Workday logo
Workday

Workday is a computer software company that provides cloud-based applications for the finance and human resources industries. Founded by co-CEOs Dave Duffield a

Senior Cybersecurity Engineer

Location

Virginia + 1 moreAll locations: Virginia | Colorado

Posted

31 days ago

Salary

$159.6K - $239.4K / year

Seniority

Senior

Job Description

Senior Cybersecurity Engineer

Workday

Title: Sr Cybersecurity Engineer Location: USA.VA.Reston USA, CO, Boulder Job Description: Your work days are brighter here. We're obsessed with making hard work pay off, for our people, our customers, and the world around us. As a Fortune 500 company and a leading AI platform for managing people, money, and agents, we're shaping the future of work so teams can reach their potential and focus on what matters most. The minute you join, you'll feel it. Not just in the products we build, but in how we show up for each other. Our culture is rooted in integrity, empathy, and shared enthusiasm. We're in this together, tackling big challenges with bold ideas and genuine care. We look for curious minds and courageous collaborators who bring sun-drenched optimism and drive. Whether you're building smarter solutions, supporting customers, or creating a space where everyone belongs, you'll do meaningful work with Workmates who've got your back. In return, we'll give you the trust to take risks, the tools to grow, the skills to develop and the support of a company invested in you for the long haul. So, if you want to inspire a brighter work day for everyone, including yourself, you've found a match in Workday, and we hope to be a match for you too. About the Team Workday's Offensive Security Team is full of skilled cybersecurity engineers who are passionate about product security...and occasionally breaking things, so they can be fixed again! We are tasked to proactively secure Workday's products, infrastructure, and internal applications. Not only do we regularly assess for security issues through manual and automated penetration testing across all levels of the application stack, but we also conduct advanced offensive security operations including red teaming, purple teaming, vulnerability research, and credentials auditing to simulate real-world threats and identify weaknesses. We collaborate with dedicated Workmates globally and manage Workday's external and internal bug bounty programs, fostering partnerships with our developers and external researchers to uncover and responsibly disclose vulnerabilities. Ultimately, we're driven by a desire to continuously improve Workday's security posture and ensure the highest level of protection for our users. About the Role As a Sr. Cybersecurity Engineer, you will be part of an elite team of security professionals and ethical hackers with deep experience in security engineering. The Workday Offensive Security is looking for a seasoned penetration tester to help us perform security assessments and scale security at Workday. On our team, you will be performing vulnerability assessments against Workday applications, services, and networks, as well as developing security automation and tools. You will be researching new threats and executing creative exploits. If you are a passionate learner, an advocate for security, and are a highly skilled offensive security engineer, then this is the right job for you! About You You will be a great fit for this role if you have - Basic Qualifications - 8+ years of progressive experience in a similar role - 3+ yrs of experience leading PenTests in one or more areas such as public cloud infrastructure (AWS, Google Cloud), modern web applications, enterprise network assessments, API testing, AI Agentic Redteaming - 3+ yrs of experience with one or more scripting languages for automation (python, Go, Bash, Ruby, etc.) - Understanding of modern security best practices such as OWASP Top 10 & MITRE ATT&CK framework - Knowledge of networking & technology fundamentals and how to attack their weaknesses (TCP/IP stack, Linux, Docker, Kubernetes, Microservice architectures) - Must have experience with Web Proxy such as BurpSuite, Zap or others Other Qualifications - Have one or more industry leading certifications (OSCP, CRTE, CRTO, ARTE, CPTS, etc.) - Have Bug Bounty submissions experience or have independent research e.g. GitHub projects - The ability to triage findings and work on remediation plans with partner teams - Excellent written & verbal communication skills Workday Pay Transparency Statement The annualized base salary ranges for the primary location and any additional locations are listed below. Workday pay ranges vary based on work location. As a part of the total compensation package, this role may be eligible for the Workday Bonus Plan or a role-specific commission/bonus, as well as annual refresh stock grants. Recruiters can share more detail during the hiring process. Each candidate's compensation offer will be based on multiple factors including, but not limited to, geography, experience, skills, job duties, and business need, among other things. For more information regarding Workday's comprehensive benefits, please click here. Primary Location: USA.VA.Reston Primary Location Base Pay Range: $159,600 USD - $239,400 USD Additional US Location(s) Base Pay Range: $144,400 USD - $258,000 USD Additional Considerations: If performed in Colorado, the pay range for this job is $152,000 - $228,000 USD based on min and max pay range for that role if performed in CO. Our Approach to Flexible Work With Flex Work, we're combining the best of both worlds: in-person time and remote. Our approach enables our teams to deepen connections, maintain a strong community, and do their best work. We know that flexibility can take shape in many ways, so rather than a number of required days in-office each week, we simply spend at least half (50%) of our time each quarter in the office or in the field with our customers, prospects, and partners (depending on role). This means you'll have the freedom to create a flexible schedule that caters to your business, team, and personal needs, while being intentional to make the most of time spent together. Those in our remote "home office" roles also have the opportunity to come together in our offices for important moments that matter. Pursuant to applicable Fair Chance law, Workday will consider for employment qualified applicants with arrest and conviction records. Workday is an Equal Opportunity Employer including individuals with disabilities and protected veterans. At Workday, we are committed to providing an accessible and inclusive hiring experience where all candidates can fully demonstrate their skills. If you require assistance or an accommodation at any point, please email accommodations@workday.com. Are you being referred to one of our roles? If so, ask your connection at Workday about our Employee Referral process! At Workday, we value our candidates' privacy and data security. Workday will never ask candidates to apply to jobs through websites that are not Workday Careers. Please be aware of sites that may ask for you to input your data in connection with a job posting that appears to be from Workday but is not. In addition, Workday will never ask candidates to pay a recruiting fee, or pay for consulting or coaching services, in order to apply for a job at Workday.

