18 hours ago
Singapore, SingaporeMid Level
Responsibilities
- Design and execute AI-specific security and safety assessments for LLM, RAG, and agentic applications.
- Implement and operationalise Moonshot and Litmus testing, including baseline suites, custom scenarios, result analysis, and repeatable assurance evidence.
- Develop representative test datasets and securely generate, classify, mask, anonymise, retain, and dispose of synthetic evaluation data.
- Translate organisational policies, government security requirements, and AI governance expectations into controls, test plans, risk assessments, and assurance evidence.
- Review AI solution designs, data flows, trust boundaries, access controls, tenant isolation, retrieval boundaries, logging, retention, model or service selection, and third-party integration risks.
- Document vulnerabilities and control gaps, guide remediation, validate fixes, communicate residual risk, and report assurance metrics and trends.
- Integrate automated AI security and evaluation tests into CI/CD pipelines and define regression checks, release gates, and acceptance criteria.
- Build and maintain automated functional, regression, API, and end-to-end tests using suitable testing frameworks.
- Reproduce defects, trace application and cloud logs, isolate root causes, and provide actionable reports.
- Promote reusable test assets and shared ownership of quality across product and engineering teams.
Requirements
- At least 3 years of relevant experience in software engineering, cybersecurity, application security, AI assurance, SDET, or technical QA automation.
- Practical understanding of LLM, RAG, and agentic application risks, including prompt injection, data leakage, unsafe tool use, excessive permissions, insecure output handling, and abuse.
- Hands-on experience with Moonshot, Litmus, or comparable AI evaluation, red-teaming, benchmarking, or adversarial-testing tools.
- Ability to interpret security, privacy, and AI governance requirements and convert them into controls, test plans, risk assessments, and assurance evidence.
- Experience reviewing system designs and data flows, assessing trust boundaries and integration risks, and recommending secure cloud application architectures.
- Strong communication and facilitation skills for explaining technical risks and guiding stakeholders toward secure implementation decisions.
- Proficiency in Python and working knowledge of TypeScript or JavaScript, with automated API, functional, regression, or end-to-end testing experience.
- Familiarity with AWS services, containerised environments, SQL databases, access controls, logging, encryption, data classification, masking, retention, and sensitive-data handling.
- Preferred experience conducting AI red-team exercises, AI threat modelling, or AI security and application assurance reviews.
- Preferred familiarity with the OWASP GenAI Security Project, NIST AI Risk Management Framework, or MITRE ATLAS.
- Preferred experience testing RAG pipelines, model integrations, agent tools, sandboxes, RBAC, tenant-isolation controls, and other AI-specific attack surfaces.
- Preferred familiarity with government enterprise environments and high-security data compliance requirements, including IM8.
Benefits
- Flexible work practices.
- 40 hours of self-development per year and access to learning opportunities.
- Diversity and inclusion initiatives and employee resource groups.
- Opportunities to participate in charity projects and volunteer days.
Tech Stack
About Capgemini
Capgemini is a global IT services and consulting firm that delivers strategy, cloud, AI, software engineering, and managed services to large enterprises and public-sector clients. Founded in 1967 and headquartered in Paris, it is publicly traded on Euronext Paris and operates in 50+ countries. The group expanded its engineering capabilities by acquiring Altran in 2020, now operating as Capgemini Engineering.
