- Home
- Remote Jobs
- Distinguished Engineer
Date Posted
Today
New!Remote Work Level
Hybrid Remote
Location
Hybrid Remote in Pleasanton, CA, Chicago, IL
Job Schedule
Full-Time
Salary
$289,800 - $434,800 Annually
Categories
About the Role
Title: Distinguished Engineer (DE) for AI & Product Security
Location: USA, CA, Pleasanton
USA, IL, Chicago
Job Description:
Your work days are brighter here.
We’re obsessed with making hard work pay off, for our people, our customers, and the world around us. As a Fortune 500 company and a leading AI platform for managing people, money, and agents, we’re shaping the future of work so teams can reach their potential and focus on what matters most. The minute you join, you’ll feel it. Not just in the products we build, but in how we show up for each other. Our culture is rooted in integrity, empathy, and shared enthusiasm. We’re in this together, tackling big challenges with bold ideas and genuine care. We look for curious minds and courageous collaborators who bring sun-drenched optimism and drive. Whether you're building smarter solutions, supporting customers, or creating a space where everyone belongs, you’ll do meaningful work with Workmates who’ve got your back. In return, we’ll give you the trust to take risks, the tools to grow, the skills to develop and the support of a company invested in you for the long haul. So, if you want to inspire a brighter work day for everyone, including yourself, you’ve found a match in Workday, and we hope to be a match for you too.
About the Team
Workday’s Cybersecurity and Trust organization functions as the primary guardian of the company’s "Trust" core value, operating under a mission to protect the HR and financial data of over 10,000 global customers. The team is structured to address risk through three main pillars: People, Process, and Technology. They manage a comprehensive Governance, Risk, and Compliance (GRC) program that ensures all business practices align with strict regulatory standards like GDPR and HIPAA, while maintaining top-tier certifications such as ISO 27001 and SOC 2 Type II. Beyond traditional defense, the team acts as a strategic "Go-To-Market" partner, directly engaging with customers to provide transparency into Workday’s security posture and leveraging AI-driven risk assessments to proactively hunt for vulnerabilities before they can be exploited.
About the Role
The Distinguished Engineer (DE) for AI & Product Security is a pivotal, hands-on technical leadership role responsible for defining and driving the security strategy across our core product portfolio, with a special emphasis on the security lifecycle of AI technologies, Large Language Models (LLMs), and cloud-native applications. This role ensures security is fundamentally built into new technologies and will serve as the top technical expert driving architectural decisions and security governance across the organization.
Responsibilities
1. AI/ML Security Architecture and Strategy (40%)
-
Secure AI/MLSDLC: Define and evangelize the secure Software Development Lifecycle (SDLC) for all AI/ML models and applications, ensuring the integrity and confidentiality of training data, model weights, and inference results.
-
LLM Governance and Control: Design and implement architectural patterns and tooling to manage and restrict the flow of proprietary data into and out of external, commodity LLMs.
-
Adversarial AI Defense: Develop novel security countermeasures against prompt injection, model inversion, data poisoning, and other advanced adversarial machine learning attacks targeting our products.
-
AI Safety: Guide the team in creating auditable and safety-aligned standards for internal AI tools (e.g., Sana AI).
2. Product and Cloud Security Leadership (30%)
-
Architectural Review: Lead the most complex and sensitive security reviews for critical products and services.
-
Defense in Depth: Modernize on the company’s Zero Trust model implementation strategy, guiding engineering teams on micro-segmentation, identity-based access, and least-privilege principles within product infrastructures.
3. Mentorship, Influence, and Research (30%)
-
Technical Advocacy: Act as the primary technical voice for Cybersecurity & Trust, representing the security organization in cross-functional working groups, executive forums, and with external parties.
-
Mentorship: Mentor senior and principal engineers across engineering teams, raising the collective security bar and fostering a culture of secure development.
-
External Research: Maintain deep expertise in emerging AI and Product threats and contribute to the external security community through patents, publications, or industry standards development.
About You
-
Experience: 12+ years of experience in Software Engineering, Infrastructure, or Product Security, with at least 5 years operating at a Principal/Staff level or higher.
-
Expertise: Deep, demonstrable expertise in the security implications of cloud-native architectures (Kubernetes, Serverless) and a strong command of modern AI/ML development frameworks and security concerns.
-
Architecture: Proven history of designing security controls that scale across large, heterogeneous production environments.
-
Compliance: Extensive experience architecting products to meet global regulatory and industry standards, including GDPR, HIPAA, ISO 27001, and SOC 2. Must have a proven track record of translating complex compliance mandates into automated technical controls and "compliance-as-code" within a CI/CD pipeline, specifically addressing emerging AI regulations (e.g., EU AI Act) and data residency requirements.
-
Communication: Exceptional ability to translate complex technical risks into business impact for executive audiences and the Board of Directors.
Preferred Qualifications
-
Advanced degree in Computer Science, Electrical Engineering, or a related field.
-
Experience with advanced security analytics and threat modeling for complex distributed systems.
-
Active participation in AI security research or industry working groups
Workday Pay Transparency Statement
The annualized base salary ranges for the primary location and any additional locations are listed below. Workday pay ranges vary based on work location. As a part of the total compensation package, this role may be eligible for the Workday Bonus Plan or a role-specific commission/bonus, as well as annual refresh stock grants. Recruiters can share more detail during the hiring process. Each candidate’s compensation offer will be based on multiple factors including, but not limited to, geography, experience, skills, job duties, and business need, among other things. For more information regarding Workday’s comprehensive benefits, please click here.
Primary Location: USA.CA.Pleasanton
Primary Location Base Pay Range: $289,800 USD - $434,800 USD
Additional US Location(s) Base Pay Range: $247,000 USD - $434,800 USD
Our Approach to Flexible Work
With Flex Work, we’re combining the best of both worlds: in-person time and remote. Our approach enables our teams to deepen connections, maintain a strong community, and do their best work. We know that flexibility can take shape in many ways, so rather than a number of required days in-office each week, we simply spend at least half (50%) of our time each quarter in the office or in the field with our customers, prospects, and partners (depending on role). This means you'll have the freedom to create a flexible schedule that caters to your business, team, and personal needs, while being intentional to make the most of time spent together. Those in our remote "home office" roles also have the opportunity to come together in our offices for important moments that matter.
Pursuant to applicable Fair Chance law, Workday will consider for employment qualified applicants with arrest and conviction records.
Workday is an Equal Opportunity Employer including individuals with disabilities and protected veterans.
At Workday, we are committed to providing an accessible and inclusive hiring experience where all candidates can fully demonstrate their skills. If you require assistance or an accommodation at any point, please email accommodations@workday.com.
Are you being referred to one of our roles? If so, ask your connection at Workday about our Employee Referral process!
At Workday, we value our candidates’ privacy and data security. Workday will never ask candidates to apply to jobs through websites that are not Workday Careers.
Please be aware of sites that may ask for you to input your data in connection with a job posting that appears to be from Workday but is not.
In addition, Workday will never ask candidates to pay a recruiting fee, or pay for consulting or coaching services, in order to apply for a job at Workday.