Security & Platform Engineer
Taxfix
Seniority
Midweight
Model
Hybrid
Sector
Salary
Undisclosed
Contract
Full-Time
As Security & Platform Engineer within the Corporate IT team, you'll sit at the intersection of IT, network security, and internal platform infrastructure. You'll be an integral part of the team that enables Taxfix's growing agent ecosystem to be secure, compliant, and accessible to all employees. This is a builder role: you'll design the frameworks, harden the platforms, and create the conditions that enable people at Taxfix to build responsibly.
What you'll do
- Develop tools, capabilities, and agentic skills that ensure compliance with EU AI Act, GDPR, and security standards, enabling people across the organization to ship, integrate and deploy high quality automations and internal tools.
- Co-design and govern the permissioning framework that defines what agents are allowed to know and access, ensuring no agent retains broader permissions than its job requires.
- Own MDM, endpoint security, and identity and access management across internal systems, and lead incident response for security events involving agents or internal infrastructure.
- Build, harden, and evolve the agentic platform layer — including secure sandboxes, credential vaults, and CI/CD pipelines with embedded security checks — and define internal platform standards that make the secure path the default path.
- Design and run adversarial testing exercises against agent deployments — covering prompt injection, privilege escalation, and data exfiltration via reasoning chains.
- Brief leadership on emerging AI threat vectors and translate them into practical, actionable mitigations.
What you'll need
- Solid background in security engineering, with hands-on experience in penetration testing, threat modelling, or red teaming.
- Familiarity with AI and machine learning-specific attack surfaces, including prompt injection, data poisoning, model inversion, and indirect injection via documents or APIs.
- Practical experience designing and enforcing least-privilege architectures and identity and access management in real-world environments.
- Understanding of GDPR and DSGVO in practice — you've built or audited data classification and retention frameworks.
- Comfort at the platform layer: CI/CD pipelines, secrets management, sandbox environments, and scripting and automation.
- Network security fundamentals and ability to have credible conversations with third-party providers.
- Clear communication and rigorous documentation of attack vectors, access decisions, and frameworks.
What they offer
- Free mental health coaching sessions and yoga.
- Monthly allowance for services, flexible use and rollover.
- Employee stock options for all employees.
- 30 annual vacation days and flexible working hours.
- Generous learning budget and internal L&D guidance.
- Work from abroad for up to six weeks per year.

