# Principal Cloud Security Engineer, Identity & Access (IAM) at Workday

- Company: Workday
- What the company does: Experience a new way to work with Sana and agentic AI from Workday. Backed by Greylock, NEA and Menlo.
- Company website: https://www.workday.com/
- Type: Startups
- Level: Principal and up
- Location: USA.VA.Reston
- Work setup: On-site
- Pay: $185K to $277K base salary per year (USD)
- Posted: 2026-09-27
- Apply by: 2026-11-11
- Apply: https://workday.wd5.myworkdayjobs.com/en-US/Workday/job/USAVAReston/Principal-Cloud-IAM-Engineer_JR-0106596
- Page: https://www.1752.vc/careers/jobs/workday-principal-cloud-security-engineer-identity-and-access-iam/

## About the role

Identity is Workday's most important security boundary. It protects the personal data of 60+ million people and the financial data of some of the world's largest companies. Our identity surface spans multi-account AWS, enterprise SaaS, a global workforce, and a fast-growing set of AI agents and workloads.

## What they're looking for

- 0+ years in cloud security or IAM, including 3+ years in staff, or architect role owning technical direction
- Deep AWS IAM expertise: multi-account Organizations, SCPs, IAM Identity Center, ABAC, and secrets management (AWS Secrets Manager, HashiCorp Vault, or similar)
- Enterprise workforce identity experience with Okta or an equivalent platform (Entra ID, Ping, etc.), including SSO, MFA, SCIM, and lifecycle management
- Strong working knowledge of SAML, OIDC, and OAuth2, including debugging them in complex environments
- Terraform fluency and an understanding of how identity controls are enforced through CI/CD
- A track record of driving alignment across engineering, security, and business teams without positional authority

