Confirmed on the employer's own hiring board on Oct 10, 2026. First seen by Alion on Aug 5, 2026.
Join Taxfix as a Staff Security & Platform Engineer, where you'll play a crucial role in ensuring the security and compliance of our growing agent ecosystem. You'll work closely with various teams, including IT, network security, and internal platform infrastructure, to design frameworks, harden platforms, and create conditions for responsible building. You'll also be responsible for developing tools and capabilities that ensure compliance with the EU AI Act and GDPR, as well as security standards. This is a builder role, not a gatekeeping role, and you'll have the opportunity to make a meaningful impact in a people-centric work environment.
Missions
- Design and implement frameworks, harden platforms, and create conditions that enable responsible building at Taxfix.
- Develop tools and capabilities to ensure compliance with EU AI Act in GDPR, as well as security standards.
- Co-design and govern the permissioning framework that defines what agents are allowed to know and access.
Profil recherché
- You have practical experience designing and enforcing least-privilege architectures and know your way around identity and access management in real-world environments- You're a collaborative partner to engineers and builders, not a blocker - your goal is safer agents, not fewer agents
- You're comfortable at the platform layer: CI/CD pipelines, secrets management, sandbox environments, and scripting and automation to build test suites and security tooling
- You have a solid background in security engineering, with hands-on experience in penetration testing, threat modelling, or red teaming - and a genuine curiosity for finding what's broken before others do
- You communicate clearly and document rigorously - every attack vector found, every access decision made, every framework designed is written up and kept current
- You understand GDPR and DSGVO not just in theory but in practice - you've built or audited data classification and retention frameworks and know what compliance actually looks like on the ground
- You bring network security fundamentals that allow you to have credible conversations with third-party providers, assess their work, and know when to ask the right questions
- You're familiar with AI and machine learning-specific attack surfaces, including prompt injection, data poisoning, model inversion, and indirect injection via documents or APIs
- Not sure if you meet all the requirements for this role? Please apply anyway. You might bring something special to the team that we hadn't considered previously

