Senior Security Engineer
3 days ago
Our Purpose
At Xero, we're here to help you supercharge your business. We do this by automating routine tasks, surfacing actionable insights and connecting businesses with the right data, advisors and apps. When that happens, we're not only making life better for small business, we'll be building a stronger economy that can change the world.
About the role
Sitting within a newly formed Application Security team, this role will focus on secure software development, DevSecOps, security automation, and vulnerability management.
Day to day, you'll work cross-functionally with engineering, product, and security teams to build and improve security tooling, secure coding practices, and automated security controls that empower developers to plan, write, test, and deploy secure applications efficiently.
We're looking for somebody with a passion for security automation and security-as-code, who can leverage tools to improve efficiency. Coupled with a growth mindset, continuously learning and adapting to emerging threats and security trends.
This position will play a key role in securing Xero's software development lifecycle (SDLC), ensuring that security is embedded into engineering workflows while enabling teams to deliver secure products at scale.
What you'll do- Develop and implement secure coding practices, working closely with engineers to uplift security awareness and adoption
- Integrate automated security testing (SAST, DAST, SCA, IaC scanning) and security policy enforcement into CI/CD pipelines to identify vulnerabilities early.
- Work with DevOps and engineering teams to build security guardrails, ensuring frictionless security adoption; driving a "shift-left" security mindset by enabling teams with secure coding guidance, tooling, and risk-based security testing.
- Assist engineering teams in threat modeling to proactively identify and mitigate security risks in software designs. Ultimately looking to improve visibility and reporting of application security risks, helping teams understand and measure their security posture.
- Build and manage security automation tools, integrating them into existing developer workflows; contribute to DevSecOps initiatives, ensuring security controls are scalable, efficient, and developer-friendly.
- Participate in cross-functional security initiatives, working on security improvements that impact multiple teams. Continuously evaluate and improve security tools, scanning coverage, and security-as-code implementations.
- Extensive experience in Application Security, Secure Software Development, and DevSecOps practices.
- Hands-on experience with automated security testing tools, including SAST, DAST, SCA, and IaC security scanning.
- Proficiency in programming and scripting languages (Python, Java, Go, JavaScript, or similar); coupled with a strong understanding of secure coding principles, OWASP Top 10, SANS CWE, and software security best practices.
- Hands-on experience securing APIs, microservices, cloud-native applications, and serverless architectures
- Experience integrating security controls into CI/CD pipelines (Jenkins, GitHub Actions, GitLab CI, or similar).
- Solid background in vulnerability management, risk assessment, and application security triage; including incident response, investigating and mitigating application security breaches.
Research has shown that women and underrepresented groups are less likely to apply to jobs unless they meet every single competency or experience . If you are excited about this role, but your past experience doesn't align perfectly, we encourage you to apply anyway. You could be just the right person for this role and Xero. If you have any support or access requirements, we encourage you to advise us at time of application and throughout the interview process.
Why Xero?
Offering very generous paid leave to use however you'd like (plus statutory holidays), dedicated paid leave to care for your physical and mental wellbeing as well as an Employee Assistance Program to access mental health care for you and your family. Health insurance, life insurance, and income protection.
We offer wellbeing and sports programmes, employee resource groups, 26 weeks of paid parental leave for primary caregivers, an Employee Share Plan, beautiful offices, flexible working, career development, and many other benefits that reflect our human value.
You'll do the best work of your life at Xero
-
Senior Security Engineer
3 days ago
Sydney, New South Wales, Australia Decipher Bureau Full time $120,000 - $2,000,000 per yearWe're partnering with a fast-growing tech company in the financial services industry, and they're looking for a highly technicalSenior Security Engineerto join their team in Sydney (possibly Melbourne). Salary wise we are talking circa$200K + Super + Bonus.This is a great opportunity for a hands-on, functional lead (no direct reports) who thrives in secure...
