Senior Security Risk

4 days ago


Auckland City, New Zealand Xero Full time

Xero is a beautiful, easy-to-use platform that helps small businesses and their accounting and bookkeeping advisors grow and thrive.

At Xero, our purpose is to make life better for people in small business, their advisors, and communities around the world. This purpose sits at the centre of everything we do. We support our people to do the best work of their lives so that they can help small businesses succeed through better tools, information and connections. Because when they succeed they make a difference, and when millions of small businesses are making a difference, the world is a more beautiful place.

**About the role and team**

The **Senior Security Risk & Compliance Specialist (M&A) **will work as part of the **Security Risk and Compliance team.** We are a large, global team who are as warm and friendly as we are astute and knowledgeable. As part of the team, you will be working with all parts of the business to improve Xero’s security risk and compliance posture, to reduce the risk of security incidents and improve the efficiency and effectiveness of Xero’s security controls. This role has a focus on Xero’s **Mergers and Acquisitions **portfolio but as part of the broader team you will be expected to contribute to other initiatives and will have the opportunity to learn about a broad range of topics in the course of your work.

**What you'll bring with you**:

- Experience working with M&A in the GRC (Governance, Risk and Compliance) space
- Experience with Regulatory Compliance Frameworks
- Experience with mentoring

**What you’ll do**:

- Ensure security risk and compliance obligations, both internally defined and externally regulated, are understood and met across Xero and its subsidiaries.
- Contribute towards the maintenance of the Xero information security management framework. Ensure that security policy and standards keep pace with the changing threat and compliance landscape, and are approved and communicated across Xero.
- Engage with and manage service providers delivering services and capabilities related to Xero’s security risk and compliance practice.
- Further develop and manage security risk and compliance frameworks and processes to ensure risks are documented, quantified, owned, communicated and escalated as appropriate across Xero.
- Assist in the development of security awareness materials and training for Xero staff.
- Respond to customer and supplier security assessments.
- Define requirements and assess solutions to automate and improve the efficiency of risk assessment, compliance management and reporting processes.
- Keep informed as to emerging security threats that have the potential to impact Xero and recommend mitigating strategies.
- Provide measurement and reporting of Xero’s risk and compliance position suitable for various levels of Xero’s leadership.
- Coach and mentor other team members to help them become the best versions of themselves they can be, using a variety of techniques which may include performance feedback and career development.
- Mentor product team members from other disciplines about security risk and compliance and raise awareness of risk and compliance concerns as a key consideration of product development.

**M&A Specific Responsibilities**:

- Perform Security Due Diligence activities for potential M&A targets and identify, assess, and report on related information security risks.
- Work with cross-functional and technical teams to perform gap analysis, identify integration requirements and security uplift opportunities, and monitor integration and remediation work to ensure alignment with desired security outcomes.
- Maintain and continually improve artifacts pertaining to M&A Security workstreams, ensuring alignment with all industry regulations, standards, and compliance requirements.
- Collaborate with subsidiaries on audit preparation, control scope and ownership, and remediation of findings to provide clarity and ensure successful compliance outcomes, dependent on integration model.
- Provide guidance and advice to the Integration Management team and Technical teams on security risk and compliance concerns and related issues throughout the M&A lifecycle.
- Demonstrate effective project management processes to work collaboratively across Xero and its subsidiaries.

**Why Xero**
- Offering very generous paid leave to use however you’d like (plus statutory holidays), dedicated paid leave to care for your physical and mental wellbeing as well as an Employee Assistance Program to access mental health care for you and your family, free medical insurance, wellbeing and sports programmes, employee resource groups, 26 weeks of paid parental leave for primary caregivers, an Employee Share Plan, beautiful offices, flexible working, career development, and many other benefits that reflect our human value, you’ll do the best work of your life at Xero.

Our collaborative and inclusive culture is one we’re immensely proud of. We



  • Auckland City, New Zealand 2degrees Mobile Limited Full time

    At 2degrees, our mission is to Fight for Fair. Join us and be part of a crew that's customer obsessed, challenges norms, owns it and cares for our people! Lead our security risk management framework and embed a risk-aware culture across 2degrees. **Senior Security Risk Advisor** **Your role, your journey | Te Huarahi Whakatipu** Want to make a real...


  • Auckland, Auckland, New Zealand BC Security Ltd Full time NZ$90,000 - NZ$120,000 per year

    Company DescriptionBC Security Ltd. possesses extensive expertise in Electronic Security Systems, including Electric Fencing and Door Automation. We provide comprehensive services encompassing Design, Installation, Service, and Maintenance. Our team is committed to delivering high-quality security solutions tailored to our clients' needs.Role DescriptionThis...


  • Wellington City, New Zealand Government Communications Security Bureau Full time

    Join our diverse and talented people and work at the heart of national security, providing essential intelligence to the NZ government to protect New Zealand and its people. About us The National Cyber Security Centre (NCSC) is the heart of Aotearoa New Zealand's cyber defence. We fulfil the cyber security responsibilities of the Government Communications...

  • Risk, Security

    4 days ago


    Wellington City, New Zealand New Zealand Customs Service Full time

    Help protect NZ Customs | Te Mana Ārai and its people - Looking for your next step in security or risk? Come join us as a Risk, Security & Assurance Advisor We have two positions available for Risk, Security & Assurance Advisors - join the Customs Whanau! As part of our Risk, Security and Assurance (RS&A) team you'll be helping to provide Customs'...

  • Security Risk Analyst

    2 weeks ago


    Wellington City, New Zealand New Zealand Government Full time

    The Ministry acts in the world to build a safer, more prosperous and more sustainable future for New Zealanders. Kia hangai ake e te Manatu he ao-haumaru, ao-tonui, ao-pumau, ki te oranga tonutanga mo Aotearoa whanui. - Do you have knowledge of risk terminology and assessment methodologies? - Produce evidence-based reporting and advice - Contribute to the...


  • Auckland City, New Zealand RWA Technology People Full time

    Strong DevSecOps, Azure Security Center, Azure Active Directory - CISSP, CISM, CCSP, PCI-DSS - 6 months contract Our Client is looking for a capable and passionate Senior Security Specialist to join their highly motivated and knowledgeable team of security professionals. Ideally looking for someone experienced working in Development...


  • Auckland City, New Zealand Fidelity Life Full time

    Flexible working options available - Supportive, collaborative team environment **The opportunity** *** We are on the lookout for an **Information Security Governance, Risk and Compliance Manager** to join us. This is a full time, permanent position based in Auckland, and we offer a fully flexible working approach. The Information Security Governance,...


  • Wellington City, New Zealand New Zealand Ministry of Justice Full time

    **Senior Risk Management Consultant** Welcome to the new Resilience and Assurance Services Team. This is an exciting time for us as we look to implement and embed our new operating and service delivery model. So, what are we striving to be? - Credible thought leaders in the development and implementation of Risk Management, Information Security (Physical,...

  • Security Officer

    2 weeks ago


    Auckland City, New Zealand Defence Line Security Limited Full time

    Defence Line Security Limited, based in Auckland has several vacancies of security guards to meet its growing demands. The role is full-time and permanent with a pay of $29.66 per hour with a minimum of 30 hours per week. Requirements: - Must have a valid driver's licence - Secondary school qualification - Clean police record - Physical fitness and ability...


  • Wellington City, New Zealand New Zealand Government Full time

    Welcome to the new “Resilience and Assurance Services” Team. This is an exciting time for us as we look to implement and embed our new operating and service delivery model. So, what are we striving to be? - Credible thought leaders in the development and implementation of Risk Management, Security (Physical, Personnel and Cyber), Privacy, Business...