Senior Security Engineer - Cloud Platform
Security Engineer · Senior · Full Time
Opens Xero's application page
Role
What you'll do.
Senior Security Engineer at Xero's Cloud Platform Access team designs and operates identity and access controls across AWS, GCP, and Azure environments. This role combines hands-on technical leadership with deep platform security expertise to build automation-first guardrails that enable teams to ship securely without excessive privilege or long-lived credentials. You'll mentor engineers, architect secure-by-default controls, and drive infrastructure as code standards while fostering psychological safety and engineering excellence across cloud-native identity and access management systems.
Responsibilities
- Design and operate identity and access controls at scale: Architect and maintain cloud-native identity and access management systems across AWS, GCP, and Azure, implementing secure-by-default controls and establishing governance frameworks that prevent privilege escalation and eliminate long-lived credentials at scale.
- Conduct IAM security assessments and gap analysis: Audit current identity and access management setups across public cloud environments, identify security risks and vulnerabilities, and develop actionable remediation strategies to strengthen organizational access controls.
- Build and maintain reusable Terraform modules and policy frameworks: Design and evolve Infrastructure as Code patterns that standardize secure access controls, create self-service capabilities, and reduce manual IAM configuration while maintaining consistent security posture across cloud platforms.
- Implement Workload Identity Federation and bounded IAM: Close critical identity handover gaps by deploying Workload Identity Federation solutions, implementing bounded IAM principles, and establishing self-service identity tools that enable teams to manage access securely without excessive privilege.
- Mentor and develop team engineers: Provide technical leadership, code reviews, and knowledge transfer to team members; model modern engineering practices, foster psychological safety, and help lift engineering standards across identity and access management implementations.
- Establish KPI baselines and contribute to design reviews: Define measurable security metrics for IAM systems, participate in architectural design reviews, contribute to incident response and post-mortems, and drive continuous improvement through data-driven insights and operational excellence.
- Collaborate across platform, security, and product teams: Work cross-functionally with platform engineering, application security, and product teams to integrate identity controls early in the delivery lifecycle, enabling rapid and secure feature deployment while maintaining governance standards.
- Develop internal tooling and automation: Create and maintain automation scripts, internal tools, and operational dashboards that reduce toil in IAM management, improve visibility into identity controls, and enable self-service access management capabilities for engineering teams.
Qualifications
What we look for.
Technical
Multi-cloud identity and access management
Solid hands-on experience securing at least one major public cloud environment (AWS, GCP, or Azure) with demonstrated willingness to master the others. Deep understanding of cloud-native identity concepts including service principals, workload identities, federated authentication, and IAM policy engines.
Terraform and Infrastructure as Code
Advanced proficiency in Terraform with proven track record of designing and maintaining reusable modules that codify IAM controls, policy guardrails, and security patterns at scale. Experience with state management, module composition, and cross-cloud orchestration.
Scripting and automation
Strong proficiency in at least one scripting language such as Python, Go, or Bash. Demonstrated ability to automate repetitive security tasks, audit procedures, and compliance workflows while maintaining code quality and testability.
Cloud security and policy frameworks
Deep understanding of cloud security best practices, principle of least privilege, identity governance frameworks, policy as code approaches, and secure access patterns. Familiarity with threat modeling and risk assessment methodologies.
Software engineering foundations
Strong software engineering practices including version control, code review disciplines, testing strategies, CI/CD pipelines, monitoring and observability, and sustainable delivery practices applied to infrastructure and security automation.
Education
Bachelor's degree in Computer Science or related field
Formal education in computer science, software engineering, information security, or equivalent demonstrating foundational knowledge in systems design, security principles, and software development fundamentals.
Experience
Multi-cloud platform security operations
Proven experience operating identity and access management systems in cloud environments, managing IAM lifecycle events, troubleshooting authentication and authorization issues, and optimizing access controls for both security and developer experience.
Technical leadership and mentorship
Demonstrated ability to lead technical design conversations, make sound architectural trade-offs, mentor junior and mid-level engineers, and establish engineering standards that improve reliability, quality, and team capability.
Cross-functional collaboration in security
Experience working collaboratively with security, platform engineering, and product teams to integrate controls early in delivery processes, balance security requirements with developer velocity, and build trust across organizational boundaries.
Identity federation and workload identity
Hands-on experience implementing and managing identity federation solutions, workload identity mechanisms, service-to-service authentication, and eliminating long-lived credentials in production environments.
Skills
Required
AWS Identity and Access Management (IAM)
Expert-level proficiency with AWS IAM including roles, policies, permissions boundaries, temporary credentials, cross-account access, and AWS-native identity federation mechanisms.
Terraform
Advanced Terraform skills including module design, state management, policy as code, testing strategies, and operational excellence patterns for infrastructure security at scale.
Python or Go
Strong scripting capabilities in Python, Go, or similar language for building automation, security tooling, audit scripts, and operational utilities that enhance IAM management efficiency.
Cloud security architecture
Ability to design secure cloud architectures, implement defense-in-depth strategies, understand attack surfaces, and architect controls that prevent common cloud security misconfigurations.
Identity and Access Management (IAM)
Comprehensive understanding of identity governance, access control models, authentication mechanisms, authorization frameworks, and modern approaches to eliminating privilege and long-lived credentials.
Preferred
Google Cloud Platform (GCP) security and Workload Identity
Nice to haveHands-on experience with GCP IAM, service accounts, Workload Identity Federation, and cross-cloud identity bridging patterns that enable secure multi-cloud deployments.
Microsoft Azure identity management
Nice to havePractical experience securing Azure environments including Azure AD/Entra integration, managed identities, role-based access control, and cross-tenant identity scenarios.
