Senior Platform Security Engineer (d/f/m)

Taxfix

2h ago 0 views 0 applications
Full-time Hybrid
Berlin
Competitive
Full-time
Security Engineer

Job Description

Revolutionize Tax Filing: Senior Platform Security Engineer - Cloud & AI

Our Mission
Millions face anxiety or forfeit refunds during tax season. We're changing that. Our intuitive app empowers anyone to file their taxes with newfound confidence, making a real difference in people's lives.
As the Taxfix Group, with brands like Taxfix, Steuerbot, and TaxScouts, we are a compassionate team of over 400 solution-finders spread across Germany, Spain, and the UK. We foster open communication and rich ideas from tax experts, developers, and IT security professionals. Since 2016, our group has facilitated over 3.5 billion euros in tax refunds, built on a foundation of trust and innovation.

Your Impact
We are seeking an exceptional Senior Platform Security Engineer to lead the charge in safeguarding our rapidly evolving cloud-native infrastructure and cutting-edge AI systems. This is a critical role where you'll design, implement, and maintain robust security solutions across our multi-cloud environments, ensuring the integrity of our containerized and Kubernetes deployments, protecting sensitive AI/ML workflows, and embedding security deep within our SDLC. You'll bring deep technical and programmatic expertise in cloud-native security, coupled with demonstrable hands-on experience in securing AI/ML systems.

What You'll Be Doing

Cloud & Infrastructure Security

Design and implement comprehensive security architectures for cloud platforms (AWS, Azure, GCP).
Implement security best practices for container and Kubernetes deployments.
Develop and maintain secure Infrastructure as Code (IaC) codebases.
Design and deploy zero-trust network architecture and secure service mesh solutions.
Build and maintain secure CI/CD pipelines following DevSecOps principles.

AI/ML Security

Secure AI-powered product features end to end, covering context assembly, tool invocation, and output handling.
Design and review security controls for RAG (Retrieval Augmented Generation) implementations.
Secure agentic solutions and their extension points: tool integrations (MCP clients and servers), agent skills, and autonomous action boundaries such as scoped credentials, sandboxing, and human-in-the-loop gates.
Build defenses against direct and indirect prompt injection and other adversarial inputs to LLM applications.
Establish data security controls for sensitive data flowing through inference, retrieval, and fine-tuning.

Security Operations & Incident Response

Lead incident response for cloud and AI infrastructure security incidents.
Develop and implement security monitoring and detection strategies.
Conduct threat modeling and risk assessments for cloud-native and AI systems.
Perform regular security assessments of cloud infrastructure and container deployments.
Create and maintain security documentation, including policies, procedures, and run-books.

Strategic Leadership & Collaboration

Collaborate with development, data science, and operations teams to integrate security seamlessly.
Communicate security requirements and recommendations to technical and non-technical stakeholders.
Stay current with emerging threats and security trends in cloud-native and AI security.
Participate in technology selections for security tooling and platforms.

What You'll Bring

Essential Skills & Experience

5+ years of experience in information security, with at least 3 years specializing in cloud security.
3+ years of hands-on experience securing containerized environments (Docker, Kubernetes).
Demonstrable hands-on experience securing AI/ML or LLM-based systems.
Strong background in at least one major cloud provider (AWS, Azure, GCP).
Expert knowledge of container security, Kubernetes security, and cloud-native security patterns.
Proficiency with Infrastructure as Code tools (Terraform, CloudFormation, etc.).
Strong understanding of network security, identity management, and access control.
Experience with security tooling for cloud environments (Cloud Security Posture Management, CSPM).
Working knowledge of AI/ML and LLM security, including familiarity with frameworks like TensorFlow and PyTorch and their security implications.
Proficiency in scripting and programming languages (Python, Go, Bash).
Experience with security automation and orchestration.

Bonus Points

Deep experience securing Large Language Models (LLMs) and generative AI systems.
Familiarity with AI/LLM security frameworks (e.g., OWASP LLM Top 10) and AI governance or compliance requirements.
Experience with secure multi-tenant AI infrastructure.
Experience with privacy-enhancing technologies for AI/ML (differential privacy, federated learning).
Contributions to open-source security projects or public security research.
Experience building security tools or automation frameworks.

Why Join Taxfix?

A chance to do meaningful, people-centric work with an international team of passionate professionals.
Holistic well-being with free mental health coaching sessions.
A monthly allowance to spend on an extensive range of services that you can use and roll over as flexibly as you like.
Employee stock options for all employees—because everyone deserves to benefit from the success they help to create.
30 annual vacation days and flexible working hours.
Work from abroad for up to six weeks every year. Just align with your team, and then enjoy your trip.
Plenty of opportunities to socialise as a team. In addition to internal tech meetups, our international team hosts regular get-togethers—virtually and in person when possible.
Free tax declaration filing, of course, through the Taxfix app—and internal support for all personal tax-related questions.
Have a four-legged friend in your life? We’re happy to have dogs join us in the office.

Excited? So are we. Learn more about Team Taxfix on our blog and get a glimpse of our culture.
At Taxfix, we believe that incredible things happen when you have a wealth of perspectives and experiences. We're proudly committed to equal employment and development opportunities no matter your gender, race, religion, age, sexual orientation, colour, disability, or place of origin. To help mitigate any potential unconscious biases, we ask that you refrain from including your picture, age, or marital status on your CV. Let your experiences speak for themselves.
Not sure if you meet all the requirements for this role? Please apply anyway. You might bring something special to the team that we hadn't considered previously.