EL1 AI/Controls Engineer Cyber Security
Australian Citizens residing in Australia only respond.
Job details
The Cyber Sustainment Section within the Cyber Security, Cloud and Networks Branch of DFAT's Information Management and Technology Division has a requirement for an ICT labour hire resource to fill the role of Artificial Intelligence Cyber Security and Controls Engineer.
The successful candidate will be responsible for leading the strategic application of AI and relevant security controls in cyber security. This role will provide expert systems guidance on AI threat detection, risk mitigation, and policy development, ensuring the department remains resilient against emerging digital threats. The increasing sophistication of cyber threats poses a significant risk to national security, critical infrastructure, and public trust. As AI technologies rapidly evolve, they offer both new opportunities and new challenges in the cyber security landscape.
The ideal candidate is a high-level operations technical expert with a deep understanding of both AI and cyber security. They possess a strong track record of applying security controls related to AI for real-world security challenges, particularly within complex or high-risk environments. With excellent communication and stakeholder engagement skills, they can bridge the gap between technical teams, architects and policy makers, translating advanced concepts into actionable controls within DFAT's ICT Enterprise environment. They are proactive, ethically minded, and committed to safeguarding national interests through innovative, secure, and responsible AI deployment. Experience in government or critical infrastructure sectors, along with relevant certifications and postgraduate qualifications, is highly desirable.
Key duties and responsibilities
Job Specific role description:
AI Governance and Controls
- Act as the AI Cyber Security Lead in the development, implementation, and continuous improvement of AI governance frameworks.
- Support the AI Accountable Authority through the development and implementation of AI strategies to enhance cyber security capabilities across the department
- Design and implement AI control frameworks aligned to cyber security, privacy, risk, and compliance requirements.
- Develop security standards, and procedures governing the use of AI technologies across the department.
- Assess AI solutions against security, privacy, ethical, and legislative requirements.
- Establish processes model for accountability, transparency, monitoring, and assurance as it relates to AI
- Conduct research and horizon scanning to identify emerging AI trends and their implications for cyber security.
AI Risk Management
- Conduct AI risk assessments and identify appropriate mitigations.
- Evaluate AI use cases and provide recommendations on secure and responsible deployment.
- Monitor emerging AI threats, such as data leakage, prompt injection, model manipulation, and unauthorised AI usage etc.
- Support the management of AI-related risks within the department's broader cyber security risk framework.
Microsoft AI and Data Protection Controls
Design, document, implement and maintain AI-related controls within Microsoft 365 and associated platforms. Configure and manage items such as:
- Microsoft Purview Data Security Posture Management (DSPM) for AI
- Microsoft Purview DLP
- Sensitivity Labels
- Information Protection
- Insider Risk Management
- Communication Compliance
- Microsoft Defender for Cloud Apps
- Copilot governance and data access controls
The Skills Framework for the Information Age (SFIA) has been used to inform the requirements. In summary, DFAT seeks suitable candidates with the following relevant skillsets:
Skills/Levels:
- AI Assurance / AI Governance - AI Governance and Assurance - Governance (GOVN) - Level 4+
- AI Assurance / AI Governance - AI Engineering / Operations - Security Operations (SCAD) - Level 4+
- AI Assurance / AI Governance - AI Change Enablement - Organisational Design and Enablement (ORDI) - Level 4+
- AI Assurance / AI Governance - Independent AI Audit and Oversight - Information and Data Compliance (PEDP) - Level 4+
Technical skills
Understanding of AI governance, cloud computing environments and secure data handling practices. / Certifications such as CISM, SC-100, SC-401, SC-500, MS-102 or equivalent are highly desirable.
About the team
The Cyber Sustainment Tools (CST) is a part of the Cyber Security, Cloud & Networks Branch (CAS/CRB/IMD). CST is responsible for several core functions relating to providing a hardened and secure environment utilising technology to safeguard DFAT's ICT environment.
Criteria
The buyer has specified that each candidate must provide a one page pitch to address all criteria specified. This is equal to 5000 characters.
Essential criteria
- 1. Experience in AI governance, technology risk, cyber security governance, or information security.
- 2. Experience implementing cyber security and compliance controls within Microsoft 365.
- 3. Experience with implementing Microsoft Purview, DLP, information protection technologies as it related to AI Governance.
- 4. Excellent stakeholder engagement skills, including collaboration with technical teams, policy makers, and external partners.
- 5. Demonstrated understanding of AI governance frameworks, responsible AI principles, privacy and data protection requirements, risk management methodologies and cyber security controls.
- 6. Familiarity with Australian Government frameworks such as PSPF, ISM, and Essential 8 along with international frameworks such as NIST.