Workday Logo

Workday

Principal Cybersecurity Engineer

Reposted 24 Days Ago
Be an Early Applicant
In-Office
Reston, VA
167K-300K Annually
Expert/Leader
In-Office
Reston, VA
167K-300K Annually
Expert/Leader
The Principal Cybersecurity Engineer will architect Cybersecurity Risk Management tools, bridging strategy and execution, and leading technical efforts in risk data automation and analysis.
The summary above was generated by AI

Your work days are brighter here.

We’re obsessed with making hard work pay off, for our people, our customers, and the world around us. As a Fortune 500 company and a leading AI platform for managing people, money, and agents, we’re shaping the future of work so teams can reach their potential and focus on what matters most. The minute you join, you’ll feel it. Not just in the products we build, but in how we show up for each other. Our culture is rooted in integrity, empathy, and shared enthusiasm. We’re in this together, tackling big challenges with bold ideas and genuine care. We look for curious minds and courageous collaborators who bring sun-drenched optimism and drive. Whether you're building smarter solutions, supporting customers, or creating a space where everyone belongs, you’ll do meaningful work with Workmates who’ve got your back. In return, we’ll give you the trust to take risks, the tools to grow, the skills to develop and the support of a company invested in you for the long haul. So, if you want to inspire a brighter work day for everyone, including yourself, you’ve found a match in Workday, and we hope to be a match for you too.

About the Team

We are seeking a highly skilled Principal cybersecurity engineer to architect the development of our internal suite of Cybersecurity Risk Management and Automation tools. This role requires a rare blend of deep domain expertise in security risk and the technical ability to bridge the gap between high-level strategy and robust software execution.
As a Principle engineer, you will serve as the primary visionary for how our risk data is structured, analyzed, and automated, acting as the bridge between the Cybersecurity Risk organization and our Engineering teams.

About the Role

As a Principle engineer, you will serve as the primary visionary for how our risk data is structured, analyzed, and automated, acting as the bridge between the Cybersecurity Risk organization and our Engineering teams.

About You

Basic Qualifications

  • 9+ Years of Experience building custom GRC (Governance, Risk, and Compliance) platforms.

  • Software Engineering & Development: Demonstrable proficiency in Python, Go, or Java with a strong background in version control (Git), API design, and the ability to build complex PoCs for risk models.

  • Full-Lifecycle Engineering Governance: Proven mastery of the end-to-end SDLC, including the creation and oversight of comprehensive SRS documentation, Project Plans, and Product Backlogs to ensure architectural alignment from initial planning through to deployment and maintenance.

  • Architectural & Quality Standards: Ability to define System Architectures, Data Models (ERDs), and API specifications while enforcing rigorous QA standards through formalized Test Plans, automated Build Scripts, and Production Operations manuals.

  • Experience leading the technical roadmap for software engineering teams or data scientists without direct reporting authority (e.g., Lead, Principal, or Staff level experience).

  • Technical Influence: Data & Automation Engineering: Validated proficiency in data pipeline logic, ELT/ETL processes, and data quality assurance, specifically as they apply to automating security telemetry.

Other Qualifications 

  • Strategic Technical Translation: Architect high-level business and security "end-states" into sophisticated process designs and technical specifications. You will own the translation of risk philosophy into the logic used by our engineering squads.

  • Risk Domain Authority: Serve as the definitive Subject Matter Expert (SME) for defining risk metrics and calculation methodologies, specifically within:

  • Enterprise Risk (ERM): Designing and implementing data-driven risk frameworks (e.g., NIST, FAIR) through sophisticated automation.

  • Third-Party Risk (TPRM): Architecting systems for automated due diligence, continuous monitoring, and assessment scoring for our vendor ecosystem.

  • Cross-Functional Influence: Champion security risk automation across the organization, mentoring junior engineers and influencing stakeholders on best practices for data-driven risk modeling.

Essential Domain Knowledge 

  • Mastery of Cybersecurity Risk: A proven track record of designing and implementing Enterprise and Third-Party Risk Management (TPRM) programs at scale.

  • Architectural Design: Demonstrated ability to take a blank slate and define complex security processes, translating them into technical user stories, functional specifications, and logic diagrams.

  • Advanced Risk Modeling: Expertise in quantitative risk analysis (e.g., Monte Carlo simulations or FAIR methodology) and how to programmatically apply these models to software.


Workday Pay Transparency Statement

The annualized base salary ranges for the primary location and any additional locations are listed below.  Workday pay ranges vary based on work location. As a part of the total compensation package, this role may be eligible for the Workday Bonus Plan or a role-specific commission/bonus, as well as annual refresh stock grants. Recruiters can share more detail during the hiring process. Each candidate’s compensation offer will be based on multiple factors including, but not limited to, geography, experience, skills, job duties, and business need, among other things. For more information regarding Workday’s comprehensive benefits, please click here.

