
Senior Security Engineer
- Wellington Auckland
- Permanent
- Full-time
- Assess, design, implement and manage security protocols, with emphasis on Data Loss Protection to protect Xero's sensitive data and meeting compliance (SOC2 and ISO27001).
- Provide input and guidance to develop security frameworks and ensure best practices are applied across the Xero network; develop and lead scalable, reliable and secure network architectures such as SASE, ZTNA, DLP, CASB and SWG.
- Automate security configurations and infrastructure-as-code (IaC) practices to reduce operational overhead and improve reliability; support high-availability network security for BAU operations, and deliver solutions in project-driven environments.
- Proactively monitor, detect, and respond to security threats, ensuring incidents are closed, contained, and remediated efficiently in a timely manner.
- Work with SOC teams and security analysts to tune and optimise network security detections for evolving threats; conduct regular security assessments, ensuring network configurations, firewalls, and security policies align with best practices and regulatory standards.
- Provide coaching and mentorship, helping teach small groups of engineers and contributing to Xero's shared knowledge base.
- Deep expertise in Data Loss Prevention (DLP) solutions, including policy configuration, monitoring, and incident management.
- Extensive experience in network security, cloud-based security solutions, and Zero Trust architectures. - Ideally with proven ability of designing and enforcing Zero Trust security models, ensuring secure authentication, segmentation, and access controls.
- Proficiency in scripting and automation (Python, Terraform, or other infrastructure-as-code tools).
- Experience working with Cloud Access Security Broker (CASB) and Secure Web Gateway (SWG)
- Deep understanding of network security compliance frameworks (SOC2, ISO 27001, NIST, CIS Benchmarks).
- Strong stakeholder management skills, with the ability to influence without authority and align security priorities with business needs.
- Solid background in cybersecurity incident response, threat detection, and network forensics. Including incident response and troubleshooting skills, ensuring rapid recovery and remediation of network security threats.