
Team Lead - Security Governance & Data Protection
- Wellington Auckland
- Permanent
- Full-time
- Lead the Data Protection team by coaching, mentoring, and connecting their work directly to Xero's strategic goals.
- Lead Data Loss Prevention (DLP) controls to protect sensitive data across Xero's environments; expanding our identity governance capabilities, ensuring scalable and efficient user access reviews, provisioning, and entitlements management across AWS and GCP.
- Develop and implement Continuous Assurance capabilities, automating security controls to support ISO, SOC2, and other regulatory attestations.
- Oversee the Identity Management Engine, ensuring it meets business needs while enabling self-service access control for teams.
- Work closely with the SASE program team to integrate data security policies into Xero's cloud and network security architecture.
- Collaborate with internal stakeholders to ensure alignment between security governance, compliance, and business objectives; streamlining audit processes, with the aim of reducing the manual effort required for security certifications.
- Proven track record of people leadership, demonstrating honesty and integrity.
- Strong expertise in Security Governance, Identity Governance, Compliance Automation, and Data Protection.
- Experience implementing and managing Identity Governance solutions (e.g., user access reviews, provisioning automation).
- Experience leading Data Protection initiatives, including DLP implementations in cloud and hybrid environments.
- Strong knowledge of SASE, Zero Trust, and cloud security principles, ensuring security is scalable and frictionless.
- Strong stakeholder management skills, with the ability to influence without authority and align security priorities with business needs.