Point your AI agent at freehire and let it find you a job.

Get the CLI →

xero

NewBe an early applicant

Associate Security Engineer

Discussion

Summary

An associate-level security engineer role on Xero's Security Defence team in Melbourne, focused on monitoring and investigating security alerts and building detections, automations and response workflows across SIEM, SOAR, EDR and cloud security tooling. A junior position with mentorship, pairing, and incident participation in a hybrid work model.

The role and its impact

As an Associate Security Engineer in our Security Defence team, you'll help design, build and continuously improve the capabilities we rely on to detect, investigate and respond to security threats. You'll work alongside Security Operations, Security Response, Engineering, Product, CX and Legal, turning threat intelligence and security requirements into practical, reliable controls that keep Xero and our customers safe.

You’ll develop your engineering capability through delivery, pairing, incident participation, and learning from more experienced engineers while contributing to the protection of Xero and our customers.

The team and how they connect

Security Defence sits at the heart of how Xero detects and responds to threats, working across SIEM, SOAR, EDR and cloud security tooling to keep our platform and customers protected. The team works closely with Security Operations, Security Response, Engineering and Product to turn insight into action, and prides itself on a high-trust, blameless, learning-oriented culture where questions and curiosity are always welcome.

The team is currently working on / Initially, you will focus on

  • Monitoring, investigating, and responding to security alerts and suspected incidents with guidance from experienced engineers and analysts.

  • Contribute to detection, monitoring, enrichment, and response workflows across security platforms such as SIEM, SOAR, EDR, cloud security, and related services.

  • Building and improving detection content, integrations, dashboards and alerting across our security platforms

  • Developing runbooks, playbooks and automations that reduce manual effort and speed up response

  • Expanding threat-intelligence-led detection engineering and automation coverage across Xero

Where and how you can work

This role is based in our Melbourne office, offering a hybrid working model that balances local team presence with a global scope of work. You will have the flexibility to work from home while connecting with your colleagues in our modern office space during designated boost days.

Here are some of the things we're looking for

  • A growth mindset and real curiosity in security engineering, cyber security, software engineering, cloud security, detection engineering, or a closely related discipline.

  • Comfortable picking up an unfamiliar codebase or platform and applying established patterns with guidance.

  • You Go Bold by turning threat intelligence and security research into practical, measurable detections and controls.

  • Clear written and verbal communication, including sharing progress, blockers and context openly with your team.

  • A collaborative approach, you enjoy pairing and feedback, and Go Together by lifting the people around you.

  • Hands-on experience scripting, debugging, automating or building small integrations, along with an interest in using AI-assisted tools responsibly.

  • Experience working in an engineering, security, IT, operations, or technology team and collaborating with others to deliver change.

Apply even if your experience isn't a perfect match! At Xero, we hire based on your skills, passion, and the unique perspective you can bring to enhance our culture and team.

Skills

See also

Security jobs by country — openings, pay and top skills →

Tailor your CV for this role?

We couldn't check your fit for this role — add a CV to your profile to see it next time.

A new version of freehire is available