Associate Security Engineer

Security Engineer · Junior · Full Time

AU: Melbourne: (260 Burwood Rd)AUD 65k – 85k1w ago
Apply for this role

Opens Xero's application page

Role

What you'll do.

As an Associate Security Engineer at Xero's Security Defence team, you'll design, build and continuously improve detection and response capabilities for threat investigation. You'll work cross-functionally with Security Operations, Engineering, and Product teams to transform threat intelligence into practical security controls, while developing your engineering expertise through hands-on delivery, incident participation, and mentorship from experienced security professionals in a blameless learning culture.

Responsibilities

  • Threat Detection and Investigation: Monitor, investigate, and respond to security alerts and suspected incidents with guidance from experienced engineers and analysts. Develop skills in alert triage, incident investigation methodologies, and threat classification while contributing to the detection engineering pipeline.
  • Security Platform Development: Contribute to detection, monitoring, enrichment, and response workflows across SIEM, SOAR, EDR, cloud security platforms, and related services. Build and improve detection content, integration rules, custom dashboards, and alerting mechanisms that enhance the organization's security posture.
  • Automation and Runbook Development: Develop runbooks, playbooks, and automations that reduce manual effort and speed up security response times. Create documentation and automation scripts that enable consistent incident response procedures across the Security Defence team.
  • Threat Intelligence Integration: Expand threat-intelligence-led detection engineering and automation coverage across Xero's infrastructure. Translate threat intelligence research and security requirements into measurable detections and practical controls using established security engineering patterns.
  • Cross-Functional Collaboration: Work alongside Security Operations, Security Response, Engineering, Product, Customer Experience, and Legal teams to turn security insights into actionable improvements. Participate in collaborative code reviews, pair programming sessions, and knowledge-sharing activities.

Qualifications

What we look for.

Technical

  • Security Platform Experience

    Hands-on experience with SIEM (Security Information and Event Management), SOAR (Security Orchestration, Automation and Response), EDR (Endpoint Detection and Response), or cloud security platforms. Familiarity with alert design, detection rules, and security event enrichment.

  • Scripting and Automation

    Demonstrated hands-on experience scripting, debugging, and automating security processes. Comfort with languages like Python, Bash, or similar, or ability to quickly learn scripting patterns for security automation and integration development.

  • Cloud Security Knowledge

    Understanding of cloud security principles and experience working with cloud platforms such as AWS, Azure, or Google Cloud. Knowledge of cloud-native security controls and detection methodologies in distributed environments.

  • Security Fundamentals

    Solid understanding of cybersecurity concepts including threat detection, incident response workflows, and security event correlation. Familiarity with MITRE ATT&CK framework or similar threat intelligence frameworks.

  • Linux and System Administration

    Comfortable working in Linux environments and understanding system-level logging, process execution, and network protocols relevant to security monitoring and detection engineering.

Education

  • Formal Education

    Bachelor's degree in Computer Science, Cybersecurity, Information Technology, or related discipline, or equivalent practical experience demonstrating technical competency in engineering and security domains.

  • Security Certifications

    Certifications such as CompTIA Security+, CEH, or GIAC certifications are beneficial but not required. Demonstrated commitment to security engineering knowledge through formal training or practical experience.

Experience

  • Security or Engineering Background

    Experience working in an engineering, security, IT operations, or technology team delivering technical solutions. This could include roles in SOC (Security Operations Center), detection engineering, security operations, or similar positions.

  • Detection and Monitoring

    Previous experience with security monitoring, alert management, or detection engineering. Familiarity with writing detection rules, analyzing security events, or contributing to security platform improvements.

  • Incident Response Participation

    Exposure to incident response procedures, whether through SOC shift work, incident response team participation, or security engineering projects involving threat investigation and response automation.

Skills

Required

  • Security Event Analysis

    Ability to analyze security events, correlate indicators of compromise, and identify patterns indicative of malicious activity or security threats.

  • Detection Engineering

    Competency in translating threat intelligence and security requirements into detection logic, alert rules, and monitoring queries across security platforms.

  • Problem Solving and Debugging

    Strong analytical skills to troubleshoot security platform issues, debug automation workflows, and resolve detection gaps through systematic investigation.

  • Communication and Documentation

    Clear written and verbal communication skills for documenting detection logic, sharing technical context with cross-functional teams, and explaining security findings to non-technical stakeholders.

  • Python or Bash Scripting

    Foundational ability to write and understand scripts for automation, data processing, and integration development to support security detection and response workflows.

Preferred

  • Playbook and Automation Development

    Nice to have

    Experience creating security playbooks, SOAR automation workflows, or response procedures that orchestrate multi-tool interactions and reduce manual incident handling effort.

  • MITRE ATT&CK Framework

    Nice to have

    Familiarity with mapping detections and mitigations to MITRE ATT&CK techniques, developing threat-intelligence-led security controls aligned with known attack patterns.

  • Cloud Security Architecture

    Nice to have

    Understanding of cloud platform security features, identity and access management, data protection, and cloud-native threat models. Experience securing multi-cloud or hybrid environments.

  • Security Tool Integration

    Nice to have

    Experience integrating security tools via APIs, webhooks, or custom connectors. Comfort building small integrations between SIEM, SOAR, ticketing systems, and other security infrastructure components.

  • Threat Intelligence Application

    Nice to have

    Experience applying threat intelligence to security operations, incorporating indicators of compromise, adversary tactics, and industry-specific threat research into detection logic.

