Senior Security Engineer - Cloud Platform

Security Engineer · Senior · Full Time

NZ: Wellington: Xero One (19-23 Taranaki St)NZD 130k – 180k1d ago
Apply for this role

Opens Xero's application page

Role

What you'll do.

Senior Security Engineer at Xero's Cloud Platform Access team designs and operates identity and access controls across AWS, GCP, and Azure environments. This role combines hands-on technical leadership with deep platform security expertise to build automation-first guardrails that enable teams to ship securely without excessive privilege or long-lived credentials. You'll mentor engineers, architect secure-by-default controls, and drive infrastructure as code standards while fostering psychological safety and engineering excellence across cloud-native identity and access management systems.

Responsibilities

  • Design and operate identity and access controls at scale: Architect and maintain cloud-native identity and access management systems across AWS, GCP, and Azure, implementing secure-by-default controls and establishing governance frameworks that prevent privilege escalation and eliminate long-lived credentials at scale.
  • Conduct IAM security assessments and gap analysis: Audit current identity and access management setups across public cloud environments, identify security risks and vulnerabilities, and develop actionable remediation strategies to strengthen organizational access controls.
  • Build and maintain reusable Terraform modules and policy frameworks: Design and evolve Infrastructure as Code patterns that standardize secure access controls, create self-service capabilities, and reduce manual IAM configuration while maintaining consistent security posture across cloud platforms.
  • Implement Workload Identity Federation and bounded IAM: Close critical identity handover gaps by deploying Workload Identity Federation solutions, implementing bounded IAM principles, and establishing self-service identity tools that enable teams to manage access securely without excessive privilege.
  • Mentor and develop team engineers: Provide technical leadership, code reviews, and knowledge transfer to team members; model modern engineering practices, foster psychological safety, and help lift engineering standards across identity and access management implementations.
  • Establish KPI baselines and contribute to design reviews: Define measurable security metrics for IAM systems, participate in architectural design reviews, contribute to incident response and post-mortems, and drive continuous improvement through data-driven insights and operational excellence.
  • Collaborate across platform, security, and product teams: Work cross-functionally with platform engineering, application security, and product teams to integrate identity controls early in the delivery lifecycle, enabling rapid and secure feature deployment while maintaining governance standards.
  • Develop internal tooling and automation: Create and maintain automation scripts, internal tools, and operational dashboards that reduce toil in IAM management, improve visibility into identity controls, and enable self-service access management capabilities for engineering teams.

Qualifications

What we look for.

Technical

  • Multi-cloud identity and access management

    Solid hands-on experience securing at least one major public cloud environment (AWS, GCP, or Azure) with demonstrated willingness to master the others. Deep understanding of cloud-native identity concepts including service principals, workload identities, federated authentication, and IAM policy engines.

  • Terraform and Infrastructure as Code

    Advanced proficiency in Terraform with proven track record of designing and maintaining reusable modules that codify IAM controls, policy guardrails, and security patterns at scale. Experience with state management, module composition, and cross-cloud orchestration.

  • Scripting and automation

    Strong proficiency in at least one scripting language such as Python, Go, or Bash. Demonstrated ability to automate repetitive security tasks, audit procedures, and compliance workflows while maintaining code quality and testability.

  • Cloud security and policy frameworks

    Deep understanding of cloud security best practices, principle of least privilege, identity governance frameworks, policy as code approaches, and secure access patterns. Familiarity with threat modeling and risk assessment methodologies.

  • Software engineering foundations

    Strong software engineering practices including version control, code review disciplines, testing strategies, CI/CD pipelines, monitoring and observability, and sustainable delivery practices applied to infrastructure and security automation.

Education

  • Bachelor's degree in Computer Science or related field

    Formal education in computer science, software engineering, information security, or equivalent demonstrating foundational knowledge in systems design, security principles, and software development fundamentals.

Experience

  • Multi-cloud platform security operations

    Proven experience operating identity and access management systems in cloud environments, managing IAM lifecycle events, troubleshooting authentication and authorization issues, and optimizing access controls for both security and developer experience.