Related Categories

Related Job Pages

More Security Engineer Jobs

Visa logo

Senior Cybersecurity Engineer - Identity and Access Management

Visa

Based in Foster City, California, Visa is a global payments technology organization. Visa was founded in 1958, coinciding with Bank of America’s launch of the

Title: Senior Cybersecurity Engineer IAM Location: Austin, TX, United States Full time job requisition id REF079838W Job Description: About Us Visa is a world leader in payments technology, facilitating transactions between consumers, merchants, financial institutions and government entities across more than 200 countries and territories, dedicated to uplifting everyone, everywhere by being the best way to pay and be paid. At Visa, you'll have the opportunity to create impact at scale — tackling meaningful challenges, growing your skills and seeing your contributions impact lives around the world. Join Visa and do work that matters – to you, to your community, and to the world. Progress starts with you. Job Description The Senior Cybersecurity Engineer – IAM is responsible for designing, implementing, and operating identity and access management controls across the Pismo platform, ensuring compliance with Pismo Visa Corporate Identity & Access Technical Security Requirements. This role operates at platform and architecture level, supporting multicloud and hybrid environments, and focuses on building secure, automated, and auditable access models for human and non‑human identities. The position partners closely with Cloud Security, Platform Engineering, API, DevSecOps, and GRC teams to embed least‑privilege, zero‑trust, and automation‑first IAM practices across a regulated, multi‑tenant payments environment. In addition to traditional IAM responsibilities, this role provides security and governance oversight for AI‑enabled identity use cases, ensuring that AI systems, agents, and automation interacting with identities comply with Internal AI Governance standards, GenAI & Agentic Systems requirements, and Corporate IAM Technical and Design requirements. This is a remote position. A remote position does not require job duties be performed within proximity of a Visa office location. Remote positions may be required to be present at a Visa office with scheduled notice. Visa requires at least 3 days in office, expectations of these days will be confirmed by your Hiring Manager. Qualifications Basic Qualifications • 5+ years of relevant work experience with a Bachelor’s Degree or at least 2 years of work experience with an Advanced degree (e.g. Masters, MBA, JD, MD) or 0 years of work experience with a PhD, OR 8+ years of relevant work experience. Preferred Qualifications • 5+ years of relevant work experience with a Bachelor’s Degree or at least 2 years of work experience with an Advanced degree (e.g. Masters, MBA, JD, MD) or 0 years of work experience with a PhD, OR 8+ years of relevant work experience. • 8+ years of cybersecurity experience, with deep specialization in Identity & Access Management (IAM). • Proven experience operating at Senior / Consultant level, influencing IAM architecture, standards, and governance decisions. • Experience supporting financial services, payments, or regulated environments • Multicloud IAM Architecture (Mandatory) • Strong hands‑on experience designing and operating IAM across multicloud environments, including AWS and hybrid/federated cloud models. Ability to design scalable permission models across cloud platforms, including: • Cloud‑native roles and permission sets • Least‑privilege and separation‑of‑duties enforcement • Human and non‑human identities (workloads, service accounts) • Permission Design & Access Modeling Deep understanding of permission structures, including: • Role‑based (RBAC) and attribute‑based (ABAC) access models • IAM‑governed access roles and entitlement cataloging • Temporary, just‑in‑time, and break‑glass access patterns • Ability to design access models that reduce audit scope, review volume, and operational risk. • IAM Automation & Engineering (Critical Requirement) Strong experience implementing IAM automation, including: • Automated provisioning and de‑provisioning (JML lifecycle) • Access revalidation and certification automation • Auto‑remediation of non‑compliant permissions • Experience integrating IAM controls with CI/CD pipelines and Infrastructure‑as‑Code (IaC). • Proven ability to codify IAM policies and controls using automation frameworks. • Coding & Scripting Skills Hands‑on coding experience to support IAM automation and integrations, including: • Python or equivalent scripting languages • Use of APIs and SDKs to manage identities, roles, and entitlements • Automation via IaC tools (e.g., Terraform‑based IAM definitions) • Ability to build reusable, auditable, and scalable IAM automation components • Privileged Access & Cloud Governance • Experience designing and governing privileged access across cloud platforms. • Ability to enforce time‑bound, auditable privileged access aligned with least‑privilege principles. • Strong understanding of cloud governance roles required for vulnerability scanning, configuration U.S. Applicants Only The estimated salary range for this position is $145,300.00 to $ 232,700.00 USD per year, which may include potential sales incentive payments (if applicable). Salary may vary depending on job-related factors which may include knowledge, skills, experience, and location. In addition, this position may be eligible for bonus and equity.Visa has a comprehensive benefits package for which this position may be eligible that includes Medical, Dental, Vision, 401(k), FSA/HSA, Life Insurance, Paid Time Off, and Wellness Program. Work Hours Varies upon the needs of the department. Travel Requirements This position requires travel 5-10% of the time. Mental/Physical Requirements This position will be performed in an office setting. The position will require the incumbent to sit and stand at a desk, communicate in person and by telephone, frequently operate standard office equipment, such as telephones and computers. Visa is an EEO Employer Qualified applicants will receive consideration for employment without regard to race, color religion, sex, national origin, sexual orientation, gender identity, disability or protect veteran status. Visa will also consider for employment qualified applicants with criminal histories in a manner consistent with the EEOC guidelines and applicable local law.

