Lead the Vulnerability Management team, ensuring effective processes for identifying and remediating vulnerabilities across systems, while fostering a collaborative culture and embedding security throughout the software development lifecycle.
Our Purpose
At Xero, we’re here to help you supercharge your business. We do this by automating routine tasks, surfacing actionable insights and connecting businesses with the right data, advisors and apps. When that happens, we’re not only making life better for small business, we’ll be building a stronger economy that can change the world.
About the role
This role will be responsible for leading a team focused on the identification, triage, and remediation of vulnerabilities across Xero’s systems and platforms.
As an expert in this space, you’ll ensure vulnerability management processes are integrated, automated, scalable, and risk-informed, reducing exposure while enabling teams to move fast and ship securely. As a dedicated and proven people leader, you'll foster a high-performing, collaborative culture that empowers your team and partner teams to own security outcomes. We're looking for somebody with a passion for developer enablement, making security accessible and empowering engineers to write secure code.
Your work will directly influence Xero’s security posture, operational resilience, and ability to respond swiftly and confidently to evolving threats.
As a engineering leader at Xero we expect you to come with high EQ, being self-aware, self-regulated, motivated and empathetic, with great interpersonal skills. You'll lead and live our vision and values – building and fostering an inclusive and positive team culture.
What you'll do
- Lead and grow a high-performing team by coaching, mentoring, and connecting their work directly to Xero's strategic goals; ensuring alignment with Xero’s security engineering and risk management strategy.
- Support the complete vulnerability management process, including discovery, risk assessment, triage, remediation coordination, and reporting. Ultimately building scalable and automated processes for vulnerability scanning and detection across infrastructure, cloud environments, and applications.
- Partner with various other teams across security, engineering, platform, and product; ensuring timely and effective remediation and removing of roadblocks, embedding security throughout Xero's software development lifecycle.
- Drive risk-based prioritisation of vulnerabilities using contextual threat intelligence, asset criticality, and exploitability data.
- Evaluate and integrate security tooling such as vulnerability scanners, container/image security tools, infrastructure-as-code scanning, and runtime security platforms.
- Implement metrics and dashboards that provide real-time visibility of security posture, vulnerability trends, and remediation progress. Continuously improve team processes to reduce response time, improve consistency, and align with evolving threats and compliance obligations.
What you'll bring with you
- People leadership, demonstrating honesty and integrity. Proven track record of leading teams to deliver high-quality engineering initiatives in a fast-paced environment, leveraging lean-agile techniques, while managing competing priorities and ensuring alignment with strategic goals.
- Coaching and mentoring; utilising software delivery, technical experience and expertise, offering the right knowledge, at the right time in the right way – understanding why and how people learn.
- Strong domain expertise in vulnerability management. Ideally operating or leading a vulnerability management program at scale, in a cloud-native or SaaS environment; understanding of vulnerability types (CVE/CWE), risk prioritisation (e.g., CVSS, EPSS), and remediation strategies.
- Strong stakeholder management skills, with the ability to influence without authority and align security priorities with business needs.
- Familiarity with security tooling such as Qualys, Tenable, Wiz, or similar; and integration into CI/CD and DevOps workflows.
- Hands-on experience with infrastructure, cloud platforms (e.g., AWS, GCP), containerisation, and related security concerns.
Research has shown that women and underrepresented groups are less likely to apply to jobs unless they meet every single competency or experience . If you are excited about this role, but your past experience doesn't align perfectly, we encourage you to apply anyway. You could be just the right person for this role and Xero. If you have any support or access requirements, we encourage you to advise us at time of application and throughout the interview process.
Why Xero?
Offering very generous paid leave to use however you’d like (plus statutory holidays!), dedicated paid leave to care for your physical and mental wellbeing as well as an Employee Assistance Program to access mental health care for you and your family. Health insurance, life insurance, and income protection.
We offer wellbeing and sports programmes, employee resource groups, 26 weeks of paid parental leave for primary caregivers, an Employee Share Plan, beautiful offices, flexible working, career development, and many other benefits that reflect our human value.
You’ll do the best work of your life at Xero!
Top Skills
AWS
GCP
Qualys
Tenable
Wiz
Xero Hawthorn West, Victoria, AUS Office
Xero Melbourne (HQ) Office
Xero’s head office in Australia is in the buzzing suburb of Hawthorn, a stone’s throw from the CBD. Here, a diverse mix of Xeros work in both global and regional teams.
Similar Jobs at Xero
Cloud • Fintech • Information Technology • Machine Learning • Software
The National Account Manager will manage relationships with accounting partners, driving sales growth, coordinating training, and supporting client migration to the Xero platform.
Top Skills:
Salesforce
Cloud • Fintech • Information Technology • Machine Learning • Software
As Team Lead in Application Security, you'll guide the AppSec teams, integrate security into the software lifecycle, ensure secure coding, and mentor staff.
Top Skills:
Ci/CdDastSastSca
Cloud • Fintech • Information Technology • Machine Learning • Software
The Principal Engineer at Xero leads multi-team engineering strategies, influences technical direction, fosters team culture, and collaborates closely with stakeholders.
Top Skills:
AWSGCP
What you need to know about the Melbourne Tech Scene
Home to 650 biotech companies, 10 major research institutes and nine universities, Melbourne is among one of the top cities for biotech. In fact, some of the greatest medical advancements were conceptualized and developed here, including Symex Lab's "lab-on-a-chip" solution that monitors hormones to predict ovulation for conception, and Denteric's vaccine for periodontal gum disease. Yet, the thousands of people working in the city's healthtech sector are just getting started, to say nothing of the tech advancements across all other sectors.