Primary Location: USA.VA.Reston


 

Primary Location Base Pay Range: $184,800 USD - $277,200 USD


 

Additional US Location(s) Base Pay Range: $167,200 USD - $300,000 USD


Our Approach to Flexible Work
 

With Flex Work, we’re combining the best of both worlds: in-person time and remote. Our approach enables our teams to deepen connections, maintain a strong community, and do their best work. We know that flexibility can take shape in many ways, so rather than a number of required days in-office each week, we simply spend at least half (50%) of our time each quarter in the office or in the field with our customers, prospects, and partners (depending on role). This means you'll have the freedom to create a flexible schedule that caters to your business, team, and personal needs, while being intentional to make the most of time spent together. Those in our remote "home office" roles also have the opportunity to come together in our offices for important moments that matter.

Pursuant to applicable Fair Chance law, Workday will consider for employment qualified applicants with arrest and conviction records.

Workday is an Equal Opportunity Employer including individuals with disabilities and protected veterans.


At Workday, we are committed to providing an accessible and inclusive hiring experience where all candidates can fully demonstrate their skills. If you require assistance or an accommodation at any point, please email
[email protected].

Are you being referred to one of our roles? If so, ask your connection at Workday about our Employee Referral process!

At Workday, we value our candidates’ privacy and data security.  Workday will never ask candidates to apply to jobs through websites that are not Workday Careers. 

  

Please be aware of sites that may ask for you to input your data in connection with a job posting that appears to be from Workday but is not.

  

In addition, Workday will never ask candidates to pay a recruiting fee, or pay for consulting or coaching services, in order to apply for a job at Workday.

Workday Boulder, Colorado, USA Office

Boulder, United States

Similar Jobs

5 Days Ago
In-Office
Boulder, CO, USA
167K-300K Annually
Expert/Leader
167K-300K Annually
Expert/Leader
Cloud • Fintech • HR Tech
Lead architecture, development, and operations of security response tooling and environments (SOAR, SIEM, DFIR, DLP, Agentic AI). Drive incident response, threat hunting, security automation, and forensics, mentor staff, and evolve cloud-native response platforms to enable automated, precise cyber defense.
Top Skills: Agentic AiCloud-Native Security SolutionsConversational AiData Loss Prevention (Dlp)DfirForensicsGenerative AiIncident ResponseScripting LanguagesSecurity AutomationSIEMSoarSsdlcThreat Hunting
5 Days Ago
In-Office
156K-235K Annually
Senior level
156K-235K Annually
Senior level
Aerospace • Logistics • Security • Software • Cybersecurity
Lead RMF activities (A&A, continuous monitoring, vulnerability management); drive secure system design in Agile; decompose software security requirements; triage SCA findings; advise on cloud security and event monitoring (Splunk); support CI/CD and private cloud implementation and ATO accreditation; perform vulnerability scanning, patch management on Windows/Red Hat; produce RMF artifacts (SSP, RAR, SCTM, POA&Ms); conduct code reviews and application security testing; provide technical leadership and mentorship.
Top Skills: CC++Ci/CdContinuous MonitoringDynamic Code AnalysisFortifyJavaNist 800-37Nist 800-53Owasp Top 10Private CloudPythonRed HatRmfSoftware Dependency ScanningSplunkStatic Code AnalysisSwdlcVirtualizationVulnerability ScanningWindows
3 Hours Ago
In-Office
197K-246K Annually
Senior level
197K-246K Annually
Senior level
Information Technology • Security • Cybersecurity
Lead architecture, implementation, and operation of information system security controls. Oversee incident detection and response, access management, risk/compliance assessments, security governance, and training. Coordinate with teams and third parties to remediate vulnerabilities and ensure NIST/CMMC compliance.
Top Skills: AutomoxAWSAzureCloudCmmc 2.0Endpoint Detection And ResponseGCPIntrusion Detection SystemsIt Service ManagementLinuxNist 800-171Nist 800-53QualysScripting LanguagesSIEMSumo LogicVpn

What you need to know about the Colorado Tech Scene

With a business-friendly climate and research universities like CU Boulder and Colorado State, Colorado has made a name for itself as a startup ecosystem. The state boasts a skilled workforce and high quality of life thanks to its affordable housing, vibrant cultural scene and unparalleled opportunities for outdoor recreation. Colorado is also home to the National Renewable Energy Laboratory, helping cement its status as a hub for renewable energy innovation.

Key Facts About Colorado Tech

  • Number of Tech Workers: 260,000; 8.5% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Lockheed Martin, Century Link, Comcast, BAE Systems, Level 3
  • Key Industries: Software, artificial intelligence, aerospace, e-commerce, fintech, healthtech
  • Funding Landscape: $4.9 billion in VC funding in 2024 (Pitchbook)
  • Notable Investors: Access Venture Partners, Ridgeline Ventures, Techstars, Blackhorn Ventures
  • Research Centers and Universities: Colorado School of Mines, University of Colorado Boulder, University of Denver, Colorado State University, Mesa Laboratory, Space Science Institute, National Center for Atmospheric Research, National Renewable Energy Laboratory, Gottlieb Institute

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account