Staff Security Engineer

2 days ago


Canberra, ACT, Australia Karbon Full time $120,000 - $180,000 per year

About Karbon

Karbon is the global leader in practice management software for growth-minded accounting firms. We provide an award-winning, highly collaborative cloud platform that streamlines work and communication, enabling the average accounting firm using Karbon to save 18.5 hours per week, per employee.

We have customers in 34 countries and have grown into a globally distributed team, with our people based throughout the US, Australia, New Zealand, Canada, the United Kingdom, and the Philippines. We are well-funded, ranked #1 on G2, have a fantastic team culture built on our values, are growing rapidly, and making a global impact.

Seeking a development & cloud focused Staff Security Engineer to join a newly formed security team focused on uplifting and maintaining Karbon;s security practices.

The ideal candidate will have passion for AppSec and be a skilled communicator and relationship builder capable of promoting and building security practices across the organization and into our development processes.

Key Responsibilities
  • Balance Security and Delivery —You know how to balance delivery needs with security and can communicate security risks and issues to non technical stakeholders. You understand when it's important to push back, when to compromise and how to work with delivery teams to reach a great outcome
  • Work effectively as part of a team— security is a team sport and you understand the need to build relationships and trust across the organization to enhance Karbon's security posture. You are happy to answer questions and offer advice to teams that will reach out for your assistance
  • Build and maintain— Our Security team is young and you are excited to bring your ideas to contribute to Karbon's security road map. You keep up to date on the latest technologies and approaches but understand the importance of foundational security practices such as good account hygiene, MFA and secret management.
  • Autonomy—You are inherently curious, focused on continual learning and faced with challenges and direction rather than predefined solutions, you engage fully and creatively with problems.
  • Own your work—You take pride in your work, feeling a deep sense of responsibility for the products we develop and ensuring we keep our customers' valuable data secure. This sense of ownership is paramount, and you share this commitment.
  • Bring your passion and personality—Your creativity, curiosity, and authentic self make the team stronger. If you've worked in highly political environments, you'll find our culture, free from office politics and valuing openness and authenticity, a refreshing change.
Qualifications

7+ years experience in a security or development role across most of the following:

  • Collaborating with teams to review designs & implementations for security issues and embedding good security practices
  • Contributing to and helping drive a security roadmap
  • Conducting risk and vulnerability assessments of web applications and APIs and working with third party penetration testing companies
  • Triaging issues and reports and assisting teams remedy items
  • Configuring and tuning SAST, SCA and DAST Tooling & WAF Protections
  • Working with build/deployment pipelines to incorporate security tooling (Github Actions or Azure Devops YAML based pipelines)
  • Implementing security focused alerting and detections and automations
  • Conducting and facilitating organizational & developer focused security training
  • Assisting with operational security items such as EDR alerts and MDM

In addition you'll need:

  • Strong communication skills (spoken and written) 
  • Some of the following Languages/Frameworks: Microsoft .NET/C#, JavaScript, Python (we use React and EmberJS)
  • At least one cloud platform: Azure, AWS or GCP (we use Azure predominantly)
  • Portswigger Burp or similar
  • Working knowledge of PowerShell or Bash and Python
  • Certifications such as Offsec OSCP & AWAE, GIAC, Burp Practitioner, PJPT, Microsoft/AWS development and cloud related are nice to have

Why work at Karbon?

  • Gain global experience across the USA, Australia, New Zealand, UK, Canada and the Philippines
  • 4 weeks annual leave plus 5 extra "Karbon Days" off a year
  • Flexible working environment
  • Work with (and learn from) an experienced, high-performing team
  • Be part of a fast-growing company that firmly believes in promoting high performers from within
  • A collaborative, team-oriented culture that embraces diversity, invests in development, and provides consistent feedback
  • Generous parental leave

Karbon embraces diversity and inclusion, aligning with our values as a business. Research has shown that women and underrepresented groups are less likely to apply to jobs unless they meet every single criteria. If you've made it this far in the job description but your past experience doesn't perfectly align, we do encourage you to still apply. You could still be the right person for the role

We recruit and reward people based on capability and performance. We don't discriminate based on race, gender, sexual orientation, gender identity or expression, lifestyle, age, educational background, national origin, religion, physical or cognitive ability, and other diversity dimensions that may hinder inclusion in the organization.

