Software Development Engineer, AI Platform

WorkdayBoulder, CO
$130,400 - $222,000Hybrid

About The Position

The Agent Runtime team develops Workday’s secure runtime for enterprise AI agents. The platform provides deterministic policy enforcement, least-privilege execution, and auditable control points for trustworthy AI workflows. We build foundational runtime components and work across platform and ML partner teams to support secure execution at enterprise scale. As a Software Development Engineer on Agent Runtime, you will build and own the AWS infrastructure foundation the platform runs on: dedicated accounts, IAM roles and trust boundaries, VPC/networking design, and the infrastructure-as-code that provisions all of it. This role is focused on cloud infrastructure rather than application development — someone who wants to build the account structure, IAM model, and network topology a security-sensitive, enterprise-scale AI platform depends on.

Requirements

  • 5+ years of experience in cloud infrastructure, DevOps, or platform engineering, with hands-on ownership of production AWS environments.
  • Deep, hands-on experience authoring and maintaining Terraform (or comparable IaC tooling) for production infrastructure — not just consuming existing modules.
  • Strong AWS fundamentals: IAM (roles, policies, cross-account trust relationships), VPC design (subnets, routing, security groups, PrivateLink/peering), and AWS account structure/Organizations.
  • Experience with serverless compute (Lambda, Fargate, or similar) — provisioning, scaling, and operating it in production.
  • Experience standing up new AWS accounts/environments from a clean slate, including navigating compliance requirements (FIPS or comparable regulatory/security standards).
  • Working knowledge of security fundamentals: least-privilege access design, secrets management, network segmentation, and secure service-to-service authentication.
  • Ability to debug complex infrastructure and networking issues under production conditions.
  • Strong written and verbal communication skills — this role documents infrastructure decisions that other engineers and security/compliance stakeholders depend on directly.

Nice To Haves

  • Familiarity with GitOps-style infrastructure delivery (e.g., ArgoCD, Crossplane) is a plus.
  • Experience integrating infrastructure provisioning into CI/CD or build/deploy pipelines.

Responsibilities

  • Design and provision dedicated AWS accounts (build, dev runtime, prod runtime) with proper account structure, guardrails, and compliance requirements (including FIPS) built in from day one.
  • Build and own Terraform modules covering IAM roles/policies, VPC and network design (subnets, routing, security groups, egress control), and account-level guardrails, so that provisioning is repeatable and reviewable rather than manual.
  • Support the infrastructure behind our serverless agent execution environment — provisioning and deprovisioning the runtime environments agents execute in.
  • Design least-privilege IAM roles and cross-account access patterns for our gateway service and build pipeline, including secure service-to-service authentication.
  • Partner directly with security/compliance teams on account guardrails, FIPS requirements, and audit readiness — this role is a primary point of contact for those conversations, not a downstream consumer of someone else's decisions.
  • Register and manage new accounts/services through Workday's internal account-governance process (Venice).
  • Collaborate with platform engineers on open infrastructure questions — service hosting model, egress authentication design, network topology between the gateway and downstream services — and bring a strong point of view grounded in AWS best practice.
  • Build monitoring and alerting for infrastructure health, and participate in code/design reviews for infrastructure changes.

Benefits

  • Workday Bonus Plan
  • Annual refresh stock grants
  • Comprehensive benefits
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service