Staff Security Engineer
Auror · Remote - New Zealand · 2026-07-13
About this role
ABOUT AUROR
At Auror, we’re empowering the retail industry to tackle theft and Organised Retail Crime, a $150 Billion problem globally. It’s high volume crime that’s increasingly organised in nature and is putting people, retailers, and communities at risk every day.
Founded in New Zealand 12 years ago, we’re working with some of the best and largest retailers in the world across the US, Canada, Australia, New Zealand, and the UK. Auror is connecting people and intelligence to reduce crime. We’re using technology for good.
Our mission is clear: reduce violent retail crime by 50% in 5 years. It's an ambitious goal - and one we believe is achievable. In partnership with our leading retail partners, we need people with the passion, determination, and innovation required to overcome one of the world's largest problems. If you’re looking to make a difference with and for the people dedicated to stopping crime, for good, then we want you on our team.
We're also embracing the potential of AI to supercharge our impact - whether that's enhancing the way we detect trends, support our customers, or improve internal workflows. As a company, we're committed to responsibly incorporating AI into how we work and what we build, and we encourage all Aurors to be curious about how AI can elevate their work, regardless of role or function.
THE ROLE
We're hiring a Staff Security Engineer to join the Product & Engineering Security pillar at Auror. This is an engineer-first role, scoped for someone who lives in the codebase, ships patches, deploys changes, and raises the security bar of the platform from the inside — not from the sidelines.
The shape of this role has shifted from where Security engineering at Auror started. The bar for impact has moved. We don't need a security specialist who points at risks and writes recommendations for someone else to take action. We need a Staff-level engineer who picks up the ticket, writes the fix, opens the PR, ships the change, and stays close enough to the platform to know what just happened in production. Threat actors are increasingly AI-capable, our platform is increasingly AI-augmented, and our customers' expectations of how fast we can detect, fix, and prove security have stepped up. The response is engineering muscle — applied to security.
At the IC4 (Staff) level, you'll set technical direction for security controls, tooling, and architecture across multiple systems. You'll design security patterns and guardrails that enable safe, repeatable delivery; lead the toughest investigations and architecture reviews; and raise the bar through code, design, and coaching. You'll be a credible engineering voice in cross-functional decisions and a force-multiplier for the engineers around you.
LOCATION:
Auror's headquarters are in Auckland, and we follow a hybrid way of working. However, we're open to hiring someone remotely for this role, provided they are based in New Zealand. While remote work is supported, we place a high value on spending time together in person. Our remote team members typically travel to Auckland approximately every six weeks to join their team and the wider company for collaboration, planning, and social events.
RESPONSIBILITIES
- Ship Code in the Platform: This is the headline. You'll work directly in the Auror codebase — writing patches, fixing vulnerabilities, refactoring weak patterns, and deploying changes in partnership with the product engineering teams. You should be comfortable opening PRs against unfamiliar services, reading through to root cause, and shipping a fix that the owning team would have signed off on themselves.
- Build Security Tooling and Automation: Write the tools, automation, and detections that scale the security team's impact. Replace manual evidence collection patterns with code. Build the guardrails that make secure defaults the easy path for the engineers around you.
- Application Security and Vulnerability Remediation: Lead threat modelling and architecture reviews for major platform changes. Drive the in-flight Wiz SAST/Code findings closure programme — your work, not someone else's. Push toward engineer-raised PRs using security-provided resolutions, and shoulder the fixes yourself when that's the faster path to closure.
- Platform and Infrastructure Security: Partner with SRE and Platform on cloud and infrastructure security — GCP, GitHub Actions hardening, CI/CD security, identity and secrets management, hash-pinning, supply chain controls. Write Terraform, build pipelines, contribute to platform-as-code where the leverage is highest. You should be as comfortable in a deployment YAML as in a vulnerability report.
- AI Security and AI-Augmented Engineering: Help define and harden how Auror builds with and defends against AI. Apply security thinking to LLM-integrated features — prompt injection, data leakage, model supply chain, agentic tool use. Use AI engineering tooling (Claude Code and similar) natively to ship security work faster, and help mature the patterns that let the rest of Engineering do the same safely. Stay close enough to the Mythos-class threat landscape to translate it into concrete engineering work — but always as an engineer, not a researcher.
- Detection and Response: Partner with the Blue Team workstream to design and tune detections. Write detection-as-code, build playbooks, operate SIEM and CloudSIEM tooling. Lead the technical side of incident response and contribute to post-incident learning.
- Customer Security and Assurance: Be the credible technical voice when enterprise customers need depth — architecture questions, technical risk conversations, evidence beyond what the audit pack covers. The Compliance team handles questionnaires; you show up when the conversation gets technical.
- Standards, Patterns, and Coaching: Set technical direction for security controls, tooling, and architecture. Publish patterns and guardrails —…
Skills asked for
- sre
- gcp
- github actions
- ci/cd
- terraform
- llm
- rest
- azure
Your next role is already in here.
Search live openings from thousands of employers, save the ones worth a second look, and let JobBob keep watch for the rest.