Principal Cyber Security Engineer, Soc Lead (us Federal)

Workday Workday · Enterprise · USA.VA.Reston

This role is for a Principal Cyber Security Engineer, SOC Lead at Workday, focusing on supporting U.S. Federal Government SaaS deployments. The role involves technical and operational leadership for a 24x7 Security Operations Center, incident response, and driving automation. It requires experience with SIEM and SOAR platforms, managing security personnel, and understanding cybersecurity frameworks. The position is for US citizens and may require a security clearance.

What you'd actually do

  1. Provide technical and operational leadership for the Cyber Defense Security Operations Center supporting U.S. Government SaaS deployments, including air-gapped environments.
  2. Oversee 24x7 monitoring operations, incident response coordination, escalation management, and continuous improvement of SOC processes and capabilities.
  3. Lead a team of SOC Analysts, ensure high-quality investigations, oversee detection engineering collaboration, and drive automation initiatives leveraging platforms such as Splunk and SOAR technologies (e.g., Tines).
  4. Interface with Red, Blue, Purple Teams and Threat Intelligence to maintain an integrated cyber defense posture.
  5. Communicate risk effectively to leadership.

Skills

Required

  • 10+ years of experience in cybersecurity operations, incident response, or threat detection
  • 5+ years of experience leading or mentoring security operations personnel
  • Deep experience operating and tuning SIEM platforms such as Splunk
  • Experience managing incident response lifecycle activities aligned to NIST SP 800-61r3
  • Experience supporting secure cloud environments and/or air-gapped networks
  • Bachelor’s degree in Cybersecurity, Computer Science, Engineering, or equivalent experience

Nice to have

  • DoD 8570/8140 compliant with at least IAT Level II certification, including a current Computing Environment (CE) credential and one approved specialty certification (e.g., CompTIA CySA+, GICSP, CASP+)
  • Strong understanding of adversary TTPs and MITRE ATT&CK framework
  • Experience with SOAR platforms (e.g., Tines) and security automation
  • Proven ability to manage escalations and high-severity incidents
  • Experience developing KPIs, SLAs, and operational metrics
  • Strong critical thinking and decision-making skills under pressure
  • Ability to coordinate cross-functional teams (Red, Blue, Engineering, Compliance)
  • Excellent written and verbal communication skills
  • Experience building and improving SOC playbooks and runbooks
  • Certifications meeting DoD 8570 requirements

What the JD emphasized

  • mandates that all Workday personnel working on the contracts be United States citizens
  • This role may require a security clearance at the TS/SCI level. Applicants must have the ability to obtain and maintain a U.S. government issued security clearance.