The role / impact
As a Senior Engineer in our Cloud Platform Access team, you'll design and operate identity and access controls at scale across AWS, GCP, and Azure. This is high-leverage platform security work where you'll shape secure access as a product rather than simply processing requests. You'll combine hands-on technical leadership with deep expertise to build guardrails that enable teams to ship quickly without creating excessive privilege or long-lived credentials.
You'll mentor engineers on the team, foster psychological safety, and role-model modern engineering practices. The work sits at the intersection of cloud infrastructure, security, developer experience, and automation - solving genuine problems that unlock productivity across the organisation.
The team / how they connect
The Cloud Platform Access team owns cloud-native identity, access management, and policy enforcement across our public cloud environments. We work collaboratively with platform, security, and product teams to integrate secure-by-default controls early in delivery. The team values psychological safety, thoughtful automation, and engineering excellence - we ship sustainably by removing toil and enabling others to succeed.
The team is currently working on
Understanding the services, risks, and gaps in our current IAM setup across AWS, GCP, and Azure Closing critical identity handover gaps and taking ownership of bounded IAM, Workload Identity Federation, or self-service improvements Establishing KPI baselines and contributing to design reviews, operations, and mentoring within the team Evolving reusable Terraform modules, policy frameworks, and internal tooling to standardise secure access patterns
Where and how you can work
This role can be based in Auckland or Wellington, offering a hybrid working model that balances local team presence with a global scope of work. You will have the flexibility to work from home while connecting with your colleagues in our modern office spaces during designated boost days.
Here are some of the things we are looking for
-
You bring solid experience securing at least one public cloud environment - AWS, GCP, or Azure - with genuine willingness to learn the others. You understand Identity and Infrastructure as Code fundamentals.
-
You've designed and maintained reusable Terraform modules and automation that codify IAM controls and policy guardrails at scale.
-
Strong software engineering foundations run through your work: you think automation-first, have proficiency in at least one scripting language like Python, and follow modern delivery practices.
-
You lead technical design conversations, make sound engineering trade-offs, and aren't afraid to mentor others. You can lift standards, improve reliability, and keep delivery quality high.
-
You approach problems collaboratively, building trust across security, platform, and product teams to enable rapid, secure delivery.
-
You're curious about thoughtful AI applications and open to exploring how it might accelerate engineering workflows or solve real problems for the team.
Apply even if your experience isn't a perfect match! At Xero, we hire based on your skills, passion, and the unique perspective you can bring to enhance our culture and team.