- Experience
- 5+ yrs
- Salary
- —
- Openings
- 1
- Posted
- 6 days ago
- Work mode
- In office
- Resume
- Required to apply
Where you'll work
Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.
Job description
About Taxfix
Taxfix is revolutionizing tax filing by providing an intuitive app that empowers millions to confidently file their taxes regardless of background or education. Since 2016, the Taxfix Group, spanning Germany, Spain, and the UK, has helped customers secure over 3.5 billion euros in tax refunds. The company consists of over 400 professionals including tax experts, IT security specialists, and developers dedicated to innovating tax solutions.
Role Overview
We are looking for a skilled Senior Platform Security Engineer to architect and uphold security for our cloud-native infrastructure and AI platforms. This position involves protecting environments across multiple clouds, securing container technologies and Kubernetes, safeguarding AI/ML workflows, and embedding security within the software development lifecycle.
Key Responsibilities
- Create and execute security architectures for cloud platforms such as AWS, Azure, and GCP.
- Apply best security practices to containerized deployments and Kubernetes configurations.
- Maintain and develop secure Infrastructure as Code (IaC) artifacts.
- Design and implement zero-trust networks and secure service mesh infrastructures.
- Build and manage secure CI/CD pipelines aligned with DevSecOps principles.
- Ensure end-to-end security of AI-driven features, covering all components from context gathering to final output handling.
- Establish and assess security controls for Retrieval-Augmented Generation (RAG) implementations.
- Secure agentic AI solutions, including tool integration points, agent functionalities, and autonomous action constraints such as scoped credentials, sandbox environments, and human oversight mechanisms.
- Develop defenses against prompt injection and adversarial attacks targeting LLM-based applications.
- Implement data security measures for sensitive information processed during inference, retrieval, and model fine-tuning workflows.
- Lead incident management related to cloud and AI infrastructure security breaches.
- Develop and deploy security monitoring and detection processes.
- Conduct thorough threat modeling and evaluate risks associated with cloud-native and AI systems.
- Perform regular security audits of cloud infrastructure and container ecosystems.
- Produce and maintain comprehensive security documentation including policies, procedures, and response runbooks.
- Work closely with cross-functional teams including development, data science, and operations to integrate security requirements effectively.
- Communicate clearly security needs and recommendations to stakeholders of varying technical backgrounds.
- Stay abreast of the latest threats and trends related to cloud-native and AI security.
- Participate in selecting technologies for enhancing the security tooling and platform landscape.
Experience & Expertise
- Minimum 5 years in information security with at least 3 years focused on cloud security.
- At least 3 years of practical experience securing containerized systems such as Docker and Kubernetes.
- Proven hands-on experience in securing AI/ML or LLM-based products and systems.
- Solid expertise in one or more major cloud providers: AWS, Azure, or GCP.
Technical Proficiencies
- Advanced knowledge of container and Kubernetes security and cloud-native security models.
- Expertise with Infrastructure as Code tools like Terraform and CloudFormation.
- Strong skills in network security, identity and access management strategies.
- Experience with cloud environment security tools such as Cloud Security Posture Management (CSPM).
- Familiarity with AI/ML and Large Language Model (LLM) security, including frameworks like TensorFlow and PyTorch, with an understanding of their security challenges.
- Competency in programming and scripting languages including Python, Go, and Bash.
- Experience in automating security operations and orchestration processes.
Preferred Qualifications
- Extensive experience securing Large Language Models and generative AI applications.
- Familiarity with AI/LLM security standards like OWASP LLM Top 10 and knowledge of AI governance or compliance frameworks.
- Experience managing secure multi-tenant AI infrastructures.
- Knowledge of privacy-enhancing techniques for AI/ML such as differential privacy and federated learning.
- Involvement in open-source security projects or public security research contributions.
- Proven ability to develop security tools or automation frameworks.
Why Join Taxfix?
- Engage in impactful, user-centered work alongside an international team of driven professionals.
- Access free mental health coaching supporting holistic well-being.
- Benefit from a flexible monthly allowance applicable to a broad spectrum of services, which can be accumulated or rolled over.
- Participate in employee stock options, ensuring access to shared success.
- Enjoy 30 vacation days annually and a flexible schedule.
- Opportunity to work remotely from abroad for up to six weeks per year with team alignment.
- Regular team-building activities, tech meetups, and social gatherings both online and in-person.
- Complimentary use of the Taxfix app for personal tax filing and internal tax assistance.
- Pet-friendly office environment welcoming dogs.
Diversity & Inclusion
Taxfix is committed to equal opportunity hiring and personal development regardless of gender, race, religion, age, sexual orientation, color, disability, or origin. The recruitment process strives to minimize unconscious bias by omitting personal photos, age, and marital status from CVs to focus on experience and skills.
Encouragement
Applicants who may not fulfill all criteria are encouraged to apply, as they may bring unique perspectives and value to the team.
Industry
FinTech