# Associate Security Engineer
**Company:** [Xero](https://scaleengineer.com/companies/xero)
As an Associate Security Engineer at Xero's Security Defence team, you'll design, build and continuously improve detection and response capabilities for threat investigation. You'll work cross-functionally with Security Operations, Engineering, and Product teams to transform threat intelligence into practical security controls, while developing your engineering expertise through hands-on delivery, incident participation, and mentorship from experienced security professionals in a blameless learning culture.
**Role:** Security Engineer
**Seniority:** Junior
**Locations:** AU: Melbourne: (260 Burwood Rd)
**Salary:** 65000–85000 AUD
[Apply](https://jobs.ashbyhq.com/xero/c99201d7-541e-4b2a-9413-d9c4ec226b7b)
Canonical: https://scaleengineer.com/jobs/xero/associate-security-engineer
---
## Responsibilities

- Threat Detection and Investigation: Monitor, investigate, and respond to security alerts and suspected incidents with guidance from experienced engineers and analysts. Develop skills in alert triage, incident investigation methodologies, and threat classification while contributing to the detection engineering pipeline.
- Security Platform Development: Contribute to detection, monitoring, enrichment, and response workflows across SIEM, SOAR, EDR, cloud security platforms, and related services. Build and improve detection content, integration rules, custom dashboards, and alerting mechanisms that enhance the organization's security posture.
- Automation and Runbook Development: Develop runbooks, playbooks, and automations that reduce manual effort and speed up security response times. Create documentation and automation scripts that enable consistent incident response procedures across the Security Defence team.
- Threat Intelligence Integration: Expand threat-intelligence-led detection engineering and automation coverage across Xero's infrastructure. Translate threat intelligence research and security requirements into measurable detections and practical controls using established security engineering patterns.
- Cross-Functional Collaboration: Work alongside Security Operations, Security Response, Engineering, Product, Customer Experience, and Legal teams to turn security insights into actionable improvements. Participate in collaborative code reviews, pair programming sessions, and knowledge-sharing activities.

## Requirements

### education

- {"name":"Formal Education","description":"Bachelor's degree in Computer Science, Cybersecurity, Information Technology, or related discipline, or equivalent practical experience demonstrating technical competency in engineering and security domains."}
- {"name":"Security Certifications","description":"Certifications such as CompTIA Security+, CEH, or GIAC certifications are beneficial but not required. Demonstrated commitment to security engineering knowledge through formal training or practical experience."}

### technical

- {"name":"Security Platform Experience","description":"Hands-on experience with SIEM (Security Information and Event Management), SOAR (Security Orchestration, Automation and Response), EDR (Endpoint Detection and Response), or cloud security platforms. Familiarity with alert design, detection rules, and security event enrichment."}
- {"name":"Scripting and Automation","description":"Demonstrated hands-on experience scripting, debugging, and automating security processes. Comfort with languages like Python, Bash, or similar, or ability to quickly learn scripting patterns for security automation and integration development."}
- {"name":"Cloud Security Knowledge","description":"Understanding of cloud security principles and experience working with cloud platforms such as AWS, Azure, or Google Cloud. Knowledge of cloud-native security controls and detection methodologies in distributed environments."}
- {"name":"Security Fundamentals","description":"Solid understanding of cybersecurity concepts including threat detection, incident response workflows, and security event correlation. Familiarity with MITRE ATT&CK framework or similar threat intelligence frameworks."}
- {"name":"Linux and System Administration","description":"Comfortable working in Linux environments and understanding system-level logging, process execution, and network protocols relevant to security monitoring and detection engineering."}

### experience

- {"name":"Security or Engineering Background","description":"Experience working in an engineering, security, IT operations, or technology team delivering technical solutions. This could include roles in SOC (Security Operations Center), detection engineering, security operations, or similar positions."}
- {"name":"Detection and Monitoring","description":"Previous experience with security monitoring, alert management, or detection engineering. Familiarity with writing detection rules, analyzing security events, or contributing to security platform improvements."}
- {"name":"Incident Response Participation","description":"Exposure to incident response procedures, whether through SOC shift work, incident response team participation, or security engineering projects involving threat investigation and response automation."}

## Skills

### required

- {"name":"Security Event Analysis","description":"Ability to analyze security events, correlate indicators of compromise, and identify patterns indicative of malicious activity or security threats."}
- {"name":"Detection Engineering","description":"Competency in translating threat intelligence and security requirements into detection logic, alert rules, and monitoring queries across security platforms."}
- {"name":"Problem Solving and Debugging","description":"Strong analytical skills to troubleshoot security platform issues, debug automation workflows, and resolve detection gaps through systematic investigation."}
- {"name":"Communication and Documentation","description":"Clear written and verbal communication skills for documenting detection logic, sharing technical context with cross-functional teams, and explaining security findings to non-technical stakeholders."}
- {"name":"Python or Bash Scripting","description":"Foundational ability to write and understand scripts for automation, data processing, and integration development to support security detection and response workflows."}

