Job Requirements
McLean, VA
Top Secret/SCI CI Polygraph
Career Level not specified
$159,600 - $239,400
Job Description
Your work days are brighter here.
We're obsessed with making hard work pay off, for our people, our customers, and the world around us. As a Fortune 500 company and a leading AI platform for managing people, money, and agents, we're shaping the future of work so teams can reach their potential and focus on what matters most. The minute you join, you'll feel it. Not just in the products we build, but in how we show up for each other. Our culture is rooted in integrity, empathy, and shared enthusiasm. We're in this together, tackling big challenges with bold ideas and genuine care. We look for curious minds and courageous collaborators who bring sun-drenched optimism and drive. Whether you're building smarter solutions, supporting customers, or creating a space where everyone belongs, you'll do meaningful work with Workmates who've got your back. In return, we'll give you the trust to take risks, the tools to grow, the skills to develop and the support of a company invested in you for the long haul. So, if you want to inspire a brighter work day for everyone, including yourself, you've found a match in Workday, and we hope to be a match for you too.
About the Team
Your work matters here. At Workday Government, we focus on outcomes that serve a larger mission. Our work supports U.S. federal agencies as they modernize and transform the full employee lifecycle experience and finance operations-so they can operate with greater clarity, accountability, and trust. As a Fortune 500 company and a proven enterprise cloud platform, Workday brings modern technology, responsible AI, and secure infrastructure to some of the most complex environments in the world. The work isn't theoretical. It's operational. It's high-impact. And it demands rigor, integrity, and long-term thinking.
From day one, you'll be part of a team that values collaboration, follow-through, and doing the right thing-especially when the stakes are high. Our culture is grounded in integrity, respect, and shared responsibility. We challenge each other to think clearly, act thoughtfully, and build solutions that stand up to real-world demands. Here, curiosity is matched with accountability. Ambition is paired with trust. You'll have the space to do your best work, the support to keep growing, and the backing of a company committed to long-term investment in both its people and the federal mission.
If you're looking to apply your experience to meaningful, mission-driven work-alongside colleagues who take pride in building things that last-you'll find that opportunity at Workday
About the Role
This role will support one or more direct or indirect contracts with the U.S. Federal Government which, due to federal government security requirements, mandates that all Workday personnel working on the contracts be United States citizens (naturalized or native).
Workday's Cyber Defense Directorate protects enterprise and U.S. Government SaaS environments operating under multiple authorization boundaries, including air-gapped regions (AGR).
Our Cyber Defense capability provides advanced monitoring, detection, threat hunting, and response across regulated cloud environments supporting federal customers. We operate in partnership with SOC, Red Team, Blue Team, Purple Team, and Threat Intelligence to ensure continuous validation of detection coverage and operational readiness.
The Detection Engineering and Threat Hunting function is foundational to maintaining compliance, reducing adversary dwell time, and ensuring resilient security posture across high-security SaaS environments.
The Threat Hunting & Detection Engineer is responsible for engineering, validating, and continuously improving detection capabilities across FedRAMP High and IL5 cloud-native SaaS environments, including air-gapped regions.
This role develops high-fidelity detection logic leveraging:
You will translate adversary behaviors into actionable detection analytics aligned to MITRE ATT&CK and NIST SP 800-61r3 incident response lifecycle principles. You will support continuous monitoring requirements under FedRAMP and DoD IL5 frameworks, ensuring detection content aligns to compliance mandates, audit traceability, and evidentiary standards.
In air-gapped environments, you will design detection strategies that account for:
• Limited telemetry pathways • Constrained automation capabilities
• Reduced external enrichment access • Secure data transfer controls
You will collaborate closely with:
As the program matures, this role will help define detection engineering standards, lifecycle governance, and detection coverage metrics across the Cyber Defense Directorate.
About You
This role may require a security clearance at the TS/SCI w/CI Poly level. Applicants must have the ability to obtain and maintain a U.S. government issued security clearance. An active TS/SCI w/CI Poly is preferred
You understand the intersection of detection engineering, cloud security, and regulatory frameworks. You can balance operational effectiveness with compliance rigor. You are comfortable operating in high-assurance, controlled, and sometimes disconnected environments where precision and auditability matter.
Basic Qualifications
Other Qualifications
Workday Pay Transparency Statement
The annualized base salary ranges for the primary location and any additional locations are listed below. Workday pay ranges vary based on work location. As a part of the total compensation package, this role may be eligible for the Workday Bonus Plan or a role-specific commission/bonus, as well as annual refresh stock grants. Recruiters can share more detail during the hiring process. Each candidate's compensation offer will be based on multiple factors including, but not limited to, geography, experience, skills, job duties, and business need, among other things. For more information regarding Workday's comprehensive benefits, please click here .
