Sr. Software Engineer, Security (Pipedream)
Pleasanton, CA - USA
Job Summary
Your work days are brighter here.
Were obsessed with making hard work pay off for our people our customers and the world around us. As a Fortune 500 company and a leading AI platform for managing people money and agents were shaping the future of work so teams can reach their potential and focus on what matters most. The minute you join youll feel it. Not just in the products we build but in how we show up for each other. Our culture is rooted in integrity empathy and shared enthusiasm. Were in this together tackling big challenges with bold ideas and genuine care. We look for curious minds and courageous collaborators who bring sun-drenched optimism and drive. Whether youre building smarter solutions supporting customers or creating a space where everyone belongs youll do meaningful work with Workmates whove got your return well give you the trust to take risks the tools to grow the skills to develop and the support of a company invested in you for the long haul. So if you want to inspire a brighter work day for everyone including yourself youve found a match in Workday and we hope to be a match for you too.
About the Team
The Pipedream team operates an integration platform that connects Workday services and the apps of our external customers to over 3000 APIs. We build and maintain public-facing APIs code execution environments a high-volume event processing pipeline and other complex services that power the platform.Our work sits at the intersection of scale and connectivity: every integration that runs on Pipedream depends on the reliability performance and security of the infrastructure we build. If you enjoy working on systems that thousands of developers rely on every day and you want to see the direct impact of your contributions this is a great team to be a part of.
About the Role
As Pipedreams first dedicated Security Engineer you will own platform security end-to-end tooling process threat modeling and audits while working hands-on in the codebase to find and fix vulnerabilities yourself. This is a deeply technical individual contributor role with broad scope. You will build a security function from scratch at a platform serving thousands of developers.
In this role you will be responsible for:
Finding and patching vulnerabilities directly in code and dependencies. Pipedream runs a polyglot stack TypeScript Rust Kotlin Ruby and more so you will read and fix code across all of it.
Building and maintaining the platforms threat model and partnering with Product and Engineering to ship new features securely without slowing them down.
Securing cloud infrastructure (AWS GCP) and the third-party vendor surface (Redis Datadog and others).
Leading incident response for critical security issues.
Owning SOC 2 HIPAA penetration tests and other compliance work end-to-end.
Partnering with Workdays security team to translate broader policy into something that fits Pipedreams stack and operations.
About You
Basic Qualifications
7 years of experience in product security application security or software engineering with a security focus
Hands-on experience with vulnerability management threat modeling and risk analysis
Experience securing AWS or comparable cloud platforms at production scale
Other Qualifications
Demonstrated experience in threat and vulnerability management including identifying assessing and mitigating potential risks and weaknesses across a platforms security infrastructure. You have conducted vulnerability assessments implemented security measures and stayed current with the latest cybersecurity trends to keep systems protected.
Solid understanding of application security including protecting software applications from potential threats and vulnerabilities. You are comfortable identifying and mitigating security risks in application design and code and you bring experience with security controls such as encryption and authentication.
Proficiency in securing cloud infrastructure with the ability to design manage and maintain cloud-based environments (AWS GCP) at scale. You understand how to effectively secure and monitor cloud services in a production setting.
Experience with security incident response including a systematic approach to managing the aftermath of security breaches or attacks. You know how to identify and analyze security incidents coordinate response activities and develop strategies to prevent future incidents.
Comfort reading and patching code across multiple languages you do not need to know Pipedreams specific stack but you are the kind of engineer who picks up new languages quickly and can operate effectively across a polyglot codebase.
A history of building security programs that engineering teams actually adopt not just policies on paper. You partner with engineers to ship secure code and balance priorities across highly visible projects involving multiple teams.
Experience with compliance frameworks such as SOC 2 or HIPAA including running audits end-to-end is a plus.
Offensive security background (vulnerability testing penetration testing red teaming) is a plus.
Experience securing Kubernetes and Docker workloads in production is a plus.
Workday Pay Transparency Statement
The annualized base salary ranges for the primary location and any additional locations are listed below. Workday pay ranges vary based on work location. As a part of the total compensation package this role may be eligible for the Workday Bonus Plan or a role-specific commission/bonus as well as annual refresh stock grants. Recruiters can share more detail during the hiring process. Each candidates compensation offer will be based on multiple factors including but not limited to geography experience skills job duties and business need among other things. For more information regarding Workdays comprehensive benefits please click here.
Primary Location:
Our Approach to Flexible Work
With Flex Work were combining the best of both worlds: in-person time and remote. Our approach enables our teams to deepen connections maintain a strong community and do their best work. We know that flexibility can take shape in many ways so rather than a number of required days in-office each week we simply spend at least half (50%) of our time each quarter in the office or in the field with our customers prospects and partners (depending on role). This means youll have the freedom to create a flexible schedule that caters to your business team and personal needs while being intentional to make the most of time spent together. Those in our remote home office roles also have the opportunity to come together in our offices for important moments that matter.
Pursuant to applicable Fair Chance law Workday will consider for employment qualified applicants with arrest and conviction records.
Workday is an Equal Opportunity Employer including individuals with disabilities and protected veterans.
At Workday we are committed to providing an accessible and inclusive hiring experience where all candidates can fully demonstrate their skills. If you require assistance or an accommodation at any point please email .
Are you being referred to one of our roles If so ask your connection at Workday about our Employee Referral process!
At Workday we value our candidates privacy and data security. Workday will never ask candidates to apply to jobs through websites that are not Workday Careers.
Please be aware of sites that may ask for you to input your data in connection with a job posting that appears to be from Workday but is not.
In addition Workday will never ask candidates to pay a recruiting fee or pay for consulting or coaching services in order to apply for a job at Workday.
Required Experience:
Senior IC
About Company
Seamlessly manage your people, money, and agents on an open, unified platform with AI at the core. It’s a new work day.