Data Security/ Compliance

Senior Open Source Security Engineer

Do what you love. Love what you do.


At Workday, we help the world’s largest organizations adapt to what’s next by bringing finance, HR, and planning into a single enterprise cloud. We work hard, and we’re serious about what we do. But we like to have fun, too. We put people first, celebrate diversity, drive innovation, and do good in the communities where we live and work.

About the Team

We’re expanding our open-source security & governance program and need an innovative engineer to help drive the adoption of key technologies & processes across the business. This exciting opportunity will put you at the forefront of open-source & supply chain security issues impacting the software industry today.

About the Role

Do you want to make a difference to how open-source software is used in a fast-growing cloud native company?

You will contribute to building & running security tools & projects to make Workday more secure for our customers. We are looking for someone who is not afraid to tackle the root cause of an issue rather than treating the symptoms. You should possess solid experience working with security or development teams and have a background working in a Secure DevOps environment.

What you will do:

  • Drive the adoption of Workday’s open-source governance framework across the organisation
  • Work with development & infrastructure teams to integrate the open-source security lifecycle into software build tool chains
  • Enhance processes to remediate vulnerabilities discovered in open-source libraries and tool
  • Stay up to date with the latest technology advancements in public cloud technologies
  • Work closely with our DevSecOps team on ‘shift left’ activities
  • Report progress against key metrics to senior management across the business

About You

What you should have:

  • 7+ years of experience in an Information Security, Application Security, or Development role with a security focus.
  • Understanding of how software build tools work in a CI/CD environment
  • Understanding of open-source software security and supply chain issues
  • Experience working in a large enterprise environment with diverse teams and technologies.
  • In-depth understanding of various operating systems, TCP/IP networking, OWASP Top 10, cloud native technologies such as docker & Kubernetes, other public cloud deployments.

What we hope you have:

  • Understanding of Secure Software Development Lifecycle (SSDLC) practices or experience working in a DevSecOps role
  • In-depth understanding of at least 1 programming language such as Java or Python

What we offer:

  • Career & Capability Growth
  • Wellness Program
  • Pension
  • Health Insurance & Dental Plan
  • Employee Assistance Program
  • Tax Saver Scheme
  • Stock Schemes
  • 27 Days Annual Leave

Our Values:

  • Employees
  • Customer Service
  • Innovation
  • Integrity
  • Fun
  • Profitability

#LI-GS


 

  • 7+ years of experience in an Information Security, Application Security, or Development role with a security focus.
  • Understanding of how software build tools work in a CI/CD environment
  • Understanding of open-source software security and supply chain issues
  • Experience working in a large enterprise environment with diverse teams and technologies.
  • In-depth understanding of various operating systems, TCP/IP networking, OWASP Top 10, cloud native technologies such as docker & Kubernetes, other public cloud deployments.