Workday is hiring a Cybersecurity Engineer to support Security Automation & Integration Engineering (SecAIE) within its Active Defense charter. The role primarily owns the agent, evaluation, and application layer that helps security teams inspect outcomes and take action using dependable shared security data.
Role Summary
In SecAIE, the Cybersecurity Engineer builds evaluation harnesses, agent scaffolds, schemas and data contracts, integrations, and internal user interfaces. These components enable security teams to work from consistent, reliable objects rather than one-off payloads, accelerating detection, response, and threat intelligence workflows.
Responsibilities
- Provide primary ownership of agent-adjacent application work, including eval harnesses, agent scaffolds, and the UIs security partners use to inspect and act on results.
- Design, build, and evolve schemas and data contracts so agents and humans operate on the same objects and shared data representations.
- Translate partner requests from vague to shipped by scoping problems, proposing approaches, selecting an approach, and driving delivery through design, review, rollout, and operational readiness. Operational readiness includes eval, tracing, and runbooks.
- Build and maintain integrations across security tooling and enterprise platforms, including SOAR, SIEM, vulnerability scanners, and ticketing, when the application or agent requires them.
- Increase the team’s baseline for AI-augmented engineering through shared skills, reusable scaffolds, review discipline for AI-generated code, and eval processes that catch drift.
- Iterate through a cycle of prototype, test, ship, learn, and improve while supporting the team through each iteration.
Required Qualifications
- Strong Python skills with hands-on experience shipping production software (APIs, services, batch jobs, or application backends), including code review, testing, and operational follow-through.
- Hands-on experience building or evaluating LLM/agent systems (harnesses, eval, tracing, or agentic pipelines) OR strong software-engineering fundamentals plus demonstrated AI-augmented development using tools such as Copilot or coding agents, with a point of view on where they help.
- Ability to design or evolve schemas and data contracts and application UIs that work on real data rather than mock-only prototypes.
- Working knowledge of core cybersecurity practices, including identity and access, secrets handling, secure-by-default configuration, and reasoning over common security data (vulnerabilities, incidents, identity, and threat intel) to build security-relevant outcomes.
- Comfort owning delivered work, including runbooks, basic observability, and eval that continues to run after code merges.
Technologies
Python; LLM / agent systems; LangChain; LangGraph; LangSmith; LLM-as-judge; offline eval; tracing; observability; React; SIEM; SOAR; vulnerability scanners; Copilot; coding agents; AWS; Terraform; Docker; Tines.
About the Team (SecAIE)
- Security Automation & Integration Engineering (SecAIE) creates intelligent automation that turns manual cybersecurity processes into scalable systems.
- SecAIE functions as an engineering excellence partner within Cybersecurity and Trust, building a unified data foundation, intelligent automation, and decision support tools.
- The team partners with Security Leadership, Operational Teams, Engineering Teams, and Governance/Risk Teams to deliver platforms that multiply security effectiveness.
- SecAIE’s charter supports Workday’s Active Defense pivot by building the reliable data and platform substrate for machine-speed security execution.
- The team is described as small, high-impact, and values curiosity, pragmatism, and collaboration.
Additional Role Context
This role focuses on the layer that partners actually use, including eval harnesses, agent scaffolds, schemas, and application UIs built on top of security data. While not expected to be the deepest security specialist, the engineer works alongside domain experts to build agents, eval, and applications that make security work faster, more reliable, and more measurable.
Location and Base Pay
- Primary location: USA.VA.Reston (onsite).
- Base salary range (USA.VA.Reston): USD 130,200 - 195,400 per year.
- Additional US location base salary range: USD 117,800 - 210,000 per year.
- Colorado note: If performed in Colorado, pay range is USD 124,000 - 186,000 based on the role’s min and max pay range for that state.
Application Deadline
The application deadline for this role is 10/16/2026.
Flexible Work Approach
- Flex Work combines in-person time with remote work.
- Spend at least 50% of your time each quarter in the office or in the field with customers, prospects, and partners (depending on role).
- Remote “home office” roles may have opportunities to come together in offices for important moments.
Accommodations
Workday is committed to providing reasonable accommodations for qualified individuals during the application process, including accommodations for qualified veterans, individuals with disabilities, and religious accommodations, as provided under applicable law.