Primary Location: USA.VA.McLean (Tyson's Corner)
Primary Location Base Pay Range: $159,600 USD - $239,400 USD
Additional US Location(s) Base Pay Range: $144,400 USD - $258,000 USD
Our Approach to Flexible Work
With Flex Work, we're combining the best of both worlds: in-person time and remote. Our approach enables our teams to deepen connections, maintain a strong community, and do their best work. We know that flexibility can take shape in many ways, so rather than a number of required days in-office each week, we simply spend at least half (50%) of our time each quarter in the office or in the field with our customers, prospects, and partners (depending on role). This means you'll have the freedom to create a flexible schedule that caters to your business, team, and personal needs, while being intentional to make the most of time spent together. Those in our remote "home office" roles also have the opportunity to come together in our offices for important moments that matter.
Pursuant to applicable Fair Chance law, Workday will consider for employment qualified applicants with arrest and conviction records.
Workday is an Equal Opportunity Employer including individuals with disabilities and protected veterans.
At Workday, we are committed to providing an accessible and inclusive hiring experience where all candidates can fully demonstrate their skills. If you require assistance or an accommodation at any point, please email accommodations@workday.com .
Are you being referred to one of our roles? If so, ask your connection at Workday about our Employee Referral process!
At Workday, we value our candidates' privacy and data security. Workday will never ask candidates to apply to jobs through websites that are not Workday Careers.
Please be aware of sites that may ask for you to input your data in connection with a job posting that appears to be from Workday but is not.
In addition, Workday will never ask candidates to pay a recruiting fee, or pay for consulting or coaching services, in order to apply for a job at Workday.
We're obsessed with making hard work pay off, for our people, our customers, and the world around us. As a Fortune 500 company and a leading AI platform for managing people, money, and agents, we're shaping the future of work so teams can reach their potential and focus on what matters most. The minute you join, you'll feel it. Not just in the products we build, but in how we show up for each other. Our culture is rooted in integrity, empathy, and shared enthusiasm. We're in this together, tackling big challenges with bold ideas and genuine care. We look for curious minds and courageous collaborators who bring sun-drenched optimism and drive. Whether you're building smarter solutions, supporting customers, or creating a space where everyone belongs, you'll do meaningful work with Workmates who've got your back. In return, we'll give you the trust to take risks, the tools to grow, the skills to develop and the support of a company invested in you for the long haul. So, if you want to inspire a brighter work day for everyone, including yourself, you've found a match in Workday, and we hope to be a match for you too.
About the Team
Your work matters here. At Workday Government, we focus on outcomes that serve a larger mission. Our work supports U.S. federal agencies as they modernize and transform the full employee lifecycle experience and finance operations-so they can operate with greater clarity, accountability, and trust. As a Fortune 500 company and a proven enterprise cloud platform, Workday brings modern technology, responsible AI, and secure infrastructure to some of the most complex environments in the world. The work isn't theoretical. It's operational. It's high-impact. And it demands rigor, integrity, and long-term thinking.
From day one, you'll be part of a team that values collaboration, follow-through, and doing the right thing-especially when the stakes are high. Our culture is grounded in integrity, respect, and shared responsibility. We challenge each other to think clearly, act thoughtfully, and build solutions that stand up to real-world demands. Here, curiosity is matched with accountability. Ambition is paired with trust. You'll have the space to do your best work, the support to keep growing, and the backing of a company committed to long-term investment in both its people and the federal mission.
If you're looking to apply your experience to meaningful, mission-driven work-alongside colleagues who take pride in building things that last-you'll find that opportunity at Workday
About the Role
This role will support one or more direct or indirect contracts with the U.S. Federal Government which, due to federal government security requirements, mandates that all Workday personnel working on the contracts be United States citizens (naturalized or native).
Workday's Cyber Defense Directorate protects enterprise and U.S. Government SaaS environments operating under multiple authorization boundaries, including air-gapped regions (AGR).
Our Cyber Defense capability provides advanced monitoring, detection, threat hunting, and response across regulated cloud environments supporting federal customers. We operate in partnership with SOC, Red Team, Blue Team, Purple Team, and Threat Intelligence to ensure continuous validation of detection coverage and operational readiness.
The Detection Engineering and Threat Hunting function is foundational to maintaining compliance, reducing adversary dwell time, and ensuring resilient security posture across high-security SaaS environments.
The Threat Hunting & Detection Engineer is responsible for engineering, validating, and continuously improving detection capabilities across FedRAMP High and IL5 cloud-native SaaS environments, including air-gapped regions.
