Karbon logo
Karbon

The collaborative practice management platform for accounting firms

AppSec Engineer

Location

United States

Posted

9 days ago

Salary

$131K - $169K / year

Seniority

Mid Level

Job Description

AppSec Engineer

Karbon

Role Description Seeking a development & cloud focused AppSec Engineer to join our expanding security team. The ideal candidate will have passion for AppSec, Cloud and AI. They will be a skilled communicator and relationship builder capable of promoting and building security practices across the organization and into our development processes. What You’ll Own: - Partner with different areas within Karbon - Ensure security is embedded from feature design and development to participating in design reviews and threat modelling. - Balance Security and Delivery - Communicate security risks and issues to non-technical stakeholders, balancing delivery needs with security. - Keep up to date on the latest technologies and approaches - Understand the importance of foundational security practices while being excited about new developments. - Identify and assess security risks introduced by AI tools - Assist with reviewing the risks of AI tooling usage & integration and AI-generated code. - Apply AI-assisted tooling to accelerate security work - Utilize AI across areas including triage, threat detection, code review, and documentation. - Flexibility and confidence to work across multiple security domains - Gain exposure to various security domains in a fast-moving company. - Work effectively as part of a team - Build relationships and trust across the organization to enhance Karbon’s security posture. - Own your work - Take pride in your work and ensure customer data security. - Bring your passion and personality - Contribute creativity, curiosity, and authenticity to strengthen the team. - Help us measure improvement and steer our roadmap - Contribute to Security Metrics to track progress and feedback into our roadmap. Qualifications - 4+ years experience in a security or development role. - Strong communication skills (spoken and written). - Some of the following Languages/Frameworks: Microsoft .NET/C#, JavaScript (React and EmberJS frameworks), Python. - At least one cloud platform: Azure, AWS, or GCP (predominantly Azure). - Working knowledge of PowerShell or Bash and Python. - Working knowledge of at least one AI development tool (e.g., Claude Code, GitHub Co-Pilot). - Experience with Portswigger Burp or similar. - Certifications such as Offsec OSCP & AWAE, GIAC, Burp Practitioner, PJPT, Microsoft/AWS development and cloud related are nice to have. - Experience with securing AI applications, systems, and AI tooling would be highly regarded. Requirements - Collaborating with teams to review designs & implementations for security issues. - Triaging issues and reports, assisting teams to remedy items and testing fixes. - Working with external penetration test companies to validate and prioritize findings. - Conducting risk and vulnerability assessments of web applications, APIs, and third-party suppliers. - Configuring and tuning SAST, SCA, and DAST Tooling. - Working with build/deployment pipelines to incorporate security tooling (GitHub Actions or Azure DevOps YAML based pipelines). - Assisting with implementing security-focused alerting, detections, and automations. - Conducting and facilitating organizational & developer-focused security training. - Assisting with operational security items such as EDR alerts and MDM. - Contributing to our security roadmap. Benefits - Gain global experience across Australia, New Zealand, UK, and Canada. - Strong benefits package including flexible time off with an encouraged 4 weeks use per year. - Company paid medical for you and eligible spouse/partner and dependents. - Paid dental and vision for you and eligible spouse/partner and dependents. - 401(k) with company matching. - Flexible Spending Account. - Up to 8 weeks paid parental leave. - Work-from-home stipend. - Collaborative, team-oriented culture that embraces diversity and invests in development. - Be part of a fast-growing company that promotes high performers from within.

Related Categories

Related Job Pages

More Engineer Jobs

Twoconnect logo

Senior Estimator

Twoconnect

We facilitate business growth through our managed offshoring services.

