Your work days are brighter here.
We’re obsessed with making hard work pay off, for our people, our customers, and the world around us. As a Fortune 500 company and a leading AI platform for managing people, money, and agents, we’re shaping the future of work so teams can reach their potential and focus on what matters most. The minute you join, you’ll feel it. Not just in the products we build, but in how we show up for each other. Our culture is rooted in integrity, empathy, and shared enthusiasm. We’re in this together, tackling big challenges with bold ideas and genuine care. We look for curious minds and courageous collaborators who bring sun-drenched optimism and drive. Whether you're building smarter solutions, supporting customers, or creating a space where everyone belongs, you’ll do meaningful work with Workmates who’ve got your back. In return, we’ll give you the trust to take risks, the tools to grow, the skills to develop and the support of a company invested in you for the long haul. So, if you want to inspire a brighter work day for everyone, including yourself, you’ve found a match in Workday, and we hope to be a match for you too.
About the Team
The Workday Continuous Verification team is looking for a highly motivated Software Development Engineer with DevOps experience to join us in helping Workday Government is seeking an experienced and security‑focused Senior Cloud Security Engineer to join our 24/7 operations team. In this role, you will be responsible for the day‑to‑day operation, maintenance, and security monitoring of our critically meaningful, IL5‑compliant Azure VDI environment in support of a new Workday region.
This is a hands‑on operational role. You will ensure the platform’s health, security, and compliance with a strong focus on Identity and Access Management (IAM) and Microsoft Entra Conditional Access.
Note: This role does not design architecture; it operates and secures an existing high‑security environment.
About the Role
This role will support one or more direct or indirect contracts with the U.S. Federal Government which, due to federal government security requirements, mandates that all Workday personnel working on the contracts be United States citizens (naturalized or native).
Identity & Access Management (IAM)
Coordinate and manage Microsoft Entra ID Governance features, including Access Packages and Microsoft 365 Groups, to govern user access lifecycle.
Monitor and troubleshoot automated Workday → Microsoft Entra ID user provisioning.
Support user onboarding, including issuing Temporary Access Passes (TAP) and assisting with MFA registration (Passkeys, Microsoft Authenticator).
VDI Operations & Maintenance
Perform monthly patching and security updates for Windows 365 custom golden images.
Lead VDI endpoints using Microsoft Intune (compliance, configuration, baselines).
Provide Tier 2/3 technical support for VDI-related issues.
Maintain operational health of VDI pools.
Security Operations & Compliance
Serve as a key member of the 24/7 incident response team, monitoring alerts from: Microsoft Sentinel, Microsoft Defender for Endpoint, and Microsoft Defender for Cloud Apps
Maintain continuous STIG compliance for all VDI endpoints.
Apply security updates to golden images and monitor for deviations using Azure Policy.
Participate in Eviction protocols, including rapid rotation of all credentials, keys, and secrets.
Manage pool‑specific access controls to segregate user populations (Engineering vs. Efficiency).
Conditional Access & Security Policy
Manage, review, and fine‑tune all Microsoft Entra Conditional Access policies.
Implement policies for: US‑only access, VPN‑only connections from named locations and device compliance integration with Intune
About You
Required Qualifications & Experience
Must be a U.S. citizen and eligible for a government security clearance.
Experience operating systems in high‑security supervised environments (DoD IL4/IL5, FedRAMP High, GCC‑High).
Deep hands‑on expertise with Microsoft Entra ID, including:
Conditional Access (building/testing/maintaining complex policies)
Identity Governance (Access Packages, Access Reviews)
MFA configurations including Passkeys and TAP
Experience with cloud-native security tools:
Strong experience managing Windows endpoints via Microsoft Intune.
Familiarity with applying/monitoring DISA STIG baselines.
Experience with on‑call rotations and formal incident response plans.
Preferred Qualifications
Experience with Windows 365 Government or Azure Virtual Desktop (AVD).
Experience with Defender for Cloud Apps (MCAS) and Microsoft Purview (DLP).
Familiarity with Azure networking (VNet, NSGs, Azure Firewall) and hybrid connectivity (VPN, ExpressRoute).
Workday Pay Transparency Statement
The annualized base salary ranges for the primary location and any additional locations are listed below. Workday pay ranges vary based on work location. As a part of the total compensation package, this role may be eligible for the Workday Bonus Plan or a role-specific commission/bonus, as well as annual refresh stock grants. Recruiters can share more detail during the hiring process. Each candidate’s compensation offer will be based on multiple factors including, but not limited to, geography, experience, skills, job duties, and business need, among other things. For more information regarding Workday’s comprehensive benefits, please click here.
Primary Location: USA.VA.McLean (Tyson's Corner)
Primary Location Base Pay Range: $135,200 USD - $202,900 USD
Additional US Location(s) Base Pay Range: $122,400 USD - $217,200 USD
Our Approach to Flexible Work
With Flex Work, we’re combining the best of both worlds: in-person time and remote. Our approach enables our teams to deepen connections, maintain a strong community, and do their best work. We know that flexibility can take shape in many ways, so rather than a number of required days in-office each week, we simply spend at least half (50%) of our time each quarter in the office or in the field with our customers, prospects, and partners (depending on role). This means you'll have the freedom to create a flexible schedule that caters to your business, team, and personal needs, while being intentional to make the most of time spent together. Those in our remote "home office" roles also have the opportunity to come together in our offices for important moments that matter.
Pursuant to applicable Fair Chance law, Workday will consider for employment qualified applicants with arrest and conviction records.
Workday is an Equal Opportunity Employer including individuals with disabilities and protected veterans.
Are you being referred to one of our roles? If so, ask your connection at Workday about our Employee Referral process!
At Workday, we value our candidates’ privacy and data security. Workday will never ask candidates to apply to jobs through websites that are not Workday Careers.
Please be aware of sites that may ask for you to input your data in connection with a job posting that appears to be from Workday but is not.
In addition, Workday will never ask candidates to pay a recruiting fee, or pay for consulting or coaching services, in order to apply for a job at Workday.