Full-Time

Senior Security Engineer

Posted on 5/7/2026

Karbon

Karbon

201-500 employees

Cloud-based team collaboration and client management

Compensation Overview

$131k - $169k/yr

San Francisco, CA, USA + 6 more

More locations: Austin, TX, USA | Los Angeles, CA, USA | Dallas, TX, USA | Chicago, IL, USA | Denver, CO, USA | San Diego, CA, USA

In Person

Category
IT & Security (1)
Required Skills
PowerShell
Bash
Microsoft Azure
Python
JavaScript
React.js
Github Actions
Threat modeling
Vulnerability Analysis
C#
AWS
penetration testing
Google Cloud Platform
Requirements
  • 4+ years experience in a security or development role across most of the following: Collaborating with teams to review designs & implementations for security issues and embedding good security practices across software development; Triaging issues and reports, assisting teams to remedy items and testing fixes; Working with external penetration test companies to validate and prioritize findings; Conducting risk and vulnerability assessments of web applications and APIs and third party suppliers and integrations; Configuring and tuning SAST, SCA and DAST Tooling; Working with build/deployment pipelines to incorporate security tooling (Github Actions or Azure Devops YAML based pipelines); Assisting with implementing security focused alerting and detections and automations; Conducting and facilitating organizational & developer focused security training; Assisting with operational security items such as EDR alerts and MDM; Contributing to our security roadmap
  • Strong communication skills (spoken and written)
  • Some of the following Languages/Frameworks: Microsoft .NET/C#, JavaScript (React and EmberJS frameworks), Python
  • At least one cloud platform: Azure, AWS or Google Cloud Platform (Azure predominantly)
  • Working knowledge of PowerShell or Bash and Python
  • Working knowledge of at least one AI development tool e.g. Claude Code, GitHub Copilot etc
  • Portswigger Burp or similar
Responsibilities
  • Partner with different areas within Karbon - you will make sure security is embedded from the start from feature design and development to participating in design reviews and threat modelling
  • Balance Security and Delivery - you know how to balance delivery needs with security and can communicate security risks and issues to non technical stakeholders
  • Keep up to date on the latest technologies and approaches - you are excited by the new developments such as AI bring to security but also understand the importance of security foundational practices such as good account hygiene, least privilege, attack surface reduction and MFA
  • Identify and assess security risks introduced by AI tools - you’ll assist with reviewing the risks of AI tooling usage & Integration and AI-generated code
  • Apply AI-assisted tooling to accelerate security work - you understand the impact AI can have and utilize it across many areas including triage, threat detection, code review, and documentation
  • Flexibility and confidence to work across multiple security domains - we’re a small team responsible for Security at a fast moving company and you’ll get exposure to many different security domains; you could be assisting with refining and investigating corporate IT security processes in the morning, reviewing a cloud hosted system after lunch and then tweaking detection rules
  • Work effectively as part of a team - security is a team sport and you understand the need to build relationships and trust across the organization to enhance Karbon’s security posture
  • Own your work - you take pride in your work, feeling a deep sense of responsibility for the products we develop and ensuring we keep our customers' valuable data secure
  • Bring your passion and personality - your creativity, curiosity, and authentic self make the team stronger
  • Help us measure improvement and steer our roadmap - Contribute to Security Metrics so we can track progress and feedback into our roadmap
Desired Qualifications
  • Certifications such as Offsec OSCP & AWAE, GIAC, Burp Practitioner, PJPT, Microsoft/AWS development and cloud related are nice to have
  • Experience with securing AI applications, systems and AI tooling would be highly regarded

Karbon is a cloud-based platform that helps professional teams collaborate, manage tasks, and handle client relationships in a shared workspace. It is a subscription-based SaaS solution with features for communication, file sharing, task tracking, and calendar integrations with Google and Outlook to manage time. It differentiates itself by offering a single source of truth for job status across the team, plus tools to monitor each client relationship and ensure promised services are delivered, as well as a suite of integrated apps and premium training and support. Its goal is to help firms run more efficiently, deliver consistent client service, and scale their operations by improving collaboration and automating administrative work.

