Workday
Software Development Engineer, Azure VDI Engineer (US Federal)
USA.VA.Reston · Mid · Contract
Stay score
odds of building a lasting career here
Thin sponsorship signal and lottery-bound. A low-probability bet with your clock running. Prioritize cap-exempt roles and proven entry-level sponsors first.
Lottery odds assume a STEM candidate.
Personalize to your clock →Employer immigration record
from this employer's Department of Labor filings
Green-card filing pattern in this occupation
Green-card intent detected
Green-card follow-through: 98%
Files H-1B transfers
Sourced from Department of Labor LCA, PERM and prevailing-wage disclosure data. Employer matching is by name, so figures may be split across an employer's legal entities. Absence of a filing means none appears in our copy of the data, not that none exists.
Community outcomes
No reports yet — be the first to help the next applicant.
About the role
- Monitor and troubleshoot automated Workday → Microsoft Entra ID user provisioning.
- The Workday Continuous Verification team is looking for a highly motivated Software Development Engineer with DevOps experience to join our 24/7 operations team.
- You will ensure the platform's health, security, and compliance with a strong focus on Identity and Access Management (IAM) and Microsoft Entra Conditional Access.
Responsibilities
- Coordinate and manage Microsoft Entra ID Governance features, including Access Packages and Microsoft 365 Groups, to govern user access lifecycle.
- Support user onboarding, including issuing Temporary Access Passes (TAP) and assisting with MFA registration (Passkeys, Microsoft Authenticator).
- Provide Tier 2/3 technical support for VDI-related issues.
- In this role, you will be responsible for the day‑to‑day operation, maintenance, and security monitoring of our critically meaningful, IL5‑compliant Azure VDI environment in support of a new Workday region.
- Note: This role does not design architecture; it operates and secures an existing high‑security environment.
- Maintain continuous STIG compliance for all VDI endpoints.
- Manage pool‑specific access controls to segregate user populations (Engineering vs. Efficiency).
- Manage, review, and fine‑tune all Microsoft Entra Conditional Access policies.
- Our approach enables our teams to deepen connections, maintain a strong community, and do their best work.
Requirements
- Minimum of 3 years of experience operating systems in high‑security supervised environments (DoD IL4/IL5, FedRAMP High, GCC‑High).
- Deep hands‑on expertise with Microsoft Entra ID, including:
- Experience with cloud-native security tools:
- We know that flexibility can take shape in many ways, so rather than a number of required days in-office each week, we simply spend at least half (50%) of our time each quarter in the office or in the field with our customers, prospects, and partners (depending on role).
- Workday is committed to providing reasonable accommodations for qualified individuals during our application process, in order to perform one or more essential functions of their job, as well as regarding the use of AI tools for employment decision-making to any degree.
- Deep hands‑on expertise with
- Conditional Access (building/testing/maintaining complex policies)
- Identity Governance (Access Packages, Access Reviews)
- MFA configurations including Passkeys and TAP
Nice to have
- Experience with Windows 365 Government or Azure Virtual Desktop (AVD).
- Experience with Defender for Cloud Apps (MCAS) and Microsoft Purview (DLP).
- Experienced in tracking and managing code changes using SCM tools, including version and branch management, and conflict resolution.
- Capable of encouraging a positive and inclusive team environment to improve team efficiency, facilitate effective decision-making, and assist with project management.
- Workday Pay Transparency Statement
- Recruiters can share more detail during the hiring process.
- Each candidate's compensation offer will be based on multiple factors including, but not limited to, geography, experience, skills, job duties, and business need, among other things.
Skills
- Microsoft Sentinel (monitoring & analytics)
- Microsoft Defender for Endpoint (VDI security)
- Strong experience managing Windows endpoints via Microsoft Intune.
- Familiarity with applying/monitoring DISA STIG baselines.
- Experience with on‑call rotations and formal incident response plans.
- Your work days are brighter here.
Compensation
- $137,000 USD - $205,400 USD
- $123,900 USD - $222,000 USD
- In addition, Workday will never ask candidates to pay a recruiting fee, or pay for consulting or coaching services, in order to apply for a job at Workday.
Benefits
- Maintain operational health of VDI pools.
- Our Approach to Flexible Work
- This means you'll have the freedom to create a flexible schedule that caters to your business, team, and personal needs, while being intentional to make the most of time spent together.
- Those in our remote "home office" roles also have the opportunity to come together in our offices for important moments that matter.
Company info
- This is a hands‑on operational role.
- This role does not design architecture; it operates and secures an existing high‑security environment.
Equal opportunity
- Workday is an Equal Opportunity Employer including individuals with disabilities and protected veterans.
- If you require a reasonable accommodation, you may email accommodations@workday.com, as far in advance as possible.
- Please see below for more details including how to request an accommodation as a qualified veteran, due to a disability or for religious reasons, or as otherwise provided under applicable law.
Visa & Work Authorization
- This role may require a security clearance at the TS/SCI w/CI Poly level
This listing is sourced directly from Workday's careers page and normalized into a canonical job model.