[![Image](https://upload.wikimedia.org/wikipedia/commons/8/82/Telegram_logo.svg) Fresh remote jobs, sorted by category — join Jobicy on Telegram  › Fresh remote jobs on Telegram  ›](https://t.me/JobicyJobs) [All remote jobs](https://jobicy.com/jobs.md)Open role[![Karbon logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/06/13eaf3d2-221.png)](https://jobicy.com/company/karbon.md)Remote opportunity at[Karbon](https://jobicy.com/company/karbon.md)

# AppSec Engineer

Review the role, location requirements, compensation details, and application process before deciding whether this opportunity fits your next career move.

[Apply for this job](#job-application)[View company](https://jobicy.com/company/karbon.md)Share1 Sep 2026Published30Listing views1Application actions1 Oct 2026Apply before  Opportunity details

## About this role.

AI SummaryKarbon is hiring an AppSec Engineer to embed application and cloud security practices throughout software design, development, deployment, and operational support. The role partners closely with engineering teams on threat modeling, security reviews, vulnerability remediation, security tooling, and risk communication. The engineer will work across Azure-centric cloud environments, CI/CD pipelines, web applications and APIs, endpoint and corporate security processes, and detection engineering. The position also emphasizes responsible use and security assessment of AI tooling and AI-generated code. Candidates need at least four years of relevant security or development experience, strong communication skills, and practical familiarity with secure SDLC tooling and cloud platforms.

## Role DNA

A quick view of the complexity, pace, ownership and collaboration implied by the job description.

### Job Complexity

4/5EasyHard

### Pace & Pressure

4/5RelaxedFast-paced

### Autonomy Level

5/5GuidedFull ownership

### Communication Load

5/5IndependentCollaborative

AI insightThis is a broad, hands-on AppSec role spanning secure development, cloud security, vulnerability management, detection engineering, and operational security. Success requires independent prioritization in a fast-moving environment while influencing technical and nontechnical stakeholders.

## Salary analysis

Estimated compensation compared with the broader US market for similar roles.

Estimated job medianMarket rate$150,000US market range$130k–$180k0$198k

AI insightThe disclosed base salary range is $131,000 to $169,000 USD per year, producing an offer median of $150,000. This aligns with the estimated US market base-pay range of $130,000 to $180,000 for a mid-level to senior application security engineer with cloud, DevSecOps, and AI-security responsibilities; bonus and equity may be additional.

## Core skills

Skills and capabilities most closely associated with this opportunity.

[Application Security](https://jobicy.com/jobs?search_keywords=Application%20Security.md)[Cloud Security](https://jobicy.com/jobs?search_keywords=Cloud%20Security.md)[Secure SDLC](https://jobicy.com/jobs?search_keywords=Secure%20SDLC.md)[Threat Modeling](https://jobicy.com/jobs?search_keywords=Threat%20Modeling.md)[Vulnerability Management](https://jobicy.com/jobs?search_keywords=Vulnerability%20Management.md)[SAST](https://jobicy.com/jobs?search_keywords=SAST.md)[DAST](https://jobicy.com/jobs?search_keywords=DAST.md)[Software Composition Analysis](https://jobicy.com/jobs?search_keywords=Software%20Composition%20Analysis.md)[Azure](https://jobicy.com/jobs?search_keywords=Azure.md)[CI/CD Security](https://jobicy.com/jobs?search_keywords=CICD%20Security.md)

Sample interview questionsHow would you embed security into a product team’s feature-development lifecycle without unnecessarily slowing delivery?I would introduce lightweight security touchpoints early, including architecture review, threat modeling for meaningful changes, secure coding guidance, and automated checks in the CI/CD pipeline. Findings should be risk-ranked, assigned clear owners, and accompanied by practical remediation advice so teams can address critical issues quickly while scheduling lower-risk improvements appropriately.

Describe how you would evaluate and prioritize findings from SAST, SCA, DAST, and an external penetration test.

I would validate each finding, remove false positives, and prioritize based on exploitability, exposure, affected data or systems, business impact, compensating controls, and availability of a fix. I would then agree remediation timelines with system owners, track exceptions transparently, retest fixes, and use recurring patterns to improve preventive controls and developer guidance.

What security controls would you focus on when reviewing an Azure-hosted web application and its CI/CD pipeline?