### preferred

- {"name":"Playbook and Automation Development","description":"Experience creating security playbooks, SOAR automation workflows, or response procedures that orchestrate multi-tool interactions and reduce manual incident handling effort."}
- {"name":"MITRE ATT&CK Framework","description":"Familiarity with mapping detections and mitigations to MITRE ATT&CK techniques, developing threat-intelligence-led security controls aligned with known attack patterns."}
- {"name":"Cloud Security Architecture","description":"Understanding of cloud platform security features, identity and access management, data protection, and cloud-native threat models. Experience securing multi-cloud or hybrid environments."}
- {"name":"Security Tool Integration","description":"Experience integrating security tools via APIs, webhooks, or custom connectors. Comfort building small integrations between SIEM, SOAR, ticketing systems, and other security infrastructure components."}
- {"name":"Threat Intelligence Application","description":"Experience applying threat intelligence to security operations, incorporating indicators of compromise, adversary tactics, and industry-specific threat research into detection logic."}
- {"name":"AI-Assisted Security Development","description":"Familiarity with responsible use of AI-assisted coding tools, prompt engineering, and large language models for accelerating detection development and security automation tasks."}

## Tech stack

### tools

- {"name":"SIEM Systems","description":"Security Information and Event Management tools such as Splunk, Elastic Security, or Microsoft Sentinel for centralized log collection, correlation, and threat detection."}
- {"name":"EDR Solutions","description":"Endpoint Detection and Response platforms such as CrowdStrike, Microsoft Defender for Endpoint, or similar for endpoint security visibility and threat investigation."}
- {"name":"Cloud Security Tools","description":"Native and third-party security tools for AWS, Azure, or Google Cloud including CloudTrail logging, security posture assessment, and cloud workload protection platforms."}
- {"name":"Threat Intelligence Platforms","description":"Tools for consuming, correlating, and operationalizing threat intelligence data including IOC feeds, malware analysis platforms, and threat actor research."}
- {"name":"Ticketing and Communication","description":"Incident management systems like Jira, ServiceNow, or Slack for coordinating incident response, tracking security tasks, and communicating findings across teams."}
- {"name":"Git and Version Control","description":"Version control systems for managing detection rules, automation scripts, runbooks, and security infrastructure code in collaborative environments."}

### others

- {"name":"Threat Intelligence Integration","description":"Ability to translate threat intelligence reports, indicators of compromise, and adversary behavior into actionable detection rules and security controls."}
- {"name":"Incident Response Procedures","description":"Familiarity with incident response workflows, containment strategies, evidence preservation, and post-incident analysis for learning and detection improvement."}
- {"name":"Security Best Practices","description":"Understanding of defense-in-depth principles, least privilege access, secure coding practices, and modern security architecture patterns."}
- {"name":"Blameless Post-Incident Review","description":"Participation in learning-oriented incident analysis focused on process improvement and systemic understanding rather than individual accountability."}

### databases

- {"name":"Security Data Lakes","description":"Centralized repositories for security event data, log aggregation, and forensic investigation data supporting detection engineering and threat hunting."}
- {"name":"Elasticsearch/OpenSearch","description":"Search and analytics engines commonly used in SIEM implementations for indexing, searching, and analyzing security event data at scale."}

### languages

- {"name":"Python","description":"Primary scripting language for security automation, data processing, and building integrations between security platforms and custom security tools."}
- {"name":"Bash","description":"Shell scripting for Linux automation, log processing, and system-level security monitoring tasks within cloud and on-premises infrastructure."}
- {"name":"SQL","description":"Query language for extracting, correlating, and analyzing security event data from SIEM systems and security data lakes."}

### frameworks

- {"name":"SOAR Platforms","description":"Security Orchestration, Automation and Response platforms like Splunk Phantom, Palo Alto Cortex XSOAR, or similar for building automated incident response workflows."}
- {"name":"Detection Engineering Frameworks","description":"Frameworks and methodologies for systematic detection rule development, threat hypothesis testing, and detection validation against attack patterns."}
- {"name":"Incident Response Frameworks","description":"Standardized incident response methodologies such as NIST Cybersecurity Framework or industry-standard IR processes for structured threat investigation."}

