16 Sep
|
Publicis Re:Sources
|
Gurugram
16 Sep
Publicis Re:Sources
Gurugram
About the Company:
Publicis Re:Sources is at the core of Publicis Groupe, the world's largest communications company. We are the only full-service, end-to-end shared service organization in the industry, enabling Groupe agencies to do what they do best: innovate and transform for their clients.
Formed in 1998 as a small team to service a few Publicis Groupe firms, Publicis Re:Sources has grown to 6,000+ employees in over 55 countries. We provide technology solutions and business services, including finance, accounting, legal, benefits, procurement, tax, real estate, treasury and risk management, information security, and global mobility — supporting 110,000+ employees across the Publicis Groupe network. Our people are at the center of everything we do, bringing curiosity, collaboration, and a commitment to excellence to their work every day.
Learn more about Publicis Re:Sources and the Publicis Groupe agencies we support at publicisresources.com.
Job Scope & Responsibilities:
- Core Penetration Testing: Conduct in-depth penetration testing across web applications, mobile applications, thick clients, cloud-native applications, APIs, and network environments using a combination of automated tools and manual testing techniques.
- AI, LLM, Agentic AI & MCP Security Testing: Assess AI chatbots, AI agents, LLM-powered applications, and Model Context Protocol (MCP) servers to identify risks introduced by AI systems and evaluate how those risks can be tested, governed, and reduced.
- AI Security Test Execution: Design and execute hands-on test scenarios covering prompt injection, tool exploitation, jailbreaks, harmful outputs, sensitive data exfiltration, excessive agency, hallucination, grounding failures, policy bypass,
and other AI-specific attack patterns.
- AI-Enabled Testing & Automation: Build and use AI agents, agent skills, and automation workflows to execute repeatable security tests, automate adversarial prompt execution, validate guardrail behaviour, analyse responses, and accelerate testing activities.
- Reporting & Remediation: Identify, classify, and prioritize vulnerabilities based on risk and business impact. Prepare clear reports that include findings, evidence, proof-of-concept details where applicable, and practical remediation guidance.
- Collaboration & Delivery Support: Work with internal security, development, and project teams to understand application functionality, validate risks, communicate findings, and support remediation discussions within the agreed engagement scope.
- Continuous Learning: Stay current with emerging security threats, vulnerabilities, technologies, AI security risks, and evolving testing methodologies.
- Methodology & Process Contribution: Contribute to agreed security testing templates, reporting formats, methodologies, and process documentation required for consistent and effective engagement delivery.
Required Job Profile:
- Bachelor’s degree in computer science, information security, or a related discipline.
- 4 Plus years of hands-on experience delivering vulnerability assessment and penetration testing engagements across application and technology environments.
- Robust understanding of Industry known standards like OWASP, SANS, OSSTMM, PTES, and NIST
- 2 Plus years of hands-on experience securing and pentesting AI/LLM applications, agentic workflows, RAG, tool/function calling, and MCP-based systems, with expertise in identifying and validating risks such as prompt injection, jailbreaks, tool abuse, privilege escalation, data exfiltration, unsafe actions, guardrail bypass, hallucinations, grounding failures, and model abuse.
- Hands-on experience creating agent skills, building and configuring AI agents, integrating tools and workflows, and using automation to streamline testing, validation, reporting, and operational activities.
- Hands-on experience with AI Assisted models such as Codex and Copilot, including prompt design techniques to generate effective, accurate, and context-aware outputs.
- Hands-on experience with application security testing tools such as HCL AppScan and Burp Suite.
- Good conceptual understanding and practical experience with SAST, DAST, and other security testing approaches relevant to software development.
- Strong foundation in application architecture, development practices, and the software development lifecycle.
- Hands-on coding experience in any technology stack, along with practical scripting experience to support testing, automation, and analysis activities.
- Strong knowledge of secure software development principles, including cryptography, authentication mechanisms, and security protocols.
- Relevant certifications such as OSCP, OSWE, or CEH are preferred.
📌 Senior Application Security Specialist (Gurugram)
🏢 Publicis Re:Sources
📍 Gurugram