Policy as Code and OPA/Rego
Nice to haveExperience with policy engines like Open Policy Agent (OPA) and Rego language for codifying security policies, compliance rules, and access control guardrails in declarative formats.
Kubernetes RBAC and workload identity
Nice to haveExperience with Kubernetes role-based access control, service accounts, OIDC provider integration, and cloud-native workload identity patterns for containerized environments.
Security compliance and audit frameworks
Nice to haveFamiliarity with compliance frameworks such as SOC 2, ISO 27001, or similar standards, and experience implementing controls that meet audit and regulatory requirements while maintaining developer agility.
AI and machine learning applications in security
Nice to haveCuriosity about thoughtful AI applications for accelerating engineering workflows, anomaly detection in access patterns, or automating security-related operational tasks with machine learning.
Tech stack
Languages
Frameworks
Databases
Tools
Other
Compensation
Pay and benefits.
Base·NZD 130,000 – 180,000
Equity·Stock options
Benefits
Hybrid work flexibility
Work from home with designated boost days in modern office spaces in Auckland or Wellington, allowing collaboration with local team members while maintaining flexibility and work-life balance.
Professional development and mentorship
Access to learning opportunities, technical mentorship, and career growth support as part of a high-performing platform security team dedicated to engineering excellence.
Psychological safety and inclusive culture
Work in an environment that values psychological safety, diverse perspectives, and blameless post-mortems, enabling teams to take calculated risks and learn from incidents without fear.
Cloud platform access and learning budget
Opportunity to gain hands-on experience with multiple cloud platforms (AWS, GCP, Azure) and invest in certifications and continuous learning in cloud security and identity technologies.
Impact and influence at scale
High-leverage work that directly influences organizational security posture and developer productivity, shaping secure access as a product rather than a process.
Cross-functional collaboration
Opportunity to work alongside platform engineers, security specialists, and product teams, building relationships and solving problems at the intersection of infrastructure and security.
Equity and ownership
Participation in company equity programs, aligning personal growth with organizational success as part of Xero's global scale-up journey in cloud accounting software.
Process
Interview steps.
- 01
Initial screening and skill assessment
Conversation with recruiter to understand your background in cloud security, multi-cloud experience, and alignment with the role's technical requirements around identity and access management.
- 02
Technical depth interview
Deep technical discussion with current team members covering AWS/GCP/Azure IAM design, Terraform module architecture, policy as code approaches, and your experience eliminating long-lived credentials at scale.
- 03
Infrastructure as Code design exercise
Collaborative technical exercise where you design Terraform modules or IAM policies to solve a real-world access control scenario, demonstrating automation-first thinking and security best practices.
- 04
Leadership and collaboration assessment
Conversation focused on technical leadership experience, mentoring capability, cross-functional collaboration, and how you approach building trust across security, platform, and product teams.
- 05
Team and culture fit discussion
Final round with team leadership to assess alignment with Xero's values around psychological safety, sustainable delivery, and collaborative problem-solving in cloud platform security.
Full posting
Original listing.
The role / impact
As a Senior Engineer in our Cloud Platform Access team, you'll design and operate identity and access controls at scale across AWS, GCP, and Azure. This is high-leverage platform security work where you'll shape secure access as a product rather than simply processing requests. You'll combine hands-on technical leadership with deep expertise to build guardrails that enable teams to ship quickly without creating excessive privilege or long-lived credentials.
You'll mentor engineers on the team, foster psychological safety, and role-model modern engineering practices. The work sits at the intersection of cloud infrastructure, security, developer experience, and automation - solving genuine problems that unlock productivity across the organisation.
The team / how they connect
The Cloud Platform Access team owns cloud-native identity, access management, and policy enforcement across our public cloud environments. We work collaboratively with platform, security, and product teams to integrate secure-by-default controls early in delivery. The team values psychological safety, thoughtful automation, and engineering excellence - we ship sustainably by removing toil and enabling others to succeed.
The team is currently working on
Understanding the services, risks, and gaps in our current IAM setup across AWS, GCP, and Azure Closing critical identity handover gaps and taking ownership of bounded IAM, Workload Identity Federation, or self-service improvements Establishing KPI baselines and contributing to design reviews, operations, and mentoring within the team Evolving reusable Terraform modules, policy frameworks, and internal tooling to standardise secure access patterns
Where and how you can work
This role can be based in Auckland or Wellington, offering a hybrid working model that balances local team presence with a global scope of work. You will have the flexibility to work from home while connecting with your colleagues in our modern office spaces during designated boost days.
Here are some of the things we are looking for
You bring solid experience securing at least one public cloud environment - AWS, GCP, or Azure - with genuine willingness to learn the others. You understand Identity and Infrastructure as Code fundamentals.
You've designed and maintained reusable Terraform modules and automation that codify IAM controls and policy guardrails at scale.
Strong software engineering foundations run through your work: you think automation-first, have proficiency in at least one scripting language like Python, and follow modern delivery practices.
You lead technical design conversations, make sound engineering trade-offs, and aren't afraid to mentor others. You can lift standards, improve reliability, and keep delivery quality high.
You approach problems collaboratively, building trust across security, platform, and product teams to enable rapid, secure delivery.
You're curious about thoughtful AI applications and open to exploring how it might accelerate engineering workflows or solve real problems for the team.
Apply even if your experience isn't a perfect match! At Xero, we hire based on your skills, passion, and the unique perspective you can bring to enhance our culture and team.
Redirects to Xero's application page.
Other roles
More at Xero.
Engineering Manager
Manager
Senior Search Engineer
Senior
Engineering Manager - Data
Manager
Senior Engineer
Senior
Senior Engineer
Senior