You and the process

With a person
Anna, in-house recruiter
9 years hiring engineers
30 minutes with a real recruiter
They read your CV with you, on a call, and say where the offers are being lost.
Didn’t find what you were looking for? Tell us what to build
Be the first to open itNo views yet
Xero

Senior Security Engineer - Cloud Platform

  • Hybrid
  • 6+ years

Salary

Not stated

AI summary

For members

The whole posting in a few lines. Sign up to read it here and on every role you open.

Sign Up to Read

Description

As a Senior Engineer in our Cloud Platform Access team, you'll design and operate identity and access controls at scale across AWS, GCP, and Azure. This is high-leverage platform security work where you'll shape secure access as a product rather than simply processing requests. You'll combine hands-on technical leadership with deep expertise to build guardrails that enable teams to ship quickly without creating excessive privilege or long-lived credentials.

You'll mentor engineers on the team, foster psychological safety, and role-model modern engineering practices. The work sits at the intersection of cloud infrastructure, security, developer experience, and automation - solving genuine problems that unlock productivity across the organisation.

The team / how they connect

The Cloud Platform Access team owns cloud-native identity, access management, and policy enforcement across our public cloud environments. We work collaboratively with platform, security, and product teams to integrate secure-by-default controls early in delivery. The team values psychological safety, thoughtful automation, and engineering excellence - we ship sustainably by removing toil and enabling others to succeed.

The team is currently working on

Understanding the services, risks, and gaps in our current IAM setup across AWS, GCP, and Azure

Closing critical identity handover gaps and taking ownership of bounded IAM, Workload Identity Federation, or self-service improvements

Establishing KPI baselines and contributing to design reviews, operations, and mentoring within the team

Evolving reusable Terraform modules, policy frameworks, and internal tooling to standardise secure access patterns.

Where and how you can work

We support a flexible working model that empowers you to balance your professional and personal life. You will have the option to work in a hybrid capacity, combining the focus of remote work with the collaboration of our office spaces and team boost days to foster connection and alignment.

Here are some of the things we are looking for

You bring solid experience securing at least one public cloud environment - AWS, GCP, or Azure - with genuine willingness to learn the others. You understand Identity and Infrastructure as Code fundamentals.

You've designed and maintained reusable Terraform modules and automation that codify IAM controls and policy guardrails at scale.

Strong software engineering foundations run through your work: you think automation-first, have proficiency in at least one scripting language like Python, and follow modern delivery practices.

You lead technical design conversations, make sound engineering trade-offs, and aren't afraid to mentor others. You can lift standards, improve reliability, and keep delivery quality high.

You approach problems collaboratively, building trust across security, platform, and product teams to enable rapid, secure delivery.

You're curious about thoughtful AI applications and open to exploring how it might accelerate engineering workflows or solve real problems for the team.

Apply even if your experience isn't a perfect match! At Xero, we hire based on your skills, passion, and the unique perspective you can bring to enhance our culture and team.

