VP of IT and Security
Karbon is the global leader in AI-powered practice management software for accounting firms. We provide an award-winning cloud platform that helps tens of thousands of accounting professionals work more efficiently and collaboratively every day. With customers in 40 countries, we are a globally distributed team across the US, Australia, New Zealand, Canada, the United Kingdom, and the Philippines. We are well-funded, ranked #1 on G2, growing rapidly, and have a people-first culture recognized with Great Place To Work® certification and on Fortune magazine's Best Small Workplaces™ List.
About the Role
This is a foundational leadership role at Karbon. As VP of IT & Security, you will own Internal IT, Security, Governance, Risk & Compliance, and Enterprise incident response, business continuity, and disaster recovery. You are a player-coach: setting strategy and owning the roadmap while also rolling up your sleeves to analyze logs, write policies, configure tools, or run vendor evaluations. You will report directly to the CEO and collaborate closely with Engineering, Finance, Legal, and the broader executive team. You will lead an existing small SecOps team and build the IT function in-house, migrating from our current MSP.
Responsibilities
Internal IT
- Own the day-to-day running of Karbon's device fleet and internal systems.
- Establish and manage IT service delivery and support, including helpdesk operations, incident and problem management, and SLAs as we migrate from our MSP to an internal function.
- Own identity and access management (Okta) including device provisioning and employee onboarding and offboarding.
- Manage endpoint management (MDM) and device policies across our global fleet of PCs and Macs.
- Build and manage vendor relationships, including contracts, renewals, and performance.
- Identify opportunities to optimize license costs.
Security
- Define, maintain, and champion Karbon's security strategy, policies, and standards across the organization.
- Own the internal security tooling stack including EDR, SIEM, and email security.
- Lead the Application Security team.
- Develop and maintain Karbon's information security policies and risk management framework.
Governance, Risk, and Compliance
- Maintain Karbon's Risk Register and own the SOC 2 program end-to-end: audit readiness, control design, and auditor relationships.
- Coordinate with internal teams and external partners as control owners for evidence collection.
- Serve as the internal subject matter expert on compliance requirements for customer, partner, and enterprise sales conversations.
Enterprise Incident Response, Business Continuity & Disaster Recovery
- Own and maintain the incident response plan and playbooks.
- Define incident severity, escalation paths, and communication protocols, coordinating legal, insurance, and regulatory notification obligations during significant events.
- Own business continuity plans and backup strategy.
Requirements
- 12+ years in IT and security with at least 5 years in a senior leadership role.
- Proven track record managing or building an internal IT function; experience transitioning from an MSP model is a strong advantage.
- Hands-on operational and security experience, able to assist teams when required.
- Deep familiarity with compliance frameworks such as SOC 2.
- Experience in a B2B SaaS environment is strongly preferred.
Skills
- Ability to move between strategy and execution without losing momentum in either direction.
- Strong communicator able to translate technical concepts into business language for a CEO, board, or enterprise customer.
- Commercially aware—understanding how security and compliance decisions affect sales, customer trust, and product velocity.
- Comfortable with ambiguity and building in environments where process is still being defined.
- Collaborative by default, with the confidence to hold the line when it matters.
Technologies
- Identity & Access Management (Okta & Entra preferred)
- Mobile Device Management / Endpoint Management
- EDR solutions such as Jamf Protect & Microsoft Defender for Endpoint
- At least one major cloud platform: Azure, AWS, or GCP
- Office Productivity Platform: Google Workspace (preferred) or O365
- Netskope experience highly regarded
Why This Role, Why Now
Karbon is at an inflection point. We're growing, our customer base includes some of the world's largest accounting firms, and enterprise trust is a competitive differentiator. This role exists because we're ready to own our IT and security function at the level our customers and ambitions demand. You'll have a seat at the table, real scope, and the support of a CEO who understands why this matters.
Benefits
- Flexible Time Off with an encouraged 4 weeks of use per year
- Company-paid medical for you and eligible spouse/partner and dependents
- Paid dental and vision for you and eligible spouse/partner and dependents
- 401(k) with company matching
- Flexible Spending Account
- Up to 8 weeks paid parental leave
- Work-from-home stipend
- Opportunity to work with and learn from an experienced, high-performing team
- A collaborative, team-oriented culture that embraces diversity, invests in development, and provides consistent feedback
- Be part of a fast-growing company that promotes high performers from within
Pay
The estimated base salary range for this role is $220,000 USD - $245,000 USD. The range accounts for factors such as physical location, cost of living, years of experience, skills, and other business needs. The base salary is one component of the total compensation package, which may also include a target bonus and competitive equity grant.