Sr Cybersecurity Engineer

Workday Workday · Enterprise · Auckland, New Zealand

This role is for a Sr. Cybersecurity Engineer at Workday, a company that uses AI in its platform. The engineer will be part of the cybersecurity response program, focusing on incident response, digital forensics, threat hunting, security automation, and data loss prevention. They will integrate AI into operational workflows, monitor and respond to security alerts, lead investigations, conduct threat hunting, design and implement improvements to IR tooling (including SOAR workflows and custom scripts), and contribute to the architecture and tuning of security tools. The role requires strong experience in security engineering and response, scripting languages (Python, Ruby), cloud/hybrid environments, and understanding of attacker techniques. While AI is mentioned as a tool to enhance processes, the core function of the role is cybersecurity engineering and response, not building AI models.

What you'd actually do

  1. Monitor and respond to security alerts and events from SIEM, EDR, network security tools, cloud platforms, and other telemetry sources as part of a follow-the-sun model.
  2. Lead and coordinate technical investigations for all‑severity security incidents (e.g., endpoint compromise, account takeover, data exfiltration, insider threat).
  3. Conduct hypothesis‑driven threat hunting using available telemetry to identify previously undetected malicious activity.
  4. Design and implement improvements to IR tooling, including SOAR workflows, custom scripts, and integrations that reduce mean time to detect/respond, identify automation opportunities and where artificial intelligence can be leveraged for enhancement.
  5. Contribute to the architecture and tuning of SIEM, EDR, logging pipelines, and security tooling to ensure high‑quality, actionable alerts.

Skills

Required

  • 6+ years of experience as a security engineer/analyst in related domains
  • Bachelor’s Degree or equivalent experience
  • Solid understanding of common attacker techniques and the threat landscape (e.g., MITRE ATT&CK, phishing, credential theft, lateral movement, data exfiltration).
  • Deep hands‑on experience with security monitoring and incident response across cloud and/or hybrid environments (e.g., AWS, Azure, GCP, SaaS platforms).
  • Python, Ruby and other scripting languages is essential, as is a strong understanding of Linux/OSX and Windows.
  • Demonstrated capability to oversee multiple complex projects and competing priorities effectively while fulfilling core operational obligations.
  • Excellent analytical and problem‑solving skills; able to reason about incomplete data and make pragmatic decisions under time pressure.
  • High level of ownership and accountability; comfortable taking the lead during high‑severity incidents.
  • Commitment to continuous learning and staying current with evolving attacker techniques, tools, and security technologies.
  • Clear written and verbal communication skills, with the ability to translate complex technical findings into language suitable for non‑technical stakeholders.
  • Security alert triage and investigation
  • Incident response and incident management
  • Threat hunting and digital forensics
  • SIEM and SOAR security technologies and solutions
  • Leveraging artificial intelligence to enhance processes
  • Secure Software Development Lifecycle (SSDLC)

Nice to have

  • Other relevant certification/s and training (e.g. Offensive Security, SANS, CISSP, Specific Security Tooling, etc.).

What the JD emphasized

  • extensive security engineering and response expertise
  • highly technical role
  • Deep hands‑on experience with security monitoring and incident response across cloud and/or hybrid environments
  • Python, Ruby and other scripting languages is essential
  • Strong understanding of Linux/OSX and Windows
  • Excellent analytical and problem‑solving skills
  • High level of ownership and accountability
  • Commitment to continuous learning and staying current with evolving attacker techniques, tools, and security technologies.
  • Clear written and verbal communication skills