I would assess identity and least-privilege access, secret storage, network segmentation, logging and monitoring, encryption, dependency management, and secure configuration of Azure services. In the pipeline, I would review branch protections, permissions for build identities, secret handling, artifact integrity, SAST/SCA/IaC scanning, deployment approvals, and the security of third-party actions or packages.

How would you assess risks associated with developer AI tools and AI-generated code?

I would identify what data is submitted to the tool, whether prompts or outputs are retained or used for training, the vendor’s access controls, and applicable legal or privacy requirements. For generated code, I would require normal peer review and automated security testing, establish safe-use guidance, restrict sensitive data in prompts, and monitor adoption and recurring issue patterns.

Give an example of communicating a security risk to a nontechnical stakeholder who wants to ship quickly.

I would describe the issue in terms of customer and business impact, likelihood, and available choices rather than technical jargon. I would present a recommended path, explain what can be safely released now versus what requires remediation, and document the decision, owner, and follow-up date if a time-bound risk acceptance is necessary.

About Karbon

Karbon is the global leader in AI-powered practice management software for accounting firms. We provide an award-winning cloud platform that helps tens of thousands of accounting professionals work more efficiently and collaboratively every day. With customers in 40 countries, we have grown into a globally distributed team across the US, Australia, New Zealand, Canada, the United Kingdom, and the Philippines. We are well-funded, ranked #1 on G2, growing rapidly, and have a people-first culture that is recognized with Great Place To Work® certification and on Fortune magazine’s Best Small Workplaces™ List.

### AppSec Engineer

Our Engineering Standards at Karbon:

Balance Speed and Quality

Engineers are expected to balance delivery speed with a strong commitment to quality, meeting agreed timelines while producing reliable, maintainable, and well-tested solutions. Sound judgment in making trade-offs between velocity and long-term sustainability is essential.

Collaborate Effectively

Engineering is collaborative by default. Team members are expected to contribute constructively in design discussions, reviews, and planning, communicate clearly about progress and risks, and support shared team outcomes in both hybrid and distributed environments.

Build and Maintain Systems

Engineers are responsible for building new capabilities while maintaining and improving existing systems. This includes designing scalable solutions, reducing technical debt, supporting operational stability, and contributing to continuous improvement.

Operate with Autonomy

A high degree of autonomy is expected. Given clear objectives, engineers should independently translate problems into actionable technical approaches, proactively identify improvements, and continuously expand relevant technical expertise.

Ownership and Accountability

Ownership is fundamental. Engineers are accountable for the quality, performance, and customer impact of their work from design through post-release support, and are expected to follow through on commitments.

AI-Enabled Engineering

AI is reshaping how software is built, and we are committed to leveraging it as a force multiplier for creativity, impact, and capability. Engineers are expected to confidently apply strong technical fundamentals while embracing AI tools and approaches to enhance productivity, problem-solving, and innovation. Curiosity, adaptability, and enthusiasm for integrating AI into meaningful product development are essential.

Contribute to Team Culture

Engineers contribute positively to a culture of professionalism, transparency, low bureaucracy, and mutual respect, strengthening team performance through authenticity, curiosity, and collaboration.

### About the Role!

Seeking a development & cloud focused AppSec Engineer to join our expanding security team.

The ideal candidate will have passion for AppSec, Cloud and AI. They will be a skilled communicator and relationship builder capable of promoting and building security practices across the organization and into our development processes.

AI is reshaping practices across the board and at Karbon we’re fully committed. We don’t see AI as a replacement but as a force multiplier. We’re looking for Security Engineers who are confident in network & security fundamentals, driven to grow, and excited by the challenges and opportunities AI brings.

What You’ll Own:

