Senior Security Engineer

4 weeks ago


Melbourne, Victoria, Australia Xero Full time
Overview

1 week ago Be among the first 25 applicants

At Xero, we're here to help supercharge small businesses. We do this by automating routine tasks, surfacing actionable insights and connecting businesses with the right data, advisors and apps. When that happens, we're not only making life better for small business, we'll be building a stronger economy that can change the world.

About the role

Sitting within a newly formed Application Security team, this role will focus on secure software development, DevSecOps, security automation, and vulnerability management. Day to day, you\'ll work cross-functionally with engineering, product, and security teams to build and improve security tooling, secure coding practices, and automated security controls that empower developers to plan, write, test, and deploy secure applications efficiently.

We\'re looking for somebody with a passion for security automation and security-as-code, who can leverage tools to improve efficiency. Coupled with a growth mindset, continuously learning and adapting to emerging threats and security trends.

This position will play a key role in securing Xero's software development lifecycle (SDLC), ensuring that security is embedded into engineering workflows while enabling teams to deliver secure products at scale.

What you\'ll do
  • Develop and implement secure coding practices, working closely with engineers to uplift security awareness and adoption
  • Integrate automated security testing (SAST, DAST, SCA, IaC scanning) and security policy enforcement into CI/CD pipelines to identify vulnerabilities early.
  • Work with DevOps and engineering teams to build security guardrails, ensuring frictionless security adoption; driving a "shift-left" security mindset by enabling teams with secure coding guidance, tooling, and risk-based security testing.
  • Assist engineering teams in threat modeling to proactively identify and mitigate security risks in software designs. Ultimately looking to improve visibility and reporting of application security risks, helping teams understand and measure their security posture.
  • Build and manage security automation tools, integrating them into existing developer workflows; contribute to DevSecOps initiatives, ensuring security controls are scalable, efficient, and developer-friendly.
  • Participate in cross-functional security initiatives, working on security improvements that impact multiple teams. Continuously evaluate and improve security tools, scanning coverage, and security-as-code implementations.
What you\'ll bring with you
  • Extensive experience in Application Security, Secure Software Development, and DevSecOps practices.
  • Hands-on experience with automated security testing tools, including SAST, DAST, SCA, and IaC security scanning.
  • Hands-on experience securing APIs, microservices, cloud-native applications, and serverless architectures
  • Experience integrating security controls into CI/CD pipelines (Jenkins, GitHub Actions, GitLab CI, or similar).
  • Solid background in vulnerability management, risk assessment, and application security triage; including incident response, investigating and mitigating application security breaches.

Research has shown that women and underrepresented groups are less likely to apply to jobs unless they meet every single competency or experience . If you are excited about this role, but your past experience doesn\'t align perfectly, we encourage you to apply anyway. You could be just the right person for this role and Xero. If you have any support or access requirements, we encourage you to advise us at time of application and throughout the interview process.

Why Xero?

Offering very generous paid leave to use however you'd like (plus statutory holidays), dedicated paid leave to care for your physical and mental wellbeing as well as an Employee Assistance Program to access mental health care for you and your family. Health insurance, life insurance, and income protection.

We offer wellbeing and sports programmes, employee resource groups, 26 weeks of paid parental leave for primary caregivers, an Employee Share Plan, beautiful offices, flexible working, career development, and many other benefits that reflect our human value.

You'll do the best work of your life at Xero

Seniority level
  • Not Applicable
Employment type
  • Full-time
Job function
  • Information Technology
  • Industries
  • Software Development

Referrals increase your chances of interviewing at Xero by 2x

Get notified about new Senior Security Engineer jobs in Melbourne, Victoria, Australia.

We're unlocking community knowledge in a new way. Experts add insights directly into each article, started with the help of AI.


#J-18808-Ljbffr

  • Melbourne, Victoria, Australia Decipher Bureau Full time

    OverviewCyber and Information Security Recruitment Specialist - Building Contract and Permanent Cyber Teams Across AustraliaOur client is a leading enterprise organisation, recognised for its strong investment in cyber security and commitment to innovation. Backed by a clear vision and supportive leadership, the business is undergoing a multi-year...


  • Melbourne, Victoria, Australia Decipher Bureau Full time

    OverviewCyber and Information Security Recruitment Specialist - Building Contract and Permanent Cyber Teams Across AustraliaOur client is a leading enterprise organisation, recognised for its strong investment in cyber security and commitment to innovation. Backed by a clear vision and supportive leadership, the business is undergoing a multi-year...


  • Melbourne, Victoria, Australia Xero Full time

    Overview1 week ago Be among the first 25 applicantsAt Xero, we're here to help supercharge small businesses. We do this by automating routine tasks, surfacing actionable insights and connecting businesses with the right data, advisors and apps. When that happens, we're not only making life better for small business, we'll be building a stronger economy that...


  • Melbourne, Victoria, Australia Airwallex Full time

    Join to apply for the Senior Application Security Engineer role at AirwallexJoin to apply for the Senior Application Security Engineer role at AirwallexAbout AirwallexAirwallex is the only unified payments and financial platform for global businesses. Powered by our unique combination of proprietary infrastructure and software, we empower over 150,000...


  • Melbourne, Victoria, Australia Spartans Security Full time $104,000 - $130,878 per year

    Company DescriptionAt Spartans Security, we protect businesses from evolving cyber threats, such as data breaches and ransomware, using advanced threat detection and vulnerability management. Our experienced team offers tailored cybersecurity strategies, penetration testing, and risk assessments to identify and resolve system weaknesses before they become...


  • Melbourne, Victoria, Australia Xero Full time

    Our Purpose At Xero, we're here to help you supercharge your business. We do this by automating routine tasks, surfacing actionable insights and connecting businesses with the right data, advisors and apps. When that happens, we're not only making life better for small business, we'll be building a stronger economy that can change the world. About the...

  • Security Engineer

    3 weeks ago


    Melbourne, Victoria, Australia Logical Full time

    OverviewJoin to apply for the Security Engineer role at LogicalPermanent | Melbourne | Hybrid (4 days in office)We're seeking a Security Engineer to join a growing team and play a key role in delivering secure, reliable, and modern environments. This role will suit someone who has a strong technical foundation across Microsoft security products and is...

  • Security Engineer

    3 weeks ago


    Melbourne, Victoria, Australia Logical Full time

    OverviewJoin to apply for the Security Engineer role at LogicalPermanent | Melbourne | Hybrid (4 days in office)We're seeking a Security Engineer to join a growing team and play a key role in delivering secure, reliable, and modern environments. This role will suit someone who has a strong technical foundation across Microsoft security products and is...


  • Melbourne, Victoria, Australia SafetyCulture Full time

    At SafetyCulture, we helpbusinesses get better everyday. As the operational heartbeat of working teams, our technology gives workers a voice and leaders the visibility to make smart decisions. We're constantly evolving our platform, expanding into sensors/IoT, Scalable and Event-Driven Architecture to name a few, but we believe there's more to be...


  • Melbourne, Victoria, Australia Logical Full time $150,000 - $200,000 per year

    Senior Cloud Infrastructure & Security EngineerPermanent | Melbourne | Hybrid (4 days in office)We're partnering with a leading Australian technology and cybersecurity provider, recognised for delivering innovative cloud, infrastructure, and security solutions to enterprise clients nationwide. With a track record of delivering complex transformation projects...