{"id":1248982,"url":"https://alion.io/job/gic-vp-ai-security-engineer-technology-group","title":"VP, AI Security Engineer, Technology Group","company":{"id":2761,"name":"GIC","domain":"gic.com.sg","url":"https://alion.io/company/gic","size_band":"1001-5000","is_staffing_agency":false,"employer_type":"direct","is_intermediary":false,"listed_via":null,"ats_vendor":"SuccessFactors","truth_index":null},"role":"AI/ML","role_family":"AI/ML","seniority":"head","employment_type":null,"work_mode":"on_site","remote_scope":null,"remote_scope_basis":null,"remote_working_hours":null,"hiring_geo_confidence":"structured","locations":["Singapore"],"countries":["SG"],"hiring_countries":[],"hiring_countries_total":0,"salary":null,"salary_estimate":{"min_usd":68000,"max_usd":179000,"period":"year","method":"global_role_cell_scaled_by_country","sample_n":67},"experience_years_min":8,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"AI Agents","optional":false},{"name":"Amazon EKS","optional":false},{"name":"AWS","optional":false},{"name":"CI/CD","optional":false},{"name":"IAM","optional":false},{"name":"Least Privilege","optional":false},{"name":"Python","optional":false},{"name":"SIEM","optional":false},{"name":"Zero Trust","optional":false},{"name":"Agile","optional":true},{"name":"ISO 27001","optional":true},{"name":"Kubernetes","optional":true},{"name":"Model Context Protocol","optional":true},{"name":"NIST AI RMF","optional":true},{"name":"SOC 2","optional":true}],"status":"live","first_seen_at":"2026-09-22T16:00:00Z","employer_posted_date":"2026-09-22","last_verified_at":"2026-09-29T15:36:17Z","board_verified":true,"closed_at":null,"days_open":7,"trust":{"level":"ok","repost_count":null,"flags":[],"days_open":7},"description":"About GIC\nGIC is one of the world's largest sovereign wealth funds. With over 2,000 employees across 11 locations around the world, we invest in more than 40 countries globally across asset classes and businesses. Working at GIC gives you exposure to an extraordinary network of the world's industry leaders. As a leading global long-term investor, we work at the Point of Impact for Singapore's financial future, and the communities we invest in worldwide.\nTechnology Group\nWe experiment, design, and lead a 24×7 global business where we support core capabilities in asset management, trading, investment operations, and risk management. We deliver secure, reliable, and integrated solutions, and provide insights on new and emerging technologies.\nStrategy, Architecture, and Transformation Group\nThe Strategy, Architecture & Transformation (SAT) group shapes and drives GIC’s technology strategy, ensuring alignment with business priorities and enterprise goals. Bringing together expertise in strategy, architecture, engineering, and transformation, the team strengthens governance, promotes consistency, and accelerates delivery across the Technology Group. Through modern practices and close collaboration, SAT leads the development of an architectural strategy that reinforces oversight and accountability while enabling reliable, scalable solutions and informed decision making across the Technology Group and, more broadly, across GIC.\nAI Engineering\nThe AI Engineering team within SAT is driving GIC's transformation from AI-enabled to AI-native. We build and operate the foundational AI platform - gateway, agent runtime, agentic IAM, memory, observability, and more - so that every team across GIC can develop and deploy AI agents that are secure, observable, and production-grade.\nWhat impact can you make in this role?\nAutonomous agents introduce a fundamentally different threat model: software that dynamically decides what to access, composes actions unpredictably, processes untrusted inputs, and operates at machine speed. Traditional security patterns assume human actors - you will design the security architecture for a world where they don’t.\nAs the AI Security Engineer, you will be the team’s subject-matter expert on both AI-specific and traditional security, responsible for the security posture of every service the AI Engineering team builds. You will design and drive the implementation of the agentic IAM layer - agent identity, composite identity (user + agent + tool), policy-driven authorisation, secret management, and blast-radius control - and embed security into every platform capability: the gateway, agent runtime, memory, and observability.