Sr Cybersecurity Engineer

Workday Workday · Enterprise · USA.VA.Reston, United States +1

Workday is seeking a Sr. Cybersecurity Engineer to join their Offensive Security Team. This role involves performing security assessments, penetration testing, red teaming, vulnerability research, and developing security automation tools against Workday's products, infrastructure, and internal applications. The ideal candidate will have extensive experience in offensive security, scripting for automation, and knowledge of modern security best practices and networking fundamentals.

What you'd actually do

  1. perform security assessments and scale security at Workday
  2. performing vulnerability assessments against Workday applications, services, and networks
  3. developing security automation and tools
  4. researching new threats and executing creative exploits
  5. AI Agentic Redteaming

Skills

Required

  • 8+ years of progressive experience in a similar role
  • 3+ yrs of experience leading PenTests in one or more areas such as public cloud infrastructure (AWS, Google Cloud), modern web applications, enterprise network assessments, API testing, AI Agentic Redteaming
  • 3+ yrs of experience with one or more scripting languages for automation (python, Go, Bash, Ruby, etc.)
  • Understanding of modern security best practices such as OWASP Top 10 & MITRE ATT&CK framework
  • Knowledge of networking & technology fundamentals and how to attack their weaknesses (TCP/IP stack, Linux, Docker, Kubernetes, Microservice architectures)
  • Must have experience with Web Proxy such as BurpSuite, Zap or others

Nice to have

  • one or more industry leading certifications (OSCP, CRTE, CRTO, ARTE, CPTS, etc.)
  • Bug Bounty submissions experience or have independent research e.g. GitHub projects
  • The ability to triage findings and work on remediation plans with partner teams
  • Excellent written & verbal communication skills

What the JD emphasized

  • AI Agentic Redteaming