Engineer9 days ago
Full TimeRemoteTeam 201-500Since 2018H1B No Sponsor

Role Description We are seeking a Senior Estimator to support the preparation of accurate project cost estimates for healthcare fit-out projects. Working closely with the Lead Estimator and Sales Director, this role is responsible for: - Preparing and maintaining accurate project cost estimates based on specifications, allowances, and available documentation. - Completing quantity take-offs and estimating activities using Bluebeam and related tools. - Supporting tender and quotation preparation, ensuring timely and accurate submissions. - Maintaining supplier, subcontractor, and materials databases to ensure data accuracy and accessibility. - Obtaining, recording, and managing supplier and subcontractor pricing information. - Providing administrative support for estimating, project tracking, documentation, and reporting activities. - Collaborating with internal stakeholders and supporting the Lead Estimator and Sales Director in project and business-related tasks. Qualifications - Minimum 3–5 years of experience in estimating, construction administration, project coordination, or a related role. - Proven experience using Bluebeam for quantity take-offs and estimating activities. - Strong proficiency in Microsoft Excel and project tracking tools such as SmartSheet. - Experience within commercial construction, fit-outs, interiors, or similar industries; healthcare fit-out experience is advantageous. - Excellent attention to detail and accuracy in preparing estimates, maintaining records, and managing project data. - Strong organisational, time management, and multitasking abilities, with the capability to meet deadlines under pressure. - Effective communication and teamwork skills, with the ability to take initiative and work independently when required. Benefits - Work from home. - Monday to Friday 7AM to 4PM PHT (adjustments will be made for daylight saving time). - HMO with 2 free dependents and medical reimbursements. - Government-mandated benefits. - Work from home allowances. - Opportunities to work with leading companies in Australia and beyond. - Training programmes for career development. - Engaging company outings, team activities, and wellness sessions. - Supportive, inclusive culture. - Dedicated managers focused on your growth and success. Company Description Twoconnect connects highly skilled Filipino professionals with established companies in Australia, New Zealand, the United States, the United Kingdom, and Europe, providing direct access to global careers and long-term opportunities. - We offer competitive pay and benefits, additional entitlements, and structured career development programs that make employment both financially rewarding and professionally sustainable. - Our industry-leading retention rate demonstrates our commitment to a people-first culture that prioritizes stability, growth, and genuine care for every employee. - Twoconnect is an equal opportunity employer. We value cultural diversity and foster an inclusive workplace where every employee is respected and supported as part of a growing global team. 🔗 Learn more about us through our official pages: - Website: twoconnect.com.au - Careers: apply.workable.com/twoconnect-careers - LinkedIn: linkedin.com/company/twoconnectau - Facebook: facebook.com/2woconnect - Instagram: instagram.com/twoconnect_

CTT (UTC+8)

Clinical Engineer Project Engineer

CommonSpirit Health

CommonSpirit Health is a nonprofit organization that is on a mission to improve people’s health while making “the healing presence of God known.” The orga

Engineer9 days ago

Role Description As a Clinical Engineering Project Engineer, you will manage the planning and implementation of key projects for Clinical Engineering by: - Developing plans and identifying process improvement opportunities. - Providing project management to successfully implement initiatives. - Managing multiple small to moderate projects or a single large project of moderate to high complexity. - Partnering with Clinical Engineering leaders and multi-disciplinary teams at a system, regional, and local level. - Driving innovative strategies that positively impact the clinical effectiveness of medical devices and improve operational performance. Key responsibilities include: - Project management of key Clinical Engineering projects, including planning, implementation, testing, deployment, and customer adoption of initiatives. - Collaborating with Clinical Engineering leadership, CommonSpirit leadership, hospital staff, and clinicians to ensure successful outcomes that align with business goals, objectives, and regulatory requirements. - Supervising project resources and vendors required to deliver project tasks. - Developing project plans that identify key issues, challenges, approaches, performance metrics, communication plans, and resources required for successful completion of deliverables. - Creating project cost estimates and strategy recommendations, monitoring project expenditures to ensure projects are delivered within approved budget. - Facilitating the Medical Device IT Connectivity and Integration (MDICI) process by working across multi-functional teams to ensure successful deployment of new medical devices on our network. Qualifications - Minimum 5 years project management and/or process improvement experience. - Minimum 5 years engineering experience. - Bachelors in project management, business administration, healthcare administration, or engineering (or equivalent experience), upon hire. Requirements - Knowledge of IT Networking fundamentals. - Experience in Biomedical Engineering or Medical Imaging preferred, specifically regarding different types of medical devices and their integration with other systems. - Strong organizational skills. - Healthcare Technology Management (Clinical Engineering) experience. - Project Management Professional, upon hire. - Lean Six Sigma Black Belt Certification, upon hire. - Six Sigma Black Belt, upon hire. - Certified Healthcare Technology Manager, upon hire. - Certified Biomedical Equipment Technician, upon hire.

