Senior Security Engineer - Defence
Security Engineer · Senior · Full Time
Opens Xero's application page
Role
What you'll do.
Senior Security Engineer focused on threat detection and response at Xero, a leading cloud accounting platform. You'll design and operate security controls, detection capabilities, and automation to protect customers across SIEM, SOAR, EDR and cloud platforms. This role requires hands-on expertise in security engineering, cloud infrastructure (AWS), threat intelligence frameworks (MITRE ATT&CK), and scripting skills to influence security outcomes at scale.
Responsibilities
- Design and Build Production Security Capabilities: Lead the design, development, and deployment of detection and response workflows across SIEM, SOAR, EDR, and cloud security platforms. Apply software engineering best practices to create reliable, scalable security controls that effectively protect Xero's customers and infrastructure.
- Develop Security Automation and Orchestration: Engineer automation solutions using Python and security orchestration tools to reduce manual security operations toil and accelerate threat response timelines. Collaborate with Security Operations to identify manual processes that can be optimized through intelligent automation and AI-driven capabilities.
- Measure and Improve Detection Coverage: Establish metrics and measurement frameworks to quantify detection coverage, control effectiveness, and operational reliability. Use data-driven insights to identify gaps in security monitoring and validate the impact of new detection rules and security controls.
- Lead Complex Technical Initiatives: Champion complex security engineering projects across multiple teams including Security Operations, Security Response, Product Engineering, and Customer Experience. Influence technical outcomes through thought leadership and clear communication without relying on formal authority.
- Translate Threat Intelligence into Controls: Partner with threat intelligence and security response teams to understand emerging threats and adversary behaviors. Transform threat intelligence findings into practical, measurable security controls using MITRE ATT&CK frameworks and threat modeling.
- Contribute to Security Engineering Culture: Foster a culture of shared ownership, continuous learning, and constructive challenge within the Security Defence team and broader security organization. Mentor team members, share knowledge openly, and support colleagues through high-pressure operational moments.
Qualifications
What we look for.
Technical
Security Engineering and Detection Design
Demonstrated hands-on experience designing, building, and operating production security capabilities, detection systems, or security services in enterprise environments. Strong understanding of detection methodologies, false positive tuning, and operational reliability.
SIEM and Security Orchestration Platforms
Proven expertise with Security Information and Event Management (SIEM) systems, Security Orchestration Automation and Response (SOAR) platforms, Endpoint Detection and Response (EDR) tools, and cloud security services. Ability to configure complex detection rules and orchestration workflows.
Python Programming and Scripting
Strong proficiency in Python for security automation, data processing, and integration between security tools. Ability to apply sound software engineering practices including code quality, testing, and maintainability to security tools and scripts.
AWS and Cloud Security
Hands-on experience with Amazon Web Services (AWS), cloud logging architectures, cloud identity and access management (IAM), cloud networking, and cloud-native security services. Understanding of cloud threat models and cloud-specific security controls.
Threat Intelligence and Adversary Frameworks
In-depth knowledge of the MITRE ATT&CK framework and adversary tactics, techniques, and procedures (TTPs). Ability to map detection requirements to threat actor behaviors and assess detection coverage against known attack chains.
Incident Response and Threat Hunting
Experience with incident response procedures, threat hunting methodologies, and security investigation workflows. Ability to analyze security alerts, triage incidents, and guide containment and remediation efforts.
Education
Bachelor's Degree in Computer Science or Related Field
Formal education in computer science, information security, computer engineering, or equivalent practical experience in security engineering roles.
Security Certifications
Professional security certifications such as CISSP, CCSK, Security+, or equivalent cloud security certifications are valued and demonstrate commitment to security engineering excellence.
Experience
5+ Years Security Engineering Experience
Minimum 5+ years of hands-on experience in security engineering roles, with significant time spent in detection engineering, security operations engineering, or threat response engineering roles.
Production Security Operations
Proven track record operating and supporting production security infrastructure and capabilities in high-stakes environments. Experience managing detection systems at scale and improving mean-time-to-response (MTTR).
Cross-Functional Collaboration
Experience working effectively across multiple teams including security operations, incident response, product engineering, and business stakeholders. Demonstrated ability to influence technical outcomes and drive consensus without formal authority.
Cloud-Scale Infrastructure
Experience designing and operating security solutions in cloud-native or hybrid environments, with familiarity with cloud deployment models and cloud-specific security challenges.
Skills
Required
Python Programming
Production-grade Python development for security automation, data processing, and tool integration. Include libraries like boto3 (AWS), requests, pandas, and logging frameworks.
SIEM Administration and Detection Engineering
Hands-on expertise configuring detection rules, correlation searches, and analytics within SIEM platforms. Experience with rule tuning, alert threshold optimization, and false positive reduction.
SOAR and Security Automation
Experience building and maintaining security orchestration playbooks, workflow automation, and response orchestration. Familiar with platforms like Splunk Phantom, Palo Alto Cortex XSOAR, or similar SOAR solutions.
