--- title: 'Platform Security Engineer at Causa Prima' canonical: 'https://feeny.ai/job/platform-security-engineer-causa-prima-madrid-6esyzfz8h6qj' type: 'job' last_seen: '2026-09-12' --- # Platform Security Engineer at Causa Prima - **Company:** Causa Prima - **Location:** Madrid, Spain - **Employment:** full-time - **Work type:** onsite - **Posted:** 2026-06-29 - **Last confirmed live:** 2026-09-12 - **Apply:** https://jobs.ashbyhq.com/causaprima/30ca8d0b-d204-4cd6-8659-14235385119e/application **Skills:** Backend systems design, Distributed systems design, Database schema design, Row Level Security (RLS), Event sourcing, Encryption models, Key management, Authentication patterns, Cerbos, OPA, Cedar, Policy-as-Code, Cryptographic primitives, Kafka, Redpanda > Design and build the System Integrity Layer, establishing foundational platform primitives that guarantee agent isolation, traceability, and security constraints. This hands-on backend security role focuses on threat modeling, auditability, and adversarial testing to ensure robust system architecture. ## Job description In this role, you will design and build the System Integrity Layer, establishing the foundational platform primitives that guarantee every agent action is isolated and attributable, every execution is traceable, every state transition is verifiable, and every software release satisfies strict security constraints by construction. This is a hands-on backend security engineering role where security, threat resilience, and compliance are natural outcomes of brilliant system architecture, not separate, bureaucratic processes. We are looking for a builder, not a governance operator—someone who treats trust guarantees as core system properties designed directly into the database and application layers from day one. Architecture or technical-leadership experience is fine, even welcome, as long as it comes with real hands-on depth you can point to—specific systems you designed and built—rather than process, documentation, or audit-standardization work alone. What you'll do: - System Integrity Layer & Threat Modeling — Design the core execution model that governs how autonomous agents run, interact, and modify system state. - Proactive Threat Modeling — Conduct continuous, code-level threat modeling across our distributed networks to identify structural vectors, memory leakage, prompt manipulation, and authorization bypasses before a single line hits staging. - Auditability as a Native Property — Build append-only, tamper-resistant event systems that make every action reconstructable without relying on external logging frameworks or reactive "audit tooling." - Isolation, Trust Boundaries, & Adversarial Testing — Engineer strict execution and data isolation layers between agents, users, and workflows in a multi-tenant infrastructure. - Continuous Offensive Testing — Run active internal pentesting, adversarial chaos testing, and targeted red teaming exercises against our own infrastructure to aggressively expose flaws in isolation barriers and cryptographic verification boundaries. - Agent Execution Guarantees — Ensure all automated, agentic accounting processes are strictly attributable, deterministic where required, verifiable in hindsight, and unalterably constrained by explicit system rules. - Robust Engineering & Pipeline Security — Architect and refine our internal software delivery pipeline to guarantee absolute integrity from code commit to production deployment. - Build deterministic verification mechanisms into the CI/CD pipeline, ensuring that all third-party dependencies, agent libraries, and compiled services are cryptographically signed, scanned, and secure by default. - Compliance Through Architecture — Translate complex regulatory and audit requirements directly into low-level system constraints, completely eliminating the need for reactive operational processes or manual review workflows. ## What we're looking for - Experience: 5+ years designing production backend platforms and distributed systems design. - Database experience: Deep schema design, RLS, and event-sourcing database expertise. - Security Architecture: Practical application-level security, encryption models, key management, and auth patterns. - Adversarial Mindset: You naturally think like an attacker to uncover race conditions, logic flaws, and vulnerabilities. - Policy-as-Code: Hands-on experience with Cerbos, OPA, Cedar, or similar. - Domain knowledge: You've owned real breadth of the security stack, not one narrow slice of it. You understand what securing mission-critical enterprise software at large scale demands. Regulated industries (fintech, banking, insurance) are a plus, but end-to-end ownership counts for more than time spent inside a large org. Nice to have: - Cryptographic primitives - Event streaming (Kafka/Redpanda) - Kubernetes and cloud-native architecture knowledge - LLM/agentic system security exposure (prompt injection defense, guardrails, agent threat modeling)—relevant to our