Talent.com
This job offer is not available in your country.
Team Lead - Application Security

Team Lead - Application Security

XeroWellington, Wellington, New Zealand
25 days ago
Job description

Our PurposeAt Xero, we're here to help you supercharge your business.

We do this by automating routine tasks, surfacing actionable insights and connecting businesses with the right data, advisors and apps.

When that happens, we're not only making life better for small business, we'll be building a stronger economy that can change the world.How you'll make an impactAs the Team Lead - Application Security, you will be responsible for establishing and leading two specialised AppSec teams : Application Security Consulting and Application Security Engineering and.

Your role is pivotal in creating and driving the successful execution of Application Security in Xero.

You will own the delivery of the AppSec roadmap.

You will ensure a proactive approach to embedding security into Xero's software development lifecycle (SDLC).

You will create an environment where your teams can perform at their best, predictably and sustainably, by fostering a strong secure-by-design / secure-by-default culture and empowering Xero's engineers to ship secure code at scale.

Your work will directly impact reducing software security risks and improving the overall security posture of Xero's internally developed applications.You will create an environment where your teams can perform at their best, predictably and sustainably, by fostering a strong secure-by-design / secure-by-default culture and empowering Xero's engineers to ship secure code at scale.

Your work will directly impact reducing software security risks and improving the overall security posture of Xero's internally developed applications.What you'll doBuild and lead the Application Security Engineering and Application Security Consulting teams, ensuring alignment with Xero's security and engineering strategy.Develop and execute the Application Security roadmap in partnership with the Security Product team, embedding security best practices throughout Xero's software development lifecycle, from architecture and design to testing and deployment.Drive the implementation and maintenance of security tools and technologies, and automate security processes within CI / CD pipelines through the AppSec Engineering team.Oversee the AppSec Engineering team in conducting security testing and vulnerability assessments focused on internally developed applications.Guide the AppSec Consulting team in the design of secure application infrastructure, the development of security frameworks and best practices, and collaboration with development teams on secure design patterns.Partner with engineering teams to shift security left, integrating automated security testing, secure coding practices, and DevSecOps methodologies.Provide technical oversight and mentorship, ensuring application security risks are well-understood, prioritised, and mitigated effectively.Work closely with product and engineering teams to balance application security requirements with developer productivity and business agility.Collaborate with the Sec-Education team to provide regular workshops and training on application security matters, enhancing understanding of application risks for relevant employees.As required, lead, develop, and grow high-performing AppSec Engineering and AppSec Consulting teams by providing coaching, mentorship, and setting a clear direction by connecting their work to the Technology and Xero's strategic objectives.Foster a culture of security enablement, where developers and engineers feel supported in building secure products.Collaborate closely with security, engineering, and product teams to embed security at every stage of the development process.Champion continuous improvement, leveraging industry best practices and emerging trends to refine application security approaches.Promote a culture of psychological safety and inclusion, ensuring all team members feel empowered to contribute and raise concerns.Success looks likeYour team implements developer-friendly security practices that reduce software security risks without slowing down development.Successfully delivers on the Application Security roadmap, embedding secure coding, threat modeling for projects, and automated security testing.Drives proactive application security initiatives that reduce the attack surface across Xero's applications.Provides strategic and technical guidance to ensure robust security measures are maintained for all applications.Works closely with engineering and platform teams to automate security practices within the development lifecycle.Provides insights on application security posture, ensuring leadership has clear visibility of risk trends and remediation progress relevant to applications.Your reports clearly understand how their work contributes to Xero's security and business success.Clearly understand their areas of development and their personal growth.

Feel supported in their career growth and technical development.Actively collaborate with engineering teams, breaking down silos and fostering a culture of shared security responsibility.Are empowered and challenged to do their best work and their skills are continuously being developed through new learnings and experiences.Contribute to security knowledge-sharing across Xero, empowering product teams to take ownership of security within their domains.Are recognised and celebrated for good performance, and effectively managed when performing poorly.Are supported to produce the best work of their lives by your understanding and ability to remove barriers.What you'll bring with youStrong domain expertise in Application Security (AppSec) with experience in securing modern software applications.Experience with security tooling, including SAST, DAST, SCA, and security automation within CI / CD pipelines.Coach and mentor – utilising software delivery, technical experience and expertise, offering the right knowledge, at the right time in the right way – understanding why and how people learn.Growth mindset – understanding that competency is not fixed but is enhanced through dedication and hard work.