Texas
$145.3K - $232.7K / year
Fusion Consulting logo

Senior IT Project Manager – Infrastructure, OT Security

Fusion Consulting

Shaping the Future of Life Science Consulting Worldwide

Full TimeRemoteTeam 501-1,000Since 2012H1B Sponsor

• Lead end-to-end planning and execution of OT Active Directory (AD) domain migrations and infrastructure upgrades across global manufacturing sites. • Manage site-level OT/AD migration activities, including backlog creation, resource alignment, execution tracking, and risk mitigation for 2026 milestones. • Coordinate global application upgrades and integrations. • Drive Global QA strategy alignment, documentation, and sign-off processes to ensure compliance with GxP requirements. • Engage with site heads, local QA representatives, system owners, and project stakeholders to secure buy-in, resolve resource conflicts, and manage commitments. • Monitor project progress against plan, report status (including risks and issues such as site engagement, QA delays, and infrastructure dependencies), and implement mitigation actions. • Industrialize migration processes to achieve repeatable, efficient domain transitions with consistent run rates. • Collaborate with global and local teams to align on standardized approaches, checklists, and quality controls for GxP-compliant execution. • Facilitate cross-functional discussions, escalations, and decision-making involving multiple geographies (Europe, Asia, Americas).

Portugal
Job Closed
Fusion Consulting logo

Senior IT Project Manager – Infrastructure, OT Security

Fusion Consulting

Shaping the Future of Life Science Consulting Worldwide

Full TimeRemoteTeam 501-1,000Since 2012H1B Sponsor

• Lead end-to-end planning and execution of OT Active Directory (AD) domain migrations and infrastructure upgrades across global manufacturing sites. • Manage site-level OT/AD migration activities, including backlog creation, resource alignment, execution tracking, and risk mitigation for 2026 milestones. • Coordinate global application upgrades and integrations. • Drive Global QA strategy alignment, documentation, and sign-off processes to ensure compliance with GxP requirements. • Engage with site heads, local QA representatives, system owners, and project stakeholders to secure buy-in, resolve resource conflicts, and manage commitments. • Monitor project progress against plan, report status (including risks and issues such as site engagement, QA delays, and infrastructure dependencies), and implement mitigation actions. • Industrialize migration processes to achieve repeatable, efficient domain transitions with consistent run rates. • Collaborate with global and local teams to align on standardized approaches, checklists, and quality controls for GxP-compliant execution.

Spain
Job Closed
Fusion Consulting logo

Senior IT Project Manager – Infrastructure, OT Security

Fusion Consulting

Shaping the Future of Life Science Consulting Worldwide

Full TimeRemoteTeam 501-1,000Since 2012H1B Sponsor

• Lead end-to-end planning and execution of OT Active Directory (AD) domain migrations and infrastructure upgrades across global manufacturing sites. • Manage site-level OT/AD migration activities, including backlog creation, resource alignment, execution tracking, and risk mitigation for 2026 milestones. • Coordinate global application upgrades and integrations. • Drive Global QA strategy alignment, documentation, and sign-off processes to ensure compliance with GxP requirements. • Engage with site heads, local QA representatives, system owners, and project stakeholders to secure buy-in, resolve resource conflicts, and manage commitments. • Monitor project progress against plan, report status (including risks and issues such as site engagement, QA delays, and infrastructure dependencies), and implement mitigation actions. • Industrialize migration processes to achieve repeatable, efficient domain transitions with consistent run rates. • Collaborate with global and local teams to align on standardized approaches, checklists, and quality controls for GxP-compliant execution. • Facilitate cross-functional discussions, escalations, and decision-making involving multiple geographies (Europe, Asia, Americas).

Poland
Job Closed