Design, build, and operate production security capabilities and services.
Develop detection, monitoring, and response workflows across SIEM, SOAR, EDR, and cloud security platforms.
Automate security operations to reduce manual work and accelerate threat response.
Measure detection coverage, control effectiveness, and operational reliability.
Explore safe and valuable applications of automation and AI in security engineering.
Lead complex technical initiatives and influence engineering direction across Security Defence and the wider Security team.
Collaborate with Security Operations, Security Response, CX, Product, and Engineering teams.
Requirements
Hands-on experience designing, building, and operating production security capabilities or services.
Programming or scripting skills, ideally in Python, with sound software engineering practices.
Strong knowledge of security monitoring, detection, threat intelligence, incident response, and automation.
Experience with SIEM, SOAR, EDR, or cloud security platforms.
Experience working in cloud environments, particularly AWS, including cloud logging, identity, networking, and security services.
Understanding of adversary behaviors and frameworks such as MITRE ATT&CK.
Ability to measure detection coverage and control effectiveness.
Experience leading complex technical initiatives and influencing outcomes without formal authority.
Ability to clearly explain technical risks and trade-offs.
Benefits
Hybrid working model based in Auckland or Wellington, with flexibility to work from home.
Connection with colleagues in modern office spaces during designated boost days.
Global scope of work and collaboration across the wider Security team.
Xero
Trusted by 5M around the world on the most loved SMB accounting platform. Xero's Community Guidelines: https://www.xero.com/support/community-guidelines/