Design and operate identity and access controls across AWS, GCP, and Azure.
Assess cloud services, risks, and gaps in the current IAM environment.
Close identity handover gaps and improve IAM, Workload Identity Federation, and self-service capabilities.
Establish KPI baselines and contribute to design reviews and operational improvements.
Develop reusable Terraform modules, policy frameworks, automation, and internal tooling for secure access patterns.
Lead technical design conversations, make sound engineering trade-offs, improve reliability, and mentor engineers.
Collaborate with security, platform, and product teams to enable secure, rapid delivery.
Requirements
Solid experience securing at least one public cloud environment: AWS, GCP, or Azure, with willingness to learn the others.
Understanding of identity and Infrastructure as Code fundamentals.
Experience designing and maintaining reusable Terraform modules and automation for IAM controls and policy guardrails at scale.
Proficiency in at least one scripting language such as Python.
Strong software engineering foundations and experience with modern delivery practices.
Ability to lead technical design discussions, make engineering trade-offs, mentor others, and improve delivery quality.
Collaborative approach to working across security, platform, and product teams.
Curiosity about AI applications and openness to exploring their use in engineering workflows.
Benefits
Hybrid working model based in Auckland or Wellington.
Flexibility to work from home with connection to modern office spaces during designated boost days.
Opportunity to work on high-leverage cloud platform security with global scope.
Xero
Trusted by 5M around the world on the most loved SMB accounting platform. Xero's Community Guidelines: https://www.xero.com/support/community-guidelines/