Software Development Engineer, AI Platform
Workday
- Location
- USA, CO, Boulder
- Work model
- On-Site
- Level
- Senior
- H-1B history
- 103 approvals (FY2023)
- Posted
- 1d ago
Skills
About this role
Your work days are brighter here. We’re obsessed with making hard work pay off, for our people, our customers, and the world around us. As a Fortune 500 company and a leading AI platform for managing people, money, and agents, we’re shaping the future of work so teams can reach their potential and focus on what matters most. The minute you join, you’ll feel it. Not just in the products we build, but in how we show up for each other. Our culture is rooted in integrity, empathy, and shared enthusiasm. We’re in this together, tackling big challenges with bold ideas and genuine care. We look for curious minds and courageous collaborators who bring sun-drenched optimism and drive. Whether you're building smarter solutions, supporting customers, or creating a space where everyone belongs, you’ll do meaningful work with Workmates who’ve got your back. In return, we’ll give you the trust to take risks, the tools to grow, the skills to develop and the support of a company invested in you for the long haul. So, if you want to inspire a brighter work day for everyone, including yourself, you’ve found a match in Workday, and we hope to be a match for you too.
About the Team
The Agent Runtime team develops Workday’s secure runtime for enterprise AI agents. The platform provides deterministic policy enforcement, least-privilege execution, and auditable control points for trustworthy AI workflows. We build foundational runtime components and work across platform and ML partner teams to support secure execution at enterprise scale.
About the Role
As a Software Development Engineer on Agent Runtime, you will build and own the AWS infrastructure foundation the platform runs on: dedicated accounts, IAM roles and trust boundaries, VPC/networking design, and the infrastructure-as-code that provisions all of it. This role is focused on cloud infrastructure rather than application development — someone who wants to build the account structure, IAM model, and network topology a security-sensitive, enterprise-scale AI platform depends on. In this role, you will: Design and provision dedicated AWS accounts (build, dev runtime, prod runtime) with proper account structure, guardrails, and compliance requirements (including FIPS) built in from day one. Build and own Terraform modules covering IAM roles/policies, VPC and network design (subnets, routing, security groups, egress control), and account-level guardrails, so that provisioning is repeatable and reviewable rather than manual. Support the infrastructure behind our serverless agent execution environment — provisioning and deprovisioning the runtime environments agents execute in. Design least-privilege IAM roles and cross-account access patterns for our gateway service and build pipeline, including secure service-to-service authentication. Partner directly with security/compliance teams on account guardrails, FIPS requirements, and audit readiness — this role is a primary point of contact for those conversations, not a downstream consumer of someone else's decisions. Register and manage new accounts/services through Workday's internal account-governance process (Venice). Collaborate with platform engineers on open infrastructure questions — service hosting model, egress authentication design, network topology between the gateway and downstream services — and bring a strong point of view grounded in AWS best practice. Build monitoring and alerting for infrastructure health, and participate in code/design reviews for infrastructure changes.
About You
Basic Qualification: 5+ years of experience in cloud infrastructure, DevOps, or platform engineering, with hands-on ownership of production AWS environments. Other Qualifications: Deep, hands-on experience authoring and maintaining Terraform (or comparable IaC tooling) for production infrastructure — not just consuming existing modules. Strong AWS fundamentals: IAM (roles, policies, cross-account trust