Karbon

Senior Security Engineer

Karbon · Dallas, TX

  • Hybrid
  • Full-time
  • $140,000 / year
  • Dallas, TX

Job highlights

  • Senior Security Engineer role with AI focus.
  • Embed security into development and design.
  • Assess AI tool risks and integration.
  • Utilize AI to accelerate security tasks.
  • Collaborate and own security initiatives.

About the role

About Karbon

Karbon is the global leader in AI-powered practice management software for accounting firms. We provide an award-winning cloud platform that helps tens of thousands of accounting professionals work more efficiently and collaboratively every day. With customers in 40 countries, we have grown into a globally distributed team across the US, Australia, New Zealand, Canada, the United Kingdom, and the Philippines. We are well-funded, ranked #1 on G2, growing rapidly, and have a people-first culture that is recognized with Great Place To Work® certification and on Fortune magazine's Best Small Workplaces™ List.

Senior Security Engineer

Our Engineering Standards at Karbon:

  • Balance Speed and Quality: Engineers are expected to balance delivery speed with a strong commitment to quality, meeting agreed timelines while producing reliable, maintainable, and well-tested solutions. Sound judgment in making trade-offs between velocity and long-term sustainability is essential.
  • Collaborate Effectively: Engineering is collaborative by default. Team members are expected to contribute constructively in design discussions, reviews, and planning, communicate clearly about progress and risks, and support shared team outcomes in both hybrid and distributed environments.
  • Build and Maintain Systems: Engineers are responsible for building new capabilities while maintaining and improving existing systems. This includes designing scalable solutions, reducing technical debt, supporting operational stability, and contributing to continuous improvement.
  • Operate with Autonomy: A high degree of autonomy is expected. Given clear objectives, engineers should independently translate problems into actionable technical approaches, proactively identify improvements, and continuously expand relevant technical expertise.
  • Ownership and Accountability: Ownership is fundamental. Engineers are accountable for the quality, performance, and customer impact of their work from design through post-release support, and are expected to follow through on commitments.
  • AI-Enabled Engineering: AI is reshaping how software is built, and we are committed to leveraging it as a force multiplier for creativity, impact, and capability. Engineers are expected to confidently apply strong technical fundamentals while embracing AI tools and approaches to enhance productivity, problem-solving, and innovation. Curiosity, adaptability, and enthusiasm for integrating AI into meaningful product development are essential.
  • Contribute to Team Culture: Engineers contribute positively to a culture of professionalism, transparency, low bureaucracy, and mutual respect, strengthening team performance through authenticity, curiosity, and collaboration.

About the Role!

Seeking a development & cloud focused Senior Security Engineer to join our expanding security team. The ideal candidate will have passion for AppSec, Cloud and AI. They will be a skilled communicator and relationship builder capable of promoting and building security practices across the organization and into our development processes.

AI is reshaping practices across the board and at Karbon we’re fully committed. We don’t see AI as a replacement but as a force multiplier. We’re looking for Security Engineers who are confident in network & security fundamentals, driven to grow, and excited by the challenges and opportunities AI brings.

What You’ll Own:

  • Partner with different areas within Karbon - You will make sure security is embedded from the start from feature design and development to participating in design reviews and threat modelling.
  • Balance Security and Delivery - You know how to balance delivery needs with security and can communicate security risks and issues to non technical stakeholders. You understand when it's important to push back, when to compromise and how to work with delivery teams to reach a great outcome.
  • You keep up to date on the latest technologies and approaches - You are excited by the new developments such as AI bring to security but also understand the importance of security foundational practices such as good account hygiene, least privilege, attack surface reduction and MFA.
  • Identify and assess security risks introduced by AI tools - You’ll assist with reviewing the risks of AI tooling usage & Integration and AI-generated code.
  • Apply AI-assisted tooling to accelerate security work - you understand the impact AI can have and utilize it across many areas including triage, threat detection, code review, and documentation.
  • Flexibility and confidence to work across multiple security domains - We’re a small team responsible for Security at a fast moving company and you’ll get exposure to many different security domains; you could be assisting with refining and investigating corporate IT security processes in the morning, reviewing a cloud hosted system after lunch and then tweaking detection rules!
  • Work effectively as part of a team - Security is a team sport and you understand the need to build relationships and trust across the organization to enhance Karbon’s security posture. You are happy to answer questions and offer advice to teams that will reach out for your assistance.
  • Own your work - You take pride in your work, feeling a deep sense of responsibility for the products we develop and ensuring we keep our customers' valuable data secure. This sense of ownership is paramount, and you share this commitment.
  • Bring your passion and personality - Your creativity, curiosity, and authentic self make the team stronger. If you've worked in highly political environments, you'll find our culture, free from office politics and valuing openness and authenticity, a refreshing change.
  • Help us measure improvement and steer our roadmap - Contribute to Security Metrics so we can track progress and feedback into our roadmap.

What Sets You Apart

  • 4+ years experience in a security or development role across most of the following:
    • Collaborating with teams to review designs & implementations for security issues and embedding good security practices across software development
    • Triaging issues and reports, assisting teams to remedy items and testing fixes
    • Working with external penetration test companies to validate and prioritize findings
    • Conducting risk and vulnerability assessments of web applications and APIs and third party suppliers and integrations
    • Configuring and tuning SAST, SCA and DAST Tooling
    • Working with build/deployment pipelines to incorporate security tooling (Github Actions or Azure Devops YAML based pipelines)
    • Assisting with implementing security focused alerting and detections and automations
    • Conducting and facilitating organizational & developer focused security training
    • Assisting with operational security items such as EDR alerts and MDM
    • Contributing to our security roadmap
  • In addition you’ll need:
    • Strong communication skills (spoken and written)
    • Some of the following Languages/Frameworks: Microsoft .NET/C#, JavaScript (we use React and EmberJS frameworks and, Python)
    • At least one cloud platform: Azure, AWS or GCP (we use Azure predominantly)
    • Working knowledge of PowerShell or Bash and Python
    • Working knowledge of at least one AI development tool e.g. Claude Code, GitHub Co-Pilot etc
    • Portswigger Burp or similar
    • Certifications such as Offsec OSCP & AWAE, GIAC, Burp Practitioner, PJPT, Microsoft/AWS development and cloud related are nice to have
    • Experience with securing AI applications, systems and AI tooling would be highly regarded

Why Work at Karbon?

