Cybersecurity Engineer
USA, VA, McLean, United States
Full Time USD 117K - 207K
Workday
Workday unites HR and finance on one AI platform to help elevate humans and supercharge work to keep business moving forever forward.Your work days are brighter here.
At Workday, it all began with a conversation over breakfast. When our founders met at a sunny California diner, they came up with an idea to revolutionize the enterprise software market. And when we began to rise, one thing that really set us apart was our culture. A culture which was driven by our value of putting our people first. And ever since, the happiness, development, and contribution of every Workmate is central to who we are. Our Workmates believe a healthy employee-centric, collaborative culture is the essential mix of ingredients for success in business. That’s why we look after our people, communities and the planet while still being profitable. Feel encouraged to shine, however that manifests: you don’t need to hide who you are. You can feel the energy and the passion, it's what makes us unique. Inspired to make a brighter work day for all and transform with us to the next stage of our growth journey? Bring your brightest version of you and have a brighter work day here.
At Workday, we value our candidates’ privacy and data security. Workday will never ask candidates to apply to jobs through websites that are not Workday Careers.
Please be aware of sites that may ask for you to input your data in connection with a job posting that appears to be from Workday but is not.
In addition, Workday will never ask candidates to pay a recruiting fee, or pay for consulting or coaching services, in order to apply for a job at Workday.
About the Team
Workday's PenTesting team is full of skilled cybersecurity engineers who are passionate about product security...and occasionally breaking things, so they can be fixed again! We are tasked to proactively secure Workday's products, infrastructure, and internal applications. Not only do we regularly assess for security issues through manual and automated penetration testing across all levels of the application stack, but we also conduct advanced offensive security operations including red teaming, purple teaming, vulnerability research, and credentials auditing to simulate real-world threats and identify weaknesses.We collaborate with dedicated Workmates globally and manage Workday's external and internal bug bounty programs, fostering partnerships with our developers and external researchers to uncover and responsibly disclose vulnerabilities. Ultimately, we're driven by a desire to continuously improve Workday's security posture and ensure the highest level of protection for our users.
About the Role
As a Cybersecurity Engineer, you will be part of an elite team of security professionals and ethical hackers with deep experience in security engineering. The Workday Pentest Team is looking for a seasoned penetration tester to help us perform security assessments and scale security at Workday. On our team, you will be performing vulnerability assessments against Workday applications, services, and networks, as well as developing security automation and tools. You will be researching new threats and executing creative exploits. If you are a passionate learner, an advocate for security, and are a highly skilled offensive security engineer, then this is the right job for you!
About You
You will be a great fit for this role if you have -
Basic Qualifications
5+ years of progressive experience in a similar role
Led PenTests in one or more areas such as public cloud infrastructure (AWS, Google Cloud), modern web applications, enterprise network assessments, or API testing
A detailed understanding of modern security best practices such as OWASP Top 10 & MITRE ATT&CK framework
In-depth knowledge of networking & technology fundamentals and how to attack their weaknesses (TCP/IP stack, Linux, Docker, Kubernetes, Microservice architectures)
Proven track record with one or more scripting languages for automation (python, Go, Bash, Ruby, etc.)
Must have experience with Web Proxy such as BurpSuite, Zap or others
Other Qualifications
One or more industry leading certifications (OSCP, CRTE, CRTO, ARTE, CPTS, etc.)
A bonus is a track record of Bug Bounty submissions or independent research e.g. GitHub projects
Excellent written & verbal communication skills
The ability to triage findings and work on remediation plans with partner teams
Workday Pay Transparency Statement
The annualized base salary ranges for the primary location and any additional locations are listed below. Workday pay ranges vary based on work location. As a part of the total compensation package, this role may be eligible for the Workday Bonus Plan or a role-specific commission/bonus, as well as annual refresh stock grants. Recruiters can share more detail during the hiring process. Each candidate’s compensation offer will be based on multiple factors including, but not limited to, geography, experience, skills, job duties, and business need, among other things. For more information regarding Workday’s comprehensive benefits, please click here.
Primary Location: USA.VA.McLean (Tyson's Corner)
Our Approach to Flexible Work
With Flex Work, we’re combining the best of both worlds: in-person time and remote. Our approach enables our teams to deepen connections, maintain a strong community, and do their best work. We know that flexibility can take shape in many ways, so rather than a number of required days in-office each week, we simply spend at least half (50%) of our time each quarter in the office or in the field with our customers, prospects, and partners (depending on role). This means you'll have the freedom to create a flexible schedule that caters to your business, team, and personal needs, while being intentional to make the most of time spent together. Those in our remote "home office" roles also have the opportunity to come together in our offices for important moments that matter.
Pursuant to applicable Fair Chance law, Workday will consider for employment qualified applicants with arrest and conviction records.
Workday is an Equal Opportunity Employer including individuals with disabilities and protected veterans.
Are you being referred to one of our roles? If so, ask your connection at Workday about our Employee Referral process!
Tags: APIs Audits Automation AWS Bash Burp Suite Cloud Docker Exploits GCP GitHub Kubernetes Linux MITRE ATT&CK Offensive security OSCP OWASP Pentesting Privacy Product security Python Red team Ruby Scripting Security assessment TCP/IP Vulnerabilities
Perks/benefits: Career development Equity / stock options Flex hours Home office stipend Salary bonus Transparency
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.