Logo for Xero

Senior Security Engineer - Cloud Platform

Role overview

Qualifications

  • Experience securing at least one public cloud environment (AWS, GCP, or Azure)
  • Understanding of Identity and Infrastructure as Code fundamentals
  • Experience designing and maintaining reusable Terraform modules and automation
  • Proficiency in at least one scripting language like Python

Responsibilities

  • Design and operate identity and access controls at scale across AWS, GCP, and Azure
  • Mentor engineers on the team and foster psychological safety
  • Establish KPI baselines and contribute to design reviews and operations
  • Evolve reusable Terraform modules, policy frameworks, and internal tooling

Key facts

Other skills

  • Collaboration
  • Mentorship

About the company

Xero logo

Xero

Accounting

Xero is a global small business platform with 3.5 million subscribers which includes a core accounting solution, payroll, workforce management, expenses and projects. Xero also has an extensive ecosystem of connected apps and connections to banks and other financial institutions helping small businesses access a range of solutions from within Xero’s open platform to help them run their business and manage their finances. For four consecutive years (2020-2023) Xero was included in the Bloomberg Gender-Equality Index. In 2021 and 2022, Xero was included in the Dow Jones Sustainability Index (DJSI), powered by the S&P Global Corporate Sustainability Assessment. Xero is a FIFA Women’s Football partner. Get support http://central.xero.com

Company details

IndustryAccounting
Company size1001 - 5000

Your match analysis

See how your profile stacks up against this role.

We compared the job requirements to your profile to show where you're strong and where you fall short.

Job description

The role / impact

As a Senior Engineer in our Cloud Platform Access team, you'll design and operate identity and access controls at scale across AWS, GCP, and Azure. This is high-leverage platform security work where you'll shape secure access as a product rather than simply processing requests. You'll combine hands-on technical leadership with deep expertise to build guardrails that enable teams to ship quickly without creating excessive privilege or long-lived credentials.

You'll mentor engineers on the team, foster psychological safety, and role-model modern engineering practices. The work sits at the intersection of cloud infrastructure, security, developer experience, and automation - solving genuine problems that unlock productivity across the organisation.

The team / how they connect

The Cloud Platform Access team owns cloud-native identity, access management, and policy enforcement across our public cloud environments. We work collaboratively with platform, security, and product teams to integrate secure-by-default controls early in delivery. The team values psychological safety, thoughtful automation, and engineering excellence - we ship sustainably by removing toil and enabling others to succeed.

The team is currently working on

Understanding the services, risks, and gaps in our current IAM setup across AWS, GCP, and Azure Closing critical identity handover gaps and taking ownership of bounded IAM, Workload Identity Federation, or self-service improvements Establishing KPI baselines and contributing to design reviews, operations, and mentoring within the team Evolving reusable Terraform modules, policy frameworks, and internal tooling to standardise secure access patterns

Where and how you can work

This role can be based in Auckland or Wellington, offering a hybrid working model that balances local team presence with a global scope of work. You will have the flexibility to work from home while connecting with your colleagues in our modern office spaces during designated boost days.

Here are some of the things we are looking for

  • You bring solid experience securing at least one public cloud environment - AWS, GCP, or Azure - with genuine willingness to learn the others. You understand Identity and Infrastructure as Code fundamentals.

  • You've designed and maintained reusable Terraform modules and automation that codify IAM controls and policy guardrails at scale.

  • Strong software engineering foundations run through your work: you think automation-first, have proficiency in at least one scripting language like Python, and follow modern delivery practices.

  • You lead technical design conversations, make sound engineering trade-offs, and aren't afraid to mentor others. You can lift standards, improve reliability, and keep delivery quality high.

  • You approach problems collaboratively, building trust across security, platform, and product teams to enable rapid, secure delivery.

  • You're curious about thoughtful AI applications and open to exploring how it might accelerate engineering workflows or solve real problems for the team.

Apply even if your experience isn't a perfect match! At Xero, we hire based on your skills, passion, and the unique perspective you can bring to enhance our culture and team.

Apply once. Then go straight to the hiring manager.

After you apply, unlock the direct contact details of the people who actually make the call. A quick follow-up makes you 5x more likely to land an interview.

MR

Marcus Rivera

Chief Revenue Officer

m.rivera@company.com
linkedin.com/in/marcusrivera
Unlocked after you apply
Β·

Cloud Security Engineer Related jobs

Other jobs at Xero

Premium

Reach out to the hiring manager directly.

Gain access to the contact details of the hiring managers who actually decide, and reach out to network with them directly. That, plus more when you upgrade:

  • Full match report with fit score and gaps
  • Career diagnostics on how recruiters read you
  • Curated company matches and warm intros
  • 48h early access to new roles

Cancel anytime.