About the Role
This exciting role would suit someone who is adventurous, established in their career, and looking for a new challenge. You can expect to conduct security assessments & exciting Red Team engagements across Workday's public & private cloud infrastructure as well as Workday's products. If you are a passionate learner, an advocate for security, and are a highly skilled offensive security engineer, then this is the right job for you!
About You
Basic Qualifications
- 5+ years of progressive experience in a similar role
- Led PenTests in one or more areas such as public cloud infrastructure (AWS, Google Cloud), modern web applications, enterprise network assessments, or API testing
- A detailed understanding of modern security best practices such as OWASP Top 10 & MITRE ATT&CK framework
- In-depth knowledge of networking & technology fundamentals and how to attack their weaknesses (TCP / IP stack, Linux, Docker, Kubernetes, Microservice architectures)
- Proven track record with one or more scripting languages for automation (python, Go, Bash, Ruby, etc.)
Other Qualifications
One or more industry leading certification (OSCP, CRTE, CRTO, ARTE, CPTS, etc.)A bonus is a track record of Bug Bounty submissions or independent research e.g. GitHub projectsExcellent written & verbal communication skillsThe ability to triage findings and work on remediation plans with partner teams