At NCS Australia, we believe in doing technology services better. Our commitment to quality, focus on people, and willingness to challenge traditional thinking set us apart. Our team brings this belief to life by partnering with our clients and communities to make tomorrow together.
We are committed to creating an environment that prioritises innovation, collaboration, and purposeful work. Our diverse team is empowered to make a meaningful impact with curiosity, creativity and resilience to shape better outcomes. Join us and accept the challenge of creating a better tomorrow.
Job DescriptionWe are seeking an experienced AI DevSecOps Governance SME for an initial 12-month contract in Sydney to pioneer and scale AI-driven security governance across our enterprise software development lifecycle (SDLC).
In this forward-looking engineering role, you will lead the implementation of governance frameworks and security standards powered by Artificial Intelligence and Large Language Models (LLMs). You will be responsible for integrating intelligent automation directly into CI/CD pipelines—transforming how security policies, compliance checks, and code reviews are enforced across enterprise delivery teams.
Key Responsibilities
AI-Driven Security Governance: Design, implement, and enforce DevSecOps governance frameworks, security guardrails, and compliance standards utilizing AI capabilities and LLMs.
Automated Policy Enforcement: Build and deploy AI-assisted controls for automated code review, policy validation, threat modeling workflows, and security compliance checks within CI/CD pipelines.
Responsible AI & Security Standards: Establish policy guidelines and security baselines for developer AI usage (e.g., AI code assistants, generative models, and agentic workflows) to manage data privacy, IP, and code vulnerability risks.
Pipeline Integration & Shift-Left: Integrate intelligent security testing and automated remediation guidance seamlessly into modern CI/CD systems (e.g., GitHub Actions, GitLab CI, Azure DevOps).
Cross-Functional Leadership: Partner closely with Security Architecture, Engineering Leads, and Product Teams to define AI governance roadmaps and drive developer adoption across squads.
Essential Experience:
DevSecOps & AppSec Foundation: Deep hands-on experience establishing DevSecOps practices, CI/CD security controls, and application security standards in enterprise environments.
AI & LLM Implementation: Practical experience using AI/LLM tools to automate security governance, policy checking, or code review workflows (not just theoretical understanding).
Governance & Compliance: Proven ability to translate complex regulatory, security, and data privacy requirements into enforceable, automated software controls.
Pipeline Tooling & Automation: Proficiency with modern CI/CD platforms, scripting (Python, Bash), and APIs to integrate AI workflows into active pipelines.
Communication & Engagement: Excellent stakeholder management skills with a track record of driving security cultural shifts and developer adoption.
Desirable:
Exposure to secure AI deployment frameworks, model risk management, or AI safety standards (e.g., OWASP Top 10 for LLMs, NIST AI RMF).
Experience with enterprise code scanning tools (SAST, SCA, DAST) and AI-driven triage mechanisms.
Why NCS?
This is a place for people who like to get stuck in, bring ideas to life and make things happen. You'll work alongside experienced people who care about what they do, contribute to meaningful work and have the support to keep learning and grow your career. Whether you want to deepen your expertise, explore something new or take your career in a different direction, there's room to make it your own. We value Adventure, Excellence, Integrity, Ownership and Unity - bringing curiosity, collaboration and accountability to the way we work with our clients and each other.
Ready to make extraordinary happen?
We'd love to hear from you.
We celebrate diversity and inclusion
We value different perspectives, experiences and strengths our people bring. We're committed to an inclusive workplace where everyone has the opportunity to contribute, grow and succeed, and to providing equal employment opportunities and reasonable adjustments throughout the recruitment process.
Important information
Applicants will need valid Australian work rights and may be required to undergo relevant background, probity and police checks.
Agencies: NCS accepts candidate submissions only from agencies on our preferred supplier panel through the NCS Agency Portal.
Skills Required
- Deep hands-on experience establishing DevSecOps practices, CI/CD security controls, and application security standards in enterprise environments
- Practical experience using AI and LLM tools to automate security governance, policy checking, or code review workflows
- Experience translating regulatory, security, and data privacy requirements into enforceable automated software controls
- Proficiency with modern CI/CD platforms, Python, Bash, and APIs for integrating AI workflows into pipelines
- Excellent stakeholder management skills and experience driving security culture changes and developer adoption
- Exposure to secure AI deployment frameworks, model risk management, or AI safety standards such as OWASP Top 10 for LLMs or NIST AI RMF
- Experience with SAST, SCA, DAST, and AI-driven security triage mechanisms
- Valid Australian work rights
What We Do
NCS in Australia is reinventing technology services from the inside out. We provide advisory, design, build and managed services to our clients, with unrivalled service, attention and understanding every step of the way. We understand day 1001 is just an important as day 1, and we collaborate with clients, striving to provide adaptive approaches, outcomes and thinking by keeping our eye on tomorrow and the days after tomorrow. Our diverse workforce of around 1,300 people has delivered a wealth of large-scale, mission-critical, and multi-platform outcomes for governments and businesses nationally. We are the Australian arm of the pan-APAC technology leader NCS Group, a subsidiary of Singtel Group. Combining the experience and expertise of its 13,000-strong team across 57 specialisations, NCS provides differentiated and end-to-end technology services to clients with its capabilities in digital, data, cloud and platforms, as well as core offerings in application, infrastructure, engineering and cybersecurity. NCS also believes in building a strong partner ecosystem with leading technology players, research institutions and start-ups to support open innovation and co-creation. For more information about NCS Australia, visit ncs.co/en-au or contact our team today. To learn more about NCS Group, visit ncs.co.








