1,389,218open jobs
80,412companies
207,731added this week
Browse all
Salary
≈ $88k – $205k per year (Estimated)
Location
Hybrid (Wellington, Auckland, New Zealand, Sydney, Melbourne, Australia)
Seniority
Senior
Employment
Full-Time

Confirmed on the employer's own hiring board on Oct 9, 2026. First seen by Alion on Oct 7, 2026. Xero scores A on the Alion truth index.

Overview
Company
Impact
Profile match
Xero is a New Zealand company founded in 2006 that built cloud accounting software for small businesses at a time when the category was dominated by desktop packages, and it grew by selling through accountants rather than around them. Its platform handles bookkeeping, invoicing, bank reconciliation, payroll and reporting, and it maintains an app marketplace of over a thousand integrations that extends it into industry-specific workflows. Headquartered in Wellington and listed in Australia, it holds a leading position in New Zealand, Australia and the United Kingdom and has spent years attempting to establish itself in the United States against Intuit.
Backed by TCV, Valar Ventures

The role and its impact

When something goes wrong in security at Xero, our Response team are first on the scene. We're looking for a Senior Security Operations Analyst who loves incident response, enjoys building things, and wants a hand in shaping what a SOC looks like when AI agents are part of the team.

You'll lead our complex investigations and take command of medium and high impact incidents, keeping people calm, decisions moving and stakeholders in the loop. When things settle down, you'll make sure what we learnt changes something, whether that's a detection, a runbook or the way we train.

You'll also help us build. Our Analysts improve the queue as well as working it, so part of your time will go on creating automations and AI-assisted workflows that take repetitive work off the team and leave more room for the investigations that need a person.

The team and how they connect

Response is a follow-the-sun global team. You'll be in the Southern Hemisphere half, based in New Zealand or Australia, and at the end of your day you'll hand over to colleagues in the UK and North America, who hand back to us the next morning. You'll work business hours in your time zone and take a share of our on-call roster for after-hours incidents.

You won't be doing it on your own. You'll join a cohort of Senior Analysts who share the load on complex work and lead our initiatives, with a Lead Analyst alongside for the hardest problems. Our XFLT, a cross-functional leadership team of Security Operations Managers, our Lead Analyst and our Product Manager, sets the direction and clears the way, so there's always someone to think out loud with.

The team is currently working on / Initially, you will focus on

We're building towards an agentic SOC, where AI agents and automation carry more of the first pass, and analysts direct them and step in where judgement matters. We're working through it carefully: which low-risk work agents can take on, where the guardrails and human approvals belong, and how we'll know it's working. People still make the big calls, because our robots aren't that good yet.

You don't need to be an AI expert. We'd love you to be curious, to have tried a few things, and to want to help us get this right.

You’ll also:

  • Lead complex investigations and step up as Incident Commander for medium and high impact incidents

  • Be a go-to escalation point for our Graduate, Associate and Analyst crew, and coach them through the tricky stuff

  • Run post incident reviews that lead to real change in detections, runbooks and training

  • Lead initiatives with our Product Manager and Security Operations Managers, turning goals into work that gets delivered

  • Build and improve automations and AI-assisted workflows, with guardrails and human sign-off where they matter

  • Work with our Defence engineers on detection and response logic, and test new capabilities in real incidents

  • Turn threat intelligence into practical action for Xero

  • Give customers and internal teams clear, timely answers to their security concerns

Where and how you can work

We support a flexible working model that empowers you to balance your professional and personal life. You will have the option to work in a hybrid capacity, combining the focus of remote work with the collaboration of our office spaces and team boost days to foster connection and alignment.

Here are some of the things we're looking for

Incident response comes first for us, so we're looking for:

  • Solid experience in security operations, and a real passion for incident response

  • A track record of leading complex investigations and incidents through to resolution, including coordinating people and making calls under pressure

  • Sound technical judgement and good knowledge of attack and defence techniques, particularly in cloud and SaaS environments

  • Confidence writing queries in a SIEM or log platform

  • Clear, calm communication and a generous approach to sharing what you know

It'd be great if you also have:

  • Scripting skills (Python or similar) and experience building automations in a SOAR platform. We use Tines, and we're happy to teach it.

  • Hands-on experience with AI tools in security work, or a clear view of where they help and where they don't

  • Intermediate or advanced certifications in incident response, threat hunting or cloud security

  • Experience in a distributed team working across time zones

If you're strong on incident response and the builder side is still growing, we'd still love to hear from you.