Kentucky + 1 moreAll locations: Kentucky | Romania
$41 - $61 / hour

Title: Senior Identity and Access Engineer Location: Philadelphia, Pennsylvania time type Full time job requisition id R4046 Morgan, Lewis & Bockius LLP, one of the world’s leading global law firms with offices in strategic hubs of commerce, law, and government across North America, Asia, Europe, and the Middle East, is seeking to hire a Sr. Identity and Access Engineer. Reporting to the Manager of Identity and Access Management, the Sr. Identity and Access Engineer provides mentoring to fellow engineers and contributes great things to the team with respect to knowledge transfer and advanced knowledge of Identity Access Management (IAM) engineering fundamentals. This position will reside in our Philadelphia office with a hybrid in-office/remote working schedule. Responsibilities: - Respond to strategies provided by the Architecture and Engineering team and its management for implementation and oversight and will be called upon to resolve the highest-level technical issues. In addition, this person will partner with applicable teams to ensure secure, scalable, and compliant identity services. - Develop innovative IAM strategies and take ownership of these through all phases. - Deliver enterprise-wide IAM, identity governance, and authentication solutions in a hybrid cloud capacity. - Design and implement lifecycle management automation for joiner, mover and leaver scenarios. - Implement role-based access control (RBAC) and apply the concept of least-privilege. - Provide programmatic solutions to include PowerShell, JSON, SQL, LDAP, and object-oriented languages for IAM systems. - Collaborate with other IAM team members on system design, architecture, and strategies to provide high levels of customer satisfaction. - Integrate enterprise applications for SSO and set up provisioning/offboarding. - Lead key meetings including technical, cross-functional, and stakeholder meetings. - Ensure Enterprise services and servers remain operational and monitor Active Directory, EntraID, and IAM services. - Provide after-hours support as needed to address incidents, system maintenance. - Create and maintain architecture and documentation for IAM systems. - Represents the team during the audit and ISO 27001 certification process. - Participate in on-call support rotation. Education and experience: - A bachelor's degree from a four-year college or university. - 5 years of hands-on experience in Identity and Access Management / Identity Governance engineering roles. - 5 years of experience with Cloud technologies (Azure, AWS, GCE) in a hybrid/multi-cloud identity environment. - Solid understanding of identity federation protocols (SAML, OAuth, OpenID Connect) and access governance concepts. - Problem-solving and analytical skills; ability to handle complex, time-sensitive incidents. - Excellent communication skills and ability to collaborate across technical and non-technical stakeholders. Technical requirements: - Expertise in MS Active Directory (design, administration, Group Policy, replication, trusts, privileged access). - Proficiency with MS Entra ID (conditional access, PIM, hybrid identity, SSO/MFA, entitlement management, access reviews). - Advanced PowerShell scripting skills for automation, reporting, integrating, and administration of AD/Entra ID/SailPoint environments. - Experience implementing and supporting SailPoint (Identity Now, IdentityIQ, or Identity Security Cloud), including custom workflows, rules, transforms, connectors, certifications, and integrations. - SailPoint Certified IdentityIQ Engineer / IdentityNow Administrator is preferred. - Familiarity with security frameworks (NIST, Zero Trust, ISO 27001); compliance requirements (SOX, GDPR, HIPAA, etc.); PAM tools (e.g., CyberArk, Delinea) are a plus. - Core back-end technologies (Microsoft Windows 2019 Server and above, Varonis, LDAP, Cloud Identity solutions, and related IAM software solutions), ISO 27001 principles. #LI-Hybrid Morgan, Lewis & Bockius LLP is committed to equal employment opportunity and providing reasonable accommodations to applicants with physical and/or mental disabilities. We value inclusion and solicit applications from all qualified applicants without regard to race, color, gender, sex, age, religion, creed, national origin, ancestry, citizenship, marital status, sexual orientation, physical or mental disability, medical condition, veteran status, gender identity, genetic information, or any other characteristic protected by federal, state, or local law. Pursuant to applicable state and municipal Fair Chance Laws and Ordinances, we will consider for employment qualified applicants with arrest and conviction records. California Applicants: Pursuant to the California Consumer Privacy Act, the following link contains the Firm's California Consumer Privacy Act Privacy Notice for Candidates which explains the categories of personal information that we collect and the purposes for which we use such personal information. CCPA Privacy Notice for Candidates Morgan, Lewis & Bockius, LLP reasonably accommodates applicants and employees who need them to perform the essential functions of the job because of disability, religious belief, or other reason protected by applicable law. If hired, your employment relationship with the firm will be on an "at-will" basis, meaning that the firm may modify the terms and conditions of your employment at any time, and that either you or the firm will be free to end the relationship at any time with or without cause and with or without advance notice, although reasonable notice would be expected.

