Jobs · Colorado

Principal Cybersecurity Engineer

Workday · Boulder, CO · 3 days ago
Hybrid$176k–$264k/yrFull-time

About the role

We are seeking a dedicated and proficient security professional with extensive security engineering and response expertise, particularly in applying AI to security response processes. This role involves leading the architecture, daily operations, and continuous development of all security response tooling and environments, contributing to the program vision, and driving the security mindset across the company.

The role includes spearheading the development and lifecycle support of the organization's response tooling infrastructure and associated environments, such as SOAR, SIEM, Incident Response, Forensics, and Agentic AI. It also entails leading and supporting security incident response across the organization, helping drive team development by mentoring new and existing staff.

Responsibilities

  • Strong leadership presence with the ability to set direction, motivate teams, and drive the security mindset across every aspect of the company.
  • Spearhead the architecture, daily operations, and continuous development of all security response tooling and environments.
  • Contribute to the program vision and implementation of a world-class Response program at Workday.
  • Evolve the response platforms that enable Cyber Defense to operate with precision, automation, and innovation.
  • Lead and support security incident response across the organization.
  • Help drive team development by mentoring new and existing staff.

Requirements

  • 10+ years of experience in cybersecurity or information security roles, including 2+ years with hands-on technical leadership experience.
  • Bachelor’s Degree.
  • Extensive expertise in architecting and deploying scalable cloud-native security solutions, complemented by a background in software development to facilitate implementation, with a particular focus on rapid prototyping and iterative methodologies.
  • Experience with security monitoring and incident response is important, as this knowledge will inform decisions on how to implement the solutions.
  • Deep knowledge of scripting languages, artificial intelligence (conversational AI, Generative AI and AI Agents) are essential.
  • Proven ability to manage multiple complex projects with various stakeholders outside of their organization, competing priorities, and core operations effectively.
  • High ownership and accountability, with comfort leading high-severity incidents.
  • A strong intellectual curiosity to rapidly acquire proficiency in emerging technologies and platforms.
  • Experience in some or all of the following: Security alert triage, investigation, incident response, and incident management; Threat hunting and digital forensics; SIEM and SOAR security technologies and solutions; Leveraging artificial intelligence to enhance security processes; Secure Software Development Lifecycle (SSDLC).

Qualifications

  • Other relevant certification/s and training are beneficial (e.g. Offensive Security, SANS, CISSP, Specific Security Tooling, etc.).

Skills

  • Strong leadership presence with the ability to set direction, motivate teams, and drive the security mindset across every aspect of the company.
  • Extensive expertise in architecting and deploying scalable cloud-native security solutions, complemented by a background in software development to facilitate implementation, with a particular focus on rapid prototyping and iterative methodologies.
  • Experience with security monitoring and incident response is important, as this knowledge will inform decisions on how to implement the solutions.
  • Deep knowledge of scripting languages, artificial intelligence (conversational AI, Generative AI and AI Agents) are essential.
  • Proven ability to manage multiple complex projects with various stakeholders outside of their organization, competing priorities, and core operations effectively.
  • High ownership and accountability, with comfort leading high-severity incidents.
  • A strong intellectual curiosity to rapidly acquire proficiency in emerging technologies and platforms.
  • Experience in some or all of the following: Security alert triage, investigation, incident response, and incident management; Threat hunting and digital forensics; SIEM and SOAR security technologies and solutions; Leveraging artificial intelligence to enhance security processes; Secure Software Development Lifecycle (SSDLC).

Benefits

This role offers a hybrid/flexible schedule for employees, enabling a balance between in-person and remote work.

Pay

The annualized base salary ranges for the primary location and any additional locations are listed below. Workday pay ranges vary based on work location. As a part of the total compensation package, this role may be eligible for the Workday Bonus Plan or a role-specific commission/bonus, as well as annual refresh stock grants.

Schedule

We offer a hybrid/flexible schedule for employees, spending at least half (50%) of our time each quarter in the office or in the field with our customers, prospects, and partners (depending on role).

Application Deadline

The application deadline for this role is August 16, 2026.

Similar jobs