  • Technical leadership and mentorship

    Demonstrated ability to lead technical design conversations, make sound architectural trade-offs, mentor junior and mid-level engineers, and establish engineering standards that improve reliability, quality, and team capability.

  • Cross-functional collaboration in security

    Experience working collaboratively with security, platform engineering, and product teams to integrate controls early in delivery processes, balance security requirements with developer velocity, and build trust across organizational boundaries.

  • Identity federation and workload identity

    Hands-on experience implementing and managing identity federation solutions, workload identity mechanisms, service-to-service authentication, and eliminating long-lived credentials in production environments.

Skills

Required

  • AWS Identity and Access Management (IAM)

    Expert-level proficiency with AWS IAM including roles, policies, permissions boundaries, temporary credentials, cross-account access, and AWS-native identity federation mechanisms.

  • Terraform

    Advanced Terraform skills including module design, state management, policy as code, testing strategies, and operational excellence patterns for infrastructure security at scale.

  • Python or Go

    Strong scripting capabilities in Python, Go, or similar language for building automation, security tooling, audit scripts, and operational utilities that enhance IAM management efficiency.

  • Cloud security architecture

    Ability to design secure cloud architectures, implement defense-in-depth strategies, understand attack surfaces, and architect controls that prevent common cloud security misconfigurations.

  • Identity and Access Management (IAM)

    Comprehensive understanding of identity governance, access control models, authentication mechanisms, authorization frameworks, and modern approaches to eliminating privilege and long-lived credentials.

Preferred

  • Google Cloud Platform (GCP) security and Workload Identity

    Nice to have

    Hands-on experience with GCP IAM, service accounts, Workload Identity Federation, and cross-cloud identity bridging patterns that enable secure multi-cloud deployments.

  • Microsoft Azure identity management

    Nice to have

    Practical experience securing Azure environments including Azure AD/Entra integration, managed identities, role-based access control, and cross-tenant identity scenarios.

  • Policy as Code and OPA/Rego

    Nice to have

    Experience with policy engines like Open Policy Agent (OPA) and Rego language for codifying security policies, compliance rules, and access control guardrails in declarative formats.

  • Kubernetes RBAC and workload identity

    Nice to have

    Experience with Kubernetes role-based access control, service accounts, OIDC provider integration, and cloud-native workload identity patterns for containerized environments.

  • Security compliance and audit frameworks

    Nice to have

    Familiarity with compliance frameworks such as SOC 2, ISO 27001, or similar standards, and experience implementing controls that meet audit and regulatory requirements while maintaining developer agility.

  • AI and machine learning applications in security

    Nice to have

    Curiosity about thoughtful AI applications for accelerating engineering workflows, anomaly detection in access patterns, or automating security-related operational tasks with machine learning.

Tech stack

Languages

PythonGoBash/Shell

Frameworks

TerraformOpenID Connect (OIDC)Kubernetes RBAC

Databases

Cloud-native identity databases

Tools

AWS IAMGoogle Cloud IAM and Workload Identity FederationAzure AD/Entra and Managed IdentitiesTerraform Cloud or Terraform EnterpriseGit and version controlCI/CD platformsMonitoring and observability tools

Other

Cloud security best practicesDevOps and SRE practicesSecurity audit and complianceThreat modeling and risk assessment

Compensation

Pay and benefits.

Base·NZD 130,000 – 180,000

Equity·Stock options

Benefits

  • Hybrid work flexibility

    Work from home with designated boost days in modern office spaces in Auckland or Wellington, allowing collaboration with local team members while maintaining flexibility and work-life balance.

  • Professional development and mentorship

    Access to learning opportunities, technical mentorship, and career growth support as part of a high-performing platform security team dedicated to engineering excellence.

  • Psychological safety and inclusive culture

    Work in an environment that values psychological safety, diverse perspectives, and blameless post-mortems, enabling teams to take calculated risks and learn from incidents without fear.

  • Cloud platform access and learning budget

    Opportunity to gain hands-on experience with multiple cloud platforms (AWS, GCP, Azure) and invest in certifications and continuous learning in cloud security and identity technologies.

