Software Development Engineer, AI Platform
WorkdayAbout the role
Your work days are brighter here.
We’re obsessed with making hard work pay off, for our people, our customers, and the world around us. As a Fortune 500 company and a leading AI platform for managing people, money, and agents, we’re shaping the future of work so teams can reach their potential and focus on what matters most. The minute you join, you’ll feel it. Not just in the products we build, but in how we show up for each other. Our culture is rooted in integrity, empathy, and shared enthusiasm. We’re in this together, tackling big challenges with bold ideas and genuine care. We look for curious minds and courageous collaborators who bring sun-drenched optimism and drive. Whether you're building smarter solutions, supporting customers, or creating a space where everyone belongs, you’ll do meaningful work with Workmates who’ve got your back. In return, we’ll give you the trust to take risks, the tools to grow, the skills to develop and the support of a company invested in you for the long haul. So, if you want to inspire a brighter work day for everyone, including yourself, you’ve found a match in Workday, and we hope to be a match for you too.
About the Team
The Agent Runtime team develops Workday’s secure runtime for enterprise AI agents. The platform provides deterministic policy enforcement, least-privilege execution, and auditable control points for trustworthy AI workflows.We build foundational runtime components and work across platform and ML partner teams to support secure execution at enterprise scale.
About the Role
- Design and provision dedicated AWS accounts (build, dev runtime, prod runtime) with proper account structure, guardrails, and compliance requirements (including FIPS) built in from day one.
- Build and own Terraform modules covering IAM roles/policies, VPC and network design (subnets, routing, security groups, egress control), and account-level guardrails, so that provisioning is repeatable and reviewable rather than manual.
- Support the infrastructure behind our serverless agent execution environment — provisioning and deprovisioning the runtime environments agents execute in.
- Design least-privilege IAM roles and cross-account access patterns for our gateway service and build pipeline, including secure service-to-service authentication.
- Partner directly with security/compliance teams on account guardrails, FIPS requirements, and audit readiness — this role is a primary point of contact for those conversations, not a downstream consumer of someone else's decisions.
- Register and manage new accounts/services through Workday's internal account-governance process (Venice).
- Collaborate with platform engineers on open infrastructure questions — service hosting model, egress authentication design, network topology between the gateway and downstream services — and bring a strong point of view grounded in AWS best practice.
- Build monitoring and alerting for infrastructure health, and participate in code/design reviews for infrastructure changes.
About You
- Deep, hands-on experience authoring and maintaining Terraform (or comparable IaC tooling) for production infrastructure — not just consuming existing modules.
- Strong AWS fundamentals: IAM (roles, policies, cross-account trust relationships), VPC design (subnets, routing, security groups, PrivateLink/peering), and AWS account structure/Organizations.
- Experience with serverless compute (Lambda, Fargate, or similar) — provisioning, scaling, and operating it in production.
- Experience standing up new AWS accounts/environments from a clean slate, including navigating compliance requirements (FIPS or comparable regulatory/security standards).
- Working knowledge of security fundamentals: least-privile
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s