Workday

Principal Cybersecurity Engineer - US Federal

Workday$184K — $277K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • 5-7 years of hands-on experience in AWS architecture and engineering.
  • Proficient in Kubernetes and Docker for lifecycle management and security hardening.
  • Strong software engineering skills with advanced proficiency in Python.
  • Experience with Infrastructure as Code (Terraform or similar) for complex environments.
  • Skilled in using AI tools to enhance efficiency and problem-solving capabilities.
  • Ability to create clear visual narratives from complex technical data.

Responsibilities

  • Design and maintain core security systems within AWS environments.
  • Secure and monitor Kubernetes clusters and container workloads.
  • Utilize Terraform or similar tools for version-controlled security infrastructure deployment.
  • Develop integrations using Python to enhance commercial security tools.
  • Employ AI tools to accelerate development and automate routine tasks.
  • Transform security data into visual insights to inform stakeholders.
  • Integrate security practices within the developer workflow for agility.

Benefits

  • Flexible work schedule combining in-office and remote work.
  • Strong community-building initiatives with in-person opportunities.
  • Access to comprehensive benefits package.
  • Eligibility for annual bonus and stock grants.
Full Job Description
About the Team
We aren't looking for someone to monitor dashboards or hunt for alerts-we need the engineer who builds the "observatory" itself. As a member of our Platform Security Engineering team, you will be responsible for the architecture, engineering, and maintenance of the systems that protect the Workday product.

Operating entirely within AWS, you will treat "Security as Code," ensuring our Vulnerability Management, SIEM, and SOAR tools are robust, scalable, and automated. You are the primary engineering partner to our SOC, building the high-fidelity tools they rely on to keep our customers safe.

About the Role

This role will support one or more direct or indirect contracts with the U.S. Federal Government which, due to federal government security requirements, mandates that all Workday personnel working on the contracts be United States citizens (naturalized or native).

  • Design and maintain the lifecycle of our core security stack (Vulnerability Management, SIEM, and SOAR) in a native AWS environment.
  • Secure, manage, and monitor Kubernetes clusters and containerized workloads. You'll ensure our tooling scales alongside our containerized infrastructure.
  • Use tools like Terraform, CloudFormation, or CDK to deploy and manage security infrastructure, ensuring our environments are version-controlled and immutable.
  • Leverage Python to bridge the gaps between commercial tools. When a tool hits its limit, you build the integration or custom logic to fix it.
  • Actively use AI tools and LLMs as a "force multiplier" to accelerate development, optimize code, and automate repetitive tasks.
  • Transform complex security telemetry into actionable, visual insights. You'll build dashboards that show our partners exactly where we stand and where the gaps remain.
  • Work to integrate security tooling into the developer workflow, ensuring our engineering is as agile as the product it protects.


About You

This role may require a security clearance at the TS/SCI w/CI Poly level. Applicants must have the ability to obtain and maintain a U.S. government issued security clearance. An active TS/SCI w/CI Poly is preferred.

You are a highly organized, technically fluent program leader who thrives in complex, fast-paced environments, managing ambiguity, aligning stakeholders, and driving execution. You balance technical understanding with program management expertise to anticipate risks and maintain momentum. You break down complex problems into actionable plans and possess a proactive, ownership-driven, and results-focused mindset.

May be required to be on site at client locations in the DC, MD, and VA (DMV) area
  • Pragmatic Engineering: You avoid "complexity for complexity's sake." You prioritize reliable, scalable paths and have a natural allergy to manual, repetitive tasks.
  • Radical Ownership: You don't wait for a ticket to address a critical gap. You investigate problems from first principles and proactively drive the solution.
  • High-Agency Problem Solving: You thrive in the "gray area." Whether it's a zero-day K8s vulnerability or an undocumented API, you possess the intellectual agility to dive in, learn, and deliver.
  • Customer-Centric Infrastructure: You treat internal teams as your customers. Your success is measured by how effectively your tools empower them, and you go deep to understand their goals before building.


Basic Requirements
  • AWS Mastery: Deep experience architecting and engineering across Compute, Storage, Networking, and Security.
  • Container Orchestration: Heavy hands-on experience with Kubernetes (K8s) and Docker, specifically regarding lifecycle management and security hardening.
  • Software Engineering: Advanced proficiency in Python. We value a developer-first approach to infrastructure; if you've mastered Python, we trust your ability to navigate any scripting environment.
  • Infrastructure as Code: Proven track record using Terraform (or equivalent IaC) to manage complex environments.
  • AI-Augmented Workflow: You are proficient at leveraging AI tools to accelerate your daily output and problem-solving.
  • Data Synthesis: Ability to distill complex technical data into clear, visual narratives for stakeholders.


Other Requirements
  • Preferred DoD 8570/8140 compliant with at least IAT Level II certification, including a current Computing Environment (CE) credential and one approved specialty certification (e.g., CompTIA CySA+, GICSP, CASP+)
  • CI/CD Expertise: Experience building or maintaining robust pipelines in GitLab CI, GitHub Actions, or Jenkins.
  • EKS Specialization: Specific experience managing production workloads on Amazon Elastic Kubernetes Service.
  • SaaS at Scale: A background in securing large-scale, high-traffic, customer-facing SaaS platforms.


Workday Pay Transparency Statement

The annualized base salary ranges for the primary location and any additional locations are listed below. Workday pay ranges vary based on work location. As a part of the total compensation package, this role may be eligible for the Workday Bonus Plan or a role-specific commission/bonus, as well as annual refresh stock grants. Recruiters can share more detail during the hiring process. Each candidate's compensation offer will be based on multiple factors including, but not limited to, geography, experience, skills, job duties, and business need, among other things. For more information regarding Workday's comprehensive benefits, please click here.

Primary Location: USA.VA.Reston

Primary Location Base Pay Range: $184,800 USD - $277,200 USD

Additional US Location(s) Base Pay Range: $167,200 USD - $300,000 USD

Our Approach to Flexible Work

With Flex Work, we're combining the best of both worlds: in-person time and remote. Our approach enables our teams to deepen connections, maintain a strong community, and do their best work. We know that flexibility can take shape in many ways, so rather than a number of required days in-office each week, we simply spend at least half (50%) of our time each quarter in the office or in the field with our customers, prospects, and partners (depending on role). This means you'll have the freedom to create a flexible schedule that caters to your business, team, and personal needs, while being intentional to make the most of time spent together. Those in our remote "home office" roles also have the opportunity to come together in our offices for important moments that matter.

About Workday

Workday, Inc. is a provider of enterprise cloud applications for finance and human resources. The Company delivers financial management, human capital management and analytics applications designed for various companies, educational institutions and government agencies. As part of its applications, the Company provides embedded analytics that capture the content and context of everyday business events, facilitating informed decision-making from wherever users are working. Its applications include Workday Financial Management, Workday Human Capital Management (HCM) and Other Applications. It also provides open, standards-based Web-services application programming interfaces, and pre-built packaged integrations and connectors. Workday, Inc. is headquartered in Pleasanton, California.
Learn more about Workday
Size
15,932 employees
Market Cap
$42.2 billion
Industry
Net Income
-$282.4 million
Founded
2005
5 Year Trend
+26.7%
Revenue
$4.3 billion
NASDAQ

Similar Jobs

More Jobs at Workday

More Information Technology Jobs

Find similar Principal Cybersecurity Engineer - US Federal jobs: