What you'll do
- Lead, develop, and grow high-performing AppSec Engineering and AppSec Consulting teams by providing coaching, mentorship, ensuring alignment with Xero’s security and engineering strategy.
- In partnership with the Security Product team, develop and execute the Application Security roadmap; embedding security best practices throughout Xero’s software development lifecycle, from architecture and design to testing and deployment.
- Drive the implementation and maintenance of security tools and technologies, partnering with engineering teams to shift security left, integrating automated security testing, secure coding practices, and DevSecOps methodologies.
- Provide technical oversight and mentorship, ensuring application security risks are well-understood, prioritised, and mitigated effectively.
- Collaborate closely with security, engineering, and product teams to embed security at every stage of the development process, balancing application security requirements with developer productivity and business agility.
- Collaborate with the Sec-Education team to provide regular workshops and training on application security matters, enhancing understanding of application risks for relevant employees.
- Foster a culture of security enablement, where developers and engineers feel supported in building secure products.
What you'll bring with you
- People leadership, demonstrating honesty and integrity. Proven track record of leading teams to deliver high-quality software in a fast-paced environment, leveraging lean-agile techniques, while managing competing priorities and ensuring alignment with strategic goals.
- Coaching and mentoring; utilising software delivery, technical experience and expertise, offering the right knowledge, at the right time in the right way – understanding why and how people learn.
- Strong domain expertise in Application Security (AppSec) with experience in securing modern software applications.
- Experience with security tooling, including SAST, DAST, SCA, and security automation within CI/CD pipelines.
- Deep understanding of secure coding practices, DevSecOps, threat modeling, security architecture, and application risk management.
- Strong stakeholder management skills, with the ability to influence without authority and align security priorities with business needs.
Similar Jobs
What We Do
Xero is small business accounting software that provides a platform on which businesses can build a fully integrated solution. It’s designed to make life better for people in small business, their advisors, and communities around the world. Xero minimises tedious admin by automating routine tasks, delivers valuable insights when needed, and brings together business data, trusted advisors, and powerful apps in one intuitive platform. By alleviating pain points, Xero empowers small business owners to supercharge their business, simplifying the complex and freeing up time from manual admin so they can focus on what really matters to build the business they’ve always envisaged.
Why Work With Us
We believe that by simplifying the complex we're not only making life better for small business, we’re helping to create a stronger, more vibrant economy. When you join this team, you’re impacting local communities, on a global scale.
Gallery










Xero Teams
Xero Offices
Hybrid Workspace
Employees engage in a combination of remote and on-site work.
Join us from home or at one of our beautiful workspaces. Xero has offices in Australia, New Zealand, United Kingdom, United States, Canada, Singapore, and South Africa.