Principal Cybersecurity Engineer

Workday Workday · Enterprise · USA.VA.Reston

This Principal Cybersecurity Engineer role focuses on architecting and developing internal Cybersecurity Risk Management and Automation tools. The role requires expertise in Python, Go, or Java, full-lifecycle engineering governance, and data pipeline logic for automating security telemetry. It bridges the gap between Cybersecurity Risk and Engineering teams, focusing on structuring, analyzing, and automating risk data.

What you'd actually do

  1. architect the development of our internal suite of Cybersecurity Risk Management and Automation tools
  2. serve as the primary visionary for how our risk data is structured, analyzed, and automated, acting as the bridge between the Cybersecurity Risk organization and our Engineering teams
  3. architect high-level business and security "end-states" into sophisticated process designs and technical specifications
  4. Serve as the definitive Subject Matter Expert (SME) for defining risk metrics and calculation methodologies
  5. designing and implementing Enterprise and Third-Party Risk Management (TPRM) programs at scale

Skills

Required

  • Python
  • Go
  • Java
  • Git
  • API design
  • SDLC
  • SRS documentation
  • Project Plans
  • Product Backlogs
  • System Architectures
  • Data Models (ERDs)
  • API specifications
  • QA standards
  • Test Plans
  • automated Build Scripts
  • Production Operations manuals
  • data pipeline logic
  • ELT/ETL processes
  • data quality assurance
  • Enterprise Risk Management (ERM)
  • Third-Party Risk Management (TPRM)
  • NIST
  • FAIR methodology
  • Monte Carlo simulations

Nice to have

  • building custom GRC platforms
  • risk models
  • security telemetry automation

What the JD emphasized

  • 9+ Years of Experience building custom GRC (Governance, Risk, and Compliance) platforms
  • Demonstrable proficiency in Python, Go, or Java
  • Proven mastery of the end-to-end SDLC
  • Ability to define System Architectures, Data Models (ERDs), and API specifications
  • Experience leading the technical roadmap for software engineering teams or data scientists without direct reporting authority
  • Validated proficiency in data pipeline logic, ELT/ETL processes, and data quality assurance, specifically as they apply to automating security telemetry
  • Mastery of Cybersecurity Risk
  • Architectural Design
  • Advanced Risk Modeling