368,530open jobs
9,432companies
50,439added this week
Browse all
Salary
$89k – $101k per year
Location
Remote (New Zealand)
Seniority
Staff
Overview
Company
Impact
Profile match
Auror empowers the retail community to prevent crime, reduce loss, and make stores safer. Every retailer deserves the chance to protect their profits, people, and property from crime. Inspired by this challenge, Tom, Phil, and James founded Auror to empower retailers with the intelligence and tools to stop crime, for good.

At Auror, we’re empowering the retail industry to tackle theft and Organised Retail Crime, a $150 Billion problem globally. It’s high volume crime that’s increasingly organised in nature and is putting people, retailers, and communities at risk every day.

Founded in New Zealand 12 years ago, we’re working with some of the best and largest retailers in the world across the US, Canada, Australia, New Zealand, and the UK. Auror is connecting people and intelligence to reduce crime. We’re using technology for good.

Our mission is clear: reduce violent retail crime by 50% in 5 years. It's an ambitious goal - and one we believe is achievable. In partnership with our leading retail partners, we need people with the passion, determination, and innovation required to overcome one of the world's largest problems. If you’re looking to make a difference with and for the people dedicated to stopping crime, for good, then we want you on our team.

We're also embracing the potential of AI to supercharge our impact - whether that's enhancing the way we detect trends, support our customers, or improve internal workflows. As a company, we're committed to responsibly incorporating AI into how we work and what we build, and we encourage all Aurors to be curious about how AI can elevate their work, regardless of role or function.

The Role

We're hiring a Staff Security Engineer to join the Product & Engineering Security pillar at Auror. This is an engineer-first role, scoped for someone who lives in the codebase, ships patches, deploys changes, and raises the security bar of the platform from the inside - not from the sidelines.

The shape of this role has shifted from where Security engineering at Auror started. The bar for impact has moved. We don't need a security specialist who points at risks and writes recommendations for someone else to take action. We need a Staff-level engineer who picks up the ticket, writes the fix, opens the PR, ships the change, and stays close enough to the platform to know what just happened in production.

Threat actors are increasingly AI-capable, our platform is increasingly AI-augmented, and our customers' expectations of how fast we can detect, fix, and prove security have stepped up. The response is engineering muscle - applied to security.

At the IC4 (Staff) level, you'll set technical direction for security controls, tooling, and architecture across multiple systems. You'll design security patterns and guardrails that enable safe, repeatable delivery; lead the toughest investigations and architecture reviews; and raise the bar through code, design, and coaching. You'll be a credible engineering voice in cross-functional decisions and a force-multiplier for the engineers around you.

Location:

Auror's headquarters are in Auckland, and we follow a hybrid way of working. However, we're open to hiring someone remotely for this role, provided they are based in New Zealand. While remote work is supported, we place a high value on spending time together in person. Our remote team members typically travel to Auckland approximately every six weeks to join their team and the wider company for collaboration, planning, and social events.

Responsibilities

  • Ship Code in the Platform: This is the headline. You'll work directly in the Auror codebase - writing patches, fixing vulnerabilities, refactoring weak patterns, and deploying changes in partnership with the product engineering teams. You should be comfortable opening PRs against unfamiliar services, reading through to root cause, and shipping a fix that the owning team would have signed off on themselves.

  • Build Security Tooling and Automation: Write the tools, automation, and detections that scale the security team's impact. Replace manual evidence collection patterns with code. Build the guardrails that make secure defaults the easy path for the engineers around you.

  • Application Security and Vulnerability Remediation: Lead threat modelling and architecture reviews for major platform changes. Drive the in-flight Wiz SAST/Code findings closure programme - your work, not someone else's. Push toward engineer-raised PRs using security-provided resolutions, and shoulder the fixes yourself when that's the faster path to closure.

  • Platform and Infrastructure Security: Partner with SRE and Platform on cloud and infrastructure security - GCP, GitHub Actions hardening, CI/CD security, identity and secrets management, hash-pinning, supply chain controls. Write Terraform, build pipelines, contribute to platform-as-code where the leverage is highest. You should be as comfortable in a deployment YAML as in a vulnerability report.