  • AI-Assisted Security Development

    Nice to have

    Familiarity with responsible use of AI-assisted coding tools, prompt engineering, and large language models for accelerating detection development and security automation tasks.

Tech stack

Languages

PythonBashSQL

Frameworks

SOAR PlatformsDetection Engineering FrameworksIncident Response Frameworks

Databases

Security Data LakesElasticsearch/OpenSearch

Tools

SIEM SystemsEDR SolutionsCloud Security ToolsThreat Intelligence PlatformsTicketing and CommunicationGit and Version Control

Other

Threat Intelligence IntegrationIncident Response ProceduresSecurity Best PracticesBlameless Post-Incident Review

Compensation

Pay and benefits.

Base·AUD 65,000 – 85,000

Equity·Stock options

Benefits

  • Hybrid Work Flexibility

    Flexible hybrid working model based in Melbourne office with designated boost days for local team collaboration, balanced with work-from-home flexibility for global scope work.

  • Learning and Development

    Continuous learning opportunities through hands-on delivery, pair programming sessions, incident participation, and mentorship from experienced security engineers in a blameless culture.

  • Cross-Functional Collaboration

    Work alongside diverse teams including Security Operations, Security Response, Engineering, Product, Customer Experience, and Legal to develop holistic security capabilities.

  • High-Trust Culture

    Blameless, learning-oriented team culture where curiosity, questions, and collaborative problem-solving are actively encouraged and valued.

  • Impact and Ownership

    Direct contribution to designing and improving threat detection and response capabilities that protect Xero's platform and customer data globally.

  • Career Development

    Clear pathway to develop security engineering expertise through exposure to modern security tools, cloud platforms, detection engineering, and emerging security technologies.

Process

Interview steps.

  1. 01

    Application Review and Screening

    Initial review of your application, CV, and cover letter to assess alignment with security engineering fundamentals, technical background, and demonstrated interest in detection engineering or security operations.

  2. 02

    Technical Phone Screening

    Conversation with a Security Defence team member to discuss your technical background, experience with security platforms, scripting capabilities, and approach to security problem-solving.

  3. 03

    Technical Interview

    Detailed technical discussion covering detection engineering concepts, scenario-based security incident analysis, scripting ability, and your approach to designing practical security controls from threat intelligence.

  4. 04

    Behavioral and Culture Fit Discussion

    Conversation focused on your collaboration style, approach to learning, communication skills, and alignment with Xero's values including 'Go Bold' and 'Go Together' principles.

  5. 05

    Team Meet and Greet

    Informal meeting with Security Defence team members to discuss team dynamics, working culture, and opportunities for mentorship and career growth in the security engineering domain.

  6. 06

    Offer Stage

    If selected, Xero will extend an offer with details on compensation, benefits, hybrid working arrangements, and onboarding process for joining the Security Defence team.

Full posting

Original listing.

The role and its impact

As an Associate Security Engineer in our Security Defence team, you'll help design, build and continuously improve the capabilities we rely on to detect, investigate and respond to security threats. You'll work alongside Security Operations, Security Response, Engineering, Product, CX and Legal, turning threat intelligence and security requirements into practical, reliable controls that keep Xero and our customers safe.

You’ll develop your engineering capability through delivery, pairing, incident participation, and learning from more experienced engineers while contributing to the protection of Xero and our customers.

The team and how they connect

Security Defence sits at the heart of how Xero detects and responds to threats, working across SIEM, SOAR, EDR and cloud security tooling to keep our platform and customers protected. The team works closely with Security Operations, Security Response, Engineering and Product to turn insight into action, and prides itself on a high-trust, blameless, learning-oriented culture where questions and curiosity are always welcome.

The team is currently working on / Initially, you will focus on

  • Monitoring, investigating, and responding to security alerts and suspected incidents with guidance from experienced engineers and analysts.

  • Contribute to detection, monitoring, enrichment, and response workflows across security platforms such as SIEM, SOAR, EDR, cloud security, and related services.

  • Building and improving detection content, integrations, dashboards and alerting across our security platforms

  • Developing runbooks, playbooks and automations that reduce manual effort and speed up response

  • Expanding threat-intelligence-led detection engineering and automation coverage across Xero

 

Where and how you can work

This role is based in our Melbourne office, offering a hybrid working model that balances local team presence with a global scope of work. You will have the flexibility to work from home while connecting with your colleagues in our modern office space during designated boost days.

Here are some of the things we're looking for

  • A growth mindset and real curiosity in security engineering, cyber security, software engineering, cloud security, detection engineering, or a closely related discipline.

  • Comfortable picking up an unfamiliar codebase or platform and applying established patterns with guidance.

  • You Go Bold by turning threat intelligence and security research into practical, measurable detections and controls.

  • Clear written and verbal communication, including sharing progress, blockers and context openly with your team.

  • A collaborative approach, you enjoy pairing and feedback, and Go Together by lifting the people around you.

  • Hands-on experience scripting, debugging, automating or building small integrations, along with an interest in using AI-assisted tools responsibly.

  • Experience working in an engineering, security, IT, operations, or technology team and collaborating with others to deliver change.

 

Apply even if your experience isn't a perfect match! At Xero, we hire based on your skills, passion, and the unique perspective you can bring to enhance our culture and team.

Redirects to Xero's application page.

Other roles

More at Xero.

View all 28 roles