Lead DevSecOps & AI Security Specialist - Contract

Sorry, this job was removed at 02:18 a.m. (UTC) on Wednesday, Sep 16, 2026
Be an Early Applicant
Sydney, New South Wales, AUS
Hybrid
Expert/Leader
Artificial Intelligence • Cloud • Information Technology • Consulting • Cybersecurity • Big Data Analytics
Extraordinary Together
The Role
Leads enterprise DevSecOps and AI security initiatives, including architecture and rollout of SAST, SCA, and DAST tooling across CI/CD pipelines. Establishes security standards, vulnerability triage processes, remediation SLAs, AI governance frameworks, policy enforcement, and secure AI usage standards. Translates regulatory and application security requirements into technical roadmaps, user stories, runbooks, and metrics while collaborating with engineering, DevOps, security architecture, and product teams.
Summary Generated by Built In
Company Description

At NCS Australia, we believe in doing technology services better. Our commitment to quality, focus on people, and willingness to challenge traditional thinking set us apart. Our team brings this belief to life by partnering with our clients and communities to make tomorrow together.

We are committed to creating an environment that prioritises innovation, collaboration, and purposeful work. Our diverse team is empowered to make a meaningful impact with curiosity, creativity and resilience to shape better outcomes. Join us and accept the challenge of creating a better tomorrow.

Job Description

We are seeking a highly specialized Lead DevSecOps & AI Security Specialist to bridge business analysis, security architecture, and hands-on application security tooling across our enterprise software delivery pipelines.

This role is ideal for a senior practitioner who combines the technical capability of a DevSecOps Subject Matter Expert (SME) with the analytical depth to drive security standards, AI-driven governance, and end-to-end policy implementation at scale.

Core Focus Areas

1. DevSecOps SME & Code Scanning Implementation

  • Hands-on Tooling Roll-Out: Lead the end-to-end implementation, configuration, and integration of code scanning platforms across the enterprise—going beyond operational usage to build the toolchain architecture from the ground up.

  • Security Testing Standards: Define, implement, and enforce SAST, SCA, and DAST scanning standards directly within automated CI/CD pipelines (e.g., GitLab CI, GitHub Actions, Azure DevOps).

  • Operational Rules & Triage: Establish baseline scanning rulesets, triage workflows, vulnerability remediation SLAs, and false-positive reduction strategies for development squads.

2. AI-Driven DevSecOps Governance

  • AI Security Architecture: Pioneer and implement DevSecOps governance frameworks and security guardrails utilizing AI capabilities and LLM tools.

  • Automated Enforcement: Establish automated policy enforcement, AI-assisted code remediation guidance, and smart threat modeling workflows for software engineering teams.

  • AI Tooling Standards: Define policies and standards for secure AI deployment, AI code-assistant usage, and data privacy governance within modern development environments.

3. Technical Business Analysis & Delivery

  • Requirements & Governance: Translate complex application security, compliance, and regulatory requirements into actionable user stories, engineering epics, and implementation roadmaps.

  • Cross-Squad Collaboration: Work closely with software engineers, security architects, DevOps specialists, and product leaders to embed security seamlessly into the SDLC.

  • Runbooks & Metrics: Develop operational runbooks, technical governance documentation, and metrics dashboards to monitor platform adoption, pipeline health, and overall security posture.

Qualifications

Essential Skills & Experience:

  • Proven DevSecOps Implementation: Demonstrated track record of implementing and deploying (not just using) enterprise SAST, SCA, and DAST tooling (e.g., Checkmarx, SonarQube, Veracode, Snyk, Fortify, or OWASP ZAP).

  • AI Security & Governance: Practical experience leveraging AI/LLM technologies to enhance DevSecOps governance, automated code review, or security policy enforcement.

  • Business Analysis Capability: Strong BA background with demonstrated experience writing technical requirements, mapping workflows, and defining security standards for enterprise delivery teams.

  • CI/CD Pipeline Integration: Deep experience embedding automated security scanning stages into modern CI/CD systems.

