Associate Security Engineer
Security Engineer · Junior · Full Time
Opens Xero's application page
Role
What you'll do.
As an Associate Security Engineer at Xero's Security Defence team, you'll design, build and continuously improve detection and response capabilities for threat investigation. You'll work cross-functionally with Security Operations, Engineering, and Product teams to transform threat intelligence into practical security controls, while developing your engineering expertise through hands-on delivery, incident participation, and mentorship from experienced security professionals in a blameless learning culture.
Responsibilities
- Threat Detection and Investigation: Monitor, investigate, and respond to security alerts and suspected incidents with guidance from experienced engineers and analysts. Develop skills in alert triage, incident investigation methodologies, and threat classification while contributing to the detection engineering pipeline.
- Security Platform Development: Contribute to detection, monitoring, enrichment, and response workflows across SIEM, SOAR, EDR, cloud security platforms, and related services. Build and improve detection content, integration rules, custom dashboards, and alerting mechanisms that enhance the organization's security posture.
- Automation and Runbook Development: Develop runbooks, playbooks, and automations that reduce manual effort and speed up security response times. Create documentation and automation scripts that enable consistent incident response procedures across the Security Defence team.
- Threat Intelligence Integration: Expand threat-intelligence-led detection engineering and automation coverage across Xero's infrastructure. Translate threat intelligence research and security requirements into measurable detections and practical controls using established security engineering patterns.
- Cross-Functional Collaboration: Work alongside Security Operations, Security Response, Engineering, Product, Customer Experience, and Legal teams to turn security insights into actionable improvements. Participate in collaborative code reviews, pair programming sessions, and knowledge-sharing activities.
Qualifications
What we look for.
Technical
Security Platform Experience
Hands-on experience with SIEM (Security Information and Event Management), SOAR (Security Orchestration, Automation and Response), EDR (Endpoint Detection and Response), or cloud security platforms. Familiarity with alert design, detection rules, and security event enrichment.
Scripting and Automation
Demonstrated hands-on experience scripting, debugging, and automating security processes. Comfort with languages like Python, Bash, or similar, or ability to quickly learn scripting patterns for security automation and integration development.
Cloud Security Knowledge
Understanding of cloud security principles and experience working with cloud platforms such as AWS, Azure, or Google Cloud. Knowledge of cloud-native security controls and detection methodologies in distributed environments.
Security Fundamentals
Solid understanding of cybersecurity concepts including threat detection, incident response workflows, and security event correlation. Familiarity with MITRE ATT&CK framework or similar threat intelligence frameworks.
Linux and System Administration
Comfortable working in Linux environments and understanding system-level logging, process execution, and network protocols relevant to security monitoring and detection engineering.
Education
Formal Education
Bachelor's degree in Computer Science, Cybersecurity, Information Technology, or related discipline, or equivalent practical experience demonstrating technical competency in engineering and security domains.
Security Certifications
Certifications such as CompTIA Security+, CEH, or GIAC certifications are beneficial but not required. Demonstrated commitment to security engineering knowledge through formal training or practical experience.
Experience
Security or Engineering Background
Experience working in an engineering, security, IT operations, or technology team delivering technical solutions. This could include roles in SOC (Security Operations Center), detection engineering, security operations, or similar positions.
Detection and Monitoring
Previous experience with security monitoring, alert management, or detection engineering. Familiarity with writing detection rules, analyzing security events, or contributing to security platform improvements.
Incident Response Participation
Exposure to incident response procedures, whether through SOC shift work, incident response team participation, or security engineering projects involving threat investigation and response automation.
Skills
Required
Security Event Analysis
Ability to analyze security events, correlate indicators of compromise, and identify patterns indicative of malicious activity or security threats.
Detection Engineering
Competency in translating threat intelligence and security requirements into detection logic, alert rules, and monitoring queries across security platforms.
Problem Solving and Debugging
Strong analytical skills to troubleshoot security platform issues, debug automation workflows, and resolve detection gaps through systematic investigation.
Communication and Documentation
Clear written and verbal communication skills for documenting detection logic, sharing technical context with cross-functional teams, and explaining security findings to non-technical stakeholders.
Python or Bash Scripting
Foundational ability to write and understand scripts for automation, data processing, and integration development to support security detection and response workflows.
Preferred
Playbook and Automation Development
Nice to haveExperience creating security playbooks, SOAR automation workflows, or response procedures that orchestrate multi-tool interactions and reduce manual incident handling effort.
MITRE ATT&CK Framework
Nice to haveFamiliarity with mapping detections and mitigations to MITRE ATT&CK techniques, developing threat-intelligence-led security controls aligned with known attack patterns.
Cloud Security Architecture
Nice to haveUnderstanding of cloud platform security features, identity and access management, data protection, and cloud-native threat models. Experience securing multi-cloud or hybrid environments.
Security Tool Integration
Nice to haveExperience integrating security tools via APIs, webhooks, or custom connectors. Comfort building small integrations between SIEM, SOAR, ticketing systems, and other security infrastructure components.