Responsibilities

  • As a Senior Engineer in our Cloud Platform Access team, you'll design and operate identity and access controls at scale across AWS, GCP, and Azure. This is high-leverage platform security work where you'll shape secure access as a product rather than simply processing requests. You'll combine hands-on technical leadership with deep expertise to build guardrails that enable teams to ship quickly without creating excessive privilege or long-lived credentials.
  • You'll mentor engineers on the team, foster psychological safety, and role-model modern engineering practices. The work sits at the intersection of cloud infrastructure, security, developer experience, and automation - solving genuine problems that unlock productivity across the organisation.
  • The team / how they connect
  • The Cloud Platform Access team owns cloud-native identity, access management, and policy enforcement across our public cloud environments. We work collaboratively with platform, security, and product teams to integrate secure-by-default controls early in delivery. The team values psychological safety, thoughtful automation, and engineering excellence - we ship sustainably by removing toil and enabling others to succeed.
  • The team is currently working on
  • Understanding the services, risks, and gaps in our current IAM setup across AWS, GCP, and Azure
  • Closing critical identity handover gaps and taking ownership of bounded IAM, Workload Identity Federation, or self-service improvements
  • Establishing KPI baselines and contributing to design reviews, operations, and mentoring within the team
  • Evolving reusable Terraform modules, policy frameworks, and internal tooling to standardise secure access patterns.
  • Where and how you can work
  • We support a flexible working model that empowers you to balance your professional and personal life. You will have the option to work in a hybrid capacity, combining the focus of remote work with the collaboration of our office spaces and team boost days to foster connection and alignment.
  • Here are some of the things we are looking for
  • You bring solid experience securing at least one public cloud environment - AWS, GCP, or Azure - with genuine willingness to learn the others. You understand Identity and Infrastructure as Code fundamentals.
  • You've designed and maintained reusable Terraform modules and automation that codify IAM controls and policy guardrails at scale.
  • Strong software engineering foundations run through your work: you think automation-first, have proficiency in at least one scripting language like Python, and follow modern delivery practices.
  • You lead technical design conversations, make sound engineering trade-offs, and aren't afraid to mentor others. You can lift standards, improve reliability, and keep delivery quality high.
  • You approach problems collaboratively, building trust across security, platform, and product teams to enable rapid, secure delivery.
  • You're curious about thoughtful AI applications and open to exploring how it might accelerate engineering workflows or solve real problems for the team.
  • Apply even if your experience isn't a perfect match! At Xero, we hire based on your skills, passion, and the unique perspective you can bring to enhance our culture and team.

Where you’d work

Part of the week in the office

You can work from

  • Australia

About the company

Xero

Offices in Wellington, New Zealand, Melbourne, Australia, Auckland, New Zealand, Sydney, Australia

Also hiring in Vancouver, Canada, Brisbane, Australia, United States and 1 more place

2 of their 37 open roles are remote

Your chances

We've checked whether it's still hiring and how crowded it is.

  • 19 checks run
  • 0 red flags

Still hiring?

13 checks

No red flags

How crowded?

6 checks

No red flags

Fits Me

How well does this role fit you?

Answer a few questions or drop your CV, and every role gets a fit score with the reasons, this one first.

  • Your field
  • Level
  • Stack
  • Work model
  • Salary floor
  • Must-haves
Details12 facts · Role, Location, Compensation, Employment
Tech stack
  • Python
  • AWS
  • Terraform
  • Azure
Seniority
Senior
Type
Full-time
Specialty
Security
Region
Australia
Pay period
Annual
Show 6 more factsShow less

Role

Category
DevOps & Infrastructure
Specialty
Security
Seniority
Senior
Experience
6+ years
Tech stack
  • Python
  • AWS
  • Terraform
  • Azure

Location

Work model
Hybrid
Region
Australia
Offices
  • Wellington, New Zealand
  • Melbourne, Australia
  • Auckland, New Zealand
  • Sydney, Australia
Remote from
  • Australia

Compensation

Salary
Salary by agreement
Pay period
Annual

Employment

Type
Full-time

Something wrong with this vacancy?

Similar vacancies

  • Early Window: Be the first to open itNo views yetCloses in
    Company hidden

    Security Engineer, New Grad

    Salary by agreement

    • Office · Dublin
    • Junior
  • Early Window: Be the first to open itNo views yetCloses in
    Company hidden

    Senior Security Operations Analyst

    Salary by agreement

    • Hybrid · Wellington, Auckland
    • Senior
  • Early Window: Be the first to open itNo views yetCloses in
    Company hidden

    Platform Security Engineer

    £90,000 - 160,000 / year

    • Hybrid · London
    • Mid-Level
  • Early Window: Be the first to open itNo views yetCloses in
    Company hidden

    Security Engineer

    $275,000 - 345,000 / year

    • Office · London

Share this vacancy

What's wrong with it?

The employer never sees who reported.

Reason