Job Description
Job Title:  Assistant Director, AI Enablement & Security Engineering
Requisition ID:  3081
Posting Start Date:  11/08/2026

Position Summary

The Team Lead, AI Enablement & Security Engineering is a hands-on technical leadership role responsible for enabling the secure adoption of Generative AI, Large Language Models and agentic AI solutions across the IT division.

The role will go beyond policy writing to translate AI security, governance and risk requirements into practical architectures, engineering controls, reusable development patterns and assurance processes. The incumbent will design, prototype, implement and assess safeguards for LLM applications, Retrieval-Augmented Generation pipelines, AI agents and supporting AI platform services.

Working closely with cybersecurity, cloud platform, enterprise architecture, data governance, risk and application teams, the Team Lead will establish secure-by-design practices that allow AI solutions to be deployed safely, efficiently and at scale. The role will also build internal engineering capability through technical guidance, reusable assets, hands-on workshops and mentoring.

Key Responsibilities

1. AI Security Engineering and Technical Governance

  • Define and maintain secure-by-design architecture patterns, engineering standards, technical controls and security baselines for Generative AI, RAG and agentic AI solutions, aligned with OWASP, NIST AI RMF, MITRE ATLAS and applicable Singapore AI security guidance.
  • Design, implement and evaluate AI runtime guardrails across inputs, outputs, tool calls and data access to mitigate prompt injection, sensitive-data exposure, harmful content, excessive agency, insecure output handling and other adversarial behaviours.
  • Lead AI threat modelling, security assessments, testing and red-teaming across models, application, prompts, RAG pipelines, agent workflows, APIs, plugins, MCP servers and supporting infrastructure.
  • Design secure RAG architectures and AI agents incorporating identity-aware retrieval, access controls, metadata filtering, tenant isolation, source validation, retrieval-poisoning protection, least-privilege access, tool allowlisting, execution boundaries, approval checkpoints, credential isolation and auditable human oversight.
  • Conduct technical assurance reviews of internal and third-party AI solutions by validating architectures, configurations, vendor claims, security evidence and controlled proof-of-concept outcomes.
  • Contribute technical inputs to the AI inventory, covering deployed models, owners, approved data sources, hosting locations, dependencies, security classifications and control status.
  • Partner with cybersecurity, risk, legal, data protection and governance team to translate policies and risk decisions and assurance outcomes into enforceable platform and application controls.

 


2. Hands-on AI Enablement, Architecture and Prototyping

  • Design and prototype secure, scalable AI solutions using commercial and open-source models, cloud AI services, AI gateways, orchestration frameworks and agent development platforms.
  • Develop reference architectures and implementation patterns for common use cases such as enterprise chat, knowledge assistants, secure RAG, workflow automation, coding assistants and tool-using agents.
  • Implement or configure AI gateway controls covering identity, authentication, authorisation, model access, secret management, quotas, rate limits, content inspection, routing, fallback, logging and cost controls.
  • Create reusable, pre-hardened development assets, including code templates, deployment pipelines, prompt patterns, agent configurations, security test cases, policy-as-code controls and infrastructure-as-code modules.
  • Establish secure AI development and deployment practices into DevSecOps pipelines, architecture reviews, release gates and production-readiness assessments.
  • Evaluate emerging AI models, frameworks, agent protocols, guardrail technologies and security tools through structured experiments, proofs of concept and applied technical learning
  • Provide hands-on technical advisory and troubleshooting support to project teams during solution design, prototyping, security review and production onboarding.
  • Balance rapid experimentation with enterprise requirements for security, data protection, resilience, supportability, interoperability and vendor portability.

3. AI Monitoring, Assurance and Operational Observability

  • Define telemetry, logging, audit and pre-production evaluation requirements such as acceptance thresholds for security, reliability and responsible AI requirements to monitor AI applications, model interactions, retrieval activities, agent decisions and external tool calls.
  • Implement or integrate monitoring capabilities to detect abnormal usage, prompt injection attempts, policy violations, unexpected tool execution, data exfiltration indicators, repeated guardrail failures and anomalous consumption patterns.
  • Establish security and operational metrics such as policy violation rates, guardrail interventions, attack success rates, evaluation pass rates, latency, availability, token consumption, model usage and cost.
  • Develop dashboards and reports that provide engineering teams and management with visibility into AI usage, security posture, operational performance and control effectiveness.
  • Coordinate with security operations, platform operations and application support teams to develop incident detection, escalation, containment, investigation and post-implementation review procedures for AI-related events.
  • Review production evidence, security telemetry and assurance findings to identify control weaknesses, recurring failure patterns and opportunities to improve AI architectures and engineering standards.

