Lead DevSecOps & AI Security Specialist Contract
Job Summary
We are seeking a highly specialized Lead DevSecOps & AI Security Specialist to bridge business analysis security architecture and hands-on application security tooling across our enterprise software delivery pipelines.
This role is ideal for a senior practitioner who combines the technical capability of a DevSecOps Subject Matter Expert (SME) with the analytical depth to drive security standards AI-driven governance and end-to-end policy implementation at scale.
Core Focus Areas
1. DevSecOps SME & Code Scanning Implementation
Hands-on Tooling Roll-Out: Lead the end-to-end implementation configuration and integration of code scanning platforms across the enterprisegoing beyond operational usage to build the toolchain architecture from the ground up.
Security Testing Standards: Define implement and enforce SAST SCA and DAST scanning standards directly within automated CI/CD pipelines (e.g. GitLab CI GitHub Actions Azure DevOps).
Operational Rules & Triage: Establish baseline scanning rulesets triage workflows vulnerability remediation SLAs and false-positive reduction strategies for development squads.
2. AI-Driven DevSecOps Governance
AI Security Architecture: Pioneer and implement DevSecOps governance frameworks and security guardrails utilizing AI capabilities and LLM tools.
Automated Enforcement: Establish automated policy enforcement AI-assisted code remediation guidance and smart threat modeling workflows for software engineering teams.
AI Tooling Standards: Define policies and standards for secure AI deployment AI code-assistant usage and data privacy governance within modern development environments.
3. Technical Business Analysis & Delivery
Requirements & Governance: Translate complex application security compliance and regulatory requirements into actionable user stories engineering epics and implementation roadmaps.
Cross-Squad Collaboration: Work closely with software engineers security architects DevOps specialists and product leaders to embed security seamlessly into the SDLC.
Runbooks & Metrics: Develop operational runbooks technical governance documentation and metrics dashboards to monitor platform adoption pipeline health and overall security posture.
Qualifications :
Essential Skills & Experience:
Proven DevSecOps Implementation: Demonstrated track record of implementing and deploying (not just using) enterprise SAST SCA and DAST tooling (e.g. Checkmarx SonarQube Veracode Snyk Fortify or OWASP ZAP).
AI Security & Governance: Practical experience leveraging AI/LLM technologies to enhance DevSecOps governance automated code review or security policy enforcement.
Business Analysis Capability: Strong BA background with demonstrated experience writing technical requirements mapping workflows and defining security standards for enterprise delivery teams.
CI/CD Pipeline Integration: Deep experience embedding automated security scanning stages into modern CI/CD systems.
Communication & Stakeholder Management: Excellent communication skills with the ability to influence engineering culture articulate security risks and drive adoption across cross-functional squads.
Additional Information :
Why NCS
This is a place for people who like to get stuck in bring ideas to life and make things happen. Youll work alongside experienced people who care about what they do contribute to meaningful work and have the support to keep learning and grow your career. Whether you want to deepen your expertise explore something new or take your career in a different direction theres room to make it your own. We value Adventure Excellence Integrity Ownership and Unity - bringing curiosity collaboration and accountability to the way we work with our clients and each other.
Ready to make extraordinary happen
Wed love to hear from you.
We celebrate diversity and inclusion
We value different perspectives experiences and strengths our people bring. Were committed to an inclusive workplace where everyone has the opportunity to contribute grow and succeed and to providing equal employment opportunities and reasonable adjustments throughout the recruitment process.
Important information
Applicants will need valid Australian work rights and may be required to undergo relevant background probity and police checks.
Agencies: NCS accepts candidate submissions only from agencies on our preferred supplier panel through the NCS Agency Portal.
Remote Work :
No
Employment Type :
Full-time
About Company
At NCS Australia, we believe in doing technology services better. Our commitment to quality, focus on people, and willingness to challenge traditional thinking set us apart. Our team brings this belief to life by partnering with our clients and communities to make tomorrow together. ... View more