Senior Platform Engineer (d/f/m)
Taxfix
- Location
- Berlin
- Employment
- Full Time
- Work model
- Remote
- Level
- Senior
- Posted
- 2h ago
Skills
About this role
Our story: Every year millions of people are either filing their taxes in fear or giving up on their tax refund altogether. We're working on fixing that. Our intuitive app enables anyone, regardless of education or background, to file their taxes with newfound confidence. Spread across Germany, Spain and the UK, the team at Taxfix Group with its brands Taxfix, Steuerbot and TaxScouts, is a compassionate group of solution-finders. We speak our minds openly, and with over 400 professionals, including tax experts, developers, and IT security experts, we're rich in ideas and voices. The group has facilitated more than 3.5 billion euros in tax refunds for its customers since its founding in 2016. Your challenge: We are seeking an experienced Senior Platform Security Engineer to design, implement, and maintain security solutions for our cloud-native infrastructure and AI systems. This role will be responsible for securing our platform across multiple cloud environments, ensuring container and Kubernetes security, protecting AI/ML workflows, and implementing robust security controls throughout our SDLC. The ideal candidate will have deep technical and programmatic expertise in cloud-native security, along with demonstrable hands-on experience securing AI/ML systems. Your responsibilities and decisions: Cloud & Infrastructure Security Design and implement comprehensive security architectures for cloud platforms (AWS, Azure, GCP) Implement security best practices for container and Kubernetes deployments Develop and maintain secure Infrastructure as Code (IaC) codebases Design and deploy zero-trust network architecture and secure service mesh solutions Build and maintain secure CI/CD pipelines following DevSecOps principles AI/ML Security Secure AI-powered product features end to end, covering context assembly, tool invocation, and output handling Design and review security controls for RAG implementations Secure agentic solutions and their extension points: tool integrations (MCP clients and servers), agent skills, and autonomous action boundaries such as scoped credentials, sandboxing, and human-in-the-loop gates Build defenses against direct and indirect prompt injection and other adversarial inputs to LLM applications Establish data security controls for sensitive data flowing through inference, retrieval, and fine-tuning Security Operations Lead incident response for cloud and AI infrastructure security incidents Develop and implement security monitoring and detection strategies Conduct threat modeling and risk assessments for cloud-native and AI systems Perform regular security assessments of cloud infrastructure and container deployments Create and maintain security documentation, including policies, procedures, and run-books Leadership & Collaboration Collaborate with development, data science, and operations teams to integrate security Communicate security requirements and recommendations to technical and non-technical stakeholders Stay current with emerging threats and security trends in cloud-native and AI security Participate in technology selections for security tooling and platforms Your profile:
Experience
5+ years of experience in information security, with at least 3 years specializing in cloud security 3+ years of hands-on experience securing containerized environments (Docker, Kubernetes) Demonstrable hands-on experience securing AI/ML or LLM-based systems Strong background in at least one major cloud provider (AWS, Azure, GCP) Technical Skills Expert knowledge of container security, Kubernetes security, and cloud-native security patterns Proficiency with Infrastructure as Code tools (Terraform, CloudFormation, etc.) Strong understanding of network security, identity management, and access control Experience with security tooling for cloud environments (Cloud Security Posture Management, CSPM) Working knowledge of AI/ML and LLM security, including familiarity with frameworks like TensorFlow and PyTorch and