Demonstrating a love of learning and resilience to adversity that is essential for great accomplishment.High EQ – self-aware, self-regulated, motivated and empathetic, with great interpersonal skills.Leading and living the vision and values – building and fostering an inclusive and positive team culture.

Keeping the team's vision and values at the forefront of decision-making.Deep understanding of secure coding practices, DevSecOps, threat modeling, security architecture, and application risk management.Proven track record of leading teams to deliver high-quality software in a fast-paced environment, leveraging lean-agile techniques, while managing competing priorities and ensuring alignment with strategic goals.Excellent grasp of modern software delivery practices and life cycle.Proven ability to balance the needs of the individual with the needs of the business.Experience with coaching and mentoring.Strong stakeholder management skills, with the ability to influence without authority and align security priorities with business needs.Passion for developer enablement, making security accessible and empowering engineers to write secure code.Communicate and help others understand the importance of the vision and values.

Translate the vision and values into day-to-day activities and behaviors.Have a good understanding of the importance of Xero's Engineering standards and practices and are able to coach teams to adhere to them.People leadership – demonstrating honesty and integrity.

Providing clear objectives, guiding career development and fostering an inclusive environment that promotes psychological safety and teamwork.

Clearly communicating expectations.

Having an open mind and the flexibility to change opinions.

Developing and supporting others.Teamwork – working with peers and stakeholders to establish an overall collaborative relationship.Outstanding communication and time management skills.Why Xero?

Offering very generous paid leave to use however you'd like (plus statutory holidays!), dedicated paid leave to care for your physical and mental wellbeing as well as an Employee Assistance Program to access mental health care for you and your family.

Health insurance, life insurance, and income protection.We offer wellbeing and sports programmes, employee resource groups, 26 weeks of paid parental leave for primary caregivers, an Employee Share Plan, beautiful offices, flexible working, career development, and many other benefits that reflect our human value.You'll do the best work of your life at Xero!

#J-18808-Ljbffr

Create a job alert for this search

Lead Application • Wellington, Wellington, New Zealand

Related jobs
  • Promoted
Senior Security Network Engineer

Senior Security Network Engineer

XeroWellington, Wellington, New Zealand
At Xero, we’re here to help you supercharge your business.We do this by automating routine tasks, surfacing actionable insights and connecting businesses with the right data, advisors and apps.When...Show moreLast updated: 30+ days ago
  • Promoted
Senior Security Engineer

Senior Security Engineer

XeroWellington, Wellington, New Zealand
Our Purpose : At Xero, we’re here to help you supercharge your business.We do this by automating routine tasks, surfacing actionable insights and connecting businesses with the right data, advisors ...Show moreLast updated: 26 days ago
  • Promoted
Senior Pm I&Am

Senior Pm I&Am

Comspek InternationalWellington, New Zealand
Senior Project Manager - Identity & Access Management.You will be working as a Senior Project Manager in the Information and Cyber Security Domain to deliver security capabilities to protect key cu...Show moreLast updated: 9 days ago
  • Promoted
Test Lead

Test Lead

New Zealand GovernmentWellington, New Zealand
The Civil Aviation Authority and the Aviation Security Service offer distinctively different career opportunities and embrace diverse talent. All jobs at the Authority contribute to ensuring safe an...Show moreLast updated: 7 days ago
  • Promoted
Ms Engineer (L3) - Cyber Security

Ms Engineer (L3) - Cyber Security

NttWellington, New Zealand
OverviewMake an impact with NTT DATAJoin a company that is pushing the boundaries of what is possible.We are renowned for our technical excellence and leading innovations, and for making a differen...Show moreLast updated: 8 days ago
  • Promoted
Team Manager Assurance & Compliance

Team Manager Assurance & Compliance

New Zealand GovernmentWellington, Wellington, New Zealand
Team Manager Assurance & Compliance at Tertiary Education Commission, Wellington## Mō tēnei tūranga mahi | About this role • Join the Tertiary Education Commission | Te Amorangi Mātauranga Matua • Ex...Show moreLast updated: 3 days ago
  • Promoted
Security Consultants and Senior Security Consultants

Security Consultants and Senior Security Consultants

Bastion Security GroupWellington, Wellington, New Zealand
We're looking for people to join our team full-time (minimim 30 hours per week) in Security Consultant and Senior Security Consultant roles based in our Wellington office.Are you looking to take t...Show moreLast updated: 5 days ago
  • Promoted
Portfolio Technical Lead

