Sr. Software Engineer, Security (Pipedream)

Workday

Pleasanton (CA)

Hybrid

USD 176,000 - 264,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Workday is seeking its first dedicated Security Engineer to own platform security end-to-end. You'll work hands-on in the codebase, managing vulnerabilities and building a security function at scale.

With 7+ years of product security experience, you'll oversee threat models and incident responses, ensuring secure cloud infrastructure and compliance. The position includes a competitive salary range of $176,000 to $264,000, with the flexibility of combining in-person and remote work.

Qualifications

  • 7+ years of experience in product security, application security, or software engineering with a security focus.
  • Hands-on experience with vulnerability management, threat modeling, and risk analysis.
  • Experience securing AWS or comparable cloud platforms at production scale.

Responsibilities

  • Find and patch vulnerabilities directly in code and dependencies across a polyglot stack.
  • Build and maintain the platform’s threat model, partnering with product and engineering.
  • Lead incident response for critical security issues.

Skills

Vulnerability management
Threat modeling
Risk analysis
Cloud security
Incident response

Job description

The Pipedream team operates an integration platform that connects Workday services to over 3,000 APIs. We build and maintain public-facing APIs, code execution environments, and a high-volume event processing pipeline, powering the platform.

Our work sits at the intersection of scale and connectivity: every integration that runs on Pipedream depends on the reliability, performance, and security of the infrastructure we build. If you enjoy working on systems that thousands of developers rely on every day, this is a great team to be part of.

About the Role

As Pipedream's first dedicated Security Engineer, you will own platform security end-to-end—tooling, process, threat modeling, and audits—while working hands‑on in the codebase to find and fix vulnerabilities yourself. This is a deeply technical individual contributor role with broad scope, building a security function from scratch at a platform serving thousands of developers.

Responsibilities
  • Find and patch vulnerabilities directly in code and dependencies across a polyglot stack (TypeScript, Rust, Kotlin, Ruby, and more).
  • Build and maintain the platform’s threat model, partnering with product and engineering to ship new features securely.
  • Secure cloud infrastructure (AWS, GCP) and third‑party vendor surface (Redis, Datadog, etc.).
  • Lead incident response for critical security issues.
  • Own SOC 2, HIPAA, penetration tests, and other compliance work end‑to‑end.
  • Partner with Workday’s security team to translate broader policy into solutions that fit Pipedream’s stack and operations.
Basic Qualifications
  • 7+ years of experience in product security, application security, or software engineering with a security focus.
  • Hands‑on experience with vulnerability management, threat modeling, and risk analysis.
  • Experience securing AWS or comparable cloud platforms at production scale.
Other Qualifications
  • Experience in threat and vulnerability management, including identifying, assessing, and mitigating potential risks and weaknesses across a platform’s security infrastructure.
  • Strong understanding of application security, protecting software applications from threats and vulnerabilities.
  • Proficiency in securing cloud infrastructure, including design, management, and maintenance of cloud‑based environments at scale.
  • Experience with security incident response, including systematic management of security breaches or attacks.
  • Comfort reading and patching code across multiple languages.
  • History of building security programs that engineering teams adopt.
  • Experience with compliance frameworks such as SOC 2 or HIPAA (running audits end‑to‑end) is a plus.
  • Offensive security background (penetration testing, red teaming) is a plus.
  • Experience securing Kubernetes and Docker workloads in production is a plus.
Pay Transparency Statement

Primary location: USA.CA.Pleasanton – Base salary range: $176,000 USD – $264,000 USD. Additional US locations: $148,200 USD – $264,000 USD. Role may be eligible for bonus plan, commission, stock grants, and other incentives. Additional compensation details will be discussed during the hiring process.

Flexible Work

We combine in‑person time and remote work. You spend at least 50 % of your time each quarter in the office or in the field. Remote “home office” roles can come together in our offices for important moments.

Pursuant to Fair Chance law, Workday considers qualified applicants with arrest and conviction records.

Workday is an Equal Opportunity Employer for individuals with disabilities, protected veterans, and all other protected classes.

We provide accessible and inclusive hiring experiences. If you require accommodations, contact accommodations@workday.com.

At Workday, we value candidate privacy. We will never ask for job applications through non‑Workday sites or require a recruiting fee.

Referral

If you are being referred to one of our roles, contact your connection at Workday about the Employee Referral process.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Infrastructure and Cloud Security Architect
Infrastructure and Cloud Security Architect

Workday • Norge (OK)

Hybrid
USD 165,000 - 247,000
Workday Bonus Plan
Annual stock grants
Flexible work options
Principal Cybersecurity Engineer
Principal Cybersecurity Engineer

HR Tech Job • Reston (VA)

Hybrid
USD 184,000 - 278,000
Hybrid/flex schedule
Sr Quality Assurance Engineer (Customer Facing)
Sr Quality Assurance Engineer (Customer Facing)

HR Tech Job • San Francisco (CA)

On-site
USD 145,600 - 218,400
Flexible Work Model
Diverse Workforce
Inclusive Hiring Experience
Principal Cybersecurity Engineer
Principal Cybersecurity Engineer

Workday • Boulder (CO)

Hybrid
USD 176,000 - 264,000
Principal Cybersecurity Engineer
Principal Cybersecurity Engineer

Workday • Reston (VA)

On-site
USD 184,800 - 300,000
Cybersecurity Engineer
Cybersecurity Engineer

Workday • Boulder (CO)

Hybrid
USD 124,000 - 186,000
Flexible work arrangements
Cybersecurity Engineer - US Federal
Cybersecurity Engineer - US Federal

Socket.dev • Reston (VA)

Hybrid
USD 130,000 - 195,000
Senior Cybersecurity Engineer (US Federal)
Senior Cybersecurity Engineer (US Federal)

Workday • Reston (VA)

On-site
USD 159,000 - 240,000
Software Development Engineer - Authorization and Configurable Security
Software Development Engineer - Authorization and Configurable Security

Workday • Pleasanton (CA)

Hybrid
USD 148,000 - 222,000
Bonus plan
Stock grants
Software Development Engineer - Authorization and Configurable Security
Software Development Engineer - Authorization and Configurable Security

Workday, Inc. • Pleasanton (CA)

Hybrid
USD 148,000 - 222,000