  • Gain global experience across Australia, New Zealand, UK, and Canada
  • Strong benefits package including:
    • Flexible Time Off with an encouraged 4 weeks use per year
    • Company paid medical for you and eligible spouse/partner and dependents
    • Paid dental and vision and eligible spouse/partner and dependents
    • 401(k) with company matching
    • Flexible Spending Account
    • Up to 8 weeks paid parental leave
    • Work-from-home stipend
    • Work with (and learn from) an experienced, high-performing team
    • A collaborative, team-oriented culture that embraces diversity, invests in development and provides consistent feedback
    • Be part of a fast-growing company that firmly believes in promoting high performers from within

Key skills/competency

  • Application Security (AppSec)
  • Cloud Security (Azure, AWS, GCP)
  • AI Security Risks
  • Threat Modeling
  • SAST, SCA, DAST Tooling
  • CI/CD Security Integration
  • Security Metrics and Roadmap Contribution
  • Vulnerability Assessment
  • Secure Coding Practices
  • Communication and Relationship Building

Skills & topics

  • Senior Security Engineer
  • Application Security
  • Cloud Security
  • AI Security
  • Threat Modeling
  • Vulnerability Assessment
  • DevSecOps
  • Azure Security
  • AWS Security
  • GCP Security
  • SAST
  • DAST
  • SCA
  • CI/CD Security
  • Security Engineering
  • Python
  • JavaScript
  • .NET
  • C#
  • PowerShell
  • Bash

How to get hired

  • Tailor your resume: Highlight your 4+ years in security/development, focusing on AppSec, Cloud, and AI experience, and specific skills like threat modeling and SAST/DAST tooling.
  • Showcase communication skills: Emphasize your ability to collaborate with development teams and communicate security risks to non-technical stakeholders.
  • Demonstrate AI proficiency: Detail your experience with AI development tools and securing AI applications, as mentioned in the job description.
  • Research Karbon's culture: Understand their people-first, low-bureaucracy, and AI-embracing approach to further align your application and interview responses.
  • Prepare for technical and behavioral questions: Be ready to discuss your approach to balancing security with delivery, assessing AI risks, and collaborating within a distributed team.

Technical preparation

Review cloud security best practices (Azure, AWS, GCP).,Practice threat modeling and risk assessment techniques.,Familiarize with SAST/DAST/SCA tools.,Understand CI/CD security integration.

Behavioral questions

How do you balance security with development speed?,Describe a time you communicated security risks.,How do you stay updated on new technologies?,How do you foster collaboration in a distributed team?

Frequently asked questions

What is the estimated salary range for the Senior Security Engineer role at Karbon?
The estimated base salary range for the Senior Security Engineer position at Karbon is $131,000 to $169,000 USD annually. This range considers factors like location, experience, and skills, and is one component of a comprehensive compensation package that may include bonuses, equity, and benefits.
Does Karbon encourage remote work for its Senior Security Engineers?
Karbon operates with a globally distributed team and emphasizes collaboration in hybrid and distributed environments. While the job description doesn't explicitly state 'remote', their distributed team structure suggests a strong possibility for remote or hybrid arrangements for the Senior Security Engineer role.
What specific AI tools or AI security experience is Karbon looking for in a Senior Security Engineer?
Karbon is looking for candidates with working knowledge of at least one AI development tool (e.g., Claude Code, GitHub Co-Pilot) and experience securing AI applications, systems, and tooling. They view AI as a force multiplier and are keen on engineers who can leverage it for productivity and innovation.
How does Karbon approach work-life balance and benefits for its Senior Security Engineers?
Karbon offers a strong benefits package including Flexible Time Off (encouraged 4 weeks use), company-paid medical, dental, and vision for employees and dependents, 401(k) matching, a Flexible Spending Account, and up to 8 weeks paid parental leave. They also provide a work-from-home stipend.
What are the key responsibilities for a Senior Security Engineer at Karbon, especially regarding AI?
Key responsibilities include partnering with teams to embed security from design to development, balancing security with delivery needs, identifying and assessing security risks of AI tools and AI-generated code, and applying AI-assisted tools to accelerate security work like triage and code review.
What technical skills are most important for the Senior Security Engineer role at Karbon?
Essential technical skills include experience with AppSec, Cloud platforms (Azure, AWS, GCP), security tooling (SAST, SCA, DAST), CI/CD pipeline security, scripting (PowerShell, Bash, Python), and familiarity with AI development tools. Experience in .NET/C# or JavaScript is also valuable.
How does Karbon foster a positive team culture for its engineers?
Karbon emphasizes a people-first culture with professionalism, transparency, low bureaucracy, and mutual respect. They encourage authenticity, curiosity, and collaboration, and are recognized with Great Place To Work® certification and on Fortune magazine's Best Small Workplaces™ List.
What is Karbon's stance on diversity and inclusion for the Senior Security Engineer position?
Karbon actively embraces diversity and inclusion. They encourage applications even if candidates don't meet every single criterion, focusing on capability and performance over rigid adherence to requirements. They do not discriminate and are committed to making adjustments for candidates needing accommodations.