  • Communication & Stakeholder Management: Excellent communication skills with the ability to influence engineering culture, articulate security risks, and drive adoption across cross-functional squads.

Additional Information

Why NCS?

This is a place for people who like to get stuck in, bring ideas to life and make things happen. You'll work alongside experienced people who care about what they do, contribute to meaningful work and have the support to keep learning and grow your career.  Whether you want to deepen your expertise, explore something new or take your career in a different direction, there's room to make it your own.  We value Adventure, Excellence, Integrity, Ownership and Unity - bringing curiosity, collaboration and accountability to the way we work with our clients and each other.

Ready to make extraordinary happen?

We'd love to hear from you.

We celebrate diversity and inclusion

We value different perspectives, experiences and strengths our people bring.  We're committed to an inclusive workplace where everyone has the opportunity to contribute, grow and succeed, and to providing equal employment opportunities and reasonable adjustments throughout the recruitment process.

Important information

Applicants will need valid Australian work rights and may be required to undergo relevant background, probity and police checks.

Agencies: NCS accepts candidate submissions only from agencies on our preferred supplier panel through the NCS Agency Portal.

Skills Required

  • Experience implementing and deploying enterprise SAST, SCA, and DAST tooling
  • Experience with application security tools such as Checkmarx, SonarQube, Veracode, Snyk, Fortify, or OWASP ZAP
  • Practical experience using AI or LLM technologies for DevSecOps governance, automated code review, or security policy enforcement
  • Strong business analysis experience writing technical requirements, mapping workflows, and defining enterprise security standards
  • Deep experience integrating automated security scanning into CI/CD systems
  • Excellent communication and stakeholder management skills
  • Valid Australian work rights
  • Ability to undergo relevant background, probity, and police checks

Similar Jobs

Legora Logo Legora

Senior Acquisition Talent Partner, APAC

Artificial Intelligence • Legal Tech • Software
In-Office
Sydney, New South Wales, AUS
700 Employees

ServiceNow Logo ServiceNow

Architect

Artificial Intelligence • Cloud • HR Tech • Information Technology • Productivity • Software • Automation
Hybrid
Sydney, New South Wales, AUS
29000 Employees

Atlassian Logo Atlassian

Senior Software Engineer

Cloud • Information Technology • Productivity • Security • Software • App development • Automation
In-Office or Remote
Sydney, New South Wales, AUS
11000 Employees

Atlassian Logo Atlassian

Principal Incident Response Analyst

Cloud • Information Technology • Productivity • Security • Software • App development • Automation
In-Office or Remote
Sydney, New South Wales, AUS
11000 Employees
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Thiruvalla
1,358 Employees
Year Founded: 2001

What We Do

NCS in Australia is reinventing technology services from the inside out. We provide advisory, design, build and managed services to our clients, with unrivalled service, attention and understanding every step of the way. We understand day 1001 is just an important as day 1, and we collaborate with clients, striving to provide adaptive approaches, outcomes and thinking by keeping our eye on tomorrow and the days after tomorrow. Our diverse workforce of around 1,300 people has delivered a wealth of large-scale, mission-critical, and multi-platform outcomes for governments and businesses nationally. We are the Australian arm of the pan-APAC technology leader NCS Group, a subsidiary of Singtel Group. Combining the experience and expertise of its 13,000-strong team across 57 specialisations, NCS provides differentiated and end-to-end technology services to clients with its capabilities in digital, data, cloud and platforms, as well as core offerings in application, infrastructure, engineering and cybersecurity. NCS also believes in building a strong partner ecosystem with leading technology players, research institutions and start-ups to support open innovation and co-creation. For more information about NCS Australia, visit ncs.co/en-au or contact our team today. To learn more about NCS Group, visit ncs.co.

Similar Companies Hiring

Kepler  Thumbnail
Artificial Intelligence • Fintech • Software
New York, New York
9 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees
Blee Thumbnail
Artificial Intelligence • Marketing Tech • Software
New York, New York
30 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account