Program Manager, Cybersecurity Risk

WorkdayReston, VA
Hybrid

About The Position

Workday is seeking a Program Manager for its Cybersecurity Risk team. This role will be a hands-on execution partner within the third-party risk management (TPRM) program, collaborating with the Principal Program Manager to assess and manage security risks across the vendor and partner ecosystem. The Program Manager will conduct third-party risk assessments, track control gaps and remediation, monitor high-risk vendors, and support broader cyber risk assessment activities. This role involves partnering with business units and stakeholders to identify and assess security issues, communicate impact, and drive remediation actions.

Requirements

  • 5+ years of experience in governance, risk, and compliance (GRC), including third-party / vendor risk management.
  • 2+ years of experience conducting security or third-party risk assessments across the vendor lifecycle.
  • Bachelor’s degree in a relevant discipline such as Information Security, Computer Science, Risk Management, Business, or a related field, or equivalent practical experience.
  • Solid understanding of third-party / vendor risk management across the lifecycle — intake, due diligence, ongoing monitoring, issue remediation, and off-boarding.
  • Working knowledge of security and risk frameworks such as NIST CSF, ISO 27001, SOC 2, PCI DSS, and SIG.
  • Familiarity with GRC / TPRM platforms and security-ratings services (e.g., OneTrust, Archer, ServiceNow, Vanta, BitSight, SecurityScorecard, RiskRecon).
  • Ability to review and interpret technical assurance evidence (e.g., SOC 2 Type II reports, penetration testing results) to evaluate vendor control effectiveness.
  • Understanding of qualitative risk analysis and the ability to translate risk into clear business impact.
  • Awareness of AI/ML vendor risk and how AI-enabled services are assessed, monitored, and governed.
  • Strong written and verbal communication skills, with the ability to work with both technical and non-technical stakeholders.
  • Strong attention to detail and the ability to manage multiple assessments and competing priorities in a fast-paced environment.

Nice To Haves

  • Certifications such as CRISC, CISA, CISSP, or CISM preferred.
  • Some hands-on automation experience such as scripting or low-code / no-code workflow tools used to streamline risk assessments and reporting.

Responsibilities

  • Conduct security risk assessments for third parties across the third-party lifecycle (intake, due diligence, ongoing monitoring, and offboarding).
  • Identify, document, track, and drive remediation of control gaps and security risks through remediation, exception, or formal risk acceptance.
  • Monitor critical and high-risk vendors for control changes, risk signals, remediation progress, and ongoing compliance concerns.
  • Partner with Legal, Procurement, Security, Privacy, and business owners to ensure third-party risks are appropriately documented, communicated, accepted, or mitigated.
  • Maintain accurate third-party records, assessment results, and issues within the system of record, and support preparation of metrics, dashboards, and management reporting.
  • Support principal-level risk assessment activities as needed, including security exception reviews and internal control assessments.
  • Contribute to the maturation of TPRM processes, procedures, and best practices, and support other risk, governance, and program activities as needed.

Benefits

  • Workday Bonus Plan or a role-specific commission/bonus
  • Annual refresh stock grants
  • Comprehensive benefits
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service