-
Senior Engineer – Security
7 days ago
Sydney, New South Wales, Australia Westpac Group Full time $120,000 - $180,000 per yearCreate your best future and join the Digital Technology – Security Engineering team as a Senior Engineer – Security. What's the role?Join our frontline security team and help protect Westpac's digital edge. In this hands-on role, you'll monitor threats, respond to incidents, and coach developers on secure coding practices. You'll work across engineering...
-
Senior Cyber Security Engineer
1 week ago
Sydney, New South Wales, Australia Allura Partners Full time $200,000 - $240,000 per yearSenior Cyber Security Engineer - 180K + Super - Permanent This role offers the opportunity to contribute directly to a large-scale security transformation and uplift program that will define the organization's future security landscape. We're looking for a seasoned Cyber Security Engineer who thrives in the hands-on implementation of modern security...
-
Senior Product Security Engineer
5 days ago
Sydney, New South Wales, Australia CoStar Group Full time $120,000 - $180,000 per yearSenior Product Security EngineerJob DescriptionAbout CoStar GroupCoStar Group (NASDAQ: CSGP) is a leading global provider of commercial and residential real estate information, analytics, and online marketplaces. Included in the S&P 500 Index and the NASDAQ 100, CoStar Group is on a mission to digitize the world's real estate, empowering all people to...
-
Senior Network Security Engineer
1 week ago
Sydney, New South Wales, Australia Profusion Full time $120,000 - $180,000 per yearCompany Overview Leading Australian Financial Service organisation experiencing rapid growth are looking for a Network Security Engineer to play a pivotal role in Network Automation initiatives.Role OverviewAs a Network Security Engineer, you bring deep expertise in low-level design and implementation of network services, with strong hands-on experience...
-
Senior Product Security Engineer
5 days ago
Sydney, New South Wales, Australia CoStar Group Full time $120,000 - $180,000 per yearSenior Product Security EngineerJob DescriptionAbout CoStar GroupCoStar Group (NASDAQ: CSGP) is a leading global provider of commercial and residential real estate information, analytics, and online marketplaces. Included in the S&P 500 Index and the NASDAQ 100, CoStar Group is on a mission to digitize the world's real estate, empowering all people to...
-
Senior Network Security Engineer
1 week ago
Sydney, New South Wales, Australia Commonwealth Bank of Australia Full time $150,000 - $200,000 per yearSenior Network Security EngineerYou are highly experienced in building customer focussed solutionsWe are a team of big thinkers, who love to push boundaries and create new solutionTogether we will build tomorrow's bank today, using world-leading technology and innovationDo work that matters:The purpose of this role is to provide design, implementation and...
-
Senior Network Security Automation Engineer
6 days ago
Sydney, New South Wales, Australia Microsoft Full time $125,000 - $175,000 per yearIn alignment with our Microsoft values, we are committed to cultivating an inclusive work environment for all employees to positively impact our culture every day and we need you as a Senior Network Security Automation Engineer. Microsoft's Cloud Operations & Innovation (CO+I) is the engine that powers our cloud services. As a Senior Cyber Security...
-
Senior Cyber Security Engineer
6 days ago
Sydney, New South Wales, Australia NSW Government Full time $129,464 - $142,665 per yearSenior Cyber Security Engineer, Ongoing opportunity based in Sydney CBD + hybrid/flexible working options availableThe Department of Customer Service (DCS) is seeking 2 x experienced Senior Cyber Security Engineers to help shape, implement, and manage a range of critical security controls. You'll work in an environment that values innovation and...
-
Senior Cyber Security Engineer
1 week ago
Sydney, New South Wales, Australia myCareer - NSW Government Full time $129,464 - $142,665Senior Cyber Security Engineer, Ongoing opportunity based in Sydney CBD + hybrid/flexible working options available The Department of Customer Service (DCS) is seeking 2 x experiencedSenior Cyber Security Engineers to help shape, implement, and manage a range ofcritical security controls. You'll work in an environment that valuesinnovation and...