
Sr. Software Engineer, Security (Pipedream)
Workday · Pleasanton, CA
- On site
- Full-time
- $200,000 / year
- Pleasanton, CA
Email the hiring manager to get a response.
Get their verified email + an intro that's ready to send.
Subject: Interested in the Sr. Software Engineer, Security (Pipedream) role at Workday
Hi Alex — I came across the Sr. Software Engineer, Security (Pipedream) opening and wanted to reach out directly. I've spent the last few years doing exactly this kind of work, and Workday stood out because…
✎ Personalized to your résumé after sign-up.
- ✓ Verified email of the hiring manager
- ✓ Intro email personalized to your résumé
- ✓ $9/mo = unlimited — any job link
Secure checkout · cancel anytime
Job highlights
- Own platform security end-to-end for Workday's Pipedream.
- Build security function from scratch for thousands of developers.
- Find and fix vulnerabilities across polyglot codebase.
- Secure cloud infrastructure and third-party vendors.
- Lead incident response and compliance efforts.
About the role
About Workday
Your work days are brighter here. We’re obsessed with making hard work pay off, for our people, our customers, and the world around us. As a Fortune 500 company and a leading AI platform for managing people, money, and agents, we’re shaping the future of work so teams can reach their potential and focus on what matters most. The minute you join, you’ll feel it. Not just in the products we build, but in how we show up for each other. Our culture is rooted in integrity, empathy, and shared enthusiasm. We’re in this together, tackling big challenges with bold ideas and genuine care. We look for curious minds and courageous collaborators who bring sun-drenched optimism and drive. Whether you're building smarter solutions, supporting customers, or creating a space where everyone belongs, you’ll do meaningful work with Workmates who’ve got your back. In return, we’ll give you the trust to take risks, the tools to grow, the skills to develop and the support of a company invested in you for the long haul. So, if you want to inspire a brighter work day for everyone, including yourself, you’ve found a match in Workday, and we hope to be a match for you too.
About The Team
The Pipedream team operates an integration platform that connects Workday services — and the apps of our external customers — to over 3,000 APIs. We build and maintain public-facing APIs, code execution environments, a high-volume event processing pipeline, and other complex services that power the platform. Our work sits at the intersection of scale and connectivity: every integration that runs on Pipedream depends on the reliability, performance, and security of the infrastructure we build. If you enjoy working on systems that thousands of developers rely on every day, and you want to see the direct impact of your contributions, this is a great team to be a part of.
About The Role
As Pipedream's first dedicated Security Engineer, you will own platform security end-to-end — tooling, process, threat modeling, and audits — while working hands-on in the codebase to find and fix vulnerabilities yourself. This is a deeply technical individual contributor role with broad scope. You will build a security function from scratch at a platform serving thousands of developers.
In this role, you will be responsible for:
- Finding and patching vulnerabilities directly in code and dependencies. Pipedream runs a polyglot stack — TypeScript, Rust, Kotlin, Ruby, and more — so you will read and fix code across all of it.
- Building and maintaining the platform's threat model, and partnering with Product and Engineering to ship new features securely without slowing them down.
- Securing cloud infrastructure (AWS, GCP) and the third-party vendor surface (Redis, Datadog, and others).
- Leading incident response for critical security issues.
- Owning SOC 2, HIPAA, penetration tests, and other compliance work end-to-end.
- Partnering with Workday's security team to translate broader policy into something that fits Pipedream's stack and operations.
About You
Basic Qualifications
- 7+ years of experience in product security, application security, or software engineering with a security focus
- Hands-on experience with vulnerability management, threat modeling, and risk analysis
- Experience securing AWS or comparable cloud platforms at production scale
Other Qualifications
- Demonstrated experience in threat and vulnerability management, including identifying, assessing, and mitigating potential risks and weaknesses across a platform's security infrastructure. You have conducted vulnerability assessments, implemented security measures, and stayed current with the latest cybersecurity trends to keep systems protected.
- Solid understanding of application security, including protecting software applications from potential threats and vulnerabilities. You are comfortable identifying and mitigating security risks in application design and code, and you bring experience with security controls such as encryption and authentication.