  • Impact and influence at scale

    High-leverage work that directly influences organizational security posture and developer productivity, shaping secure access as a product rather than a process.

  • Cross-functional collaboration

    Opportunity to work alongside platform engineers, security specialists, and product teams, building relationships and solving problems at the intersection of infrastructure and security.

  • Equity and ownership

    Participation in company equity programs, aligning personal growth with organizational success as part of Xero's global scale-up journey in cloud accounting software.

Process

Interview steps.

  1. 01

    Initial screening and skill assessment

    Conversation with recruiter to understand your background in cloud security, multi-cloud experience, and alignment with the role's technical requirements around identity and access management.

  2. 02

    Technical depth interview

    Deep technical discussion with current team members covering AWS/GCP/Azure IAM design, Terraform module architecture, policy as code approaches, and your experience eliminating long-lived credentials at scale.

  3. 03

    Infrastructure as Code design exercise

    Collaborative technical exercise where you design Terraform modules or IAM policies to solve a real-world access control scenario, demonstrating automation-first thinking and security best practices.

  4. 04

    Leadership and collaboration assessment

    Conversation focused on technical leadership experience, mentoring capability, cross-functional collaboration, and how you approach building trust across security, platform, and product teams.

  5. 05

    Team and culture fit discussion

    Final round with team leadership to assess alignment with Xero's values around psychological safety, sustainable delivery, and collaborative problem-solving in cloud platform security.

Full posting

Original listing.

The role / impact

As a Senior Engineer in our Cloud Platform Access team, you'll design and operate identity and access controls at scale across AWS, GCP, and Azure. This is high-leverage platform security work where you'll shape secure access as a product rather than simply processing requests. You'll combine hands-on technical leadership with deep expertise to build guardrails that enable teams to ship quickly without creating excessive privilege or long-lived credentials.

You'll mentor engineers on the team, foster psychological safety, and role-model modern engineering practices. The work sits at the intersection of cloud infrastructure, security, developer experience, and automation - solving genuine problems that unlock productivity across the organisation.

The team / how they connect

The Cloud Platform Access team owns cloud-native identity, access management, and policy enforcement across our public cloud environments. We work collaboratively with platform, security, and product teams to integrate secure-by-default controls early in delivery. The team values psychological safety, thoughtful automation, and engineering excellence - we ship sustainably by removing toil and enabling others to succeed.

The team is currently working on

Understanding the services, risks, and gaps in our current IAM setup across AWS, GCP, and Azure Closing critical identity handover gaps and taking ownership of bounded IAM, Workload Identity Federation, or self-service improvements Establishing KPI baselines and contributing to design reviews, operations, and mentoring within the team Evolving reusable Terraform modules, policy frameworks, and internal tooling to standardise secure access patterns

Where and how you can work

This role can be based in Auckland or Wellington, offering a hybrid working model that balances local team presence with a global scope of work. You will have the flexibility to work from home while connecting with your colleagues in our modern office spaces during designated boost days.

Here are some of the things we are looking for

  • You bring solid experience securing at least one public cloud environment - AWS, GCP, or Azure - with genuine willingness to learn the others. You understand Identity and Infrastructure as Code fundamentals.

  • You've designed and maintained reusable Terraform modules and automation that codify IAM controls and policy guardrails at scale.

  • Strong software engineering foundations run through your work: you think automation-first, have proficiency in at least one scripting language like Python, and follow modern delivery practices.

  • You lead technical design conversations, make sound engineering trade-offs, and aren't afraid to mentor others. You can lift standards, improve reliability, and keep delivery quality high.

  • You approach problems collaboratively, building trust across security, platform, and product teams to enable rapid, secure delivery.

  • You're curious about thoughtful AI applications and open to exploring how it might accelerate engineering workflows or solve real problems for the team.

Apply even if your experience isn't a perfect match! At Xero, we hire based on your skills, passion, and the unique perspective you can bring to enhance our culture and team.

Redirects to Xero's application page.

Other roles

More at Xero.

View all 32 roles