Your work days are brighter here.
We’re obsessed with making hard work pay off, for our people, our customers, and the world around us. As a Fortune 500 company and a leading AI platform for managing people, money, and agents, we’re shaping the future of work so teams can reach their potential and focus on what matters most. The minute you join, you’ll feel it. Not just in the products we build, but in how we show up for each other. Our culture is rooted in integrity, empathy, and shared enthusiasm. We’re in this together, tackling big challenges with bold ideas and genuine care. We look for curious minds and courageous collaborators who bring sun-drenched optimism and drive. Whether you're building smarter solutions, supporting customers, or creating a space where everyone belongs, you’ll do meaningful work with Workmates who’ve got your back. In return, we’ll give you the trust to take risks, the tools to grow, the skills to develop and the support of a company invested in you for the long haul. So, if you want to inspire a brighter work day for everyone, including yourself, you’ve found a match in Workday, and we hope to be a match for you too.
About the Team
Our team is responsible for operating the systems and controls that we build, building upon core Workday network engineering and network security team design and applying it to the U.S. Federal marketplace. We partner with our information security team to ensure policy compliance and address gaps. We operate cloud environments in support of the U.S. Federal government Workday regions and are constantly tackling new challenges as we seek to improve our network security posture and capabilities.
About the Role
This role will support one or more direct or indirect contracts with the U.S. Federal Government which, due to federal government security requirements, mandates that all Workday personnel working on the contracts be United States citizens (naturalized or native).
As a networking engineer with a strong network security background, you will be responsible for designing and implementing systems and security controls in production environments, developing automation for deployment and validation tasks, partnering with internal customers to drive projects forward, and researching new technologies and opportunities for improving how we operate.
This is a technical role that will require collaboration with team members across the world, bringing to bear a strong ability to communicate, detail, and document ideas and work. It's expected to have a taste for challenging yourself - and hopefully the team! It is expected that you are a self-starter, able to lead sophisticated initiatives and have organizational impact.
You'll be encouraged to improve your skills with training, conferences, and domain-specific workshops. Other members of the team will be available to mentor and support, and there are opportunities for stretch projects outside of normal work responsibilities. You will have the flexibility of a hybrid schedule.
About You
Basic Qualifications
- 7+ years of direct, technical experience related to network design in LAN/WAN, SDN, and cloud connected infrastructure along with network security, platform, or infrastructure security
- 2+ years crafting, deploying, and operating web application firewall controls (WAF)
- Operational experience supporting DDoS detection, WAF, and IPS in a production environment
- Expertise with Terraform, Go Lang or Python, Kubernetes operators and familiarity with using these and/or other tools to deliver consistent, scalable security solutions
Other Qualifications
- Experience deploying infrastructure components, and application and network security systems in AWS and GCP
- Extensive experience designing, implementing, and managing enterprise-scale networks (LAN/WAN, SDN, and cloud-connected infrastructures).
- Deep knowledge of network security principles including firewalls, IDS/IPS, VPNs, NAC, and zero-trust architectures
- Proficient with routing and switching protocols (BGP, OSPF, EIGRP), VLANs, load balancing, and high-availability design
- Skilled in network hardening and threat mitigation, including vulnerability management, segmentation, and policy enforcement
- Hands-on experience with security frameworks and compliance (NIST 800-53, ISO 27001, FedRAMP, DoD IL4/IL5,)
- Hands-on experience of the DoD’s Boundary Cloud Access Point (BCAP) and onboarding SaaS and/or CSP technologies to the BCAP through authorized networking architectures and implementations
- Proven understanding of public cloud network security concepts and hands-on experience documenting and implementing security controls of the same
- Understanding of application, system, and security threats, attack techniques and mitigating controls in public cloud and containerized environments
- Demonstrated experience designing, implementing, and maintaining network security con
#LI-JH1
Workday Pay Transparency Statement
The annualized base salary ranges for the primary location and any additional locations are listed below. Workday pay ranges vary based on work location. As a part of the total compensation package, this role may be eligible for the Workday Bonus Plan or a role-specific commission/bonus, as well as annual refresh stock grants. Recruiters can share more detail during the hiring process. Each candidate’s compensation offer will be based on multiple factors including, but not limited to, geography, experience, skills, job duties, and business need, among other things. For more information regarding Workday’s comprehensive benefits, please click here.
Primary Location: USA.VA.McLean (Tyson's Corner)
Primary Location Base Pay Range: $161,300 USD - $241,900 USD
Additional US Location(s) Base Pay Range: $145,900 USD - $259,200 USD
Our Approach to Flexible Work
With Flex Work, we’re combining the best of both worlds: in-person time and remote. Our approach enables our teams to deepen connections, maintain a strong community, and do their best work. We know that flexibility can take shape in many ways, so rather than a number of required days in-office each week, we simply spend at least half (50%) of our time each quarter in the office or in the field with our customers, prospects, and partners (depending on role). This means you'll have the freedom to create a flexible schedule that caters to your business, team, and personal needs, while being intentional to make the most of time spent together. Those in our remote "home office" roles also have the opportunity to come together in our offices for important moments that matter.
Pursuant to applicable Fair Chance law, Workday will consider for employment qualified applicants with arrest and conviction records.
Workday is an Equal Opportunity Employer including individuals with disabilities and protected veterans.
Are you being referred to one of our roles? If so, ask your connection at Workday about our Employee Referral process!
At Workday, we value our candidates’ privacy and data security. Workday will never ask candidates to apply to jobs through websites that are not Workday Careers.
Please be aware of sites that may ask for you to input your data in connection with a job posting that appears to be from Workday but is not.
In addition, Workday will never ask candidates to pay a recruiting fee, or pay for consulting or coaching services, in order to apply for a job at Workday.