EDR and Endpoint Security
Operational knowledge of Endpoint Detection and Response platforms for threat detection, artifact collection, and response execution. Experience with behavioral analysis, malware detection, and endpoint investigation.
AWS Security Services
Hands-on expertise with AWS security services including CloudTrail, VPC Flow Logs, GuardDuty, Security Hub, IAM, KMS, and cloud networking security controls.
MITRE ATT&CK Framework
Deep understanding of MITRE ATT&CK taxonomy for mapping threat actor behaviors to detection logic. Ability to assess detection coverage gaps and prioritize new detections based on threat actor TTP prevalence.
Threat Intelligence Analysis
Ability to consume threat intelligence feeds, analyze indicators of compromise (IOCs), and translate threat insights into actionable detection rules and security controls.
Incident Response and Investigation
Experience conducting security investigations, analyzing indicators of compromise, performing root cause analysis, and guiding containment and remediation workflows.
Preferred
Kubernetes and Container Security
Nice to haveExperience with Kubernetes security, container scanning, runtime security, and cloud-native application security patterns. Knowledge of securing containerized workloads in AWS ECS, EKS, or similar.
Machine Learning for Security
Nice to haveFamiliarity with machine learning and AI applications in security, including anomaly detection, behavioral analytics, and automated threat classification. Experience integrating ML models into security workflows.
Infrastructure as Code (IaC)
Nice to haveExperience with infrastructure automation tools like Terraform, CloudFormation, or Ansible for deploying and managing security infrastructure. Version control and CI/CD practices for security tooling.
Golang Programming
Nice to haveSecondary programming language expertise in Go for performance-critical security tools, agent development, or security service creation. Understanding of concurrency patterns and system-level programming.
Adversary Emulation and Red Team Experience
Nice to haveBackground in offensive security, red teaming, or adversary emulation exercises. Direct experience understanding attack methodologies to improve detection design and coverage assessment.
Splunk, Elastic, or DataDog Expertise
Nice to haveDeep expertise with enterprise logging and observability platforms. Experience with custom queries, dashboards, alerting, and optimization of security data pipelines.
API Development and Integration
Nice to haveExperience designing and consuming APIs for security tool integration, including REST API development, webhook implementations, and multi-tool orchestration patterns.
Tech stack
Languages
Frameworks
Databases
Tools
Other
Compensation
Pay and benefits.
Base·NZD 130,000 – 170,000
Equity·Stock options
Full posting
Original listing.
The role / impact
As a Senior Engineer in Security Defence, you'll design, build and operate the capabilities that help Xero detect and respond to security threats. You'll work across Security Operations, Security Response, CX, Product and Engineering, turning threat intelligence and security requirements into reliable, measurable security controls that keep our customers and our business safe.
You'll lead complex technical work, help shape our engineering direction, and build a culture of shared ownership and continuous learning across Security Defence and the wider Security team. It's a role for people who like to Go Bold on hard problems, backed by a team that knows how to Go Fast and figure things out together.
The team / how they connect
Security Defence sits at the centre of how Xero detects, investigates and responds to threats. The team covers detection engineering and security automation, working closely with Security Operations, Security Response and Product Engineering to turn intelligence into practical controls. It's a close knit group that shares knowledge openly, challenges assumptions constructively, and backs each other through high pressure moments.
The team is currently working on / Initially, you will focus on
Detection, monitoring and response workflows across SIEM, SOAR, EDR and cloud security platforms
Automation that reduces manual toil and speeds up how Security Operations respond to threats
Ways to measure detection coverage, control effectiveness and operational reliability
Safe, valuable ways to bring automation and AI into security engineering
Where and how you can work
This role can be based in Auckland or Wellington, offering a hybrid working model that balances local team presence with a global scope of work. You will have the flexibility to work from home while connecting with your colleagues in our modern office spaces during designated boost days.
Here are some of the things we're looking for
You bring hands on experience designing, building and operating production security capabilities or services.
Your programming or scripting skills, ideally in Python, help you apply sound software engineering practices to security problems.
Security monitoring, detection, threat intelligence, incident response and automation are all areas you know well, alongside tools such as SIEM, SOAR, EDR or cloud security platforms.
Working in cloud environments feels natural to you, particularly AWS, along with cloud logging, identity, networking and security services.
You understand adversary behaviours and frameworks like MITRE ATT&CK, and know how to measure detection coverage and control effectiveness.
Leading complex technical initiatives and influencing outcomes without relying on formal authority comes naturally, and you can explain technical risk and trade offs with clarity.
Apply even if your experience isn't a perfect match! At Xero, we hire based on your skills, passion, and the unique perspective you can bring to enhance our culture and team.
Redirects to Xero's application page.
Other roles
More at Xero.
Integration Engineer
Mid
Senior Security Engineer - Cloud Platform
Senior
Engineering Manager
Manager
Senior Search Engineer
Senior
Engineering Manager - Data
Manager