  • AI Security and AI-Augmented Engineering: Help define and harden how Auror builds with and defends against AI. Apply security thinking to LLM-integrated features - prompt injection, data leakage, model supply chain, agentic tool use. Use AI engineering tooling (Claude Code and similar) natively to ship security work faster, and help mature the patterns that let the rest of Engineering do the same safely. Stay close enough to the Mythos-class threat landscape to translate it into concrete engineering work - but always as an engineer, not a researcher.

  • Detection and Response: Partner with the Blue Team workstream to design and tune detections. Write detection-as-code, build playbooks, operate SIEM and CloudSIEM tooling. Lead the technical side of incident response and contribute to post-incident learning.

  • Customer Security and Assurance: Be the credible technical voice when enterprise customers need depth - architecture questions, technical risk conversations, evidence beyond what the audit pack covers. The Compliance team handles questionnaires; you show up when the conversation gets technical.

  • Standards, Patterns, and Coaching: Set technical direction for security controls, tooling, and architecture. Publish patterns and guardrails - authentication, secrets, logging, secure-by-default templates - and drive adoption. Coach engineers (inside and outside Security) on secure design and judgement. Raise the bar through code review, design review, and documentation.

This role reports to

Scotland Symons

, Senior Director of Information Security

Scotland has been working in the Technology & Security industry for the last twenty years and has worked for Microsoft, Apple, Amazon, and a few more. Coming to Auror from the US, she runs the security team at Auror focusing on all of our efforts to secure the platform, code and efforts to protect Auror and its customers. In her own words below:

“Security for me is about critical thinking and flexibility, Security is also not linear and requires lots of exploration and through good iteration driving towards the goal of good architecture. I try to weigh the needs of immediate action with long term Security & Engineering efforts while weighing the need of keeping the business going. The role of Information Security can sometimes be stressful especially in times where there is an incident and so I try to approach things with deep honesty as well as levity. I always keep failure in mind but don’t look at it as a dead end but rather an opportunity to learn how to get up and keep going.”

Requirements

  • A track record of writing production code and shipping changes that landed in real systems used by real users

  • Comfort working in unfamiliar codebases - reading through to root cause, opening PRs, and partnering with owning teams to get changes merged and deployed

  • Hands-on experience with cloud platforms (GCP preferred, Azure or AWS welcome), CI/CD pipelines, and infrastructure-as-code (Terraform or similar)

  • Deep technical understanding of multiple classes of security defects and how to design them out, not just catch them

  • Strong application security background - threat modelling, architecture review, SAST and DAST, secure SDLC - with the engineering chops to act on what you find

  • Working knowledge of AI and LLM security concerns - prompt injection, data exposure, model and tool-use supply chain - and a pragmatic view on how to build with AI safely

  • Comfort and fluency using AI engineering tooling (Claude Code/Gemini or similar) to ship work faster, with judgement about where to apply it and where not to

  • Experience with SIEM tooling - writing queries, building detections, running log analysis

  • Comfort partnering with SRE and Platform on production systems and shipping changes alongside them

  • Strong communication skills - explains the "why" behind security decisions in language engineers respect

  • Curiosity, low ego, and the ability to lead work independently in ambiguous territory

  • Models thoughtful, calm decision-making under pressure, especially in incidents

  • We are looking for people who demonstrate a strong alignment to our Guiding Principles (you can find these on our

    Careers page).

Benefits:

  • Competitive salary range: The hiring salary range for this role is $150,000-$170,000, depending on level of experience (this role has been scoped as IC4 level).

  • Annual bonus: Eligibility for a NZD $5,500 bonus at the end of the financial year if we’ve hit our revenue goals together.

  • Employee share scheme: You’ll own part of a company making a real difference!

  • Flexibility: We are hard-working and outcome focused, but recognise there is more to life than work. We promote a healthy work/life blend.

  • Shorter work weeks (at full pay): Everyone gets Friday afternoons off, so you can start your weekend early, and do more of whatever it is that makes you happy.

  • Health insurance: We prioritise looking after your health by covering 100% of your individual health insurance plan with nib.

  • Focus on mental and physical health: We understand how vital our health is and have policies to support your wellness, including Wellness Days, and up to $750 for expert sessions every year.

