Xero

Senior Security Engineer - Cloud Platform

Xero

Remote · Full Time

Be the first to apply

Experience
Any
Salary
—
Openings
1
Posted
1 hour ago
Work mode
Work from home
Resume
Required to apply

Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.

Job description

Role and Impact

As a Senior Engineer in the Cloud Platform Access team, you will architect and manage identity and access controls at scale across public cloud environments including AWS, GCP, and Azure. This role focuses on platform security, framing secure access as a product to enable efficient, safe delivery without excess privilege or long-term credentials.

You will provide hands-on technical leadership, mentoring team members, promoting psychological safety, and exemplifying modern engineering practices. This role blends cloud infrastructure, security, developer experience, and automation to solve challenges that enhance organizational productivity.

The Team and Collaboration

The Cloud Platform Access team is responsible for cloud-native identity management, access control, and enforcement of policies across public cloud platforms. Collaboration with platform, security, and product teams enables embedding secure-by-default controls early in delivery cycles. The team values psychological safety, thorough automation, and engineering excellence, aiming to sustainably reduce toil while empowering others.

Current Initiatives

  • Analyzing services, risks, and gaps in the existing IAM configurations across AWS, GCP, and Azure.
  • Addressing critical identity handover issues and managing bounded IAM, Workload Identity Federation, and self-service improvements.
  • Setting KPI baselines, contributing to design reviews, day-to-day operations, and providing mentorship within the team.
  • Advancing reusable Terraform modules, policy frameworks, and internal tools to standardize secure access practices.

Work Environment

The company embraces a flexible working approach, allowing a blend of remote work and office collaboration. This hybrid model combines focused work-from-home periods with team gatherings and office days to boost connection and alignment.

Candidate Profile

  • Proven experience securing at least one major public cloud platform (AWS, GCP, or Azure), along with eagerness to learn others. Solid understanding of Identity and Infrastructure as Code principles.
  • Expertise designing and maintaining reusable Terraform modules and automation that enforce IAM controls and policy guardrails at scale.
  • Strong software engineering background, with an automation-first mindset. Skilled in at least one scripting language such as Python and adherent to contemporary delivery methods.
  • Ability to lead technical design discussions, make prudent engineering decisions, mentor colleagues, elevate standards, enhance reliability, and maintain delivery quality.
  • Collaborative problem solver who builds trust across security, platform, and product groups to facilitate swift, secure releases.
  • Interest in exploring thoughtful applications of AI to improve engineering workflows or tackle meaningful challenges.

Applicants whose experience does not exactly align with the description are encouraged to apply. Selection is based on skills, passion, and the unique contributions each candidate brings to the culture and team.

Tools & software

Terraform required

How they work

Teamwork & Collaboration Problem Solving Adaptability Leadership

Leave it if you'd like a reply — we won't use it for anything else.

Click to browse, drag & drop, or paste a screenshot

PNG, JPG, GIF, MP4, WebM, MOV · Max 20MB each · Up to 5 files

🤖
Online · instant AI help
Broxer