Your work days are brighter here.
Were obsessed with making hard work pay off for our people our customers and the world around us. As a Fortune 500 company and a leading AI platform for managing people money and agents were shaping the future of work so teams can reach their potential and focus on what matters most. The minute you join youll feel it. Not just in the products we build but in how we show up for each other. Our culture is rooted in integrity empathy and shared enthusiasm. Were in this together tackling big challenges with bold ideas and genuine care. We look for curious minds and courageous collaborators who bring sun-drenched optimism and drive. Whether youre building smarter solutions supporting customers or creating a space where everyone belongs youll do meaningful work with Workmates whove got your return well give you the trust to take risks the tools to grow the skills to develop and the support of a company invested in you for the long haul. So if you want to inspire a brighter work day for everyone including yourself youve found a match in Workday and we hope to be a match for you too.
About the Team
Workdays Cybersecurity GRC team is the guardian of customer trust. We are responsible for building and managing programs designed to protect the confidentiality integrity and availability (CIA) of our customers most sensitive data. We ensure that company practices policies and processes are performed in accordance with contractual and regulatory requirements and Workdays core values and help represent these practices to our customers.About the Role
The Senior Cybersecurity Engineer (P4) is a key technical leader responsible for defining and driving the strategic direction and implementation of security controls across the organizations infrastructure. This role requires deep technical expertise in infrastructure security and strong coding/automation skills to industrialize compliance and security processes. The Senior Engineer is expected to lead complex projects mentor junior staff and significantly influence security governance decisions.
About You
Responsibilities include:
Champion the principle of translating security policies directly into testable automated code to ensure non-bypassable compliance.
Design and execute the roadmap for industrializing and automating security governance compliance verification and control enforcement across the organization.
Drive the adoption of DevSecOps principles by embedding security controls directly into the CI/CD pipeline and contributing secure reusable modules (e.g. secure Terraform/CloudFormation modules) for engineering teams.
Basic Qualifications:
7 years of progressive hands-on experience in engineering with a strong emphasis on security architecture leading complex security initiatives and developing advanced security solutions with 2 years focused on security governance/compliance.
Extensive and deep hands-on experience architecting implementing and securing infrastructure and services within major cloud service providers (e.g. AWS GCP Azure) at scale.
Strong proficiency in at least one scripting language (e.g. Python Go Bash Ruby) with the ability to develop automation for security operations configuration management and compliance.
Expert-level understanding and practical application of cloud security concepts principles architectures and technologies with a proven track record of designing and implementing robust enterprise-grade security controls in complex multi-cloud environments.
A deep expert-level understanding of network application and platform security including advanced threat landscapes attack vectors and mitigation techniques.
Proven experience in architecting implementing and evangelizing secure Infrastructure as Code (IaC) practices and automation at scale using tools like Terraform CloudFormation etc.
Desired Qualifications:
Relevant industry certifications (e.g. AWS Certified Security - Specialty Google Professional Cloud Security Engineer Certified Kubernetes Administrator (CKA) Certified Kubernetes Security Specialist (CKS) or equivalent focused training.
Proven experience implementing auditing and maintaining controls for major compliance frameworks (NIST CSF ISO 27001).
Professional and Soft Skills:
Exceptional communication presentation and interpersonal skills with the ability to influence and align senior leadership diverse engineering teams and non-technical stakeholders.
Proven ability to analyze complex technical security problems and propose pragmatic business-enabling solutions.
Ability to lead technical security initiatives end-to-end from conceptual design through successful implementation.
Exceptional ability to communicate highly technical security risks and compliance requirements into clear quantitative business terms for executive leadership.
Our Approach to Flexible Work
With Flex Work were combining the best of both worlds: in-person time and remote. Our approach enables our teams to deepen connections maintain a strong community and do their best work. We know that flexibility can take shape in many ways so rather than a number of required days in-office each week we simply spend at least half (50%) of our time each quarter in the office or in the field with our customers prospects and partners (depending on role). This means youll have the freedom to create a flexible schedule that caters to your business team and personal needs while being intentional to make the most of time spent together. Those in our remote home office roles also have the opportunity to come together in our offices for important moments that matter.
At Workday we are committed to providing an accessible and inclusive hiring experience where all candidates can fully demonstrate their skills. If you require assistance or an accommodation at any point please email .
Are you being referred to one of our roles If so ask your connection at Workday about our Employee Referral process!
At Workday we value our candidates privacy and data security. Workday will never ask candidates to apply to jobs through websites that are not Workday Careers.
Please be aware of sites that may ask for you to input your data in connection with a job posting that appears to be from Workday but is not.
In addition Workday will never ask candidates to pay a recruiting fee or pay for consulting or coaching services in order to apply for a job at Workday.
Required Experience:
Senior IC