The role and it’s impact
As a Senior Engineer, you will take a hands-on approach to designing, building, and operating cross-cloud identity and access controls at scale. You will play a pivotal role in designing secure patterns that serve as guardrails rather than roadblocks, ensuring product teams can ship securely with minimal friction.
By leveraging automation to reduce operational overhead, you will help evolve our platform standards while actively mentoring teammates and fostering a culture of technical excellence and psychological safety.
The team & how they connect
The Cloud Platform Access team focuses on cloud-native identity and access across AWS, GCP, and Azure. We own platform-native IAM services, Terraform modules, and policy enforcement tooling to provide secure, scalable, and automated access in public cloud environments.
The team is currently working on
Designing and operating cloud-native IAM and policy frameworks across AWS, GCP, and Azure.
Owning and evolving reusable Terraform modules and Service Control Policies to standardise access controls.
Building internal tooling and automation bots to provision and revoke access with strong auditability.
Designing secure patterns for Workload Identity Federation to remove the need for long-lived credentials.
Where and how you can work
We’re a team split across Wellington and Auckland, this role can be based anywhere in New Zealand. We feel our working environment allows you to do the best work of your life, supported by a diverse team that respects and challenges you.
Here are some of the things we're looking for, for this role
You have experience securing public cloud environments (AWS, GCP, or Azure) with a willingness to learn others.
A strong understanding of the core concepts of Identity (IAM) and Infrastructure as Code is essential.
You bring proven capability in designing and maintaining reusable Terraform modules that codify IAM controls.
Proficiency in at least one scripting language, such as Python, alongside an automation-first mindset.
You demonstrate the ability to lead technical design, make sound engineering trade-offs, and mentor others.
A collaborative approach is key, as you will work effectively across security, platform, and product teams.
Apply even if your experience isn't a perfect match! At Xero, we hire based on your skills, passion, and the unique perspective you can bring to enhance our culture and team.
Top Skills
Xero Toronto, Ontario, CAN Office
250 University Ave, Toronto, Ontario, Canada

