About the Role
Seeking a development & cloud focused AppSec Engineer to join our expanding security team. The ideal candidate will have a passion for AppSec, Cloud, and AI, and be a skilled communicator capable of promoting security practices across the organization and into development processes. We are looking for Security Engineers who are confident in network & security fundamentals, driven to grow, and excited by the challenges and opportunities AI brings.
Responsibilities
- Partner with different areas within Karbon to ensure security is embedded from the start, from feature design and development to participating in design reviews and threat modeling.
- Balance delivery needs with security, communicating risks and issues to non-technical stakeholders, and working with delivery teams to reach optimal outcomes.
- Stay up-to-date on the latest technologies and approaches, including AI developments, while understanding the importance of foundational security practices.
- Identify and assess security risks introduced by AI tools, including reviewing risks of AI tooling usage, integration, and AI-generated code.
- Apply AI-assisted tooling to accelerate security work in areas such as triage, threat detection, code review, and documentation.
- Work across multiple security domains, potentially assisting with corporate IT security processes, reviewing cloud-hosted systems, and tweaking detection rules.
- Work effectively as part of a team, building relationships and trust across the organization to enhance Karbon’s security posture.
- Take pride in work, feeling a deep sense of responsibility for products and customer data security.
- Contribute positively to team culture through creativity, curiosity, and authenticity.
- Help measure improvement and steer the roadmap by contributing to Security Metrics.
Requirements
- 4+ years experience in a security or development role.
- Experience collaborating with teams to review designs & implementations for security issues and embedding good security practices across software development.
- Experience triaging issues and reports, assisting teams to remedy items and testing fixes.
- Experience working with external penetration test companies to validate and prioritize findings.
- Experience conducting risk and vulnerability assessments of web applications, APIs, and third-party suppliers and integrations.
- Experience configuring and tuning SAST, SCA, and DAST Tooling.
- Experience working with build/deployment pipelines to incorporate security tooling (Github Actions or Azure Devops YAML based pipelines).
- Experience assisting with implementing security-focused alerting, detections, and automations.
- Experience conducting and facilitating organizational & developer focused security training.
- Experience assisting with operational security items such as EDR alerts and MDM.
- Experience contributing to our security roadmap.
- Strong communication skills (spoken and written).
- Experience with at least one cloud platform (Azure, AWS, or GCP).
- Working knowledge of PowerShell or Bash and Python.
- Working knowledge of at least one AI development tool (e.g., Claude Code, GitHub Co-Pilot).
- Experience with Portswigger Burp or similar.
- Experience with securing AI applications, systems, and AI tooling is highly regarded.
Skills
- AppSec
- Cloud
- AI
- Microsoft .NET/C#
- JavaScript
- React
- EmberJS
- Python
- Azure
- AWS
- GCP
- PowerShell
- Bash
- Claude Code
- GitHub Co-Pilot
- Portswigger Burp
Location
- USA
Work Type
- Work-from-home
Experience Level
- 4+ years experience in a security or development role
Education Level
- Certifications such as Offsec OSCP & AWAE, GIAC, Burp Practitioner, PJPT, Microsoft/AWS development and cloud related are nice to have
Salary/Compensations
- $131,000—$169,000 USD
Benefits
- Flexible Time Off with an encouraged 4 weeks use per year
- Company paid medical for you and eligible spouse/partner and dependents
- Paid dental and vision and eligible spouse/partner and dependents
- 401(k) with company matching
- Flexible Spending Account
- Up to 8 weeks paid parental leave
- Work-from-home stipend
About the Company
- Karbon is the global leader in AI-powered practice management software for accounting firms.
- We provide an award-winning cloud platform that helps tens of thousands of accounting professionals work more efficiently and collaboratively every day.
- With customers in 40 countries, we have grown into a globally distributed team across the US, Australia, New Zealand, Canada, the United Kingdom, and the Philippines.
- We are well-funded, ranked #1 on G2, growing rapidly, and have a people-first culture that is recognized with Great Place To Work® certification and on Fortune magazine's Best Small Workplaces™ List.
Equal Opportunity
- Karbon embraces diversity and inclusion, aligning with our values as a business.
- Research has shown that women and underrepresented groups are less likely to apply to jobs unless they meet every single criteria. If you've made it this far in the job description but your past experience doesn't perfectly align, we do encourage you to still apply. You could still be the right person for the role!
- We recruit and reward people based on capability and performance.
- We don’t discriminate based on race, gender, sexual orientation, gender identity or expression, lifestyle, age, educational background, national origin, religion, physical or cognitive ability, and other diversity dimensions that may hinder inclusion in the organization.
- Generally, if you are a good person, we want to talk to you.
- If there are any adjustments or accommodations that we can make to assist you during the recruitment process, and your journey at Karbon, contact us at people.support@karbonhq.com for a confidential discussion.