\nYou will work closely with enterprise security teams - Cybersecurity Engineering, Cybersecurity Assurance & Defence, and IAM Engineering - to co-design the identity model, policy framework, and secret management patterns that make autonomous agents governable. Where enterprise solutions exist, you translate them into detailed design and implementation for the AI platform. Where they are still being built, you bridge the gap with interim frameworks and tooling so the team is never left unprotected.\nYou will partner with the AI Site Reliability Engineer to ensure the platform is both resilient and secure - inseparable concerns - and work with the core AI platform squad to make every service, SDK, and tool secure by design: threat models before architecture reviews, policy-as-code before deployment, and automated compliance checks before release.\nYou are not a security auditor reviewing after the fact. You are a hands-on security engineer who writes policy, builds identity frameworks, implements controls, and raises the security bar for the entire engineering squad - mentoring and equipping the team to do the same.\nThis is a platform security engineering role embedded within the AI Engineering team - not an enterprise cybersecurity function. Enterprise Cybersecurity Engineering owns the organisation-wide strategy, threat intelligence, and assurance standards; you engineer those standards into the AI platform.\nYour Impact:\nEnable agentic IAM with enterprise IAM Engineering - architect the agent identity model (composite identity: user + agent + tool), session scoping, delegation chains, and identity propagation across the full call chain\nImplement policy-as-code - stand up the policy engine (Cedar / Amazon Verified Permissions preferred; OPA / Rego for cross-platform needs) enforcing zero-trust authorisation, action risk tiers, toxic combination detection, and blast-radius controls\nOwn the AI threat model - identify, document, and mitigate AI-specific attack surfaces: prompt injection, tool poisoning, agent hijacking, privilege escalation, data exfiltration, and model manipulation\nSecure the gateway - embed controls for content-safety filtering, jailbreak mitigation, credential injection prevention, and per-request policy evaluation\nBridge enterprise and platform security - translate enterprise baselines (network segmentation, SIEM integration, vulnerability management, incident response) into AI-platform-specific implementations\nPartner on resilience - design scoped sessions, kill switches, and deployment safety controls with the AI Site Reliability Engineer\nEnsure the platform is secure by design - embed threat modelling, scanning, policy validation, and compliance checks into CI/CD and deployment pipelines\nBuild the security framework for the squad - define standards, review checklists, secure coding guidelines, and incident response playbooks\nManage agent secrets - design the agent secret broker for just-in-time credential issuance, scoped access, and automatic revocation\nWhat will you do as an AI Security Engineer?\nYou will design and implement the security architecture for the AI platform, embedding zero-trust principles and agentic identity management into every layer of the stack. You will:\nArchitect and implement the agentic IAM layer and policy-as-code engine\nDevelop and maintain the AI-specific threat model and mitigation strategies\nCollaborate with enterprise cybersecurity and IAM teams to align standards and tooling\nEmbed security controls into the AI gateway, runtime, and memory systems\nIntegrate security scanning, validation, and compliance automation into CI/CD pipelines\nPartner with the AI Site Reliability Engineer to ensure resilience and security reinforce each other\nMentor engineers on secure development practices and lead by example through hands-on implementation\nBuild interim security frameworks and tooling where enterprise solutions are still evolving\n.\nWhat makes you a successful candidate?