Company Size

201-500

Company Stage

Late Stage VC

Total Funding

$95.8M

Headquarters

Sausalito, California

Founded

2014

Simplify Jobs

Simplify's Take

What believers are saying

  • Gusto beta integration on May 1, 2026, automates payroll workflows for US firms.
  • Aider acquisition on September 30, 2025, accelerates AI advisory and reporting features.
  • Brooke Brockman appointed CMO in 2026 to drive global brand and AI marketing growth.

What critics are saying

  • Jetpack Workflow's simpler interface captures mid-sized firms frustrated by Karbon's complex setup.
  • Practice Ignition's $99/user pricing undercuts Karbon's $149+ rates, driving small firm churn.
  • Xero's 2026 practice management module cannibalizes Karbon's US Xero-user customer base.

What makes Karbon unique

  • Karbon unites email, tasks, and client communication in one AI-powered platform for accountants.
  • Founders from Paycycle, acquired by Xero in 2011, built Karbon specifically for accounting workflows.
  • Saves accounting firms 18.5 hours per employee weekly through automation and collaboration.

Help us improve and share your feedback! Did you find this helpful?

Your Connections

People at Karbon who can refer or advise you

Benefits

Unlimited Paid Time Off

Flexible Work Hours

Paid Vacation

Parental Leave

Growth & Insights and Company News

Headcount

6 month growth

0%

1 year growth

0%

2 year growth

0%
AldenSync
Feb 14th, 2026
Automated document collection, AI filing, and DMS sync for modern accounting firms.

Automated document collection, AI filing, and DMS sync for modern accounting firms. Technical Deep-Dive AldenSync + Karbon: A technical integration walkthrough. This isn't a marketing overview. This is the technical walkthrough its implementation team uses internally, now published for firms evaluating how deeply AldenSync connects to Karbon. Authentication & connection setup. AldenSync connects to Karbon via OAuth 2.0 with PKCE. During onboarding, an admin authorizes AldenSync with read/write access to Contacts, Work Items, and Client Tasks. Aldensync request the minimum scopes needed: - `contacts:read` - pull client names, emails, entity details - `work:read` / `work:write` - read engagement status, update task completion - `tasks:read` / `tasks:write` - create document request tasks, mark as complete - `notes:write` - post automated status updates to engagement timelines Aldensync never request access to Karbon's financial data, budgets, or team management features. Principle of least privilege. Engagement mapping. The first step after connection is mapping your Karbon Work Items to AldenSync engagements. Aldensync support three mapping strategies: - Automatic by client name + work type - AldenSync matches Karbon work items to engagements using client name and engagement type (e.g., '1040 Individual Tax Return'). Works for 90%+ of firms. - Template-based - you define a mapping template: 'All Karbon work items of type X map to AldenSync engagement template Y.' Useful for firms with custom work types. - Manual override - for edge cases, you can manually link specific Karbon work items to specific AldenSync engagements. Real-Time task sync. This is where it gets interesting. When a client uploads a document through the AldenSync portal: 1. AldenSync's AI classifies the document (W-2, 1099, K-1, etc.) 2. The document is filed in your DMS with your naming convention 3. AldenSync sends a webhook to its Karbon sync service 4. The sync service identifies the corresponding Karbon Work Item 5. The matching Client Task in Karbon is marked as complete 6. A note is posted to the Work Item timeline: 'W-2 received and filed via AldenSync' This happens in under 3 seconds from upload to Karbon update. No polling - Aldensync use event-driven architecture with webhook delivery. Handling multi-entity engagements. Firms with clients that have multiple entities (e.g., an individual with an S-Corp and a rental LLC) need documents routed to the correct engagement. Aldensync handle this by: - Matching the entity name on the uploaded document to the Karbon Work Item's client entity - If ambiguous, routing to a review queue where a staff member confirms the correct engagement (takes ~5 seconds) - Learning from these corrections - after 3-5 manual confirmations for a client, the system handles it automatically Error handling & edge cases. What happens when things go wrong: - Karbon API timeout: Aldensync queue the update and retry with exponential backoff (30s, 60s, 120s). If Karbon is down for extended periods, updates batch and apply when the API recovers. No data loss. - Duplicate work items: If multiple Karbon Work Items match a single document, Aldensync flag it for manual routing rather than guessing. - Deleted work items: If a Karbon Work Item is deleted after a document was linked, Aldensync notify the firm admin and re-queue the document for manual assignment. What Aldensync don't do. Aldensync intentionally don't: - Create new Work Items in Karbon (your workflow, your creation process) - Modify work item status beyond task completion (Aldensync update tasks, not engagement stages, unless you configure it) - Sync backward (if you manually mark a task complete in Karbon, Aldensync don't retroactively look for the document) This keeps the integration predictable and debuggable. Performance at scale. Its largest Karbon-connected firm processes 1,200 engagements per season with 15,000+ documents. Average sync latency is 2.4 seconds. Aldensync has had zero data mismatches in the last 12 months across all Karbon-connected firms. Want to see this in action? Start your 14-day free trial or schedule a technical walkthrough with its engineering team.

