About the RoleThis is a foundational leadership role at Karbon.
As VP of IT & Security, you will own the following areas:
- Internal IT - Identity & Access, devices and configuration
- Security - Corporate & Application
- Governance, Risk & Compliance
- Enterprise incident response, business continuity, and disaster recovery
You are a player-coach. You'll set strategy and own the roadmap, but you're comfortable rolling up your sleeves, analyzing logs, writing and tweaking policies, configuring tools, running a vendor evaluation, or sitting in a SOC 2 evidence review.
You'll report directly to the CEO and work closely with Engineering, Finance, Legal, and the broader executive team.
You will lead, on day one, an existing small SecOps team that will report to you.
This role doesn't exist yet in its current form. You'll be building something meaningful from the ground up and leading the migration of our IT function from our MSP to an in-house team.
What You'll OwnInternal IT- Own the day-to-day running of Karbon's device fleet and internal systems.
- Establish and manage IT service delivery and support, including helpdesk operations, incident and problem management, and SLAs as we migrate away from our MSP to an internal function.
- Own identity and access management (Okta) including device provisioning and employee onboarding and offboarding.
- Manage endpoint management (MDM) and device policies across our global fleet of pc's and mac's.
- Build and manage vendor relationships, including contracts, renewals, and performance.
- Identify opportunities to optimize licence costs.
Security- Define, maintain, and champion Karbon's strategy, policies, and standards across the organisation.
- Own the internal security tooling stack including EDR, SIEM, email security.
- Lead the Application Security team.
- Develop and maintain Karbon's information security policies and risk management framework.
Governance, Risk and Compliance- Maintain Karbon's Risk Register and own Karbon's SOC 2 program end to end: audit readiness, control design, and auditor relationships, coordinating with internal teams and external partners as control owners for evidence collection.
- Serve as the internal subject matter expert on compliance requirements for customer, partner, and enterprise sales conversations.
Enterprise Incident Response, Business Continuity & Disaster Recovery- Own and maintain the incident response plan and playbooks
- Define incident severity, escalation paths, and communication protocols, coordinating legal, insurance, and regulatory notification obligations during significant events.
- Own business continuity plans and backup strategy.
What We're Looking ForExperience- 12+ years in IT and security with at least 5 years in a senior leadership role.
- Proven track record managing or building an internal IT function - experience having transitioned from an MSP model is a strong advantage.
- Hands-on operational & security experience and able to assist teams when required.
- Deep familiarity with compliance frameworks such as SOC 2.
- Experience in a B2B SaaS environment is strongly preferred.
Technologies- Identity & Access Management (Okta & Entra preferred)
- Mobile Device Management / Endpoint Management
- EDR solutions such as Jamf Protect & Microsoft Defender for Endpoint
- At least one major cloud platform either Azure, AWS or GCP
- Office Productivity Platform - Google Workspace (preferred) or O365
- Netskope Experience highly regarded
Skills and Approach- You can move between strategy and execution without losing momentum in either direction.
- Strong communicator able to translate technical concepts into business language for a CEO, board, or enterprise customer.
- Commercially aware - you understand how security and compliance decisions affect sales, customer trust, and product velocity.
- Comfortable with ambiguity and building in environments where process is still being defined.
- Collaborative by default, with the confidence to hold the line when it matters.
Why This Role, Why NowKarbon is at an inflection point. We're growing, our customer base includes some of the world's largest accounting firms, and enterprise trust is a competitive differentiator for us. This role exists because we're ready to own our IT and security function at the level our customers and our ambitions demand.
You'll have a seat at the table, real scope, and the support of a CEO who understands why this matters.
As we hire across various locations within the USA we are required by law to include a reasonable estimate of the compensation range for this role.
The range provided is broad and takes into consideration a wide range of factors that are reviewed when making a hiring decision, such as physical location/cost of living in that location, years of experience, skills, and other business needs.
It is not typical for a candidate to be hired at or near the top of the pay range and each compensation decision is dependent on each individual case. The base salary is one component of the total compensation package, which for some roles may include a target bonus, for some roles very competitive equity grant, and very generous benefits. While we believe competitive compensation is a critical aspect of you deciding to join us, we do hope you also spend time considering why our mission, purpose and values are right for you. We are creating something transformational here, and we hope you are as excited about the future as we are!
The estimated base salary range for this role is:
$220,000-$245,000 USD
Please be aware that Karbon will only contact you via email from our domain, karbonhq.com. If you receive an email from any other domain, please do not click any of those links.Karbon embraces diversity and inclusion, aligning with our values as a business. Research has shown that women and underrepresented groups are less likely to apply to jobs unless they meet every single criteria. If you've made it this far in the job description but your past experience doesn't perfectly align, we do encourage you to still apply. You could still be the right person for the role!