Jobs
Your work days are brighter here.
We’re obsessed with making hard work pay off, for our people, our customers, and the world around us. As a Fortune 500 company and a leading AI platform for managing people, money, and agents, we’re shaping the future of work so teams can reach their potential and focus on what matters most. The minute you join, you’ll feel it. Not just in the products we build, but in how we show up for each other. Our culture is rooted in integrity, empathy, and shared enthusiasm. We’re in this together, tackling big challenges with bold ideas and genuine care. We look for curious minds and courageous collaborators who bring sun-drenched optimism and drive. Whether you're building smarter solutions, supporting customers, or creating a space where everyone belongs, you’ll do meaningful work with Workmates who’ve got your back. In return, we’ll give you the trust to take risks, the tools to grow, the skills to develop and the support of a company invested in you for the long haul. So, if you want to inspire a brighter work day for everyone, including yourself, you’ve found a match in Workday, and we hope to be a match for you too.
About the Team
We are seeking a highly skilled Principal cybersecurity engineer to architect the development of our internal suite of Cybersecurity Risk Management and Automation tools. This role requires a rare blend of deep domain expertise in security risk and the technical ability to bridge the gap between high-level strategy and robust software execution.As a Principle engineer, you will serve as the primary visionary for how our risk data is structured, analyzed, and automated, acting as the bridge between the Cybersecurity Risk organization and our Engineering teams.
About the Role:
As a Principle engineer, you will serve as the primary visionary for how our risk data is structured, analyzed, and automated, acting as the bridge between the Cybersecurity Risk organization and our Engineering teams.
About You
Basic Qualifications
-
9+ Years of Experience building custom GRC (Governance, Risk, and Compliance) platforms.
-
Software Engineering & Development: Proficient in Python, Go, or Java with a strong background in version control (Git), API design, and the ability to build complex Po Cs for risk models.
-
Full-Lifecycle Engineering Governance: Mastery of the end-to-end SDLC, including the creation and oversight of comprehensive SRS documentation, Project Plans, and Product Backlogs to ensure architectural alignment from initial planning through to deployment and maintenance.
-
Architectural & Quality Standards: Expert ability to define System Architectures, Data Models (ERDs), and API specifications while enforcing rigorous QA standards through formalized Test Plans, automated Build Scripts, and Production Operations manuals.
-
Experience leading the technical roadmap for software engineering teams or data scientists without direct reporting authority (e.g., Lead, Principal, or Staff level experience).
-
Technical Influence: Data & Automation Engineering: High proficiency in data pipeline logic, ELT/ETL processes, and data quality assurance, specifically as they apply to automating security telemetry.
Other Qualifications
-
Strategic Technical Translation: Architect high-level business and security "end-states" into sophisticated process designs and technical specifications. You will own the translation of risk philosophy into the logic used by our engineering squads.
-
Risk Domain Authority: Serve as the definitive Subject Matter Expert (SME) for defining risk metrics and calculation methodologies, specifically within:
-
Enterprise Risk (ERM): Designing and implementing data-driven risk frameworks (e.g., NIST, FAIR) through sophisticated automation.
-
Third-Party Risk (TPRM): Architecting systems for automated due diligence, continuous monitoring, and assessment scoring for our vendor ecosystem.
-
Cross-Functional Influence: Champion security risk automation across the organization, mentoring junior engineers and influencing stakeholders on best practices for data-driven risk modeling.
Essential Domain Knowledge
-
Mastery of Cybersecurity Risk: A proven track record of designing and implementing Enterprise and Third-Party Risk Management (TPRM) programs at scale.
-
Architectural Design: Demonstrated ability to take a blank slate and define complex security processes, translating them into technical user stories, functional specifications, and logic diagrams.
-
Advanced Risk Modeling: Expertise in quantitative risk analysis (e.g., Monte Carlo simulations or FAIR methodology) and how to programmatically apply these models to software.
Our Approach to Flexible Work:
With Flex Work, we’re combining the best of both worlds: in-person time and remote. Our approach enables our teams to deepen connections, maintain a strong community, and do their best work. We know that flexibility can take shape in many ways, so rather than a number of required days in-office each week, we simply spend at least half (50%) of our time each quarter in the office or in the field with our customers, prospects, and partners (depending on role). This means you'll have the freedom to create a flexible schedule that caters to your business, team, and personal needs, while being intentional to make the most of time spent together. Those in our remote "home office" roles also have the opportunity to come together in our offices for important moments that matter.
At Workday, we are committed to providing an accessible and inclusive hiring experience where all candidates can fully demonstrate their skills. If you require assistance or an accommodation at any point, please email accommodations@workday.com.
Are you being referred to one of our roles? If so, ask your connection at Workday about our Employee Referral process!
At Workday, we value our candidates’ privacy and data security. Workday will never ask candidates to apply to jobs through websites that are not Workday Careers.
Please be aware of sites that may ask for you to input your data in connection with a job posting that appears to be from Workday but is not.
In addition, Workday will never ask candidates to pay a recruiting fee, or pay for consulting or coaching services, in order to apply for a job at Workday.
Total Views
0
Apply Clicks
0
Mock Applicants
0
Scraps
0
Similar Jobs

Security Officer
Mass General Brigham · Newton-MA

Senior, Cybersecurity Penetration Tester
Schneider Electric · Bangalore, India

Security Rep Sr Staff / Enterprise Performance
Lockheed Martin · grand prairie

TÉCNICO SEGURANÇA DO TRABALHO - IPOJUCA/PE
Schneider Electric · Recife, Brazil

Sr. Security Engineer I
Yum! Brands · Gurgaon, Haryana, India, IN
About Workday

Workday
PublicWorkday, Inc., is an American on‑demand (cloud-based) financial management, human capital management, and student information system software vendor.
10,001+
Employees
Pleasanton
Headquarters
Reviews
2.6
15 reviews
Work Life Balance
3.0
Compensation
4.0
Culture
2.5
Career
2.8
Management
2.2
25%
Recommend to a Friend
Pros
Competitive compensation packages
Principal/senior level opportunities available
AI/technology focus areas
Cons
Major layoffs (8.5% workforce reduction)
Age discrimination lawsuit regarding AI hiring tools
Proprietary Xpresso language is difficult and non-transferable
Salary Ranges
2 data points
Junior/L3
Senior/L5
Staff/L6
Junior/L3 · Data Scientist P2
0 reports
$130,000
total / year
Base
-
Stock
-
Bonus
-
$110,500
$149,500
Interview Experience
9 interviews
Difficulty
3.9
/ 5
Duration
14-28 weeks
Experience
Positive 11%
Neutral 11%
Negative 78%
Interview Process
1
Application Review
2
Recruiter Screen
3
Hiring Manager Interview
4
Director Interview
5
Team Interviews
6
Offer Decision
Common Questions
Behavioral/STAR
Past Experience
Culture Fit
Technical Knowledge
Management/Leadership
News & Buzz
The Truth About Workday Inc: Why Everyone Is Suddenly Paying Attention - AD HOC NEWS
Source: AD HOC NEWS
News
·
5w ago
Eightfold, Workday lawsuits hint at legal reckoning for AI - AIM Group
Source: AIM Group
News
·
5w ago
Does Workday (WDAY) Offer a Compelling Risk/Reward Opportunity? - Insider Monkey
Source: Insider Monkey
News
·
5w ago
PG&E buys one of Workday's Pleasanton office buildings for less than half the price of a decade ago - The Business Journals
Source: The Business Journals
News
·
5w ago