* Partner with different areas within Karbon – You will make sure security is embedded from the start from feature design and development to participating in design reviews and threat modelling.
* Balance Security and Delivery – You know how to balance delivery needs with security and can communicate security risks and issues to non technical stakeholders. You understand when it’s important to push back, when to compromise and how to work with delivery teams to reach a great outcome.
* You keep up to date on the latest technologies and approaches – You are excited by the new developments such as AI bring to security but also understand the importance of security foundational practices such as good account hygiene, least privilege, attack surface reduction and MFA.
* Identify and assess security risks introduced by AI tools – You’ll assist with reviewing the risks of AI tooling usage & Integration and AI-generated code.
* Apply AI-assisted tooling to accelerate security work – you understand the impact AI can have and utilize it across many areas including triage, threat detection, code review, and documentation.
* Flexibility and confidence to work across multiple security domains – We’re a small team responsible for Security at a fast moving company and you’ll get exposure to many different security domains; you could be assisting with refining and investigating corporate IT security processes in the morning, reviewing a cloud hosted system after lunch and then tweaking detection rules!
* Work effectively as part of a team – Security is a team sport and you understand the need to build relationships and trust across the organization to enhance Karbon’s security posture. You are happy to answer questions and offer advice to teams that will reach out for your assistance.
* Own your work – You take pride in your work, feeling a deep sense of responsibility for the products we develop and ensuring we keep our customers’ valuable data secure. This sense of ownership is paramount, and you share this commitment.
* Bring your passion and personality – Your creativity, curiosity, and authentic self make the team stronger. If you’ve worked in highly political environments, you’ll find our culture, free from office politics and valuing openness and authenticity, a refreshing change.
* Help us measure improvement and steer our roadmap – Contribute to Security Metrics so we can track progress and feedback into our roadmap.

### What Sets You Apart

4+ years experience in a security or development role across most of the following:

* Collaborating with teams to review designs & implementations for security issues and embedding good security practices across software development
* Triaging issues and reports, assisting teams to remedy items and testing fixes
* Working with external penetration test companies to validate and prioritize findings
* Conducting risk and vulnerability assessments of web applications and APIs and third party suppliers and integrations
* Configuring and tuning SAST, SCA and DAST Tooling
* Working with build/deployment pipelines to incorporate security tooling (Github Actions or Azure Devops YAML based pipelines)
* Assisting with implementing security focused alerting and detections and automations
* Conducting and facilitating organizational & developer focused security training
* Assisting with operational security items such as EDR alerts and MDM
* Contributing to our security roadmap

In addition you’ll need:

* Strong communication skills (spoken and written)
* Some of the following Languages/Frameworks: Microsoft .NET/C#, JavaScript (we use React and EmberJS frameworks and, Python)
* At least one cloud platform: Azure, AWS or GCP (we use Azure predominantly)
* Working knowledge of PowerShell or Bash and Python
* Working knowledge of at least one AI development tool e.g. Claude Code, GitHub Co-Pilot etc
* Portswigger Burp or similar
* Certifications such as Offsec OSCP & AWAE, GIAC, Burp Practitioner, PJPT, Microsoft/AWS development and cloud related are nice to have
* Experience with securing AI applications, systems and AI tooling would be highly regarded

Why Work at Karbon?

* Gain global experience across Australia, New Zealand, UK, and Canada
* Strong benefits package including:

* Flexible Time Off with an encouraged 4 weeks use per year
* Company paid medical for you and eligible spouse/partner and dependents
* Paid dental and vision and eligible spouse/partner and dependents
* 401(k) with company matching
* Flexible Spending Account
* Up to 8 weeks paid parental leave
* Work-from-home stipend

* Work with (and learn from) an experienced, high-performing team
* A collaborative, team-oriented culture that embraces diversity, invests in development and provides consistent feedback
* Be part of a fast-growing company that firmly believes in promoting high performers from within

As we hire across various locations within the USA we are required by law to include a reasonable estimate of the compensation range for this role.

The range provided is broad and takes into consideration a wide range of factors that are reviewed when making a hiring decision, such as physical location/cost of living in that location, years of experience, skills, and other business needs.

It is not typical for a candidate to be hired at or near the top of the pay range and each compensation decision is dependent on each individual case. The base salary is one component of the total compensation package, which for some roles may include a target bonus, for some roles very competitive equity grant, and very generous benefits. While we believe competitive compensation is a critical aspect of you deciding to join us, we do hope you also spend time considering why our mission, purpose and values are right for you. We are creating something transformational here, and we hope you are as excited about the future as we are!

The estimated base salary range for this role is:

$131,000—$169,000 USD

Please be aware that Karbon will only contact you via email from our domain, karbonhq.com. If you receive an email from any other domain, please do not click any of those links.

Karbon embraces diversity and inclusion, aligning with our values as a business. Research has shown that women and underrepresented groups are less likely to apply to jobs unless they meet every single criteria. If you’ve made it this far in the job description but your past experience doesn’t perfectly align, we do encourage you to still apply. You could still be the right person for the role!

