Cybersecurity Engineer, Workday SIRT

Ireland, Dublin

Workday

Workday unites HR and finance on one AI platform to help elevate humans and supercharge work to keep business moving forever forward.

View all jobs at Workday

Apply now Apply later

Your work days are brighter here.

At Workday, it all began with a conversation over breakfast. When our founders met at a sunny California diner, they came up with an idea to revolutionize the enterprise software market. And when we began to rise, one thing that really set us apart was our culture. A culture which was driven by our value of putting our people first. And ever since, the happiness, development, and contribution of every Workmate is central to who we are. Our Workmates believe a healthy employee-centric, collaborative culture is the essential mix of ingredients for success in business. That’s why we look after our people, communities and the planet while still being profitable. Feel encouraged to shine, however that manifests: you don’t need to hide who you are. You can feel the energy and the passion, it's what makes us unique. Inspired to make a brighter work day for all and transform with us to the next stage of our growth journey? Bring your brightest version of you and have a brighter work day here.

At Workday, we value our candidates’ privacy and data security.  Workday will never ask candidates to apply to jobs through websites that are not Workday Careers. 

  

Please be aware of sites that may ask for you to input your data in connection with a job posting that appears to be from Workday but is not.

  

In addition, Workday will never ask candidates to pay a recruiting fee, or pay for consulting or coaching services, in order to apply for a job at Workday.

About the Team

Workday is looking for a passionate and experienced security professional. This is an opportunity to contribute to a highly visible team involved in all major cybersecurity events, where your skills and experience will be used to inspire confidence and trust in Workday.
This is a highly technical role with the understanding that you are already conversant in incident response, security automation, system security, network security, and threat hunting. The role primarily focuses on supporting the tooling and automation requirements of the Workday SIRT. However you will be expected to take part as required in the investigative and response operations of the team. We offer a hybrid/flexible schedule for employees.

About the Role

Workday is looking for a passionate and experienced security professional. This is an opportunity to contribute to a highly visible team involved in all major cybersecurity events, where your skills and experience will be used to inspire confidence and trust in Workday. 
 

This is a highly technical role with the understanding that you are already conversant in incident response, security automation, system security, network security, and threat hunting. The role primarily focuses on supporting the tooling and automation requirements of the Workday SIRT. However you will be expected to take part as required in the investigative and response operations of the team. We offer a hybrid/flexible schedule for employees.


 

You will engage in the following activities:

  • Design, implement, deploy, and maintain critical SIRT infrastructure and tooling (e.g., SOAR, SIEM, EDR), ensuring optimal performance and availability for 24/7/365 SIRT operations.

  • Develop, integrate, and manage custom automations, scripts, and playbooks to enhance operational efficiency, automate response actions, and improve forensic capabilities.

  • Serve as a subject matter expert for key security technologies, providing advanced support, configuration management, and optimization to the SIRT..

  • Proactively identify and implement enhancements to security detection and response capabilities by optimizing tool configurations, developing new detection logic, and integrating threat intelligence feeds.

  • Lead the evaluation, selection, and implementation of new security tools and technologies, ensuring they align with strategic security objectives and integrate effectively into the existing ecosystem.

  • Participate in a scheduled on-call rotation, providing expert-level support for SIRT tooling and assisting with complex technical escalations during incident response activities in a global, follow-the-sun model.

  • Collaborate with incident responders, threat hunters, and other internal teams to understand their tooling needs, gather requirements, and deliver effective engineering solutions.

  • Actively participate in incident response activities, including digital forensic investigations and security event analysis, leveraging and enhancing security tools to support these efforts.

About You

Basic Qualifications

  • Bachelor’s Degree in Computer Science, Cybersecurity, Information Technology, or a related STEM field, or equivalent demonstrable practical experience and engineering excellence.

  • 3+ years of hands-on experience in an incident response, security engineering, security operations, or a similar technical role with a strong focus on security tooling and automation.

  • Proven experience in designing, implementing, and maintaining core security technologies such as SIEM, SOAR platforms, and EDR solutions.

  • Proficiency in Linux/Unix administration and strong scripting/programming skills in languages such as Python, Go, or PowerShell, with experience in developing security automation and integrations.

  • Demonstrable experience with configuration management tools (e.g., Ansible, Chef, Puppet, Terraform) and version control systems (e.g., Git).

Other Qualifications

  • Relevant industry certifications such as GIAC (e.g., GCIH, GCIA, GCDA, GDAT), Offensive Security (e.g., OSCP, OSWE), or vendor-specific certifications for SIEM/SOAR technologies.

  • Experience with security in public cloud environments (AWS, GCP, Azure), including native security services and infrastructure-as-code practices.

  • Solid understanding of network protocols (TCP/IP, DNS, HTTP/S), security principles, and common attack vectors (MITRE ATT&CK Framework).

  • Experience participating in incident response processes, including evidence collection, analysis, and containment, supported by strong tooling.

  • Excellent problem-solving skills, with the ability to troubleshoot complex technical issues related to security tools and infrastructure.

  • Strong communication and collaboration skills, with the ability to explain complex technical concepts to both technical and non-technical audiences.

  • Experience with continuous integration/continuous deployment (CI/CD) pipelines and methodologies (e.g., Jenkins, GitLab CI).

  • A proactive mindset with a passion for continuous learning and staying updated on the latest security threats, vulnerabilities, and technologies.



Our Approach to Flexible Work
 

With Flex Work, we’re combining the best of both worlds: in-person time and remote. Our approach enables our teams to deepen connections, maintain a strong community, and do their best work. We know that flexibility can take shape in many ways, so rather than a number of required days in-office each week, we simply spend at least half (50%) of our time each quarter in the office or in the field with our customers, prospects, and partners (depending on role). This means you'll have the freedom to create a flexible schedule that caters to your business, team, and personal needs, while being intentional to make the most of time spent together. Those in our remote "home office" roles also have the opportunity to come together in our offices for important moments that matter.

Are you being referred to one of our roles? If so, ask your connection at Workday about our Employee Referral process!

Apply now Apply later

* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰

Job stats:  1  0  0

Tags: Ansible Automation AWS Azure CI/CD Cloud Computer Science DNS EDR GCIA GCIH GCP GIAC GitLab Incident response Jenkins Linux MITRE ATT&CK Network security Offensive security OSCP OSWE PowerShell Privacy Puppet Python Scripting SIEM SOAR STEM TCP/IP Terraform Threat intelligence UNIX Vulnerabilities

Perks/benefits: Career development Flex hours Home office stipend Team events

Region: Europe
Country: Ireland

More jobs like this

Explore more career opportunities

Find even more open roles below ordered by popularity of job title or skills/products/technologies used.