  • Family-friendly: We offer comprehensive paid parental leave - 12 weeks for birth parents and 6 weeks for non-birth parents following birth, adoption, or surrogacy, available to all Aurors from day one.

  • Personal growth: We support our team to participate in courses, conferences, or events that will help them develop their skills.

  • Team love: We have regular team lunches and social events where most (if not all) activities are during work hours.

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
368,530 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
Auckland
$25k – $42k per year • Equity 0–0.2% • Remote • Full-Time • 3+ years exp
Bash
Go
JavaScript
Python
TypeScript
DevOps
AWS
Azure
CI/CD
Datadog
Docker
GCP
GitHub Actions
GitLab CI
Grafana
Incident Management
Kubernetes
Platform Engineering
Prometheus
Terraform
Amazon CloudWatch
GitHub
GitLab
IAM
Cybersecurity
Least Privilege
Apply
$100k – $210k per year • Equity 0–0.5% • Remote • Full-Time • 3+ years exp • San Francisco
Bash
Go
JavaScript
Python
TypeScript
DevOps
AWS
Azure
CI/CD
Datadog
Docker
GCP
GitHub Actions
GitLab CI
Grafana
Incident Management
Kubernetes
Platform Engineering
Prometheus
Terraform
Amazon CloudWatch
GitHub
GitLab
IAM
Cybersecurity
Least Privilege
Apply
$100k – $200k per year • Equity 0.5–5% • In office • Full-Time • 1+ year exp • New York
Python
TypeScript
JavaScript
Python
FastAPI
Databases
DynamoDB
PostgreSQL
AI/ML
Claude
LLM
OpenAI
AI Agents
Frontend
Next.js
Tailwind CSS
React.js
DevOps
AWS
Docker
Vercel
GitHub
Management
Slack
Apply
$230k – $300k per year • Equity 0.1–0.2% • In office • Full-Time • 3+ years exp • PhD • New York
TypeScript
Databases
PostgreSQL
AI/ML
AI Agents
Claude
Claude Code
Cursor
Devin
OpenAI Codex
Frontend
Next.js
tRPC
DevOps
Platform Engineering
Vercel
Apply
Team Lead DevOps 1 day ago
$23k – $62k per year (Estimated) • Remote • 5+ years exp • Moscow
Bash
Python
Erlang
Erlang
EMQX
Databases
Apache Kafka
ClickHouse
PostgreSQL
RabbitMQ
Redis
Redpanda
Trino
DevOps
Ansible
AWS
AWX
FinOps
HAProxy
Hetzner
Kubernetes
SLI/SLO/SLA
Terraform
Yandex Cloud
Amazon S3
Apply
$59k – $71k per year • Remote • Auckland
C#
TypeScript
JavaScript
C#
.NET
AI/ML
LLM
Frontend
React.js
DevOps
Azure
Apply
$120k – $150k per year • Remote/Hybrid • Full-Time • Auckland
C#
TypeScript
JavaScript
C#
.NET
AI/ML
LLM
AI Agents
Frontend
React.js
DevOps
Azure
Apply
$83k – $124k per year • Remote
Apply
$71k – $101k per year • Remote
C#
TypeScript
C#
.NET
Databases
Snowflake
DevOps
Azure
GCP
Apply
$71k – $89k per year • Remote/Hybrid • Full-Time • Auckland
C#
TypeScript
C#
.NET
Databases
Snowflake
DevOps
Azure
GCP
Apply
Remote • Full-Time • 6+ years exp • Auckland
C#
C#
.NET
AI/ML
AI Agents
DevOps
AWS
Azure
Apply
Remote/Hybrid • Full-Time • Wellington • Auckland
Go
Apply
In office • Full-Time • 10+ years exp • Auckland • Wellington
Apex
Marketing
Salesforce
Apply
In office • Full-Time • 3+ years exp • Auckland • Wellington
Apex
Marketing
Salesforce
Apply
Remote/Hybrid • Full-Time • Auckland • Wellington
Python
DevOps
AWS
Cybersecurity
MITRE ATT&CK
Apply
See all jobs
This is one of many
368,530 more open roles from verified company boards, updated every day.