Senior Security Engineer - Defence

Security Engineer · Senior · Full Time

NZ: Auckland: Xero 4 (96 St Georges Bay Rd, Level 2 & 3)NZD 130k – 170k1d ago
Apply for this role

Opens Xero's application page

Role

What you'll do.

Senior Security Engineer focused on threat detection and response at Xero, a leading cloud accounting platform. You'll design and operate security controls, detection capabilities, and automation to protect customers across SIEM, SOAR, EDR and cloud platforms. This role requires hands-on expertise in security engineering, cloud infrastructure (AWS), threat intelligence frameworks (MITRE ATT&CK), and scripting skills to influence security outcomes at scale.

Responsibilities

  • Design and Build Production Security Capabilities: Lead the design, development, and deployment of detection and response workflows across SIEM, SOAR, EDR, and cloud security platforms. Apply software engineering best practices to create reliable, scalable security controls that effectively protect Xero's customers and infrastructure.
  • Develop Security Automation and Orchestration: Engineer automation solutions using Python and security orchestration tools to reduce manual security operations toil and accelerate threat response timelines. Collaborate with Security Operations to identify manual processes that can be optimized through intelligent automation and AI-driven capabilities.
  • Measure and Improve Detection Coverage: Establish metrics and measurement frameworks to quantify detection coverage, control effectiveness, and operational reliability. Use data-driven insights to identify gaps in security monitoring and validate the impact of new detection rules and security controls.
  • Lead Complex Technical Initiatives: Champion complex security engineering projects across multiple teams including Security Operations, Security Response, Product Engineering, and Customer Experience. Influence technical outcomes through thought leadership and clear communication without relying on formal authority.
  • Translate Threat Intelligence into Controls: Partner with threat intelligence and security response teams to understand emerging threats and adversary behaviors. Transform threat intelligence findings into practical, measurable security controls using MITRE ATT&CK frameworks and threat modeling.
  • Contribute to Security Engineering Culture: Foster a culture of shared ownership, continuous learning, and constructive challenge within the Security Defence team and broader security organization. Mentor team members, share knowledge openly, and support colleagues through high-pressure operational moments.

Qualifications

What we look for.

Technical

  • Security Engineering and Detection Design

    Demonstrated hands-on experience designing, building, and operating production security capabilities, detection systems, or security services in enterprise environments. Strong understanding of detection methodologies, false positive tuning, and operational reliability.

  • SIEM and Security Orchestration Platforms

    Proven expertise with Security Information and Event Management (SIEM) systems, Security Orchestration Automation and Response (SOAR) platforms, Endpoint Detection and Response (EDR) tools, and cloud security services. Ability to configure complex detection rules and orchestration workflows.

  • Python Programming and Scripting

    Strong proficiency in Python for security automation, data processing, and integration between security tools. Ability to apply sound software engineering practices including code quality, testing, and maintainability to security tools and scripts.

  • AWS and Cloud Security

    Hands-on experience with Amazon Web Services (AWS), cloud logging architectures, cloud identity and access management (IAM), cloud networking, and cloud-native security services. Understanding of cloud threat models and cloud-specific security controls.

  • Threat Intelligence and Adversary Frameworks

    In-depth knowledge of the MITRE ATT&CK framework and adversary tactics, techniques, and procedures (TTPs). Ability to map detection requirements to threat actor behaviors and assess detection coverage against known attack chains.

  • Incident Response and Threat Hunting

    Experience with incident response procedures, threat hunting methodologies, and security investigation workflows. Ability to analyze security alerts, triage incidents, and guide containment and remediation efforts.

Education

  • Bachelor's Degree in Computer Science or Related Field

    Formal education in computer science, information security, computer engineering, or equivalent practical experience in security engineering roles.

  • Security Certifications

    Professional security certifications such as CISSP, CCSK, Security+, or equivalent cloud security certifications are valued and demonstrate commitment to security engineering excellence.

Experience

  • 5+ Years Security Engineering Experience

    Minimum 5+ years of hands-on experience in security engineering roles, with significant time spent in detection engineering, security operations engineering, or threat response engineering roles.

  • Production Security Operations

    Proven track record operating and supporting production security infrastructure and capabilities in high-stakes environments. Experience managing detection systems at scale and improving mean-time-to-response (MTTR).

  • Cross-Functional Collaboration

    Experience working effectively across multiple teams including security operations, incident response, product engineering, and business stakeholders. Demonstrated ability to influence technical outcomes and drive consensus without formal authority.

  • Cloud-Scale Infrastructure

    Experience designing and operating security solutions in cloud-native or hybrid environments, with familiarity with cloud deployment models and cloud-specific security challenges.

Skills

Required

  • Python Programming

    Production-grade Python development for security automation, data processing, and tool integration. Include libraries like boto3 (AWS), requests, pandas, and logging frameworks.

  • SIEM Administration and Detection Engineering

    Hands-on expertise configuring detection rules, correlation searches, and analytics within SIEM platforms. Experience with rule tuning, alert threshold optimization, and false positive reduction.

  • SOAR and Security Automation

    Experience building and maintaining security orchestration playbooks, workflow automation, and response orchestration. Familiar with platforms like Splunk Phantom, Palo Alto Cortex XSOAR, or similar SOAR solutions.