We recruit and reward people based on capability and performance. We don’t discriminate based on race, gender, sexual orientation, gender identity or expression, lifestyle, age, educational background, national origin, religion, physical or cognitive ability, and other diversity dimensions that may hinder inclusion in the organization.

Generally, if you are a good person, we want to talk to you. 😛

If there are any adjustments or accommodations that we can make to assist you during the recruitment process, and your journey at Karbon, contact us at people.support@karbonhq.com for a confidential discussion.

At this time, we request that agency referrals are not submitted for this position. We appreciate your understanding and encourage direct applications from interested candidates. Thank you!

Show more

[Apply now >](https://jobicy.com/jobs/152273-appsec-engineer.md)

*

![Upload CV](data:image/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHdpZHRoPSI2NSIgaGVpZ2h0PSI2NSIgZmlsbD0ibm9uZSIgeG1sbnM6dj0iaHR0cHM6Ly92ZWN0YS5pby9uYW5vIj48ZyBjbGlwLXBhdGg9InVybCgjQSkiPjxwYXRoIGQ9Ik0wIDBINjVWNjVIMFYwWiIgZmlsbD0iIzAyOWFlYiIvPjxnIGZpbGw9IiNmZmYiIHN0cm9rZT0iI2ZmZiIgc3Ryb2tlLXdpZHRoPSIyIj48cGF0aCBkPSJNMzMuMDQ5IDE1LjQ1NGExLjQzIDEuNDMgMCAwIDAtMi4wOTcgMGwtNy41NzkgOC4xNDdhMS4zOCAxLjM4IDAgMCAwIC4wOSAxLjk3MyAxLjQ0IDEuNDQgMCAwIDAgMi4wMDgtLjA4OGw1LjEwOS01LjQ5MnYyMC42MWExLjQxIDEuNDEgMCAwIDAgMS40MjEgMS4zOTdjLjc4NSAwIDEuNDIxLS42MjUgMS40MjEtMS4zOTd2LTIwLjYxbDUuMTA5IDUuNDkyYTEuNDQgMS40NCAwIDAgMCAyLjAwOC4wODggMS4zOCAxLjM4IDAgMCAwIC4wOS0xLjk3M2wtNy41NzktOC4xNDZ6TTE2Ljc2OSAzOC40YzAtLjc3My0uNjItMS40LTEuMzg1LTEuNFMxNCAzNy42MjcgMTQgMzguNHYuMTAybC4yMTUgNi4yMjljLjIyMyAxLjY4LjcwMSAzLjA5NSAxLjgxMyA0LjIxOHMyLjUxIDEuNjA3IDQuMTcyIDEuODMzYzEuNi4yMTggMy42MzYuMjE4IDYuMTYuMjE4aDExLjI4bDYuMTYtLjIxOGMxLjY2Mi0uMjI2IDMuMDYxLS43MDkgNC4xNzItMS44MzNzMS41ODktMi41MzggMS44MTMtNC4yMThDNTAgNDMuMTEzIDUwIDQxLjA1NSA1MCAzOC41MDNWMzguNGMwLS43NzMtLjYyLTEuNC0xLjM4NS0xLjRzLTEuMzg1LjYyNy0xLjM4NSAxLjRsLS4xOSA1Ljk1OGMtLjE4MiAxLjM3LS41MTUgMi4wOTUtMS4wMjYgMi42MTJzLTEuMjI4Ljg1My0yLjU4MyAxLjAzOGMtMS4zOTUuMTktMy4yNDMuMTkzLTUuODkzLjE5M0gyNi40NjJjLTIuNjUgMC00LjQ5OC0uMDAzLTUuODkzLS4xOTMtMS4zNTUtLjE4NC0yLjA3Mi0uNTIxLTIuNTgzLTEuMDM4cy0uODQ0LTEuMjQyLTEuMDI2LTIuNjEyYy0uMTg3LTEuNDEtLjE5MS0zLjI3OS0uMTkxLTUuOTU4eiIvPjwvZz48L2c+PGRlZnM+PGNsaXBQYXRoIGlkPSJBIj48cGF0aCBmaWxsPSIjZmZmIiBkPSJNMCAwaDY1djY1SDB6Ii8+PC9jbGlwUGF0aD48L2RlZnM+PC9zdmc+)

### Upload your resume now

To unlock remote work opportunities and be discovered by global employers.

