Cybersecurity Engineer

Workday•Boulder, CO
•$117,800 - $210,000•Hybrid

About The Position

Workday is seeking a Cybersecurity Engineer to join the Security Automation & Integration Engineering (SecAIE) team. This role will focus on engineering the agent, eval, and application layer that Workday's Active Defense charter relies on. The engineer will be responsible for creating reusable software solutions, including eval harnesses, agent scaffolds, schemas, and application UIs, to enable security teams to make faster, more reliable, and measurable decisions. The position requires a strong understanding of cybersecurity concepts and best practices, with the ability to partner with domain experts to build tools that enhance their work. The role is ideal for someone who enjoys solving complex operational problems with clean software and leveraging AI as a force multiplier.

Requirements

  • Strong Python skills with hands-on experience shipping production software (APIs, services, batch jobs, or application backends), including code review, testing, and operational follow-through
  • Hands-on experience building or evaluating LLM / agent systems (harnesses, eval, tracing, or agentic pipelines) or strong software-engineering fundamentals plus demonstrated AI-augmented development (Copilot, coding agents) with a point of view on where they help
  • Comfort designing or evolving schemas / data contracts and application UIs that sit on real data - not mock-only prototypes
  • Working knowledge of core cybersecurity practices - identity and access, secrets handling, secure-by-default configuration, and reasoning over common security data (vulnerabilities, incidents, identity, threat intel) - so you can build for security outcomes.
  • Comfortable owning what you ship (runbooks, basic observability, eval that still runs after you merge)

Nice To Haves

  • Agent / eval - LangChain, LangGraph, LangSmith, or similar; LLM-as-judge or offline eval; tracing and observability for agent runs
  • Application / UI - frontend (React or similar) for internal tools; watchlist / dashboard / workflow UIs on security data
  • Security domain - hands-on with security tools or data for triage and investigation (SIEM, vulnerability scanners, identity systems, orchestration platforms such as Tines); curiosity about detection-engineering workflows
  • Data / schema - comfort reasoning about shared schemas or data contracts that span team boundaries, treating what / who / state as a first-class artifact
  • Cloud / platform familiarity - working AWS fluency (enough to ship and operate); IaC (Terraform/Docker) is useful but not the daily job
  • Comfort operating in ambiguous problem spaces where you help define the solution, not just implement it

Responsibilities

  • Own agent-adjacent application work: eval harnesses, agent scaffolds, and the UIs that security partners use to inspect and act on results
  • Design, build, and evolve schemas and data contracts so agents and humans share the same objects rather than one-off payloads
  • Take partner requests from vague to shipped: scope the problem, propose approaches, choose one, and drive it through design, review, rollout, and operational readiness (eval, tracing, runbooks)
  • Build and maintain integrations across security tools and enterprise platforms - SOAR, SIEM, vulnerability scanners, ticketing - when the application or agent needs them
  • Raise the team's AI-augmented engineering floor: shared skills, reusable scaffolds, a review discipline for AI-generated code, and eval that catches drift
  • Iterate quickly: prototype, test, ship, learn, improve - and bring the team with you

Benefits

  • Workday Bonus Plan or a role-specific commission/bonus
  • Annual refresh stock grants
  • Comprehensive benefits
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service