yoinka

Security & Platform Engineer (d/f/m)

Taxfix

RemoteBerlinFull TimeMid
Sign in to applyVerified 1h ago
Location
Berlin
Employment
Full Time
Work model
Remote
Level
Mid
Posted
18h ago

Skills

CI/CDMachine Learning

About this role

Our story: Every year millions of people are either filing their taxes in fear or giving up on their tax refund altogether. We're working on fixing that. Our intuitive app enables anyone, regardless of education or background, to file their taxes with newfound confidence. Spread across Germany, Spain and the UK, the team at Taxfix Group with its brands Taxfix and Steuerbot, is a compassionate group of solution-finders. We speak our minds openly, and with over 400 professionals, including tax experts, developers, and IT security experts, we're rich in ideas and voices. The group has facilitated more than 3.5 billion euros in tax refunds for its customers since its founding in 2016.

The opportunity

As our Security & Platform Engineer within the Corporate IT team, you'll sit at the intersection of IT, network security, and internal platform infrastructure. Reporting to our Director of IT, Security & Infrastructure and working closely with our Systems Engineer, Platform Engineering, SRE,Engineering leads, and Legal and Compliance, you'll be an integral part of the team that enables Taxfix's growing agent ecosystem to be secure, compliant, and accessible to all employees. As agentic infrastructure becomes central to how we operate, the attack surface evolves in ways traditional tooling simply wasn't built for — and IT together with you are the team which stays ahead of it. This isn't a gatekeeping role. It's a builder role: you'll design the frameworks, harden the platforms, and create the conditions that enables people at Taxfix to build responsibly.

Your responsibilities

Develop tools, capabilities, and agentic skills that ensure compliance with EU AI Act in GDPR, as well as security standards, enabling people across the organization to ship, integrate and deploy high quality automations and internal tools. Co-design and govern the permissioning framework that defines what agents are allowed to know and access, ensuring no agent retains broader permissions than its job requires. Own MDM, endpoint security, and identity and access management across internal systems, and lead incident response for security events involving agents or internal infrastructure. Work alongside the Systems Engineer to build, harden, and evolve the agentic platform layer — including secure sandboxes, credential vaults, and CI/CD pipelines with embedded security checks — and define internal platform standards that make the secure path the default path. Design and run adversarial testing exercises against agent deployments — covering prompt injection, privilege escalation, and data exfiltration via reasoning chains — and maintain a growing library of AI-specific attack patterns and test cases focusing on internal business operation use cases. Brief leadership on emerging AI threat vectors and translate them into practical, actionable mitigations — keeping the whole team informed as the landscape evolves.

Your profile

You have a solid background in security engineering, with hands-on experience in penetration testing, threat modelling, or red teaming — and a genuine curiosity for finding what's broken before others do. You're familiar with AI and machine learning-specific attack surfaces, including prompt injection, data poisoning, model inversion, and indirect injection via documents or APIs. You have practical experience designing and enforcing least-privilege architectures and know your way around identity and access management in real-world environments. You understand GDPR and DSGVO not just in theory but in practice — you've built or audited data classification and retention frameworks and know what compliance actually looks like on the ground. You're comfortable at the platform layer: CI/CD pipelines, secrets management, sandbox environments, and scripting and automation to build test suites and security tooling. You bring network security fundamentals that allow you to have credible conversations with third-party providers, assess