Sr. Software Engineer, Security (pipedream)

Workday Workday · Enterprise · Pleasanton, CA

Workday is seeking a Sr. Software Engineer, Security for their Pipedream team. This role will own platform security end-to-end, including tooling, process, threat modeling, and audits, while also working hands-on in the codebase to find and fix vulnerabilities. The engineer will be responsible for securing cloud infrastructure, leading incident response, and owning compliance work like SOC 2 and HIPAA. The role requires extensive experience in product security, application security, or software engineering with a security focus, and experience securing cloud platforms.

What you'd actually do

  1. Finding and patching vulnerabilities directly in code and dependencies. Pipedream runs a polyglot stack — TypeScript, Rust, Kotlin, Ruby, and more — so you will read and fix code across all of it.
  2. Building and maintaining the platform's threat model, and partnering with Product and Engineering to ship new features securely without slowing them down.
  3. Securing cloud infrastructure (AWS, GCP) and the third-party vendor surface (Redis, Datadog, and others).
  4. Leading incident response for critical security issues.
  5. Owning SOC 2, HIPAA, penetration tests, and other compliance work end-to-end.

Skills

Required

  • product security
  • application security
  • software engineering with a security focus
  • vulnerability management
  • threat modeling
  • risk analysis
  • securing AWS or comparable cloud platforms at production scale
  • security incident response
  • reading and patching code across multiple languages

Nice to have

  • compliance frameworks such as SOC 2 or HIPAA
  • Offensive security background (vulnerability testing, penetration testing, red teaming)
  • Experience securing Kubernetes and Docker workloads in production

What the JD emphasized

  • own platform security end-to-end
  • build a security function from scratch
  • 7+ years of experience in product security, application security, or software engineering with a security focus
  • Hands-on experience with vulnerability management, threat modeling, and risk analysis
  • Experience securing AWS or comparable cloud platforms at production scale
  • Demonstrated experience in threat and vulnerability management
  • Solid understanding of application security
  • Proficiency in securing cloud infrastructure
  • Experience with security incident response
  • Comfort reading and patching code across multiple languages
  • A history of building security programs that engineering teams actually adopt
  • Experience with compliance frameworks such as SOC 2 or HIPAA