SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Taxfix is a fintech company that has helped millions file taxes confidently and claim refunds, facilitating over €3.5 billion in tax refunds since 2016. Operating across Germany, Spain, and the UK with 400+ professionals, the company is now building secure infrastructure for an expanding agent ecosystem.
As Security & Platform Engineer within the Corporate IT team, you'll report to the Director of IT, Security & Infrastructure and work at the intersection of IT, network security, and internal platform infrastructure. You'll partner closely with Systems Engineers, Platform Engineering, SRE, Engineering leads, Legal, and Compliance to ensure Taxfix's agentic infrastructure remains secure, compliant, and accessible.
Key responsibilities include: developing tools and capabilities that ensure compliance with EU AI Act and GDPR while enabling secure automation deployment; co-designing and governing permissioning frameworks to enforce least-privilege access for agents; owning MDM, endpoint security, and identity/access management across internal systems; leading incident response for security events; building and hardening the agentic platform layer including secure sandboxes, credential vaults, and CI/CD pipelines with embedded security; designing and running adversarial testing exercises against agent deployments (prompt injection, privilege escalation, data exfiltration); and briefing leadership on emerging AI threat vectors.
You bring solid security engineering experience with hands-on penetration testing, threat modeling, or red teaming. You understand AI/ML-specific attack surfaces (prompt injection, data poisoning, model inversion, indirect injection). You have practical experience designing least-privilege architectures and identity/access management. You understand GDPR/DSGVO in practice, having built or audited data classification frameworks. You're comfortable with CI/CD pipelines, secrets management, sandbox environments, and security automation. You have network security fundamentals and communicate clearly with documentation rigor. You're a collaborative partner to engineers—your goal is safer agents, not fewer agents.