Agentic Automation & LLM Integration for AppSec (SAST/SCA) (Sydney)

Agentic Automation & LLM Integration for AppSec (SAST/SCA) (Sydney)

02 Oct
|
Ampstek
|
Sydney

02 Oct

Ampstek

Sydney

Hi

Role: AI Expert – Agentic Automation & LLM Integration for AppSec (SAST/SCA)

Location: Sydney

Contract

Role Purpose

Build the AI/agentic layer on top of the SAST/SCA capability. GitLab’s own Duo/agentic features are out of scope for this programme. The role is responsible for designing and building custom automation using OpenAI or equivalent LLM APIs and agentic patterns to reduce triage effort, cut false-positive noise, and speed up remediation.

Key Responsibilities

- Design and build integrations that pull SAST/SCA findings out of GitLab via API/webhooks into an external pipeline for AI-assisted processing.
- Build LLM-based triage assistance, including:
- False-positive likelihood scoring
- Vulnerability explanation in plain language
- Contextual remediation suggestions based on actual code diff/repository context
- Design agentic workflows using multi-step, tool-using LLM agents to:
- Correlate a dependency CVE with actual usage in code
- Check available safe upgrade paths
- Draft remediation MRs for human review
- Own prompt engineering, evaluation, and guardrails, including:
- Hallucination checks
- Human-in-the-loop approval gates
- Approval before auto-generated fixes reach a merge request
- Audit logging for every AI-assisted decision
- Select and integrate the LLM provider/stack such as OpenAI API or alternatives, considering data residency and confidentiality constraints.
- Build feedback loops so agent outputs, including false-positive calls and fix suggestions,



are measured against actual analyst/developer decisions to improve accuracy over time.
- Work with SMEs to ensure the AI layer complements rather than duplicates native GitLab scanning logic.
- Work with the BA to translate desired outcomes such as reduced MTTR and lower false-positive rates into technical automation targets.
- Document architecture, data flows, and model usage for security/compliance review in a regulated telco workplace.

Experience Level

- Senior professional with 8+ years of software/AI engineering experience .
- At least 1–2 years of hands-on experience building production LLM-based or agentic systems .
- AppSec domain experience is a strong plus.

Required Knowledge & Skills

- Hands-on experience with LLM APIs such as OpenAI, Anthropic, or equivalent.
- Experience with:
- Function calling / tool use
- Structured outputs
- Context management at production scale
- Practical experience designing agentic systems , including:
- Multi-step reasoning
- Tool-use orchestration
- Human-approval checkpoints rather than fully autonomous action
- Strong software engineering skills with the ability to build and maintain integration pipelines using:
- GitLab APIs/webhooks
- CI/CD hooks
- Strong understanding of prompt engineering best practices and evaluation methodologies , including measuring whether an AI triage decision is actually accurate rather than simply plausible.

Regards

James

Lead APAC Recruiter | Amsptek LLC

Cell: +61862450617

📌 Agentic Automation & LLM Integration for AppSec (SAST/SCA) (Sydney)
🏢 Ampstek
📍 Sydney

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: agentic automation & llm integration for appsec (sast/sca) (sydney) / sydney

Subscribe to this job alert:

Get the latest job offers by email for: agentic automation & llm integration for appsec (sast/sca) (sydney) / sydney