Senior AI Security Engineer II
Zip
| Company | Zip |
| Category | Engineering |
| Location | Melbourne; Sydney |
| Remote | On-site (inferred) |
| Employment | Not stated |
| Level | Senior |
| Salary | Not stated by the employer |
| Posted | 26 May 2026 |
| Last verified | 8 Aug 2026 |
| Source | Employer ATS (greenhouse) |
Description
Senior AI Security Engineer II
Deep experience across AI security, application security, cloud security or security engineering, with hands-on exposure to LLMs, RAG systems and AI APIs
Shape how AI security is embedded across Zip’s next generation products, LLM applications and agentic workflows, helping protect millions of customers and merchants
Hybrid working flexibility, with team connection days in our Sydney or Melbourne offices
Write your story with a career at Zip
Join Zip’s Technology function, responsible for building and maintaining seamless, secure and sustainable platforms that enable customers to shop with confidence and merchant partners to grow their brands.
As part of our Cyber Security team, you’ll play a key role in helping Zip adopt AI safely, responsibly and at scale. Working across AI-enabled products, internal tooling and emerging technologies, you’ll partner closely with Engineering, Product, Data, Privacy, Legal and Risk teams to embed security by design into how we build and deliver.
This is an opportunity to work at the forefront of AI security, tackling evolving threats and designing practical controls that protect customers, merchants and Zipsters alike. You’ll bring a pragmatic and forward-thinking approach to threat modelling, secure AI architecture and risk reduction, while helping shape the future of AI governance and security practices across the business.
What you’ll own
Lead security reviews and threat modelling activities across AI-enabled products, LLM applications, RAG systems, agentic workflows and AI APIs
Identify and assess AI-specific threats including prompt injection, model abuse, sensitive data disclosure, insecure output handling, excessive agency and model or data poisoning risks
Design and implement secure AI patterns including least-privilege access controls, output validation, audit logging, monitoring, abuse detection and human approval workflows
Partner with Engineering teams to embed AI security controls into SDLC, CI/CD, MLOps and LLMOps practices
Contribute to AI governance frameworks, standards, policies and control mapping activities across the organisation
Review third-party AI vendors, SaaS AI capabilities and model providers to support secure and compliant adoption of AI technologies
Help develop AI security tooling, testing approaches and monitoring capabilities to proactively identify and reduce risk before production deployment
Deliver practical guidance and awareness sessions that improve understanding of AI security risks, controls and secure design practices across technical and non-technical teams
What you'll bring to the team
Zipsters work on a broad range of initiatives, and our skills and experiences all look a little different. What really matters to us is that you’re a great fit with our four Values, and have a desire to learn and grow.
So whether you meet some or all of the desirable attributes below, we’d still love to hear from you:
5+ years experience across security engineering, application security, cloud security, product security, security architecture, penetration testing or red teaming
Hands-on experience securing or reviewing AI/ML, LLM, RAG or agent-based systems
Threat modelling capabilities with the ability to translate security risk into practical engineering outcomes
Experience across web and API security, IAM, secrets management, secure SDLC, cloud security, logging, detection and incident response
Programming experience with Python or another modern programming language
Familiarity with LLM architectures, vector databases, embeddings, AI agents and modern AI data flows
Exposure to frameworks such as OWASP LLM Top 10, MITRE ATLAS, NIST AI RMF, Google SAIF or ISO/IEC 42001 is highly regarded
Expert communication and stakeholder engagement skills, with the ability to influence and collaborate across technical and business teams
A mindset that embraces A