You'll do work that matters to millions of small businesses and their advisors, in a team that shares what it knows and backs each other up, with a real say in how an AI-powered SOC works in practice.

Apply even if your experience isn't a perfect match! At Xero, we hire based on your skills, passion, and the unique perspective you can bring to enhance our culture and team.

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
1,389,218 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account Continue with Google
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Security
Similar stack
Same company
Wellington
≈ $80k – $187k per year (Estimated) • Hybrid • Full-Time • Auckland
AI/ML
Copilot
AI Agents
DevOps
Azure
Cybersecurity
Microsoft Sentinel
Microsoft Defender
Microsoft Defender for Cloud
Apply
≈ $57k – $158k per year (Estimated) • Hybrid • Full-Time • Wellington
Apply
≈ $39k – $89k per year (Estimated) • In office • Full-Time • Jakarta
Apply
Security Engineer 24 min ago
≈ $31k – $87k per year (Estimated) • In office • Full-Time • Jakarta
AI/ML
Red Teaming
DevOps
Kali Linux
Linux
Cybersecurity
Metasploit
Crowdstrike
Nmap
OWASP ZAP
ISO 27001
OWASP Top 10
IBM QRadar
Sophos
SIEM
Apply
≈ $102k – $239k per year (Estimated) • Remote (United States, Netherlands) • Top Secret • 7+ years exp • Bachelor's Degree
Databases
Databricks
AI/ML
AI Agents
LLM
DevOps
GCP
Azure
AWS
Cybersecurity
SIEM
Apply
≈ $37k – $70k per year (Estimated) • Hybrid • 5+ years exp • Moscow
Python
JavaScript
PHP
PHP
Bitrix
AI/ML
LangChain
Claude
ChatGPT
LlamaIndex
Prompt Engineering
AI Agents
DevOps
Rest API
Git
Docker
Management
n8n
Apply
In office • Shenzhen
SQL
AI/ML
AI Agents
LLM
Apply
DevOps Principal 1 day ago
≈ $73k – $181k per year (Estimated) • In office • Full-Time • Cairo
Python
Go
PowerShell
Bash
DevOps
Terraform
GCP
Azure DevOps
GitHub Actions
Istio
OpenTelemetry
GitLab CI
Azure
CI/CD
GitOps
ArgoCD
Jenkins
Git
AWS
Kubernetes
Platform Engineering
Service Mesh
Amazon EKS
Google GKE
Azure AKS
FinOps
IAM
Windows
Cybersecurity
Kyverno
Apply
≈ $8.5k – $21k per year (Estimated) • In office • 1+ year exp • Bachelor's Degree • George Town
AI/ML
AI Agents
DevOps
HPC
Apply
Credit Accountant 1 day ago
≈ $8k – $20k per year (Estimated) • In office • 1+ year exp • Bachelor's Degree • George Town
AI/ML
AI Agents
DevOps
HPC
Management
Microsoft Office
Apply
≈ $87k – $201k per year (Estimated) • Hybrid • Full-Time • Wellington • Auckland • Sydney • Melbourne
Python
DevOps
Terraform
GCP
Azure
AWS
IAM
Management
Xero
Apply
≈ $86k – $199k per year (Estimated) • Hybrid • Full-Time • Sydney • Melbourne
Python
DevOps
AWS
Cybersecurity
MITRE ATT&CK
SIEM
Management
Xero
Apply
Hybrid • Full-Time • Melbourne • Sydney
Python
Go
JavaScript
TypeScript
AI/ML
LangGraph
LangChain
Function Calling
AI Agents
Pydantic AI
Tool Use
Frontend
React.js
DevOps
CI/CD
Git
Management
Xero
Apply
Hybrid • Full-Time • Melbourne
C#
C#
.NET
DevOps
CI/CD
AWS
Kubernetes
Management
Xero
Apply
Search Engineer 1 day ago
≈ $67k – $144k per year (Estimated) • Hybrid • Full-Time • Melbourne • Sydney • Canberra • Brisbane
Management
Xero
Apply
$45k – $56k per year • In office • Top Secret • Wellington
Apply
Hybrid • Full-Time • 1+ year exp • Wellington
Apply
≈ $82k – $195k per year (Estimated) • In office • Wellington
Apply
$89k – $108k per year • Hybrid • Full-Time • Wellington
Analytics
Power BI
Management
Power Automate
Apply
≈ $44k – $119k per year (Estimated) • In office • Wellington
Apply
See all jobs
This is one of many
1,389,218 more open roles from verified company boards, updated every day.