## Benefits

### benefits

- {"name":"Hybrid Work Flexibility","description":"Flexible hybrid working model based in Melbourne office with designated boost days for local team collaboration, balanced with work-from-home flexibility for global scope work."}
- {"name":"Learning and Development","description":"Continuous learning opportunities through hands-on delivery, pair programming sessions, incident participation, and mentorship from experienced security engineers in a blameless culture."}
- {"name":"Cross-Functional Collaboration","description":"Work alongside diverse teams including Security Operations, Security Response, Engineering, Product, Customer Experience, and Legal to develop holistic security capabilities."}
- {"name":"High-Trust Culture","description":"Blameless, learning-oriented team culture where curiosity, questions, and collaborative problem-solving are actively encouraged and valued."}
- {"name":"Impact and Ownership","description":"Direct contribution to designing and improving threat detection and response capabilities that protect Xero's platform and customer data globally."}
- {"name":"Career Development","description":"Clear pathway to develop security engineering expertise through exposure to modern security tools, cloud platforms, detection engineering, and emerging security technologies."}

## Compensation

- **max:** 85000
- **min:** 65000
- **currency:** AUD
- **stockOptions:** true

## Interview process

### steps

- {"name":"Application Review and Screening","description":"Initial review of your application, CV, and cover letter to assess alignment with security engineering fundamentals, technical background, and demonstrated interest in detection engineering or security operations."}
- {"name":"Technical Phone Screening","description":"Conversation with a Security Defence team member to discuss your technical background, experience with security platforms, scripting capabilities, and approach to security problem-solving."}
- {"name":"Technical Interview","description":"Detailed technical discussion covering detection engineering concepts, scenario-based security incident analysis, scripting ability, and your approach to designing practical security controls from threat intelligence."}
- {"name":"Behavioral and Culture Fit Discussion","description":"Conversation focused on your collaboration style, approach to learning, communication skills, and alignment with Xero's values including 'Go Bold' and 'Go Together' principles."}
- {"name":"Team Meet and Greet","description":"Informal meeting with Security Defence team members to discuss team dynamics, working culture, and opportunities for mentorship and career growth in the security engineering domain."}
- {"name":"Offer Stage","description":"If selected, Xero will extend an offer with details on compensation, benefits, hybrid working arrangements, and onboarding process for joining the Security Defence team."}

## Full description
**The role and its impact**

As an Associate Security Engineer in our Security Defence team, you'll help design, build and continuously improve the capabilities we rely on to detect, investigate and respond to security threats. You'll work alongside Security Operations, Security Response, Engineering, Product, CX and Legal, turning threat intelligence and security requirements into practical, reliable controls that keep Xero and our customers safe.

You’ll develop your engineering capability through delivery, pairing, incident participation, and learning from more experienced engineers while contributing to the protection of Xero and our customers.

**The team and how they connect**

Security Defence sits at the heart of how Xero detects and responds to threats, working across SIEM, SOAR, EDR and cloud security tooling to keep our platform and customers protected. The team works closely with Security Operations, Security Response, Engineering and Product to turn insight into action, and prides itself on a high-trust, blameless, learning-oriented culture where questions and curiosity are always welcome.

**The team is currently working on / Initially, you will focus on**

* Monitoring, investigating, and responding to security alerts and suspected incidents with guidance from experienced engineers and analysts.
* Contribute to detection, monitoring, enrichment, and response workflows across security platforms such as SIEM, SOAR, EDR, cloud security, and related services.
* Building and improving detection content, integrations, dashboards and alerting across our security platforms
* Developing runbooks, playbooks and automations that reduce manual effort and speed up response
* Expanding threat-intelligence-led detection engineering and automation coverage across Xero

**Where and how you can work**

This role is based in our Melbourne office, offering a hybrid working model that balances local team presence with a global scope of work. You will have the flexibility to work from home while connecting with your colleagues in our modern office space during designated boost days.

**Here are some of the things we're looking for**

* A growth mindset and real curiosity in security engineering, cyber security, software engineering, cloud security, detection engineering, or a closely related discipline.
* Comfortable picking up an unfamiliar codebase or platform and applying established patterns with guidance.
* You _Go Bold_ by turning threat intelligence and security research into practical, measurable detections and controls.
* Clear written and verbal communication, including sharing progress, blockers and context openly with your team.
* A collaborative approach, you enjoy pairing and feedback, and _Go Together_ by lifting the people around you.
* Hands-on experience scripting, debugging, automating or building small integrations, along with an interest in using AI-assisted tools responsibly.
* Experience working in an engineering, security, IT, operations, or technology team and collaborating with others to deliver change.

Apply even if your experience isn't a perfect match! At Xero, we hire based on your skills, passion, and the unique perspective you can bring to enhance our culture and team.