Generally, if you are a good person, we want to talk to you.

If there are any adjustments or accommodations that we can make to assist you during the recruitment process, and your journey at Karbon, contact us at for a confidential discussion.

At this time, we request that agency referrals are not submitted for this position. We appreciate your understanding and encourage direct applications from interested candidates. Thank you


  • Security Engineer

    1 week ago


    Canberra, ACT, Australia Apple Full time

    Security Engineering & Architecture (SEAR) is at the core of Apple's product security strategy and we're fanatical about protecting our users. We are building a new team to defend our most valuable security boundaries and mitigations by bringing new data-driven insights delivered at scale. We're looking for an outstanding Security Engineer to join our small,...


  • Canberra, ACT, Australia Security 1 Full time

    Trainee Security TechniciansSecurity 1 currently services alarm clients and patrol clients across Australia from our centrally located head office in the ACT and our QLD office. Together with a hands on management team, dedicated, trained staff and the integration of the latest security products; sourced from Australia and around the world, we offer security...


  • Canberra, ACT, Australia Nixil Full time $80,000 - $120,000 per year

    Security Clearance Required for this role:Must have a Current NV2 and PV cleared resources with current OSA or previously help OSA.We're seeking a Security Engineer who's passionate about cyber defence, enjoys solving complex security challenges, and thrives in a collaborative, high-trust environment.In this role, you'll work alongside a multi-disciplinary...

  • Security Engineer

    2 weeks ago


    Canberra, ACT, Australia Fujitsu Full time $80,000 - $120,000 per year

    We are FujitsuWe use technology to make happier lives. We are a global leader in technology and business solutions that transform organisations and the world around us. We have a long heritage of bringing innovation and expertise, continuously working to contribute to the growth of society and our customers.About the roleWe are seeking an...


  • Canberra, ACT, Australia Certis Security Australia Full time $60,000 - $90,000 per year

    Company description: Certis Security Australia is one of Australia's leading security service provider with over 3,000 employees nationwide, providing our clients with industry leading security services with our state-of-the-art technology and highly qualified staff. As part of the Certis Group, SNP Security and BRI Security deliver integrated security...


  • Canberra, ACT, Australia Aurec Full time $120,000 - $240,000 per year

    Canberra based2 year contract$1,100 Daily RateThis is not your average security role. We are seeking a high calibre Senior Security Engineer to act as a technical authority and secure government platforms. You will be the lead architect and hands on expert responsible for designing, implementing, and defending our client's infrastructure. You will be given...


  • Canberra, ACT, Australia Netier HR & Learning Full time $80,000 - $120,000 per year

    Introduction Please note: Due to security requirements of this role, we are only able to consider applications from Australian citizens and permanent residents.Description As a Cyber Security Engineer, you will understand the demands of the position, working closed with the Senior Cyber Security Engineer, you will be a champion of our vision and values,...

  • Security Engineer

    2 weeks ago


    Canberra, ACT, Australia Softtest pays pty Full time $120,000 - $180,000 per year

    Job Description: Australian Citizens residing in Australia only respond. must have top secret Positive VettingEssential Criteria :Major Responsibilities:1. Develop and operate IT security systems, this may include next generation firewalls, intrusion detection, web application firewalls, content filtering, API security, DDoS protection, proxies,...

  • Senior Civil Engineer

    2 weeks ago


    Canberra, ACT, Australia TTW Staff Portal Full time $120,000 - $180,000 per year

    Introduction Due to upcoming and on-going projects we have a Senior Civil Engineering role in our Canberra office. As a Senior Civil Engineer, your role will be to provide technical expertise on a wide variety of large public and private sector projects. This position offers exposure to a number of landmark projects and excellent career progression...


  • Canberra, ACT, Australia Peoplebank Australia ACT Full time $120,000 - $180,000 per year

    About the CompanyPeoplebank are a leading information technology talent consultancy that focuses on providing specialised IT consultants to Tier-1 clients in diverse industries like Banking/Financial Services, Retail, Telecommunications, and Government. Our consultants are engaged in a variety of cutting-edge projects throughout Australia. About the RoleOur...