Чтобы адаптировать резюме под вакансию или составить сопроводительное письмо, загрузите резюме
описание
Taxfix develops an intuitive tax filing app that helps people file their taxes and claim refunds with confidence. The Taxfix Group operates across Germany, Spain, and the UK through the Taxfix, Steuerbot, and TaxScouts brands.
задачи
Design and implement security architectures for AWS, Azure, and GCP cloud platforms;
Implement security best practices for container and Kubernetes deployments;
Develop and maintain secure Infrastructure as Code codebases;
Design and deploy zero-trust network architecture and secure service mesh solutions;
Build and maintain secure CI/CD pipelines following DevSecOps principles;
Secure AI-powered product features end to end, including context assembly, tool invocation, and output handling;
Design and review security controls for RAG implementations;
Secure agentic solutions and extension points, including MCP clients and servers, agent skills, scoped credentials, sandboxing, and human-in-the-loop gates;
Build defenses against direct and indirect prompt injection and other adversarial inputs to LLM applications;
Establish data security controls for sensitive data used in inference, retrieval, and fine-tuning;
Lead incident response for cloud and AI infrastructure security incidents;
Develop and implement security monitoring and detection strategies;
Conduct threat modeling and risk assessments for cloud-native and AI systems;
Perform regular security assessments of cloud infrastructure and container deployments;
Create and maintain security documentation, including policies, procedures, and run-books;
Collaborate with development, data science, and operations teams to integrate security;
Communicate security requirements and recommendations to technical and non-technical stakeholders;
Stay current with emerging threats and security trends in cloud-native and AI security;
Participate in technology selections for security tooling and platforms.
требования
5+ Years of experience in information security, including at least 3 years specializing in cloud security;
3+ Years of hands-on experience securing containerized environments with Docker and Kubernetes;
Demonstrable hands-on experience securing AI/ML or LLM-based systems;
Strong background in at least one major cloud provider: AWS, Azure, or GCP;
Expert knowledge of container security, Kubernetes security, and cloud-native security patterns;
Proficiency with Infrastructure as Code tools such as Terraform and CloudFormation;
Strong understanding of network security, identity management, and access control;
Experience with cloud security tooling, including Cloud Security Posture Management;
Working knowledge of AI/ML and LLM security, including TensorFlow and PyTorch security implications;
Proficiency in Python, Go, or Bash;
Experience with security automation and orchestration;
Nice to have: Deep experience securing LLMs and generative AI systems, familiarity with AI/LLM security frameworks such as OWASP LLM Top 10, AI governance or compliance experience, secure multi-tenant AI infrastructure experience, privacy-enhancing technologies for AI/ML, contributions to open-source security projects or public security research, experience building security tools or automation frameworks.
условия
Free mental health coaching sessions;
Monthly allowance for an extensive range of services, with flexible rollover;
Employee stock options for all employees;
30 Annual vacation days and flexible working hours;
Work from abroad for up to six weeks every year;
Free tax declaration filing through the Taxfix app and internal support for personal tax-related questions;