Pennsylvania
Full TimeRemoteTeam 5,001-10,000Since 2011H1B Sponsor

As a global leader in cybersecurity, CrowdStrike protects the people, processes and technologies that drive modern organizations. Since 2011, our mission hasn’t changed — we’re here to stop breaches, and we’ve redefined modern security with the world’s most advanced AI-native platform. Our customers span all industries, and they count on CrowdStrike to keep their businesses running, their communities safe and their lives moving forward. We’re also a mission-driven company. We cultivate a culture that gives every CrowdStriker both the flexibility and autonomy to own their careers. We’re always looking to add talented CrowdStrikers to the team who have limitless passion, a relentless focus on innovation and a fanatical commitment to our customers, our community and each other. Ready to join a mission that matters? The future of cybersecurity starts with you. About the Role: As the Technology Strategist for Canada, you will work and support the CTO Labs and Field CTO Teams team at CrowdStrike. The Field CTO team’s mission is to identify & deliver new strategic direction & thought leadership to customers, analysts, media & partners while supporting platform maturity journeys of customers, and supporting the identification of new markets and TAM. This includes driving strategy through cross functional collaboration across the company including Product, Sales, Marketing, and Data Science. As the region's Technology Strategist, you will be responsible for creating and communicating the company’s technical vision and strategy on a regional basis and working closely with the company’s product CTO’s, Product Managers and Engineering functions on a regular basis. You will also work closely with other groups within CrowdStrike, which includes: sales, public sector and industry teams, legal and corporate affairs, and public relations, data science, corporate development as well as detection engineering. This role reports to the Field CTO Americas. With your extensive cybersecurity background and your ability to think and operate at a strategic level, you will drive CrowdStrike’s technical vision and strategy across the Eastern US but will also provide support on strategic engagements across the CrowdStrike organization internationally. What You'll Do: - Support current customers and new customers by sharing CrowdStrike’s long-range strategic vision and product roadmap, facilitating the entry of new technology concepts to market, and positioning CrowdStrike as the leading thought leader for Cybersecurity with customers, partners, analysts and media. - Driving and communicating CrowdStrike’s technology strategy to customers, partners, and investors as well as media and industry events. - Engaging with governments and regulators on cybersecurity, technical policy, and innovation. - Maintaining an in-depth knowledge of the cyber security industry, the competitive landscape and related industry developments to ensure we continue to be thought leaders who innovate ahead of the market. - Using stakeholders’ feedback to inform necessary improvements and adjustments to technology. - Focusing on technology improvements that will improve your region. - Discovering new technologies that yield competitive advantage as part of the core platform or through technology partnerships. - Providing recommendations for continuous improvement. - Support customers and prospects as part of our Executive Briefing Program either virtually or onsite in Sunnyvale. What You'll Need: - The ability or experience in developing security strategies for companies and/or governments and for overseeing the successful implementation and execution of these strategies. - Execute corporate security strategy with the ability to be able to differentiate CrowdStrike’s products and services. - Broad information security competency and experience across strategy, governance, technology, and policy. - Demonstrate a deep and broad knowledge of security issues and trends (GRC space) and are able to articulate a high-level security strategy to both technical and non-technical audiences. - An ability to develop and maintain relationships with senior leaders both within customers and in CrowdStrike, up to and including C-level executives. - A history of speaking at industry conferences, published blogs, podcasts, white papers, books, PR and Media interviews. - Working in a role such as or similar to Regional CTO, Enterprise Technology Strategist, Strategic Consultant, Enterprise Security Architect. - Hands on experience in detailed research and analysis. - Experience across various security disciplines, including nation state, e-crime, and hacktivist tradecraft across multiple industries. - Experience with/exposure to Endpoint Security, Cloud Security, SIEM/Log Management, Mobile Security, Identity Security, Incident Response as well as other cyber security domains. - Regional travel with some international travel is expected. #LI-Remote #LI-RC1 Benefits of Working at CrowdStrike: - Market leader in compensation and equity awards - Comprehensive physical and mental wellness programs - Competitive vacation and holidays for recharge - Paid parental and adoption leaves - Professional development opportunities for all employees regardless of level or role - Employee Networks, geographic neighborhood groups, and volunteer opportunities to build connections - Vibrant office culture with world class amenities - Great Place to Work Certified™ across the globe CrowdStrike is proud to be an equal opportunity employer. We are committed to fostering a culture of belonging where everyone is valued for who they are and empowered to succeed. We support veterans and individuals with disabilities through our affirmative action program. CrowdStrike is committed to providing equal employment opportunity for all employees and applicants for employment. The Company does not discriminate in employment opportunities or practices on the basis of race, color, creed, ethnicity, religion, sex (including pregnancy or pregnancy-related medical conditions), sexual orientation, gender identity, marital or family status, veteran status, age, national origin, ancestry, physical disability (including HIV and AIDS), mental disability, medical condition, genetic information, membership or activity in a local human rights commission, status with regard to public assistance, or any other characteristic protected by law. We base all employment decisions--including recruitment, selection, training, compensation, benefits, discipline, promotions, transfers, lay-offs, return from lay-off, terminations and social/recreational programs--on valid job requirements. If you need assistance accessing or reviewing the information on this website or need help submitting an application for employment or requesting an accommodation, please contact us at recruiting@crowdstrike.com for further assistance. CrowdStrike Canada ULC is committed to equal pay for equal work in its compensation practices. The base salary range for this position in Canada is $150,000 - $265,000 CAD per year + variable/incentive compensation + equity + benefits. A candidate’s salary is determined by various factors including, but not limited to, relevant work experience, skills, certifications and location. This is Canadian-based employment, and it is expected that all employees maintain legal entitlement to work in Canada. Applicants selected to move forward in the hiring process are subject to background checks, including but not limited to criminal record, credit, and/or reference checks.

Canada
C$150K - C$265K / year