SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Taxfix is a fintech company that has helped millions of people file taxes confidently and claim refunds, facilitating over €3.5 billion in tax refunds since 2016. Operating across Germany, Spain, and the UK with 400+ professionals, the company is now seeking a Senior Platform Security Engineer to design and maintain security solutions for cloud-native infrastructure and AI systems.
In this role, you will own cloud and infrastructure security across AWS, Azure, and GCP environments. You'll design comprehensive security architectures, implement container and Kubernetes security best practices, develop secure Infrastructure as Code, establish zero-trust network architectures, and build secure CI/CD pipelines following DevSecOps principles.
A critical focus area is AI/ML security. You'll secure AI-powered product features end-to-end, including context assembly, tool invocation, and output handling. You'll design security controls for RAG implementations, secure agentic solutions and their extension points (tool integrations, agent skills, autonomous action boundaries), build defenses against prompt injection and adversarial inputs, and establish data security controls for sensitive data flowing through inference, retrieval, and fine-tuning.
You'll lead incident response for cloud and AI infrastructure security incidents, develop security monitoring and detection strategies, conduct threat modeling and risk assessments, perform regular security assessments, and create security documentation. Collaboration is key—you'll work closely with development, data science, and operations teams to integrate security throughout the organization and communicate requirements to both technical and non-technical stakeholders.
Required: 5+ years in information security with 3+ years in cloud security, 3+ years securing containerized environments (Docker, Kubernetes), hands-on experience securing AI/ML or LLM systems, and strong background in at least one major cloud provider. You'll need expert knowledge of container and Kubernetes security, proficiency with IaC tools (Terraform, CloudFormation), strong understanding of network security and identity management, experience with cloud security tooling (CSPM), working knowledge of AI/ML and LLM security frameworks, and proficiency in Python, Go, or Bash.
Preferred: deep experience with LLMs and generative AI, familiarity with OWASP LLM Top 10 and AI governance, experience with secure multi-tenant AI infrastructure, privacy-enhancing technologies (differential privacy, federated learning), open-source security contributions, and experience building security tools.