Threat Intelligence Application
Nice to haveExperience applying threat intelligence to security operations, incorporating indicators of compromise, adversary tactics, and industry-specific threat research into detection logic.
AI-Assisted Security Development
Nice to haveFamiliarity with responsible use of AI-assisted coding tools, prompt engineering, and large language models for accelerating detection development and security automation tasks.
Tech stack
Languages
Frameworks
Databases
Tools
Other
Compensation
Pay and benefits.
Base·AUD 65,000 – 85,000
Equity·Stock options
Benefits
Hybrid Work Flexibility
Flexible hybrid working model based in Melbourne office with designated boost days for local team collaboration, balanced with work-from-home flexibility for global scope work.
Learning and Development
Continuous learning opportunities through hands-on delivery, pair programming sessions, incident participation, and mentorship from experienced security engineers in a blameless culture.
Cross-Functional Collaboration
Work alongside diverse teams including Security Operations, Security Response, Engineering, Product, Customer Experience, and Legal to develop holistic security capabilities.
High-Trust Culture
Blameless, learning-oriented team culture where curiosity, questions, and collaborative problem-solving are actively encouraged and valued.
Impact and Ownership
Direct contribution to designing and improving threat detection and response capabilities that protect Xero's platform and customer data globally.
Career Development
Clear pathway to develop security engineering expertise through exposure to modern security tools, cloud platforms, detection engineering, and emerging security technologies.
Process
Interview steps.
- 01
Application Review and Screening
Initial review of your application, CV, and cover letter to assess alignment with security engineering fundamentals, technical background, and demonstrated interest in detection engineering or security operations.
- 02
Technical Phone Screening
Conversation with a Security Defence team member to discuss your technical background, experience with security platforms, scripting capabilities, and approach to security problem-solving.
- 03
Technical Interview
Detailed technical discussion covering detection engineering concepts, scenario-based security incident analysis, scripting ability, and your approach to designing practical security controls from threat intelligence.
- 04
Behavioral and Culture Fit Discussion
Conversation focused on your collaboration style, approach to learning, communication skills, and alignment with Xero's values including 'Go Bold' and 'Go Together' principles.
- 05
Team Meet and Greet
Informal meeting with Security Defence team members to discuss team dynamics, working culture, and opportunities for mentorship and career growth in the security engineering domain.
- 06
Offer Stage
If selected, Xero will extend an offer with details on compensation, benefits, hybrid working arrangements, and onboarding process for joining the Security Defence team.
Full posting
Original listing.
The role and its impact
As an Associate Security Engineer in our Security Defence team, you'll help design, build and continuously improve the capabilities we rely on to detect, investigate and respond to security threats. You'll work alongside Security Operations, Security Response, Engineering, Product, CX and Legal, turning threat intelligence and security requirements into practical, reliable controls that keep Xero and our customers safe.
You’ll develop your engineering capability through delivery, pairing, incident participation, and learning from more experienced engineers while contributing to the protection of Xero and our customers.
The team and how they connect
Security Defence sits at the heart of how Xero detects and responds to threats, working across SIEM, SOAR, EDR and cloud security tooling to keep our platform and customers protected. The team works closely with Security Operations, Security Response, Engineering and Product to turn insight into action, and prides itself on a high-trust, blameless, learning-oriented culture where questions and curiosity are always welcome.
The team is currently working on / Initially, you will focus on
Monitoring, investigating, and responding to security alerts and suspected incidents with guidance from experienced engineers and analysts.
Contribute to detection, monitoring, enrichment, and response workflows across security platforms such as SIEM, SOAR, EDR, cloud security, and related services.
Building and improving detection content, integrations, dashboards and alerting across our security platforms
Developing runbooks, playbooks and automations that reduce manual effort and speed up response
Expanding threat-intelligence-led detection engineering and automation coverage across Xero
Where and how you can work
This role is based in our Melbourne office, offering a hybrid working model that balances local team presence with a global scope of work. You will have the flexibility to work from home while connecting with your colleagues in our modern office space during designated boost days.
Here are some of the things we're looking for
A growth mindset and real curiosity in security engineering, cyber security, software engineering, cloud security, detection engineering, or a closely related discipline.
Comfortable picking up an unfamiliar codebase or platform and applying established patterns with guidance.
You Go Bold by turning threat intelligence and security research into practical, measurable detections and controls.
Clear written and verbal communication, including sharing progress, blockers and context openly with your team.
A collaborative approach, you enjoy pairing and feedback, and Go Together by lifting the people around you.
Hands-on experience scripting, debugging, automating or building small integrations, along with an interest in using AI-assisted tools responsibly.
Experience working in an engineering, security, IT, operations, or technology team and collaborating with others to deliver change.
Apply even if your experience isn't a perfect match! At Xero, we hire based on your skills, passion, and the unique perspective you can bring to enhance our culture and team.
Redirects to Xero's application page.
Other roles
More at Xero.
Senior Mobile Engineer - React Native
Senior
Lead Engineer - AI Workflows
Lead
ENGINEERING MANAGER - SRE
Manager
Senior Security Engineer - Defence
Senior
Senior Security Engineer - Cloud Platform
Senior