Monitor, investigate, and respond to security alerts and suspected incidents with guidance from experienced engineers and analysts.
Contribute to detection, monitoring, enrichment, and response workflows across SIEM, SOAR, EDR, cloud security, and related services.
Build and improve detection content, integrations, dashboards, and alerting across security platforms.
Develop runbooks, playbooks, and automations to reduce manual effort and accelerate security response.
Expand threat-intelligence-led detection engineering and automation coverage across Xero.
Collaborate with Security Operations, Security Response, Engineering, Product, CX, and Legal teams.
Requirements
Demonstrated curiosity or interest in security engineering, cybersecurity, software engineering, cloud security, detection engineering, or a related discipline.
Ability to learn an unfamiliar codebase or platform and apply established patterns with guidance.
Hands-on experience scripting, debugging, automating, or building small integrations.
Experience working in an engineering, security, IT, operations, or technology team and collaborating to deliver change.
Clear written and verbal communication, including openly sharing progress, blockers, and context.
Interest in using AI-assisted tools responsibly.
Collaborative approach and willingness to pair, receive feedback, and support teammates.
Benefits
Hybrid working model based in the Melbourne office, with flexibility to work from home.
Opportunity to work with a global team and connect in the office during designated boost days.
Professional development through delivery, pairing, incident participation, feedback, and learning from experienced engineers.
High-trust, blameless, learning-oriented team culture.
Xero
Trusted by 5M around the world on the most loved SMB accounting platform. Xero's Community Guidelines: https://www.xero.com/support/community-guidelines/