Software Development Engineer, Security at Workday

Toronto, Ontario, Canada

Workday Logo
Not SpecifiedCompensation
Mid-level (3 to 4 years)Experience Level
Full TimeJob Type
UnknownVisa
Technology, Cybersecurity, Enterprise SoftwareIndustries

Requirements

  • 5+ years of experience in software engineering focused on security or building security tools
  • 3+ years experience with Python and Python web development framework (FastAPI, Flask, or Django)
  • 3+ years experience with cloud platforms (e.g., AWS, GCP) and containerization technologies (e.g., Docker, Kubernetes)
  • Familiarity with AI security concepts
  • Experience with building AI
  • Familiarity with SOC2, ISO27001, ISO 27701 and ISO 42001
  • Proficiency in security tools (e.g., Snyk, Semgrep, Contrast, Wiz)
  • Familiarity with infrastructure as code (IaC) tools (e.g., Terraform, Cloudformation, Ansible)
  • Full-stack generalist
  • Proficient in database systems (Postgres, DynamoDB, Redis, Pinecone)
  • Strong understanding of platform, application, and cloud security fundamentals
  • Strong understanding and practical application of modern software development practices, working with DevOps, automated testing, and observability
  • Understanding of network and application security threats, attack techniques, and mitigation options
  • Experience with incident response

Responsibilities

  • Design and build security products that empower the entire Workday AI organization
  • Integrate security at every stage of the software development lifecycle (SDLC) and deployment pipelines
  • Partner with engineering and platform teams to implement security-by-design and shift-left security practices
  • Patch vulnerable dependencies
  • Design and build security products that support and protect the broader organization
  • Manage the end-to-end vulnerability management lifecycle, including discovery, assessment, prioritization, remediation, and reporting

Skills

Key technologies and capabilities for this role

Cloud SecurityApplication SecurityAI SecurityRuntime SecuritySecurity ToolsSDLCSecurity Engineering

Questions & Answers

Common questions about this position

What are the basic qualifications for this role?

The position requires 5+ years of experience in software engineering focused on security or build.

What does the security team at Workday do?

The Evisort Security team is a hands-on security engineering team focused on building security software, enabling secure development across the stack, securing AI agent infrastructure, and embedding security into every phase of the SDLC, spanning cloud security, application security, AI security, runtime security, and compliance frameworks like SOC 2 and ISO 27001.

What are the main responsibilities of the Software Development Engineer, Security?

Responsibilities include designing and building security products for the Workday AI organization, integrating security into the SDLC and deployment pipelines, partnering with engineering teams for security-by-design, patching vulnerable dependencies, managing vulnerability lifecycles, and implementing shift-left security practices.

What is Workday's company culture like?

Workday has an employee-centric, collaborative culture that puts people first, emphasizes happiness, development, and contribution of every Workmate, encourages authenticity, and balances care for people, communities, and the planet with profitability.

Is this a remote position or does it require office work?

This information is not specified in the job description.

Workday

Cloud applications for finance and HR management

About Workday

Workday provides enterprise cloud applications that focus on finance and human resources for medium to large-sized businesses across various industries. Its main products include Workday Human Capital Management, Workday Financial Management, Workday Adaptive Planning, and Workday Student, which help organizations manage their workforce and streamline financial operations. The software operates on a subscription model, allowing clients to pay a recurring fee based on the number of users and specific modules needed. This model supports continuous updates and improvements to the software. Workday stands out from competitors due to its strong emphasis on customer satisfaction and employee engagement, offering tools like Workday Peakon Employee Voice to enhance workforce experience. The company's goal is to provide essential tools that improve operational efficiency and support businesses in managing their human resources and financial operations effectively.

Pleasanton, CaliforniaHeadquarters
2005Year Founded
$209.4MTotal Funding
IPOCompany Stage
Consulting, Enterprise SoftwareIndustries
10,001+Employees

Benefits

Flexible Work Hours
Hybrid Work Options
Performance Bonus
Stock Options
Professional Development Budget
Conference Attendance Budget

Risks

Emerging HR tech startups like Buk could challenge Workday's market share.
Dependency on third-party platforms like Udemy may complicate service delivery.
Strategic shifts under new leadership could disrupt existing customer relationships.

Differentiation

Workday is a leader in cloud-based HCM and ERP solutions for large enterprises.
The company offers a subscription model ensuring steady revenue and continuous software updates.
Workday's focus on employee engagement tools like Peakon sets it apart in the market.

Upsides

Increased demand for cloud HCM solutions boosts Workday's market potential.
AI-driven analytics enhance Workday's financial management offerings with predictive insights.
Workday's partner ecosystem expansion, like with MetLife, opens new customer opportunities.

Land your dream remote job 3x faster with AI