Workday

Sr. Software Engineer, Security (Pipedream)

Workday$176K — $264K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 7+ years of experience in product or application security with a software engineering focus.
  • Hands-on experience in vulnerability management and threat modeling.
  • Experience in securing AWS or comparable cloud platforms at production scale.
  • Understanding of application security and risk mitigation in design and code.
  • Familiarity with compliance frameworks like SOC 2 or HIPAA is a plus.

Responsibilities

  • Find and patch vulnerabilities in code and dependencies across a polyglot stack.
  • Build and maintain the platform's threat model and collaborate with teams for secure feature delivery.
  • Secure cloud infrastructure and third-party services effectively.
  • Lead incident response for critical security issues.
  • Own compliance work, including SOC 2 and HIPAA, from start to finish.

Benefits

  • Flexible work approach with a balance of in-person and remote time.
  • Opportunity for personal schedule flexibility while achieving business needs.
  • In-person team gatherings for key moments and collaboration.
Full Job Description

About the Team

The Pipedream team operates an integration platform that connects Workday services — and the apps of our external customers — to over 3,000 APIs. We build and maintain public-facing APIs, code execution environments, a high-volume event processing pipeline, and other complex services that power the platform.
Our work sits at the intersection of scale and connectivity: every integration that runs on Pipedream depends on the reliability, performance, and security of the infrastructure we build. If you enjoy working on systems that thousands of developers rely on every day, and you want to see the direct impact of your contributions, this is a great team to be a part of.

About the Role

As Pipedream's first dedicated Security Engineer, you will own platform security end-to-end — tooling, process, threat modeling, and audits — while working hands-on in the codebase to find and fix vulnerabilities yourself. This is a deeply technical individual contributor role with broad scope. You will build a security function from scratch at a platform serving thousands of developers. 

In this role, you will be responsible for:

  • Finding and patching vulnerabilities directly in code and dependencies. Pipedream runs a polyglot stack — TypeScript, Rust, Kotlin, Ruby, and more — so you will read and fix code across all of it.

  • Building and maintaining the platform's threat model, and partnering with Product and Engineering to ship new features securely without slowing them down.

  • Securing cloud infrastructure (AWS, GCP) and the third-party vendor surface (Redis, Datadog, and others).

  • Leading incident response for critical security issues. 

  • Owning SOC 2, HIPAA, penetration tests, and other compliance work end-to-end.

  • Partnering with Workday's security team to translate broader policy into something that fits Pipedream's stack and operations.

About You

Basic Qualifications

  • 7+ years of experience in product security, application security, or software engineering with a security focus 

  • Hands-on experience with vulnerability management, threat modeling, and risk analysis

  • Experience securing AWS or comparable cloud platforms at production scale

Other Qualifications

  • Demonstrated experience in threat and vulnerability management, including identifying, assessing, and mitigating potential risks and weaknesses across a platform's security infrastructure. You have conducted vulnerability assessments, implemented security measures, and stayed current with the latest cybersecurity trends to keep systems protected. 

  • Solid understanding of application security, including protecting software applications from potential threats and vulnerabilities. You are comfortable identifying and mitigating security risks in application design and code, and you bring experience with security controls such as encryption and authentication.

  • Proficiency in securing cloud infrastructure, with the ability to design, manage, and maintain cloud-based environments (AWS, GCP) at scale. You understand how to effectively secure and monitor cloud services in a production setting.

  • Experience with security incident response, including a systematic approach to managing the aftermath of security breaches or attacks. You know how to identify and analyze security incidents, coordinate response activities, and develop strategies to prevent future incidents.

  • Comfort reading and patching code across multiple languages — you do not need to know Pipedream's specific stack, but you are the kind of engineer who picks up new languages quickly and can operate effectively across a polyglot codebase.

  • A history of building security programs that engineering teams actually adopt — not just policies on paper. You partner with engineers to ship secure code and balance priorities across highly visible projects involving multiple teams. 

  • Experience with compliance frameworks such as SOC 2 or HIPAA, including running audits end-to-end, is a plus.

  • Offensive security background (vulnerability testing, penetration testing, red teaming) is a plus.

  • Experience securing Kubernetes and Docker workloads in production is a plus.


Workday Pay Transparency Statement

The annualized base salary ranges for the primary location and any additional locations are listed below.  Workday pay ranges vary based on work location. As a part of the total compensation package, this role may be eligible for the Workday Bonus Plan or a role-specific commission/bonus, as well as annual refresh stock grants. Recruiters can share more detail during the hiring process. Each candidate’s compensation offer will be based on multiple factors including, but not limited to, geography, experience, skills, job duties, and business need, among other things. For more information regarding Workday’s comprehensive benefits, please .

Primary Location: USA.CA.PleasantonPrimary Location Base Pay Range: $176,000 USD - $264,000 USD


 

Additional US Location(s) Base Pay Range: $148,200 USD - $264,000 USD



Our Approach to Flexible Work
 

With Flex Work, we’re combining the best of both worlds: in-person time and remote. Our approach enables our teams to deepen connections, maintain a strong community, and do their best work. We know that flexibility can take shape in many ways, so rather than a number of required days in-office each week, we simply spend at least half (50%) of our time each quarter in the office or in the field with our customers, prospects, and partners (depending on role). This means you’ll have the freedom to create a flexible schedule that caters to your business, team, and personal needs, while being intentional to make the most of time spent together. Those in our remote "home office" roles also have the opportunity to come together in our offices for important moments that matter.

About Workday

Workday, Inc. is a provider of enterprise cloud applications for finance and human resources. The Company delivers financial management, human capital management and analytics applications designed for various companies, educational institutions and government agencies. As part of its applications, the Company provides embedded analytics that capture the content and context of everyday business events, facilitating informed decision-making from wherever users are working. Its applications include Workday Financial Management, Workday Human Capital Management (HCM) and Other Applications. It also provides open, standards-based Web-services application programming interfaces, and pre-built packaged integrations and connectors. Workday, Inc. is headquartered in Pleasanton, California.
Learn more about Workday
Size
15,932 employees
Market Cap
$42.2 billion
Industry
Net Income
-$282.4 million
Founded
2005
5 Year Trend
+26.7%
Revenue
$4.3 billion
NASDAQ

Similar Jobs

More Information Technology Jobs

Find similar Sr. Software Engineer, Security (Pipedream) jobs: