Principal Software Development Engineer

Workday Workday · Enterprise · USA.VA.Reston

Workday is seeking a Principal Software Development Engineer to architect the development of their internal suite of Cybersecurity Risk Management and Automation tools. This role requires deep domain expertise in security risk and the technical ability to bridge strategy and software execution, focusing on structuring, analyzing, and automating risk data. The engineer will lead the technical roadmap for software engineering teams or data scientists, focusing on data pipeline logic, ELT/ETL processes, and automating security telemetry. Experience with custom GRC platforms, Python/Go/Java, full-lifecycle engineering governance, architectural design, and advanced risk modeling (e.g., Monte Carlo, FAIR) is required.

What you'd actually do

  1. architect the development of our internal suite of Cybersecurity Risk Management and Automation tools
  2. serve as the primary visionary for how our risk data is structured, analyzed, and automated, acting as the bridge between the Cybersecurity Risk organization and our Engineering teams
  3. lead the technical roadmap for software engineering teams or data scientists without direct reporting authority
  4. Architect high-level business and security "end-states" into sophisticated process designs and technical specifications
  5. Serve as the definitive Subject Matter Expert (SME) for defining risk metrics and calculation methodologies, specifically within: Enterprise Risk (ERM) and Third-Party Risk (TPRM)

Skills

Required

  • Python, Go, or Java
  • version control (Git)
  • API design
  • build complex PoCs for risk models
  • end-to-end SDLC
  • SRS documentation
  • Project Plans
  • Product Backlogs
  • System Architectures
  • Data Models (ERDs)
  • API specifications
  • Test Plans
  • automated Build Scripts
  • Production Operations manuals
  • data pipeline logic
  • ELT/ETL processes
  • data quality assurance
  • automating security telemetry
  • quantitative risk analysis (e.g., Monte Carlo simulations or FAIR methodology)
  • programmatically apply these models to software

Nice to have

  • mentoring junior engineers
  • influencing stakeholders

What the JD emphasized

  • 9+ Years of Experience building custom GRC (Governance, Risk, and Compliance) platforms
  • Mastery of Cybersecurity Risk
  • Advanced Risk Modeling