Get more replies from employers
Send a job-specific resume in minutes.
Xero is seeking a Senior Engineer for the Cloud Platform Access team to design and operate identity and access controls at scale across AWS, GCP, and Azure. You will shape secure access as a product and lead hands‑on engineering initiatives.
You will mentor teammates, foster psychological safety, and contribute to reusable automation and Terraform‑based tooling. The role sits at the intersection of cloud infrastructure, security, and developer experience, with hybrid work from Auckland or
As a Senior Engineer in our Cloud Platform Access team, you'll design and operate identity and access controls at scale across AWS, GCP, and Azure. This is high-leverage platform security work where you'll shape secure access as a product rather than simply processing requests. You'll combine hands‑on technical leadership with deep expertise to build guardrails that enable teams to ship quickly without creating excessive privilege or long‑lived credentials.
As a Senior Engineer in our Cloud Platform Access team, you'll design and operate identity and access controls at scale across AWS, GCP, and Azure. This is high-leverage platform security work where you'll shape secure access as a product rather than simply processing requests. You'll combine hands‑on technical leadership with deep expertise to build guardrails that enable teams to ship quickly without creating excessive privilege or long‑lived credentials.
You'll mentor engineers on the team, foster psychological safety, and role‑model modern engineering practices. The work sits at the intersection of cloud infrastructure, security, developer experience, and automation - solving genuine problems that unlock productivity across the organisation.
The Cloud Platform Access team owns cloud‑native identity, access management, and policy enforcement across our public cloud environments. We work collaboratively with platform, security, and product teams to integrate secure‑by‑default controls early in delivery. The team values psychological safety, thoughtful automation, and engineering excellence - we ship sustainably by removing toil and enabling others to succeed.
Understanding the services, risks, and gaps in our current IAM setup across AWS, GCP, and Azure Closing critical identity handover gaps and taking ownership of bounded IAM, Workload Identity Federation, or self‑service improvements Establishing KPI baselines and contributing to design reviews, operations, and mentoring within the team Evolving reusable Terraform modules, policy frameworks, and internal tooling to standardise secure access patterns.
This role can be based in Auckland or Wellington, offering a hybrid working model that balances local team presence with a global scope of work. You will have the flexibility to work from home while connecting with your colleagues in our modern office spaces during designated boost days.