Manager AI Security Engineer
Johannesburg - South Africa
Job Summary
The key objective of this role is to design build and operate the security controls that protect Artificial Intelligence (AI) and Large Language Model (LLM) systems. The role is hands-on and engineering-focused: developing and integrating AI security control components such as policy engines guardrails input/output filters AI firewalls and secure API / AI gateway configurations.
The role takes assurance threat and architecture findings and builds the controls that mitigate them engineering protective guardrails authoring and tuning policy-as-code and embedding security into AI/LLM pipelines and platforms across Fintech markets. Where the assurance function tests and verifies this role builds and hardens.
- Bachelors or Masters degree in Computer Science Software Engineering Information Security or related field.
- Relevant certification/accreditation/membership with professional body as required
- Cloud security / engineering certifications (Azure AWS or GCP Security).
- AI/ML security certifications and secure-AI engineering training.
- Secure coding / DevSecOps certifications.
- CISSP CSSLP or equivalent.
- Minimum 810 years in security engineering or software engineering with at least 5 years building and operating security controls.
- Strong software and automation engineering ability (Python preferred).
- Demonstrable experience building guardrails policy engines content filtering or API security controls.
- Experience with policy-as-code frameworks (OPA/Rego or similar) and authorization engines.
- Experience integrating with LLM/AI platforms AI firewalls and API gateways and with MLOps pipelines.
- Experience designing secure data pipelines: encryption at rest and in transit tokenization and data masking.
Functional Knowledge:
- Deep understanding of AI/LLM security control design guardrails input/output filters policy engines and AI firewalls.
- Strong software engineering and automation skills including infrastructure- and policy-as-code.
- Policy-as-code and authorization frameworks (e.g. OPA/Rego).
- API security engineering (gateways OAuth2/OIDC mTLS rate limiting schema validation).
- Secure RAG agent and tool-use architecture patterns.
- DevSecOps and MLOps practices for embedding controls into delivery pipelines.
- Compliance with PSD2 GDPR PCI DSS POPIA and emerging AI regulation (e.g. EU AI Act).
Required Experience:
Manager
About Company
With 15 years of experience in the Telecommunications and Financial Services industry in Africa and the Middle East, we are experts at supporting our clients through their digital transformation journeys. We believe in blending traditional methods with cutting-edge strategies to drive ... View more