product surface, but a plus on top of the backend and security fundamentals above, not a substitute for them. ## About Causa Prima ## Company Overview - **One-liner**: Causa Prima operates an agent-to-agent network that automates invoicing, dispute resolution, and payment-term negotiations between buyers and suppliers for finance teams. - **Entity Type**: Private (Pre-Seed) - **Headquarters**: Madrid, Spain & Munich, Germany - **Founded**: 2025 (implied by recent funding and hiring activity in early 2026) - **Founders**: Maex Ament (CEO), Henrik Gebbing (COO), Philip Stanislaus (CTO) ## Core Business - **Primary industry**: B2B Fintech / Accounts Payable & Receivable Automation - **Target customers**: SMB and Enterprise finance teams (buyers and suppliers) - **Mission or purpose**: To eliminate fixed payment terms (Net-30, Net-60) by enabling AI agents on both sides of a transaction to settle instantly, so money moves on the right terms at the right time automatically. ## Products & Services - **Causa Prima Network**: A two-sided agent-to-agent network where AI agents handle invoicing, dispute resolution, and dynamic discounting. Buyers and suppliers connect on one platform, removing manual handoffs between AP and AR systems. - **Scribo (Open Source)**: A free, AI-native e-invoicing tool compliant with EN 16931 (ZUGFeRD/XRechnung for Germany, US plain PDF). Available as an MCP server, Claude/Codex skill, CLI, HTTP API, and web app. Designed to help developers and finance teams generate compliant invoices programmatically. ## Market Standing - **Valuation/Market Cap**: Not disclosed (pre-seed stage) - **Key Metric**: $10M in total funding (pre-seed round, announced June 2026) - **Notable Investors/Partners**: Creandum (led the round), Kfund, HelloWorld, Angel Invest, plus angel investors from Qonto, Pennylane, SAP, ING, SoFi, LIDL, and DeepMind. - **Growth Signals**: Already trusted by 3,000+ accounts; headcount grew 28.6% monthly (LinkedIn data as of mid-2026); hiring for engineering and product roles in Madrid and Munich; open-source Scribo project gaining traction (12 stars on GitHub). ## Competitive Advantages - **Two-sided network**: Unlike competitors that automate only one side (AP or AR), Causa Prima connects both buyers and suppliers on a shared network, eliminating the gap between systems. - **Founder credibility**: Maex Ament invented dynamic discounting and co-founded Taulia (acquired by SAP, processing $50B/quarter). Henrik Gebbing built Finoa to $10B in assets under custody. Philip Stanislaus led 600+ enterprise security audits at Oak Security. - **Agent-native design**: The platform is built from the ground up for AI agents to negotiate in real time, not just to speed up human workflows. ## Strategic Focus - **Current priorities**: Grow the engineering and product teams in Madrid and Munich; scale the network beyond 3,000 accounts; push toward eliminating fixed payment terms entirely by making agent-to-agent settlement the default. - **Direction**: Move from automating existing finance processes to replacing the underlying paradigm of B2B payments (Net-30/60/90) with instant, AI-driven settlement. ## Why Work Here - **Culture**: Described by founders as a “once-in-a-lifetime opportunity” for people who want to build high-impact infrastructure from scratch. Emphasis on entrepreneurial drive and solving a problem that software has never fully addressed. - **Remote/Hybrid/Office**: Presence in Madrid and Munich; roles appear to be in-office or hybrid (engineering roles listed in these cities). - **Notable perks/engineering culture**: Early-stage startup with a small team (6 employees as of mid-2026) — high ownership and direct impact. Tech stack includes TypeScript, GraphQL, PostgreSQL, Redis, Terraform, Kubernetes, and Python. Open-source contributions (Scribo) are a core part of the product strategy. Backed by top-tier VC (Creandum) with strong founder track record. ## Sources 1. [causaprima.ai](https://causaprima.ai/) 2. [jobs.ashbyhq.com](https://jobs.ashbyhq.com/causaprima) 3. [linkedin.com](https://www.linkedin.com/company/causa-prima) 4. [github.com](https://github.com/causa-prima-ai) 5. [techfundingnews.com](https://techfundingnews.com/causa-prima-10m-pre-seed-creandum-b2b-payments-ai-agents-network/) ## Other roles at Causa Prima - [Executive Assistant](https://feeny.ai/job/executive-assistant-causa-prima-madrid-pyey8jsm4y1s) — Madrid, Spain - [Founders' Associate](https://feeny.ai/job/founders-associate-causa-prima-madrid-4v0bbe0gr36x) — Madrid, Spain - [Marketing Lead](https://feeny.ai/job/marketing-lead-causa-prima-madrid-7pvpq4xs2c3f) — Madrid, Spain - [Open Application](https://feeny.ai/job/open-application-causa-prima-madrid-5fx837v9ker4) — Madrid, Spain - [Senior Backend / Platform Engineer](https://feeny.ai/job/senior-backend-platform-engineer-causa-prima-madrid-q3bcr2bmcw7y) — Madrid, Spain - [Platform Security Engineer](https://feeny.ai/job/platform-security-engineer-glean-united-sates-s0bk70snnv63) — United Sates