Xero

Senior Security Engineer - Cloud Platform

Xero

Remote · Full Time

Be the first to apply

Experience
Any
Salary
—
Openings
1
Posted
3 days ago
Work mode
Work from home
Resume
Required to apply

Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.

Job description

About the Role

As a Senior Engineer in the Cloud Platform Access team, you will be responsible for designing and managing identity and access controls at scale across major public clouds including AWS, GCP, and Azure. This role involves shaping secure access as a product, going beyond just fulfilling requests, to establish guardrails that allow teams to deploy rapidly while minimizing excessive privileges and avoiding long-lived credentials.

Your role will combine hands-on technical leadership with deep knowledge in cloud security to build solutions that enhance productivity across the organization. Additionally, you will mentor fellow engineers, cultivate a psychologically safe environment, and exemplify modern engineering standards.

Team Overview

The Cloud Platform Access team manages cloud-native identity, access management, and security policy enforcement for the company's public cloud landscapes. The team collaborates with platform, security, and product groups to embed secure-by-default controls early in the development lifecycle. Values include psychological safety, thoughtful automation, and engineering excellence, with a focus on reducing toil and empowering others to succeed.

Current Focus Areas

  • Analyzing services, identifying risks, and addressing gaps in the current IAM configurations across AWS, GCP, and Azure.
  • Resolving critical identity handover issues and taking responsibility for bounded IAM, Workload Identity Federation, and enhancing self-service capabilities.
  • Establishing key performance indicator baselines, participating in design reviews and operational tasks, and mentoring team members.
  • Enhancing and standardizing secure access patterns via reusable Terraform modules, policy frameworks, and internal tools.

Work Environment

The company supports a flexible work approach, enabling a balance between professional and personal life. Employees can choose a hybrid work style, combining remote work flexibility with office collaborations and designated team days to strengthen connections and alignment.

Candidate Profile

  • Demonstrated experience securing at least one major public cloud platform (AWS, GCP, or Azure) with eagerness to learn others, along with a solid understanding of Identity and Infrastructure as Code concepts.
  • Experience in designing and maintaining reusable Terraform modules and automations that enforce scalable IAM controls and guardrails.
  • Strong software engineering principles underpin your work; you take an automation-first approach, are proficient in at least one scripting language such as Python, and adhere to modern delivery methodologies.
  • Capable of leading technical design discussions, making well-informed engineering decisions, mentoring peers, raising quality standards, and enhancing system reliability and delivery.
  • Collaborative problem solver who builds trust across security, platform, and product teams to facilitate fast and secure delivery.
  • Interest in exploring thoughtful artificial intelligence applications to potentially accelerate engineering workflows and solve practical team challenges.

Additional Information

Applicants are encouraged to apply even if their experience does not exactly match the listed qualifications. The company values skills, passion, and diverse perspectives that enrich team culture and performance.

Tools & software

Terraform required

How they work

Teamwork & Collaboration Problem Solving Leadership
🤖
Online · instant AI help
Broxer