 


4. Secure AI capability development

  • Uplift A*STAR's proficiency in secure AI engineering and implementation. This would be achieved through hands-on workshops, labs and technical clinics covering secure AI application development, prompt and context security, RAG protection, agent tool security, AI gateway controls, threat modelling and AI security testing.
  • Develop a practical secure AI engineering capability programme for architects, developers, platform engineers, cybersecurity professionals and product managers.
  • Create role-based learning paths, engineering playbooks, sample applications, coding exercises and reusable reference materials.
  • Uplift the proficiency of fellow IT colleagues, building federated capability in secure AI delivery. This would be achieved through advising project teams on real implementation challenges and embedding secure AI engineering practices, and communities of practice to share patterns, lessons learned, emerging threats, reusable components and implementation experience. 
  • Establish technical competency expectations and proficiency indicators for key AI engineering and AI security roles, in partnership with IT leadership and learning development teams.

Qualifications

Education

  • Bachelor’s degree or equivalent in Computer Science, Computer Engineering, Cybersecurity, Information Systems or another relevant technical discipline.
  • A postgraduate qualification in cybersecurity, artificial intelligence, machine learning or a related field is advantageous but not mandatory.

 

Professional Experience

  • At least 8 years of relevant professional experience across software engineering, cybersecurity, cloud architecture, platform engineering, machine learning engineering or related technical domains.
  • At least 2 years of recent hands-on experience designing, building, securing or assessing Generative AI, LLM, RAG or agentic AI solutions.
  • Demonstrated experience leading technical workstreams, mentoring engineers, establishing engineering standards or influencing architecture across multiple teams.
  • Experience operating in an enterprise, regulated, public-sector, research-intensive or similarly complex environment is advantageous.

 

Experience

Essential Technical Capabilities

  • Hands-on programming or scripting experience in Python, with the ability to independently develop prototypes, test harnesses, API integrations and security automation.
  • Practical experience implementing LLM applications using one or more relevant frameworks or SDKs, such as LangChain, LlamaIndex, Semantic Kernel, Hugging Face, cloud AI SDKs or equivalent technologies.
  • Good understanding of LLM application architectures, including prompts, context management, embeddings, vector retrieval, reranking, tool use, agents, model gateways and model hosting patterns.
  • Practical understanding of AI security risks, including prompt injection, jailbreaks, sensitive-information disclosure, retrieval poisoning, insecure output handling, excessive agency, model denial of service and AI supply-chain risks.
  • Experience designing or evaluating application security controls, API security, identity and access management, secrets management, network controls and secure cloud architectures, or working with other teams or vendors on the same..
  • Experience with at least one major cloud platform—AWS, Microsoft Azure or Google Cloud—and familiarity with containerised platforms, CI/CD pipelines, infrastructure as code and modern observability practices.
  • Ability to analyse technical architectures, configurations, logs, API behaviours and security test evidence rather than relying solely on vendor declarations or compliance documentation.

 

Desirable Technical Capabilities

  • Experience with AI or LLM guardrail technologies such as but not limited to NVIDIA NeMo Guardrails, Llama Guard, Guardrails AI, cloud-native content safety services or equivalent policy-enforcement technologies.
  • Experience in one or more areas including AI security testing, adversarial evaluation, red teaming, penetration testing or security research, or in working with other teams or vendors on the same.
  • Familiarity with vector technologies such as pgvector, OpenSearch, Pinecone, Milvus, Weaviate, Chroma or equivalent platforms, including metadata-based access control and multi-tenant retrieval patterns.
  • Experience with AI gateways, API management platforms, model routers, agent gateways, Model Context Protocol, agent-to-agent communication or policy enforcement for autonomous AI systems.
  • Familiarity with AI risk and security guidance such as OWASP GenAI Security guidance, NIST AI RMF, MITRE ATLAS, ISO/IEC 42001, Singapore’s Model AI Governance Framework and CSA Guidelines on Securing AI Systems.
  • Experience integrating AI telemetry with enterprise monitoring, SIEM, security operations or FinOps platforms, or working with other teams or vendors on the same.

Leadership and Stakeholder Capabilities

  • Ability to provide technical advice while remaining sufficiently hands-on to prototype solutions, inspect implementations and support complex troubleshooting.
  • Strong judgement in balancing security, usability, delivery speed, cost, scalability and operational sustainability.
  • Ability to translate technical weaknesses and attack scenarios into clear business risks, control decisions and prioritised remediation actions.
  • Ability to work across cybersecurity, architecture, cloud, application development, data governance, procurement, risk, legal and business teams.
  • Demonstrated ability to uplift the proficiency of fellow colleagues in other IT functional teams, in his/her area of expertise.

Certifications

 

Relevant certifications are advantageous but should not be mandatory. These may include:

  • CISSP, CCSP, CSSLP or equivalent cybersecurity certifications;
  • AWS, Azure or Google Cloud professional-level architecture or security certifications;
  • Kubernetes, DevSecOps or application security certifications;
  • AI, machine learning or responsible AI qualifications from recognised institutions or technology providers.

Equivalent demonstrated technical experience should be considered in place of formal certifications.

The above eligibility criteria are not exhaustive. A*STAR may include additional selection criteria based on its prevailing recruitment policies. These policies may be amended from time to time without notice. We regret that only shortlisted candidates will be notified.