VP of IT and Security

KARBON, INC.
Seattle, WA, United States
18 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Compensation
$220,000.0 - $245,000.0
Working hours
Regular working hours
Job source

Tech stack

Amazon Web Services Microsoft Azure Communications Protocols Cyber Security Disaster Recovery Identity and Access Management Office Suite Security Information and Event Management Cloud Platform System Okta Office365 Software Security
+3 more
Azure Security Center Casper Suite Gsuite

Job description

This is a foundational leadership role at Karbon.

As VP of IT & Security, you will own the following areas:

  • Internal IT - Identity & Access, devices and configuration
  • Security - Corporate & Application
  • Governance, Risk & Compliance
  • Enterprise incident response, business continuity, and disaster recovery

You are a player-coach. You’ll set strategy and own the roadmap, but you’re comfortable rolling up your sleeves, analyzing logs, writing and tweaking policies, configuring tools, running a vendor evaluation, or sitting in a SOC 2 evidence review.

You’ll report directly to the CEO and work closely with Engineering, Finance, Legal, and the broader executive team.

You will lead, on day one, an existing small SecOps team that will report to you.

This role doesn’t exist yet in its current form. You’ll be building something meaningful from the ground up and leading the migration of our IT function from our MSP to an in-house team., * Own the day-to-day running of Karbon’s device fleet and internal systems.

  • Establish and manage IT service delivery and support, including helpdesk operations, incident and problem management, and SLAs as we migrate away from our MSP to an internal function.
  • Own identity and access management (Okta) including device provisioning and employee onboarding and offboarding.
  • Manage endpoint management (MDM) and device policies across our global fleet of pc’s and mac’s.
  • Build and manage vendor relationships, including contracts, renewals, and performance.
  • Identify opportunities to optimize licence costs., * Define, maintain, and champion Karbon’s strategy, policies, and standards across the organisation.
  • Own the internal security tooling stack including EDR, SIEM, email security.
  • Lead the Application Security team.

  • Develop and maintain Karbon’s information security policies and risk management framework.

Governance, Risk and Compliance

  • Maintain Karbon’s Risk Register and own Karbon’s SOC 2 program end to end: audit readiness, control design, and auditor relationships, coordinating with internal teams and external partners as control owners for evidence collection.
  • Serve as the internal subject matter expert on compliance requirements for customer, partner, and enterprise sales conversations.

Enterprise Incident Response, Business Continuity & Disaster Recovery

  • Own and maintain the incident response plan and playbooks
  • Define incident severity, escalation paths, and communication protocols, coordinating legal, insurance, and regulatory notification obligations during significant events.
  • Own business continuity plans and backup strategy.

Requirements

  • 12+ years in IT and security with at least 5 years in a senior leadership role.
  • Proven track record managing or building an internal IT function - experience having transitioned from an MSP model is a strong advantage.
  • Hands-on operational & security experience and able to assist teams when required.
  • Deep familiarity with compliance frameworks such as SOC 2.
  • Experience in a B2B SaaS environment is strongly preferred.

Technologies

  • Identity & Access Management (Okta & Entra preferred)
  • Mobile Device Management / Endpoint Management
  • EDR solutions such as Jamf Protect & Microsoft Defender for Endpoint
  • At least one major cloud platform either Azure, AWS or GCP
  • Office Productivity Platform - Google Workspace (preferred) or O365
  • Netskope Experience highly regarded

Skills and Approach

  • You can move between strategy and execution without losing momentum in either direction.
  • Strong communicator able to translate technical concepts into business language for a CEO, board, or enterprise customer.
  • Commercially aware - you understand how security and compliance decisions affect sales, customer trust, and product velocity.
  • Comfortable with ambiguity and building in environments where process is still being defined.
  • Collaborative by default, with the confidence to hold the line when it matters.

Benefits & conditions

Pulled from the full job description

  • Work from home stipend
  • Paid parental leave
  • Parental leave
  • 401(k) matching
  • Vision insurance
  • Dental insurance
  • Flexible spending account, Karbon is at an inflection point. We’re growing, our customer base includes some of the world’s largest accounting firms, and enterprise trust is a competitive differentiator for us. This role exists because we’re ready to own our IT and security function at the level our customers and our ambitions demand.

You’ll have a seat at the table, real scope, and the support of a CEO who understands why this matters.

Why work at Karbon?

  • Gain global experience across Australia, New Zealand, UK, and Canada
  • Strong benefits package including: *

  • Flexible Time Off with an encouraged 4 weeks use per year
  • Company paid medical for you and eligible spouse/partner and dependents
  • Paid dental and vision and eligible spouse/partner and dependents
  • 401(k) with company matching
  • Flexible Spending Account
  • Up to 8 weeks paid parental leave
  • Work-from-home stipend
  • Work with (and learn from) an experienced, high-performing team
  • A collaborative, team-oriented culture that embraces diversity, invests in development and provides consistent feedback
  • Be part of a fast-growing company that firmly believes in promoting high performers from within

About the company

Karbon is the global leader in AI-powered practice management software for accounting firms. We provide an award-winning cloud platform that helps tens of thousands of accounting professionals work more efficiently and collaboratively every day. With customers in 40 countries, we have grown into a globally distributed team across the US, Australia, New Zealand, Canada, the United Kingdom, and the Philippines. We are well-funded, ranked #1 on G2, growing rapidly, and have a people-first culture that is recognized with Great Place To Work® certification and on Fortune magazine’s Best Small Workplaces List., Karbon embraces diversity and inclusion, aligning with our values as a business. Research has shown that women and underrepresented groups are less likely to apply to jobs unless they meet every single criteria. If you’ve made it this far in the job description but your past experience doesn’t perfectly align, we do encourage you to still apply. You could still be the right person for the role!

We recruit and reward people based on capability and performance. We don’t discriminate based on race, gender, sexual orientation, gender identity or expression, lifestyle, age, educational background, national origin, religion, physical or cognitive ability, and other diversity dimensions that may hinder inclusion in the organization.

Generally, if you are a good person, we want to talk to you.

If there are any adjustments or accommodations that we can make to assist you during the recruitment process, and your journey at Karbon, contact us at people.support@karbonhq.com for a confidential discussion.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

2:33 min

Introduction to security advocacy and automation testing

Chris Heilmann +2 · LIVE

1:34 min

Pivoting careers into specialized platform engineering roles

Xavier Portilla Edo · LIVE

4:37 min

Architecting single sign-on flows across multiple application domains

Gift Egwuenu · World Congress 2023

2:20 min

Addressing security risks with central single sign-on setups

Gift Egwuenu · World Congress 2023

4:18 min

Prioritizing communication and structural awareness over strict tool mastery

Liam Hurrel +1 · World Congress 2021

Videos

See all

Related articles

See all