SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Taxfix is a fintech company that helps millions of people file taxes confidently through an intuitive app. Operating across Germany, Spain, and the UK with over 400 professionals, the company has facilitated €3.5 billion in tax refunds since 2016.
You will design, implement, and maintain security solutions for cloud-native infrastructure and AI systems. This is a hands-on technical role with significant responsibility for securing the platform across multiple cloud environments, container orchestration, and AI/ML workflows.
Key responsibilities include:
**Cloud & Infrastructure Security:** Design comprehensive security architectures for AWS, Azure, and GCP; implement container and Kubernetes security best practices; develop secure Infrastructure as Code; design zero-trust network architecture and service mesh solutions; build and maintain secure CI/CD pipelines following DevSecOps principles.
**AI/ML Security:** Secure AI-powered product features end-to-end, including context assembly, tool invocation, and output handling; design and review security controls for RAG implementations; secure agentic solutions and their extension points (tool integrations, agent skills, autonomous action boundaries); build defenses against prompt injection and adversarial inputs to LLM applications; establish data security controls for sensitive data in inference, retrieval, and fine-tuning.
**Security Operations:** Lead incident response for cloud and AI infrastructure security incidents; develop security monitoring and detection strategies; conduct threat modeling and risk assessments; perform regular security assessments; create and maintain security documentation.
**Leadership & Collaboration:** Collaborate with development, data science, and operations teams; communicate security requirements to technical and non-technical stakeholders; stay current with emerging threats; participate in security tooling selections.
Taxfix offers 30 annual vacation days, flexible working hours, work-from-abroad allowance (up to 6 weeks/year), employee stock options, free mental health coaching, monthly service allowance, and a dog-friendly office.
**Requirements:**
- 5+ years in information security, with at least 3 years specializing in cloud security
- 3+ years hands-on experience securing containerized environments (Docker, Kubernetes)
- Demonstrable hands-on experience securing AI/ML or LLM-based systems
- Strong background in at least one major cloud provider (AWS, Azure, GCP)
- Expert knowledge of container security, Kubernetes security, and cloud-native security patterns
- Proficiency with Infrastructure as Code tools (Terraform, CloudFormation, etc.)
- Strong understanding of network security, identity management, and access control
- Experience with cloud security tooling (CSPM)
- Working knowledge of AI/ML and LLM security, including TensorFlow and PyTorch security implications
- Proficiency in scripting/programming (Python, Go, Bash)
- Experience with security automation and orchestration
**Preferred Experience:**
- Deep experience securing Large Language Models and generative AI systems
- Familiarity with AI/LLM security frameworks (OWASP LLM Top 10) and AI governance/compliance
- Experience with secure multi-tenant AI infrastructure
- Experience with privacy-enhancing technologies (differential privacy, federated learning)
- Open-source security contributions or public security research
- Experience building security tools or automation frameworks