- As our Security & Platform Engineer within the Corporate IT team, you’ll sit at the intersection of IT, network security, and internal platform infrastructure
- Reporting to our Director of IT, Security & Infrastructure and working closely with our Systems Engineer, Platform Engineering, SRE,Engineering leads, and Legal and Compliance, you’ll be an integral part of the team that enables Taxfix’s growing agent ecosystem to be secure, compliant, and accessible to all employees
- As agentic infrastructure becomes central to how we operate, the attack surface evolves in ways traditional tooling simply wasn’t built for — and IT together with you are the team which stays ahead of it
- This isn’t a gatekeeping role
- It’s a builder role: you’ll design the frameworks, harden the platforms, and create the conditions that enables people at Taxfix to build responsibly
- Develop tools, capabilities, and agentic skills that ensure compliance with EU AI Act in GDPR, as well as security standards, enabling people across the organization to ship, integrate and deploy high quality automations and internal tools
- Co-design and govern the permissioning framework that defines what agents are allowed to know and access, ensuring no agent retains broader permissions than its job requires
- Own MDM, endpoint security, and identity and access management across internal systems, and lead incident response for security events involving agents or internal infrastructure
- Work alongside the Systems Engineer to build, harden, and evolve the agentic platform layer — including secure sandboxes, credential vaults, and CI/CD pipelines with embedded security checks — and define internal platform standards that make the secure path the default path
- Design and run adversarial testing exercises against agent deployments — covering prompt injection, privilege escalation, and data exfiltration via reasoning chains — and maintain a growing library of AI-specific attack patterns and test cases focusing on internal business operation use cases
- Brief leadership on emerging AI threat vectors and translate them into practical, actionable mitigations — keeping the whole team informed as the landscape evolves
Benefits
- A chance to do meaningful, people-centric work with an international team of passionate professionals
- Holistic wellbeing with free mental health coaching sessions, yoga, and a discounted membership to Urban Sports Club
- A monthly allowance to spend on home support services, including childcare, housekeeping, pet sitting, tutoring, and elderly care
- Employee stock options for all employees—because everyone deserves to benefit from the success they help to create
- Dedicated relocation and visa support for those that need it
- 30 annual vacation days and flexible working hours
- Full trust to take ownership of your work in a flat hierarchy where feedback is encouraged and expected
- A generous learning budget to support your personal and professional development and guidance from our internal L&D experts
- Work from abroad for up to six weeks every year. Just align with your team, and then enjoy your trip
- Plenty of opportunities to socialise as a team. In addition to internal meetups, our international team hosts regular get-togethers—virtually and in person when possible
- Free tax declaration filing, of course, through the Taxfix app—and internal support for all personal tax-related questions
- Have a four-legged friend in your life? We’re happy to have dogs join us in the office
You communicate clearly and document rigorously — every attack vector found, every access decision made, every framework designed is written up and kept currentYou’re a collaborative partner to engineers and builders, not a blocker — your goal is safer agents, not fewer agentsYou’re comfortable at the platform layer: CI/CD pipelines, secrets management, sandbox environments, and scripting and automation to build test suites and security toolingYou bring network security fundamentals that allow you to have credible conversations with third-party providers, assess their work, and know when to ask the right questionsYou’re familiar with AI and machine learning-specific attack surfaces, including prompt injection, data poisoning, model inversion, and indirect injection via documents or APIsYou have a solid background in security engineering, with hands‑on experience in penetration testing, threat modelling, or red teaming — and a genuine curiosity for finding what’s broken before others doYou understand GDPR and DSGVO not just in theory but in practice — you’ve built or audited data classification and retention frameworks and know what compliance actually looks like on the groundYou have practical experience designing and enforcing least-privilege architectures and know your way around identity and access management in real-world environments