Lead Security Operations Analyst

3 weeks ago


Wellington City, New Zealand Xero Full time

Xero is a beautiful, easy-to-use platform that helps small businesses and their accounting and bookkeeping advisors grow and thrive.

At Xero, our purpose is to make life better for people in small business, their advisors, and communities around the world. This purpose sits at the centre of everything we do. We support our people to do the best work of their lives so that they can help small businesses succeed through better tools, information and connections. Because when they succeed they make a difference, and when millions of small businesses are making a difference, the world is a more beautiful place.

**About the role**

As the Lead Security Operations Analyst you will work with internal Xero teams and 3rd party security service providers to monitor, detect and respond to events impacting the security of Xero and its customers.

You'll be expected to take a leading role in the Security Operations team from a technical perspective; demonstrating an EQ-driven approach in collaborating with and communicating and delivering to stakeholders across Xero.

As part of a 24 x 7 Security Operations capability, you will lead the triaging & investigation of alerts received from the SIEM and other sources. This will involve working with CX and Legal counterparts to ensure we communicate to regulatory authorities and customers in a timely manner; documenting standards and defining requirements and working with the other security teams to ensure these operational security standards are communicated and met across Xero.

You will take ownership of invoking and managing the Security Incident Response Plan, performing root cause analysis and recommend security improvements.

Whilst we don't need you have to used all the tools we do, we hope you have exposure to some of the following:

- Using a SIEM toolset to monitor alerts. E.g. Sumo logic, Splunk, Microsoft Sentinel, ELK stack. Ideally, you would be versed in understanding and contributing to detection logic that sits behind the SIEM tool.
- Using a SOAR function to perform automatic response and remediation actions within the SIEM.
- Using the AWS platform from a security detection and response perspective, e.g. reviewing CloudTrail logs, investigating anomalies in AWS accounts, reviewing GuardDuty alerts.
- Investigating alerts from an Endpoint Detection and Response (EDR) toolset e.g. Crowdstrike Falcon, Microsoft Defender for Endpoint, SentinelOne.
- Leading security incidents as an incident manager, and directing detection, containment, eradication, and recovery efforts.
- Performing windows and linux forensics in a cloud environment. Threat hunting and cyber threat intelligence would also be ideal.

**What you'll do**:

- Define requirements to automate and continuously improve the efficiency of threat detection, alerting and response.
- Exploit security tools to continuously improve the detection, prevention and analysis of security incidents.
- Keep informed as to emerging security threats that have the potential to impact Xero and implement/recommend mitigating strategies. Utilise available threat intelligence sources to inform and improve attack detection techniques.
- Ensure the analyst team develops and maintains security operations playbooks and runbooks in support of the Security Incident Response Plan.
- Coach and mentor members of the security operations team to increase the technical efficacy of the team
- Assist the people leader with people-focused tasks including recruitment, training and development.
- Mentor pod team members from other disciplines about security operations and raise awareness of security and operational concerns as a key consideration of product development.
- Have a influential role in the development of the SOC design and how the tools and resourcing requirements to achieve this might be established
- Be actively engaged with the Product Owner to shape and develop the roadmap for Defense and Response Pods

**What you'll bring**:

- Previous experience in a role within the Information Security Practice
- Extensive experience in security operations.
- Proven experience in developing and maintaining a highly motivated team of individuals.
- Been recognised as a technical lead or the senior contributor in your team.
- Strong coordination and incident management skills.
- Excellent stakeholder management.
- Fast learner, detail oriented, decisive, and enjoys fast paced work environment.

Our collaborative and inclusive culture is one we’re immensely proud of. We know that a diverse workforce is a strength that enables businesses, including ours, to better understand and serve customers, attract top talent and innovate successfully. At Xero we embrace diversity and inclusion and value a #challenge mindset.

Xero is an NZ Immigration Accredited Employer and Rainbow Tick certified too.



  • Wellington City, New Zealand Government Communications Security Bureau Full time

    The secret to our success is our people. While we are ordinary people, we are not all the same. We welcome diversity, in all its forms, in fact we consider it a strength. Join us and work at the heart of national security to protect New Zealand and New Zealanders. We are currently recruiting Analysts to join our dedicated, driven and delivery focussed...


  • Wellington, Wellington, New Zealand First Security Full time

    Operations Security Supervisor - Wellington Add expected salary to your profile for insights Operations Security Supervisor - WellingtonJoin Our Elite Security Team Are you a seasoned security professional with a passion for protecting what matters most? Do you thrive in environments where integrity and vigilance are paramount? If so, we invite you to become...


  • Wellington City, New Zealand ANZ Banking Group Full time

    **Date**: 13-Apr-2023 **Location**: Wellington, NZ **Company**: ANZ Banking Group Limited About the role At ANZ our purpose is to shape a world where people and communities thrive. We’re making this happen by improving the financial wellbeing and sustainability of our customers so they can achieve incredible things - whether they’re buying a home,...

  • Security Analyst

    2 weeks ago


    Wellington City, New Zealand New Zealand Government Full time

    We are looking for an experienced analyst to join our Security team who are ensuring New Zealand's Parliament is always open, accessible, efficient, safe, and secure. Te tĪma - The team The Security Group is responsible for providing security services to members of Parliament, staff, contractors, stakeholders, visitors, and customers who work within and...

  • Security Analyst

    2 weeks ago


    Wellington City, New Zealand New Zealand Parliament Full time

    We are looking for an experienced analyst to join our Security team who are ensuring New Zealand's Parliament is always open, accessible, efficient, and safe and secure. **Te tĪma | The team**: The Security Group is responsible for providing security services to members of Parliament, staff, contractors, stakeholders, visitors, and customers who work...