Portfolio Technical Lead

Randstad New ZealandWellington, Wellington, New Zealand
Portfolio Technical Lead role at Randstad New Zealand.This is a 6-month Fixed-Term or hourly rate contract.Responsible for the delivery of technical projects with a development background and leade...Show moreLast updated: 1 day ago
  • Promoted
Cybersecurity Consultant

Cybersecurity Consultant

DatacomWellington, Wellington, New Zealand
Datacom works with organisations and communities across Australia and New Zealand to make a difference in people’s lives and help them to use the power of tech to innovate and grow.The Cybersecurit...Show moreLast updated: 9 days ago
  • Promoted
Team Leader Security & Infrastructure (Fixed Term)

Team Leader Security & Infrastructure (Fixed Term)

Talent Propeller LimitedNew Zealand
Team Leader Security & Infrastructure (fixed term) Whakatane District Council Play a critical role in protecting Council's digital environment and safeguarding community data.Build your leadership ...Show moreLast updated: 10 days ago
  • Promoted
Security Team Member – Front Door

Security Team Member – Front Door

Mitre 10Wellington, Wellington, New Zealand
Mitre 10 Wellington Central is a brand new store in the heart of the City! As we prepare to welcome our community, we’re looking for a reliable and customer-focused Security Team Member to be the f...Show moreLast updated: 15 days ago
  • Promoted
Portfolio Technical Lead

Portfolio Technical Lead

RandstadWellington, Wellington, New Zealand
Our client is looking to hire a Portfolio Technical Lead who will be responsible for the delivery of technical projects.You will ideally have a development background and have leadership experience...Show moreLast updated: 9 days ago
  • Promoted
Application Lead

Application Lead

Environmental Protection AuthorityWellington, New Zealand
OverviewJoin to apply for the Application Lead role at Environmental Protection Authority NZAs New Zealand's environmental regulator, the work we do today helps shape the future of our tomorrow.Abo...Show moreLast updated: 30+ days ago
  • Promoted
Mechatronics And Electrical Team Lead

Mechatronics And Electrical Team Lead

Syos AerospaceNew Zealand
OverviewSyos, an innovative tech company focused on developing industry leading utilitarian autonomous vehicles across air, land and sea, is seeking a highly skilled and driven Mechatronics and Ele...Show moreLast updated: 30+ days ago
  • Promoted
Engineering Team Lead - Security Governance & Data Protection

Engineering Team Lead - Security Governance & Data Protection

XeroWellington, Wellington, New Zealand
At Xero, we’re here to help supercharge small businesses.We do this by automating routine tasks, surfacing actionable insights and connecting businesses with the right data, advisors and apps.When ...Show moreLast updated: 15 days ago
  • Promoted
  • New!
Security Engineering Manager - Detection & Response

Security Engineering Manager - Detection & Response

Working NomadsWorkFromHome, New Zealand
Security Engineering Manager - Detection & Response.Join the team redefining how the world experiences design.We know job hunting can be a little time consuming and you're probably keen to find out...Show moreLast updated: 14 hours ago
  • Promoted
Hardware Team Leader - Mitre 10 Wellington Central

Hardware Team Leader - Mitre 10 Wellington Central

Mitre 10Wellington, Wellington, New Zealand
Hardware Team Leader - Mitre 10 Wellington Central.Are you passionate about DIY, tools, andleading high-performing teams? Mitre 10 is looking for a Hardware Team Leaderto drive excellence in our ha...Show moreLast updated: 18 days ago
  • Promoted
Cybersecurity Advisor | Wellington

Cybersecurity Advisor | Wellington

DatacomWellington, Wellington, New Zealand
Datacom works with organisations and communities across Australia and New Zealand to make a difference in people’s lives and help them to use the power of tech to innovate and grow.As a Cybersecuri...Show moreLast updated: 1 day ago
  • Promoted
Information Security Analyst

Information Security Analyst

New Zealand GovernmentWellington, Wellington, New Zealand
Mō tēnei tūranga mahi | About this role • •Te Haeata / The Opportunity • •The Ministry of Justice is growing its ICT Security team and has an opportunity for a passionate security team player and self-st...Show moreLast updated: 9 days ago
  • Promoted
Team Leader Security & Infrastructure (Fixed Term)

Team Leader Security & Infrastructure (Fixed Term)

Whakatane District CouncilNew Zealand
Overview Team Leader Security & Infrastructure (fixed term)Whakatane, New ZealandReference : Play a critical role in protecting Council's digital environment and safeguarding community data.Build yo...Show moreLast updated: 10 days ago