  • EDR and Endpoint Security

    Operational knowledge of Endpoint Detection and Response platforms for threat detection, artifact collection, and response execution. Experience with behavioral analysis, malware detection, and endpoint investigation.

  • AWS Security Services

    Hands-on expertise with AWS security services including CloudTrail, VPC Flow Logs, GuardDuty, Security Hub, IAM, KMS, and cloud networking security controls.

  • MITRE ATT&CK Framework

    Deep understanding of MITRE ATT&CK taxonomy for mapping threat actor behaviors to detection logic. Ability to assess detection coverage gaps and prioritize new detections based on threat actor TTP prevalence.

  • Threat Intelligence Analysis

    Ability to consume threat intelligence feeds, analyze indicators of compromise (IOCs), and translate threat insights into actionable detection rules and security controls.

  • Incident Response and Investigation

    Experience conducting security investigations, analyzing indicators of compromise, performing root cause analysis, and guiding containment and remediation workflows.

Preferred

  • Kubernetes and Container Security

    Nice to have

    Experience with Kubernetes security, container scanning, runtime security, and cloud-native application security patterns. Knowledge of securing containerized workloads in AWS ECS, EKS, or similar.

  • Machine Learning for Security

    Nice to have

    Familiarity with machine learning and AI applications in security, including anomaly detection, behavioral analytics, and automated threat classification. Experience integrating ML models into security workflows.

  • Infrastructure as Code (IaC)

    Nice to have

    Experience with infrastructure automation tools like Terraform, CloudFormation, or Ansible for deploying and managing security infrastructure. Version control and CI/CD practices for security tooling.

  • Golang Programming

    Nice to have

    Secondary programming language expertise in Go for performance-critical security tools, agent development, or security service creation. Understanding of concurrency patterns and system-level programming.

  • Adversary Emulation and Red Team Experience

    Nice to have

    Background in offensive security, red teaming, or adversary emulation exercises. Direct experience understanding attack methodologies to improve detection design and coverage assessment.

  • Splunk, Elastic, or DataDog Expertise

    Nice to have

    Deep expertise with enterprise logging and observability platforms. Experience with custom queries, dashboards, alerting, and optimization of security data pipelines.

  • API Development and Integration

    Nice to have

    Experience designing and consuming APIs for security tool integration, including REST API development, webhook implementations, and multi-tool orchestration patterns.

Tech stack

Languages

Python 3.8+Go (Golang)Bash/Shell ScriptingSQL

Frameworks

SplunkElastic Stack (ELK)SOAR PlatformsEDR Solutions

Databases

ElasticsearchClickHouseDynamoDBPostgreSQL

Tools

AWS CloudTrailAWS GuardDutyAWS Security HubVPC Flow LogsGit and GitHubDockerTerraformJenkins or GitLab CI/CD

Other

MITRE ATT&CK FrameworkThreat Intelligence Feeds and SourcesIncident Response FrameworksDetection Engineering MethodologiesLinux/Unix Administration

Compensation

Pay and benefits.

Base·NZD 130,000 – 170,000

Equity·Stock options

Full posting

Original listing.

The role / impact

As a Senior Engineer in Security Defence, you'll design, build and operate the capabilities that help Xero detect and respond to security threats. You'll work across Security Operations, Security Response, CX, Product and Engineering, turning threat intelligence and security requirements into reliable, measurable security controls that keep our customers and our business safe.

You'll lead complex technical work, help shape our engineering direction, and build a culture of shared ownership and continuous learning across Security Defence and the wider Security team. It's a role for people who like to Go Bold on hard problems, backed by a team that knows how to Go Fast and figure things out together.

The team / how they connect

Security Defence sits at the centre of how Xero detects, investigates and responds to threats. The team covers detection engineering and security automation, working closely with Security Operations, Security Response and Product Engineering to turn intelligence into practical controls. It's a close knit group that shares knowledge openly, challenges assumptions constructively, and backs each other through high pressure moments.

The team is currently working on / Initially, you will focus on

  • Detection, monitoring and response workflows across SIEM, SOAR, EDR and cloud security platforms

  • Automation that reduces manual toil and speeds up how Security Operations respond to threats

  • Ways to measure detection coverage, control effectiveness and operational reliability

  • Safe, valuable ways to bring automation and AI into security engineering

Where and how you can work

This role can be based in Auckland or Wellington, offering a hybrid working model that balances local team presence with a global scope of work. You will have the flexibility to work from home while connecting with your colleagues in our modern office spaces during designated boost days.

Here are some of the things we're looking for

  • You bring hands on experience designing, building and operating production security capabilities or services.

  • Your programming or scripting skills, ideally in Python, help you apply sound software engineering practices to security problems.

  • Security monitoring, detection, threat intelligence, incident response and automation are all areas you know well, alongside tools such as SIEM, SOAR, EDR or cloud security platforms.

  • Working in cloud environments feels natural to you, particularly AWS, along with cloud logging, identity, networking and security services.

  • You understand adversary behaviours and frameworks like MITRE ATT&CK, and know how to measure detection coverage and control effectiveness.

  • Leading complex technical initiatives and influencing outcomes without relying on formal authority comes naturally, and you can explain technical risk and trade offs with clarity.

Apply even if your experience isn't a perfect match! At Xero, we hire based on your skills, passion, and the unique perspective you can bring to enhance our culture and team.

Redirects to Xero's application page.

Other roles

More at Xero.

View all 33 roles