Trending in Taxation
Nov 18th, 2025
Karbon Appoints Brooke Brockman as CMO to Lead Global Brand Growth and AI Innovation for Accounting Firms

Veteran SaaS marketing leader joins Karbon to accelerate global expansion, strengthen customer advocacy, and advance the company's leadership in AI-powered practice management. Karbon, the global leader in AI-driven accounting practice management software, today announced the appointment of Brooke Brockman as Chief Marketing Officer. In this role, Brockman will lead Karbon's global marketing and brand strategy as the company continues to expand its capabilities, audience, and influence across the accounting profession. Brockman joins Karbon with more than 15 years of experience driving growth and customer engagement for leading SaaS brands. Most recently, she served as CMO at Buildertrend, where she helped scale the company's marketing function, strengthened customer loyalty, and positioned the brand as an industry standout. Prior to Buildertrend, Brockman led multi-channel campaigns and lifecycle marketing at advertising agencies, and held revenue-focused roles at Fortune 500 companies including Target and UPS. Additionally, Brockman was named one of The Top 50 Women Leaders in Software for 2024 by The Software Report. "Brooke is a proven leader who knows how to build trusted brands grounded in customer impact," said Mary Delaney, CEO of Karbon. "Her experience and perspective will help us share Karbon's story with even greater reach as we continue to lead the profession forward through AI-driven innovation, automation, and connected firm intelligence." In her role, Brockman will focus on deepening market presence, amplifying customer advocacy, and evolving the Karbon brand to reflect the company's leadership in driving AI adoption in the profession for smarter operations. "Karbon has redefined what's possible for accounting firms by combining innovation with a deep understanding of how teams actually work," said Brockman. "I'm thrilled to help amplify that story and support the customers and partners shaping the next chapter of the profession." Brockman's appointment follows Karbon's recent acquisition of AI-powered advisory platform Aider and underscores the company's ongoing investment in leadership, innovation, and customer success, driving the next generation of AI-powered, modern accounting firms worldwide. The post Karbon appoints Brooke Brockman as CMO to lead global brand growth and AI innovation for accounting firms appeared first on accounting insight news. By: Karbon Title: Karbon appoints Brooke Brockman as CMO to lead global brand growth and AI innovation for accounting firms. Share this. Supporting an indiana caregiver during national family caregivers month. Bright selects credas to deliver director verification checks ahead of companies house reforms. 5 ways to use a $25K business loan to grow before year-end. Is it time to revisit your indiana special needs plan?

Karbon
Oct 3rd, 2025
Karbon acquires Aider to deliver the future of AI-powered accounting and bookkeeping

Karbon has acquired Aider, an in AI-powered advisory and reporting tool, accelerating Karbon’s vision to transform the accounting profession through AI.

GlobeNewswire
Sep 30th, 2025
Karbon Acquires Aider to Deliver the Future of AI-Powered Accounting and Bookkeeping

SAN FRANCISCO, Sept. 30, 2025 (GLOBE NEWSWIRE) - Karbon, the global leader in practice management software for accounting, bookkeeping, tax and audit firms, today announced its acquisition of Aider, a pioneer in AI-powered advisory and reporting technology.

Trending in Taxation
Sep 13th, 2025
Karbon Appoints Vivek Srivastava as Senior Director of Product to Drive AI Innovation in Accounting

Karbon, the global leader in accounting practice management software, today announced the appointment of Vivek Srivastava as Senior Director of Product.