\n Must Have:8+ years in security engineering, application security, or platform security, with at least 2 years in a lead role responsible for platform or product security architecture\nDeep security engineering expertise - hands-on in threat modelling, secure architecture review, penetration testing, and incident response\nZero-trust architecture experience - designing per-request verification, least-privilege access, micro-segmentation, and ABAC-based systems\nCloud-native workload identity - hands-on with AWS workload identity (EKS Pod Identity / IRSA, IAM Identity Center, SCIM, IAM Roles Anywhere)\nPolicy-as-code - production experience with Cedar / Amazon Verified Permissions or OPA / Rego\nCloud security (AWS preferred) - IAM, EKS, KMS, Secrets Manager, GuardDuty, Security Hub, WAF, and VPC security\nCI/CD security - embedding SAST, DAST, dependency and container scanning, secrets detection, and policy gates\nHands-on coding proficiency in Python - building security tooling, policy integrations, and prototypes\nProven experience partnering with enterprise security teams and translating standards into platform implementations\n\n Nice to Have:Experience with AI/ML security - prompt injection defence, content-safety filtering, model poisoning detection, and adversarial robustness\nFamiliarity with agentic systems and their unique security challenges\nExperience with SPIFFE / SPIRE and platform-agnostic workload identity\nBackground in trusted identity propagation and data access control frameworks\nExpertise in secret management architectures (Vault, AWS Secrets Manager)\nExperience designing data classification and access control frameworks\nFamiliarity with MCP and its security considerations\nExposure to compliance frameworks (MAS TRM, ISO 27001, SOC 2, NIST AI RMF)\nContributions to open-source security tooling or published research\n\nMindset & Working Style:Secure by design, not by audit - security is architected in, not bolted on\nHands-on leader - you lead by building and mentoring\nBridge builder - you collaborate seamlessly across enterprise and platform teams\nPragmatic risk thinker - you calibrate controls to risk and make trade-offs explicit\nStrong communicator - you can explain threat models, write clear documentation, and mentor effectively\nBuilder at heart - you thrive in early-stage environments defining foundational security architecture\n\nWork at the Point of Impact\nWe need to be forward-looking to attract the right people to help us become the Leading Global Long-term Investor. Join our ambitious, agile, and diverse teams - be empowered to push boundaries and pursue innovative ideas, share your views, and be heard. Be anchored on our PRIME Values: Prudence, Respect, Integrity, Merit and Excellence, which guides us in how we make our day-to-day decisions. We strive to inspire. To make an impact.\nFlexibility at GIC\nAt GIC, our offices are vibrant hubs for ideation, professional growth, and interpersonal connection. At the same time, we believe that flexibility allows us to do our best work and be our best selves. Thus, our teams come into the office four days per week to harness the benefits of in-person collaboration, but have the flexibility to choose which days they work from home and adjust this arrangement as situational needs arise.\nGIC is an equal opportunity employer\nGIC is an equal opportunity employer, and we value diversity. We do not discriminate based on race, religion, color, national origin, sex, gender, gender expression, sexual orientation, age, marital status, veteran status, or disability status. We will ensure that individuals with disabilities are provided reasonable accommodation to participate in the job application or interview process, to perform essential job functions, and to receive other benefits and privileges of employment.\nLearn more about our Technology Group here:\nhttps://gic.careers/group/technology-group/","description_format":"text","description_chars":10576,"description_truncated":false,"requirements":{"experience_years_min":8,"management_years_min":2,"team_size_min":null,"manages_managers":false,"education":null,"security_clearance":false,"languages":[]},"benefits":[],"hiring_locations":[],"hiring_excludes":[],"relocation_offered":false,"industries":["Information Security","Pension & Sovereign Wealth Funds"],"lifecycle":[{"event":"open","at":"2026-09-25T18:14:55Z"}],"liveness":{"score":76,"band":"hot","label":"Hiring now","p_open":1,"p_active":0.842,"p_room":0.9,"age_days":6,"expected_fill_days":15,"reasons":["conf:1","velocity","win:mid","comp:brand"],"computed_at":"2026-09-29T05:45:00Z"},"pay":null,"html_url":"https://alion.io/job/gic-vp-ai-security-engineer-technology-group","json_url":"https://alion.io/job/gic-vp-ai-security-engineer-technology-group.json","meta":{"generated_at":"2026-09-30T01:06:02Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":650,"day_limit":5000,"remaining_today":4350,"minute_limit":60,"resets_at":"2026-10-01T00:00:00Z"}}}