- Proficiency in securing cloud infrastructure, with the ability to design, manage, and maintain cloud-based environments (AWS, GCP) at scale. You understand how to effectively secure and monitor cloud services in a production setting.
- Experience with security incident response, including a systematic approach to managing the aftermath of security breaches or attacks. You know how to identify and analyze security incidents, coordinate response activities, and develop strategies to prevent future incidents.
- Comfort reading and patching code across multiple languages — you do not need to know Pipedream's specific stack, but you are the kind of engineer who picks up new languages quickly and can operate effectively across a polyglot codebase.
- A history of building security programs that engineering teams actually adopt — not just policies on paper. You partner with engineers to ship secure code and balance priorities across highly visible projects involving multiple teams.
- Experience with compliance frameworks such as SOC 2 or HIPAA, including running audits end-to-end, is a plus.
- Offensive security background (vulnerability testing, penetration testing, red teaming) is a plus.
- Experience securing Kubernetes and Docker workloads in production is a plus.
Key skills/competency
- Software Engineering
- Security Engineering
- Application Security
- Cloud Security (AWS, GCP)
- Vulnerability Management
- Threat Modeling
- Incident Response
- Compliance (SOC 2, HIPAA)
- Polyglot Programming
- Security Audits
Skills & topics
- Software Engineer
- Security Engineer
- Application Security
- Cloud Security
- Vulnerability Management
- Threat Modeling
- Incident Response
- Compliance
- AWS
- GCP
- TypeScript
- Rust
- Kotlin
- Ruby
- SOC 2
- HIPAA
- Kubernetes
- Docker
- Senior
How to get hired
- Tailor your resume: Highlight your 7+ years in product/application security and experience with vulnerability management, threat modeling, and cloud security (AWS/GCP).
- Showcase technical skills: Emphasize your ability to read and patch code across multiple languages and secure production cloud environments.
- Demonstrate program building: Provide examples of building security programs that engineering teams adopt and partner effectively.
- Prepare for interviews: Be ready to discuss your experience with incident response, compliance frameworks (SOC 2, HIPAA), and offensive security concepts.
Technical preparation
Behavioral questions
Frequently asked questions
- What are the primary responsibilities for a Senior Software Engineer, Security at Workday's Pipedream?
- As the first dedicated Security Engineer for Pipedream, you'll own platform security from tooling and process to threat modeling and audits. This includes hands-on vulnerability identification and patching across a polyglot stack, securing AWS/GCP infrastructure, leading incident response, and managing compliance efforts like SOC 2 and HIPAA. You'll also collaborate with the broader Workday security team to adapt policies for Pipedream's environment.
- What technical skills are most important for this Senior Software Engineer, Security role at Workday?
- Key technical skills include extensive experience in product/application security, vulnerability management, threat modeling, and risk analysis. Proficiency in securing AWS or GCP at scale is crucial. You should be comfortable reading and patching code in multiple languages (TypeScript, Rust, Kotlin, Ruby) and have a solid understanding of application security principles, including encryption and authentication. Experience with Kubernetes and Docker is a plus.
- How does Workday approach flexible work for its Senior Software Engineer, Security position?
- Workday utilizes a 'Flex Work' approach, blending in-person and remote work. Employees are expected to spend at least 50% of their time each quarter in the office or with customers/partners, depending on the role. This offers flexibility in scheduling while ensuring intentional time for collaboration and connection. Remote 'home office' roles also have opportunities to gather in offices for key events.
- What kind of security programs is Workday looking for this Senior Software Engineer, Security to build?
- Workday seeks an engineer who can build security programs that engineering teams actually adopt. This means going beyond theoretical policies to actively partnering with engineers to ship secure code and effectively balancing security priorities with project timelines and cross-team collaboration on highly visible initiatives.
- Does Workday Pipedream require specific experience with certain compliance frameworks for the Senior Software Engineer, Security role?
- While experience with compliance frameworks like SOC 2 or HIPAA and running end-to-end audits is a plus, it's not a strict basic qualification. However, demonstrating an understanding of these frameworks and the ability to manage compliance work is highly beneficial for this role, as you will be responsible for owning these processes.
