About Capgemini
Capgemini is an AI-powered global business and technology transformation partner, delivering tangible business value. We imagine the future of organizations and make it real with AI, technology and people. With our strong heritage of nearly 60 years, we are a responsible and diverse group of over 420,000 team members in more than 50 countries. We deliver end-to-end services and solutions with our deep industry expertise and strong partner ecosystem, leveraging our capabilities across strategy, technology, design, engineering and business operations. The Group reported 2025 global revenues of €22.5 billion.
About the Role
We are looking for a highly technical Software Engineer to strengthen the security, compliance, and quality assurance of our enterprise-grade Generative AI and agent orchestration platform. The primary focus of this role is AI security assurance: implementing and operating Moonshot and Litmus testing, conducting adversarial and risk-based assessments of LLM and agentic applications, translating compliance requirements into practical controls, and advising internal stakeholders on secure data handling and solution architecture. Software test automation remains an important secondary responsibility to support reliable product delivery. This role suits an engineer who can combine hands‑on security testing with sound architectural judgement, communicate risk clearly, and work collaboratively with product, engineering, security, governance, and business teams.
Responsibilities
- AI Security, Compliance & Architecture:
- AI Security Testing: Design and execute AI-specific security and safety assessments for LLM, RAG, and agentic applications, covering threats such as prompt injection, jailbreaks, sensitive-data disclosure, insecure output handling, excessive agency, tool misuse, and cross‑tenant data exposure. Conventional application penetration testing is performed by third‑party providers and is outside the primary scope of this role.
- Moonshot & Litmus Implementation: Implement and operationalise Moonshot and Litmus testing across relevant AI use cases. Configure baseline and application-specific test suites, curate adversarial scenarios, analyse results, and establish repeatable evidence for assurance reviews.
- AI Evaluation & Test Data Governance: Develop representative test datasets and securely generate synthetic data for functional, safety, and security evaluation. Ensure test data is appropriately classified, masked, anonymised, retained, and disposed of in accordance with applicable policies.
- Compliance, Assurance & Risk Advisory: Translate organisational policies, government security requirements, and AI governance expectations into testable controls and evidence. Advise internal stakeholders on secure use of enterprise and sensitive data in GenAI solutions, including data flows, access controls, tenant isolation, retrieval boundaries, logging, retention, model or service selection, and third‑party integration risks. Support risk assessments, security reviews, audit responses, remediation plans, and go‑live assurance activities.
- Secure Solution Architecture: Review proposed AI solution designs, identify security and privacy risks, recommend proportionate controls, and collaborate with engineering and architecture teams to embed security by design throughout the solution lifecycle.
- Security Findings, Remediation & Reporting: Document vulnerabilities and control gaps with clear risk, impact, evidence, and remediation guidance. Work with delivery teams to track and validate fixes, communicate residual risk to technical and non‑technical stakeholders, and report assurance metrics, recurring findings, and risk trends.
- Security Automation & Release Assurance: Integrate automated AI security and evaluation tests into CI/CD pipelines and release processes. Define security regression checks, release gates, and acceptance criteria to identify material risks before production deployment.
- Software Test Automation:
- Test Automation: Build and maintain automated functional, regression, API, and end‑to‑end tests using suitable frameworks such as Pytest, Playwright, Cypress, or Postman.
- Defect Investigation: Reproduce issues, trace application and cloud logs, isolate root causes, and provide actionable defect reports to engineering teams.
- Quality Enablement: Promote pragmatic testing practices, reusable test assets, and shared ownership of quality across product and engineering teams.
Requirements
- Experience: 3+ years of relevant experience in software engineering, cybersecurity, application security, AI assurance, SDET, or technical QA automation.
- AI Security Knowledge: Practical understanding of security and safety risks affecting LLM, RAG, and agentic applications, including prompt injection, data leakage, unsafe tool use, excessive permissions, insecure output handling, and model or application abuse.
- AI Testing Toolkits: Hands‑on experience with Moonshot,