLP).
- Sensitivity Labels.
- Information Protection.
- Insider Risk Management.
- Communication Compliance.
- Microsoft Defender for Cloud Apps.
- Copilot governance and data access controls.
Education/Certifications Required
Relevant certifications are highly desirable, including:
- Microsoft SC-100.
- Microsoft SC-401.
- Microsoft SC-500.
- Microsoft MS-102.
- Equivalent certifications.
Postgraduate qualifications relevant to AI, cyber security, information security or a related discipline are also highly desirable.
Knowledge/Skills Required
Essential
- Experience in AI governance, technology risk, cyber security governance or information security.
- Experience implementing cyber security and compliance controls within Microsoft 365.
- Experience implementing Microsoft Purview, DLP and information protection technologies in relation to AI governance.
- Excellent stakeholder engagement skills, including collaboration with technical teams, policy makers and external partners.
- Demonstrated understanding of:
- AI governance frameworks.
- Responsible AI principles.
- Privacy and data protection requirements.
- Risk management methodologies.
- Cyber security controls.
- Familiarity with Australian Government frameworks, including PSPF, ISM and Essential Eight, and international frameworks such as NIST.
SFIA-aligned capabilities
- AI Governance and Assurance - Governance (GOVN), Level 4+.
- AI Engineering/Operations - Security Operations (SCAD), Level 4+.
- AI Change Enablement - Organisational Design and Enablement (ORDI), Level 4+.
- Independent AI Audit and Oversight - Information and Data Compliance (PEDP), Level 4+.
- Desirable
- Experience with Microsoft Fabric, Azure AI Foundry, Power Platform and Copilot Studio.
- Exposure to cloud-based AI and data solutions across multiple vendors, including AWS.
- Experience with third-party generative AI platforms and large language models, such as Anthropic Claude and similar technologies.
- Understanding of emerging AI, automation and low-code/no-code solutions within enterprise environments.
- Government or critical infrastructure experience.
Employment Benefits / Contract Details
- Initial contract:12 months.
- Extensions:Up to two additional 12-month extensions.
- Maximum hours:40 hours per week.
- Estimated start date:26 October 2026.
- Experience level:EL1 equivalent.
- Engagement type:ICT Labour Hire - DMP2.
- Contract:Simple contract.
- Maximum candidates per seller:
- DFAT contractor stand-down:Typically 4-6 weeks during December and January, at DFAT's discretion.
Diversity and Inclusion
We are committed to fostering a diverse and inclusive workplace. We welcome applications from candidates of all backgrounds and experiences.
Veterans
Defence and Federal Government industry experience is highly desirable. We strongly encourage veterans and individuals with Defence experience to apply. Your unique skills and background are highly valued, and we are committed to supporting your transition into this role.
About Cleared
At Cleared, we provide tailored recruitment solutions to individuals seeking their next opportunity and to organisations searching for talent within Defence Industry, Intelligence and National Security.