This job listing has been manually reviewed by the Jobicy Trust & Safety Team for compliance with our posting guidelines, including verification of the company's legitimacy, accuracy of job details, clarity of remote work policy, and absence of misleading or fraudulent content.

Next step

## Apply now.

Follow the employer’s application method and review Jobicy’s safety guidance before sharing personal information.

Keep exploring

## Related remote jobs.

Matched by job category10 related opportunities[Cybersecurity](https://jobicy.com/categories/cybersecurity.md) [Browse all jobs](https://jobicy.com/jobs.md)
*
![Karbon logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/06/13eaf3d2-221.png)
Karbon  Sep 1

### [Senior Security Engineer](https://jobicy.com/jobs/152293-senior-security-engineer-3.md)

About Karbon Karbon is the global leader in AI-powered practice management software for accounting firms. We provide an award-winning cloud platform that helps tens of thousands of accounting professionals work…

*
![Zscaler logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/08/b3234031-221.png)
Zscaler  Aug 31

### [Director, Specialist Sales Engineering – Data Security](https://jobicy.com/jobs/152257-director-specialist-sales-engineering-data-security.md)

About Zscaler Zscaler accelerates digital transformation to ensure our customers can be more agile, efficient, resilient, and secure. As an AI-forward enterprise, we are constantly pushing the envelope, leveraging the…

*
![Reddit logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2020/10/Reddit.jpg)
Reddit  Aug 31

### [Staff Product Security Engineer](https://jobicy.com/jobs/152256-staff-product-security-engineer.md)

Reddit is a community of communities. It’s built on shared interests, passion, and trust, and is home to the most open and authentic conversations on the internet. Every day, Reddit…

*
![SWORD Health logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/06/5dda1790-221.jpg)
SWORD Health  Aug 31

### [Senior Security Operations Engineer](https://jobicy.com/jobs/152254-senior-security-operations-engineer-2.md)

At Sword, we’re building AI to heal billions and unlock humanity’s full potential. In doing so, we’re pioneering AI Care, a fundamentally new approach to healthcare built for medical reasoning,…

*
![Apollo.io logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2022/01/f3c639242c4d1f4cb9c0730ac3842a72.jpeg)
Apollo.io  Aug 31

### [Senior Application Security Engineer](https://jobicy.com/jobs/152253-senior-application-security-engineer-2.md)

Apollo.io is the leading go-to-market solution for revenue teams, trusted by over 500,000 companies and millions of users globally, from rapidly growing startups to some of the world’s largest enterprises….

*
![Reddit logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2020/10/Reddit.jpg)
Reddit  Aug 31

### [Senior Security Engineer, AI Security](https://jobicy.com/jobs/152252-senior-security-engineer-ai-security.md)

Reddit is a community of communities. It’s built on shared interests, passion, and trust, and is home to the most open and authentic conversations on the internet. Every day, Reddit…

*
![Maven Clinic logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2026/07/c4b2d5ecf34b-221.webp)
Maven Clinic  Aug 31

### [Staff Software Engineer – Product Security](https://jobicy.com/jobs/152250-staff-software-engineer-product-security.md)

Maven Clinic is the world’s largest virtual clinic for women and families on a mission to make healthcare work for all of us. Through Maven Enterprise, the company partners with…

*
![SWORD Health logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/06/5dda1790-221.jpg)
SWORD Health  Aug 31

### [Security Operations Lead (SecOps)](https://jobicy.com/jobs/152249-security-operations-lead-secops.md)

At Sword, we’re building AI to heal billions and unlock humanity’s full potential. In doing so, we’re pioneering AI Care, a fundamentally new approach to healthcare built for medical reasoning,…

*
![Apollo.io logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2022/01/f3c639242c4d1f4cb9c0730ac3842a72.jpeg)
Apollo.io  Aug 31

### [Engineering Manager, Security Detection & Response](https://jobicy.com/jobs/152248-engineering-manager-security-detection-response.md)

Apollo.io is the leading go-to-market solution for revenue teams, trusted by over 500,000 companies and millions of users globally, from rapidly growing startups to some of the world’s largest enterprises….

*
![YipitData logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/06/e1bee9df-221.jpg)
YipitData  Aug 31

### [Product Security Engineer](https://jobicy.com/jobs/152175-product-security-engineer.md)

About Us: YipitData is the leading market research and analytics firm for the disruptive economy and most recently raised $475M from The Carlyle Group at a valuation of over $1B….