This role develops high-fidelity detection logic leveraging:
- Splunk (correlation searches, data models, CIM alignment, SPL optimization)
- Cloud-native telemetry (AWS CloudTrail, GuardDuty, Inspector, VPC Flow Logs, SaaS application logs)
- Identity and access telemetry
- Endpoint and container telemetry
- Vulnerability intelligence sources
You will translate adversary behaviors into actionable detection analytics aligned to MITRE ATT&CK and NIST SP 800-61r3 incident response lifecycle principles. You will support continuous monitoring requirements under FedRAMP and DoD IL5 frameworks, ensuring detection content aligns to compliance mandates, audit traceability, and evidentiary standards.
In air-gapped environments, you will design detection strategies that account for:
• Limited telemetry pathways • Constrained automation capabilities
• Reduced external enrichment access • Secure data transfer controls
You will collaborate closely with:
- SOC Analysts to improve alert quality and reduce false positives
- Security Engineers to ensure log integrity and coverage
- Red/Purple Teams to validate detection effectiveness
- Threat Intelligence to operationalize adversary reporting
- Compliance stakeholders to support audit and continuous monitoring requirements
As the program matures, this role will help define detection engineering standards, lifecycle governance, and detection coverage metrics across the Cyber Defense Directorate.
About You
This role may require a security clearance at the TS/SCI w/CI Poly level. Applicants must have the ability to obtain and maintain a U.S. government issued security clearance. An active TS/SCI w/CI Poly is preferred
You understand the intersection of detection engineering, cloud security, and regulatory frameworks. You can balance operational effectiveness with compliance rigor. You are comfortable operating in high-assurance, controlled, and sometimes disconnected environments where precision and auditability matter.
Basic Qualifications
- 6+ years of experience in cybersecurity operations, detection engineering, or threat hunting
- Hands-on experience building detections in Splunk, including correlation searches and SPL development • Experience operating in FedRAMP, DoD IL4/IL5, or similarly regulated cloud environments
- Experience working with AWS security services (CloudTrail, GuardDuty, Inspector, VPC Flow Logs)
- Strong understanding of MITRE ATT&CK mapping and adversary tradecraft
- Familiarity with NIST SP 800-61r3 incident response lifecycle
- Bachelor's degree in Cybersecurity, Computer Science, Engineering, or equivalent experience
Other Qualifications
- Experience conducting hypothesis-driven threat hunting within SaaS and cloud-native architectures
- Strong understanding of identity-based attack vectors (IAM abuse, token theft, federation misuse)
- Experience detecting container and workload-level attacks
- Familiarity with secure logging architectures in air-gapped environments
- Experience leveraging SOAR platforms (e.g., Tines) within constrained or controlled automation boundaries
Workday Pay Transparency Statement
The annualized base salary ranges for the primary location and any additional locations are listed below. Workday pay ranges vary based on work location. As a part of the total compensation package, this role may be eligible for the Workday Bonus Plan or a role-specific commission/bonus, as well as annual refresh stock grants. Recruiters can share more detail during the hiring process. Each candidate's compensation offer will be based on multiple factors including, but not limited to, geography, experience, skills, job duties, and business need, among other things. For more information regarding Workday's comprehensive benefits, please click here .
Primary Location: USA.VA.McLean (Tyson's Corner)
Primary Location Base Pay Range: $159,600 USD - $239,400 USD
Additional US Location(s) Base Pay Range: $144,400 USD - $258,000 USD
Our Approach to Flexible Work
With Flex Work, we're combining the best of both worlds: in-person time and remote. Our approach enables our teams to deepen connections, maintain a strong community, and do their best work. We know that flexibility can take shape in many ways, so rather than a number of required days in-office each week, we simply spend at least half (50%) of our time each quarter in the office or in the field with our customers, prospects, and partners (depending on role). This means you'll have the freedom to create a flexible schedule that caters to your business, team, and personal needs, while being intentional to make the most of time spent together. Those in our remote "home office" roles also have the opportunity to come together in our offices for important moments that matter.
Pursuant to applicable Fair Chance law, Workday will consider for employment qualified applicants with arrest and conviction records.
Workday is an Equal Opportunity Employer including individuals with disabilities and protected veterans.
At Workday, we are committed to providing an accessible and inclusive hiring experience where all candidates can fully demonstrate their skills. If you require assistance or an accommodation at any point, please email accommodations@workday.com .
Are you being referred to one of our roles? If so, ask your connection at Workday about our Employee Referral process!
At Workday, we value our candidates' privacy and data security. Workday will never ask candidates to apply to jobs through websites that are not Workday Careers.
Please be aware of sites that may ask for you to input your data in connection with a job posting that appears to be from Workday but is not.
In addition, Workday will never ask candidates to pay a recruiting fee, or pay for consulting or coaching services, in order to apply for a job at Workday.
group id: 501386132