Workday-posted 2 days ago
Full-time • Mid Level
Hybrid • McLean, VA
5,001-10,000 employees

Your work days are brighter here. We’re obsessed with making hard work pay off, for our people, our customers, and the world around us. As a Fortune 500 company and a leading AI platform for managing people, money, and agents, we’re shaping the future of work so teams can reach their potential and focus on what matters most. The minute you join, you’ll feel it. Not just in the products we build, but in how we show up for each other. Our culture is rooted in integrity, empathy, and shared enthusiasm. We’re in this together, tackling big challenges with bold ideas and genuine care. We look for curious minds and courageous collaborators who bring sun-drenched optimism and drive. Whether you're building smarter solutions, supporting customers, or creating a space where everyone belongs, you’ll do meaningful work with Workmates who’ve got your back. In return, we’ll give you the trust to take risks, the tools to grow, the skills to develop and the support of a company invested in you for the long haul. So, if you want to inspire a brighter work day for everyone, including yourself, you’ve found a match in Workday, and we hope to be a match for you too. About the Team The Workday Continuous Verification team is looking for a highly motivated Software Development Engineer with DevOps experience to join our 24/7 operations team. In this role, you will be responsible for the day‑to‑day operation, maintenance, and security monitoring of our critically meaningful, IL5‑compliant Azure VDI environment in support of a new Workday region. This is a hands‑on operational role. You will ensure the platform’s health, security, and compliance with a strong focus on Identity and Access Management (IAM) and Microsoft Entra Conditional Access. Note: This role does not design architecture; it operates and secures an existing high‑security environment. About the Role This role will support one or more direct or indirect contracts with the U.S. Federal Government which, due to federal government security requirements, mandates that all Workday personnel working on the contracts be United States citizens (naturalized or native).

  • Identity & Access Management (IAM)
  • Coordinate and manage Microsoft Entra ID Governance features, including Access Packages and Microsoft 365 Groups , to govern user access lifecycle.
  • Monitor and troubleshoot automated Workday → Microsoft Entra ID user provisioning.
  • Support user onboarding, including issuing Temporary Access Passes (TAP) and assisting with MFA registration (Passkeys, Microsoft Authenticator).
  • VDI Operations & Maintenance
  • Perform monthly patching and security updates for Windows 365 custom golden images .
  • Lead VDI endpoints using Microsoft Intune (compliance, configuration, baselines).
  • Provide Tier 2/3 technical support for VDI-related issues.
  • Maintain operational health of VDI pools.
  • Security Operations & Compliance
  • Serve as a key member of the 24/7 incident response team , monitoring alerts from: Microsoft Sentinel, Microsoft Defender for Endpoint , and Microsoft Defender for Cloud Apps
  • Maintain continuous STIG compliance for all VDI endpoints.
  • Apply security updates to golden images and monitor for deviations using Azure Policy.
  • Participate in Eviction protocols, including rapid rotation of all credentials, keys, and secrets.
  • Manage pool‑specific access controls to segregate user populations (Engineering vs. Efficiency).
  • Conditional Access & Security Policy
  • Manage, review, and fine‑tune all Microsoft Entra Conditional Access policies.
  • Implement policies for: US‑only access, VPN‑only connections from named locations and device compliance integration with Intune
  • Required Qualifications & Experience
  • Experience operating systems in high‑security supervised environments (DoD IL4/IL5, FedRAMP High, GCC‑High).
  • Deep hands‑on expertise with Microsoft Entra ID , including:
  • Conditional Access (building/testing/maintaining complex policies)
  • Identity Governance (Access Packages, Access Reviews)
  • MFA configurations including Passkeys and TAP
  • Experience with cloud-native security tools: Microsoft Sentinel (monitoring & analytics) Microsoft Defender for Endpoint (VDI security)
  • Strong experience managing Windows endpoints via Microsoft Intune .
  • Familiarity with applying/monitoring DISA STIG baselines.
  • Experience with on‑call rotations and formal incident response plans.
  • This role may require a security clearance at the TS/SCI w/CI Poly level. Applicants must have the ability to obtain and maintain a U.S. government issued security clearance. An active TS/SCI w/CI Poly is preferred.
  • Preferred Qualifications
  • Experience with Windows 365 Government or Azure Virtual Desktop (AVD) .
  • Experience with Defender for Cloud Apps (MCAS) and Microsoft Purview (DLP) .
  • Familiarity with Azure networking (VNet, NSGs, Azure Firewall) and hybrid connectivity (VPN, ExpressRoute).
  • Expertise in designing, implementing, and analyzing algorithms to solve complex problems, optimize business processes, improve data analysis, and enhance decision-making strategies.
  • Proficient in the entire software lifecycle (conception, design, programming, testing, and maintenance), applying knowledge of programming languages, data structures, and system build to deliver custom solutions and ensure software performance and security.
  • Experienced in tracking and managing code changes using SCM tools, including version and branch management, and conflict resolution.
  • Able to streamline the development process and maintain codebase integrity, ensuring accurate documentation and reversibility of changes.
  • Capable of encouraging a positive and inclusive team environment to improve team efficiency, facilitate effective decision-making, and assist with project management.
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service