Sr Application Security Engineer- GTM Platform

Company: Workday
Company: Workday
Location: USA, CA, Pleasanton
Commitment: Full Time
Posted on: 2023-05-03 16:58
Your work days are brighter here.At Workday, it all began with a conversation over breakfast. When our founders met at a sunny California diner, they came up with an idea to revolutionize the enterprise software market. And when we began to rise, one thing that really set us apart was our culture. A culture which was driven by our value of putting our people first. And ever since, the happiness, development, and contribution of every Workmate is central to who we are. Our Workmates believe a healthy employee-centric, collaborative culture is the essential mix of ingredients for success in business. That’s why we look after our people, communities and the planet while still being profitable. Feel encouraged to shine, however that manifests: you don’t need to hide who you are. You can feel the energy and the passion, it's what makes us unique. Inspired to make a brighter work day for all and transform with us to the next stage of our growth journey? Bring your brightest version of you and have a brighter work day here.About the TeamJoin our team and experience Workday!It’s fun to work in a company where people truly believe in what they’re doing. At Workday, we’re committed to bringing passion and customer centricity to the business of enterprise applications. We work hard, and we’re serious about what we do. We like to have a good time, too. We put people first, celebrate diversity, drive innovation, and do good in the communities where we live and work.The Business Technology Go-To-Market (GTM) team builds solutions that enable Workday's growth strategy while providing outstanding Customer and employee experiences. The GTM team designs and develops innovative applications for our Marketing, Sales, Services, Customer Support & Legal business functions using technologies such as Salesforce, SnapLogic, Conga/Apttus, AWS, Adobe Experience Manager (Cloud), Coveo Search Platform, Okta and others.Our team cultivates relationships with built on collaboration and trust to support a rapidly growing business. We strive to improve efficiency and operational effectiveness through technology, innovation and inspiration.This position will be based in Pleasanton, California.GTM (Go-To-Market) Platform team is responsible for the Salesforce implementation at Workday. Our team designs and develops software applications on the Salesforce Cloud Platform for Workday’s Marketing, Sales, Professional Services, Support and Legal business functions. Our GTM Platform caters to the business needs of 5000+ (and growing) internal power users, 10,000+ workday’s external usersAbout the RoleYou will be part of a core Salesforce Platform team that is responsible for platform engineering, governance and security.The role will focus on developing and implementing a scalable application security model,and own the complete security controls baselines for the GTM Salesforce platform.Key Responsibilities include, but are not limited to:Perform application security reviews on architecture, threat model, coding, QA and deployment. Provide insights on security best practice throughout all phases of software development.Apply a risk-based approach to anticipate the need to add/update cloud security controls leveraging security expertise, partner feedback, industry trends, and other data insights.Continuously assess the baseline security control’s effectiveness.Define cloud security controls and work across organizations to drive their successful and timely implementation.Develop prescriptive guidance for Engineers to meet the control requirements and provide subject matter expertise in the implementation of secure cloud services.Leverage native capabilities and/or develop scripts to facilitate compliance to the established security controls.Identify new capabilities that will strengthen Workday’s security posture and work with the Portfolio InfoSec Officers to achieve capabilities through influence and sound data driven justification.Communicate state of baseline compliance to leadership.Perform penetration tests and security scans including static code scans, dynamic web interface scans, open source package scans and dependency package scans.Develop and enhance new and existing security-focused tools, systems, and services.Develop new security solutions/tools to prevent security vulnerabilities and assist in addressing existing security problems.Help detect, highlight, and close security vulnerabilities that surface during the software development lifecycle.Create and maintain the application security documentation.Stop cyber threats from compromising our data.Continuously monitor the environment for anomalies and indicators of compromise.Triage security bugs and vulnerabilities.Practical experience designing and implementing cloud security solutions.About YouBasic QualificationsBachelor degree in Computer Software, Information Science, Cybersecurity or related field.8+ years’ experience as an application security engineer OR secure cloud application development (Salesforce, Heroku, or Adobe AEM).Which includes experience in:4+ Experience with Review and contribution to application designs and solutionsHands-on experience and expertise in cloud security and identity management services.Thorough understanding of common security risks in cloud applications and web APIs.Ability to demonstrate solid understanding of security protocols, cryptography, authentication, authorization.Other QualificationsExpert knowledge of security problems associated with modern web languages and frameworks, including but not limited to JavaScript (front and backend), Java, Go, Python and others.Expert knowledge of microservice architecture, containerization, cluster orchestration, Kubernetes, Docker, and/or Terraform.Knowledge of penetration testing techniques, application security vulnerabilities, OWASP Top 10, SANS 25, and Whitebox exploitation.Excellent ability to discover, demonstrate flaws, and remediate common vulnerabilities in OWASP 10 and SANS 25.Experience with testing methods such as SAST/DAST/IASTTechnical security certifications such as CISSP, CEH, or GIAC.Working knowledge of NIST (CSF, 800-53), CSA, and AICPA SOC 2.Hands-on experience with Splunk Cloud.Experience working in CI Systems such as JenkinsExcellent collaborative skills along with written and verbal communication​​#LI-TS10As a federal contractor, Workday is requiring all new hires to verify that they are fully-vaccinated against COVID-19 within 72 hours of beginning employment with Workday, consistent with applicable law. Workday is an equal opportunity employer. Candidates who are not vaccinated due to a sincerely held religious belief, medical reasons, or other legally-protected reason should contact accommodations@workday.com to explore what, if any, reasonable accommodations or exemptions Workday is able to offer.Workday Pay Transparency StatementThe base pay range for the primary location of this job is listed below. Workday pay ranges vary based on work location. As a part of the total compensation package, this role may be eligible for the Workday Bonus Plan or a role-specific commission/bonus, as well as annual refresh stock grants. Recruiters can share more detail during the hiring process. Each candidate’s compensation offer will be based on multiple factors including, but not limited to, geography, experience, skills, future potential and internal pay parity. For more information regarding Workday’s comprehensive benefits, please click here.Primary Location: USA.CA.PleasantonBase Pay Min to Max Range: $144,000 - $216,000Pursuant to applicable Fair Chance law, Workday will consider for employment qualified applicants with arrest and conviction records.Workday is an Equal Opportunity Employer including individuals with disabilities and protected veterans.Are you being referred to one of our roles? If so, ask your connection at Workday about our Employee Referral process!
View Original Job Posting