  • Security Analyst

    4 weeks ago


    Auckland City, New Zealand Potentia Full time

    **Overview** Our client is New Zealand’s leading electronic payments company and Kiwis rely on us to ensure that electronic purchasing is available wherever purchases for goods and services need to be made. In our history to date, we have put through a whopping 16 billion transactions, worth an estimated $700B, and have worked with over 120,000 merchants....


  • Wellington City, New Zealand Absolute IT Recruitment Specialists Full time

    Wellington- Security- NZD115000 - NZD130000 per annum- Full Time- Permanent- 20 Mar 2023- **Passion for Information Security**: - **SentinelOne, Cloud based Azure AD/Office 365 solutions, Splunk**: - **Permanent role based in Johnsonville + attractive benefits** **ABOUT THE ROLE** The Security Analyst will be responsible to Develop and promote security...


  • Wellington City, New Zealand H2R Consulting Full time

    **Location**: Wellington Type: Contract Reference: 862570 Join a NZ wide known Organisation as a Principal Security Analyst or Senior Security Analyst to support a large transformation programme that is seeking to move from on premise technology to a multi cloud environment, replace end of life systems, and introduce modern secure enterprise...

  • IT Security Analyst

    4 weeks ago


    Wellington City, New Zealand New Zealand Government Full time

    About us The Ministry of Social Development is a people-centred organisation. We're in communities across the motu, working with partners to help New Zealanders be safe, strong and independent. We provide social policy and advice to government and assistance, including income, employment and housing support to people of all ages, families, whānau and...


  • Wellington City, New Zealand Government Communications Security Bureau Full time

    The secret to our success is our people. While we are ordinary people, we are not all the same. We welcome diversity, in all its forms, in fact we consider it a strength. Join us and work at the heart of national security to protect New Zealand and New Zealanders. The National Cyber Security Centre is more than a great place to work; our workforce tackles...


  • Auckland City, New Zealand TOWER Insurance Full time

    **Why you'll love working with Tower** At Tower, we live and breathe our values - they are at the heart of every interaction. **Our people come first, **we pride ourselves on creating a diverse and inclusive space that allows our people to thrive. Encouraging everyone to bring their whole selves to work, we aim to represent the diverse communities we work...


  • Wellington City, New Zealand Accident Compensation Corporation Full time

    **Te āhua o Te Tūrunga - The nature of the role** ACC have an exciting new piece of work and are ramping up resources to assist with the planning and design phase. We are currently building new Salesforce teams and are looking for a Senior Information Security Analyst to assist with this work. Reporting into the Chief Information Security Officer, the...


  • Wellington City, New Zealand New Zealand Government Full time

    About us The Ministry of Social Development is a people-centred organisation. We're in communities across the motu, working with partners to help New Zealanders be safe, strong and independent We provide social policy and advice to government and assistance, including income, employment and housing support to people of all ages, families, whānau and...

  • Security Operations

    3 weeks ago


    Auckland City, New Zealand Potentia Full time

    **Company profile**: Our client is an award-winning brand that is renowned for coming up with innovative solutions and keeping the environment at the forefront of everything they do. Their current goal is to be the leading brand in their sector in the coming year. **The opportunity**: A household name in the NZ utility sector, security is imperative for...

  • Security Lead

    3 weeks ago


    Wellington City, New Zealand New Zealand Parliament Full time

    We're looking for an exceptional leader to join our energetic, dynamic and high performing security operations team. - Unique, challenging and highly rewarding role - Opportunities for professional development - We're gearing up for Election 2023 **Te tĪma **| **The team**: Our Security Group is committed to providing comprehensive security services to New...


  • Wellington City, New Zealand H2R Consulting Full time

    **Location**: Wellington Type: Permanent / Full Time Reference: 854612 Currently supporting an enterprise sized organisation recruit a Senior IT Security Analyst to support the monitoring, uplift, and maintenance of a large inhouse technology environment which has brought its security capability in house. This is a senior position where your...

  • Security Analyst

    2 weeks ago


    Auckland City, New Zealand Momentum Consulting Group Full time

    Rare DevSec opening - 6 month contract - Central Auckland offices with flexible work - Rare DevSec opening - 6 month contract - Central Auckland offices with flexible work **About the client**: Our client is New Zealand's leading electronic payments company, dedicated to providing accessible electronic purchasing options for goods and services. Over the...


  • Wellington City, New Zealand Government Communications Security Bureau Full time

    The secret to our success is our people. While we are ordinary people, we are not all the same. We welcome diversity, in all its forms, in fact we consider it a strength. Join us and work at the heart of national security to protect New Zealand and New Zealanders. We are recruiting for Senior Vetting Analysts in Wellington or Auckland. We are looking for...


  • Auckland City, New Zealand ANZ Banking Group Full time

    An exciting opportunity for an experienced Analyst! A collaborative and innovative work environment Ongoing professional development and career building opportunities Your Mission The mission of Cyber Defence - Security Operations squad is to protect the bank from cyber threats and to ensure that our systems remain secure and available. We want our...


  • Wellington City, New Zealand New Zealand Government Full time

    About us The Ministry of Social Development is a people-centred organisation. We're in communities across the motu, working with partners to help New Zealanders be safe, strong and independent. We provide social policy and advice to government and assistance, including income, employment and housing support to people of all ages, families, whānau and...