Sr Cybersecurity Engineer

Posted 8 Hours Ago
Be an Early Applicant
2 Locations
In-Office
144K-258K Annually
Senior level
Cloud • Fintech • HR Tech
The Role
The Sr Cybersecurity Engineer will assess and secure Workday's applications and infrastructure, perform penetration testing, develop automation tools, and research threats.
Summary Generated by Built In

Your work days are brighter here.

We’re obsessed with making hard work pay off, for our people, our customers, and the world around us. As a Fortune 500 company and a leading AI platform for managing people, money, and agents, we’re shaping the future of work so teams can reach their potential and focus on what matters most. The minute you join, you’ll feel it. Not just in the products we build, but in how we show up for each other. Our culture is rooted in integrity, empathy, and shared enthusiasm. We’re in this together, tackling big challenges with bold ideas and genuine care. We look for curious minds and courageous collaborators who bring sun-drenched optimism and drive. Whether you're building smarter solutions, supporting customers, or creating a space where everyone belongs, you’ll do meaningful work with Workmates who’ve got your back. In return, we’ll give you the trust to take risks, the tools to grow, the skills to develop and the support of a company invested in you for the long haul. So, if you want to inspire a brighter work day for everyone, including yourself, you’ve found a match in Workday, and we hope to be a match for you too.

About the Team

Workday's Offensive Security Team is full of skilled cybersecurity engineers who are passionate about product security...and occasionally breaking things, so they can be fixed again! We are tasked to proactively secure Workday's products, infrastructure, and internal applications. Not only do we regularly assess for security issues through manual and automated penetration testing across all levels of the application stack, but we also conduct advanced offensive security operations including red teaming, purple teaming, vulnerability research, and credentials auditing to simulate real-world threats and identify weaknesses.
We collaborate with dedicated Workmates globally and manage Workday's external and internal bug bounty programs, fostering partnerships with our developers and external researchers to uncover and responsibly disclose vulnerabilities. Ultimately, we're driven by a desire to continuously improve Workday's security posture and ensure the highest level of protection for our users.

About the Role

As a Sr. Cybersecurity Engineer, you will be part of an elite team of security professionals and ethical hackers with deep experience in security engineering. The Workday Offensive Security is looking for a seasoned penetration tester to help us perform security assessments and scale security at Workday.  On our team, you will be performing vulnerability assessments against Workday applications, services, and networks, as well as developing security automation and tools. You will be researching new threats and executing creative exploits. If you are a passionate learner, an advocate for security, and are a highly skilled offensive security engineer, then this is the right job for you!

About You

You will be a great fit for this role if you have -

Basic Qualifications

  • 8+ years of progressive experience in a similar role

  • 3+ yrs of experience leading PenTests in one or more areas such as public cloud infrastructure (AWS, Google Cloud), modern web applications, enterprise network assessments, API testing, AI Agentic Redteaming

  • 3+ yrs of experience with one or more scripting languages for automation (python, Go, Bash, Ruby, etc.)

  • Understanding of modern security best practices such as OWASP Top 10 & MITRE ATT&CK framework

  • Knowledge of networking & technology fundamentals and how to attack their weaknesses (TCP/IP stack, Linux, Docker, Kubernetes, Microservice architectures)

  • Must have experience with Web Proxy such as BurpSuite, Zap or others

Other Qualifications

  • Have one or more industry leading certifications (OSCP, CRTE, CRTO, ARTE, CPTS, etc.)

  • Have Bug Bounty submissions experience or have independent research e.g. GitHub projects

  • The ability to triage findings and work on remediation plans with partner teams

  • Excellent written & verbal communication skills

Workday Pay Transparency Statement

The annualized base salary ranges for the primary location and any additional locations are listed below.  Workday pay ranges vary based on work location. As a part of the total compensation package, this role may be eligible for the Workday Bonus Plan or a role-specific commission/bonus, as well as annual refresh stock grants. Recruiters can share more detail during the hiring process. Each candidate’s compensation offer will be based on multiple factors including, but not limited to, geography, experience, skills, job duties, and business need, among other things. For more information regarding Workday’s comprehensive benefits, please click here.

Primary Location: USA.VA.Reston


 

Primary Location Base Pay Range: $159,600 USD - $239,400 USD


 

Additional US Location(s) Base Pay Range: $144,400 USD - $258,000 USD

Additional Considerations:

If performed in Colorado, the pay range for this job is $152,000 - $228,000 USD based on min and max pay range for that role if performed in CO.

The application deadline for this role is the same as the posting end date stated as below:
 

04/30/2026

Our Approach to Flexible Work
 

With Flex Work, we’re combining the best of both worlds: in-person time and remote. Our approach enables our teams to deepen connections, maintain a strong community, and do their best work. We know that flexibility can take shape in many ways, so rather than a number of required days in-office each week, we simply spend at least half (50%) of our time each quarter in the office or in the field with our customers, prospects, and partners (depending on role). This means you'll have the freedom to create a flexible schedule that caters to your business, team, and personal needs, while being intentional to make the most of time spent together. Those in our remote "home office" roles also have the opportunity to come together in our offices for important moments that matter.

Pursuant to applicable Fair Chance law, Workday will consider for employment qualified applicants with arrest and conviction records.

Workday is an Equal Opportunity Employer including individuals with disabilities and protected veterans.


At Workday, we are committed to providing an accessible and inclusive hiring experience where all candidates can fully demonstrate their skills. If you require assistance or an accommodation at any point, please email
[email protected].

Are you being referred to one of our roles? If so, ask your connection at Workday about our Employee Referral process!

At Workday, we value our candidates’ privacy and data security.  Workday will never ask candidates to apply to jobs through websites that are not Workday Careers. 

  

Please be aware of sites that may ask for you to input your data in connection with a job posting that appears to be from Workday but is not.

  

In addition, Workday will never ask candidates to pay a recruiting fee, or pay for consulting or coaching services, in order to apply for a job at Workday.

Top Skills

AWS
Bash
Go
GCP
Mitre Att&Ck
Owasp Top 10
Python
Ruby
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Pleasanton, CA
14,894 Employees
Year Founded: 2005

What We Do

Workday is a leading provider of enterprise cloud applications for finance, HR, and planning. Founded in 2005, Workday delivers financial management, human capital management, and analytics applications designed for the world’s largest companies, educational institutions, and government agencies. Organizations ranging from medium-sized businesses to Fortune 50 enterprises have selected Workday.

Similar Jobs

ECS Logo ECS

Senior Cybersecurity DevOps and Kubernetes Engineer

Artificial Intelligence • Cloud • Information Technology • Security • Software
In-Office
Homeland, VA, USA
2129 Employees
100K-160K Annually

Workday Logo Workday

Cybersecurity Engineer

Cloud • Fintech • HR Tech
In-Office
2 Locations
14894 Employees
144K-258K Annually

MetroStar Logo MetroStar

Cybersecurity Engineer

Information Technology • Consulting
In-Office
Reston, VA, USA
250 Employees
165K-193K Annually
In-Office
McLean, VA, USA
87K-198K Annually

Similar Companies Hiring

Rain Thumbnail
Blockchain • Fintech • Payments • Financial Services • Cryptocurrency • Web3 • Infrastructure as a Service (IaaS)
New York, NY
100 Employees
Scotch Thumbnail
Artificial Intelligence • eCommerce • Fintech • Payments • Retail • Software • Analytics
US
35 Employees
Kepler  Thumbnail
Fintech • Software
New York, New York
6 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account