About The Position

Your work days are brighter here. We’re obsessed with making hard work pay off, for our people, our customers, and the world around us. As a Fortune 500 company and a leading AI platform for managing people, money, and agents, we’re shaping the future of work so teams can reach their potential and focus on what matters most. The minute you join, you’ll feel it. Not just in the products we build, but in how we show up for each other. Our culture is rooted in integrity, empathy, and shared enthusiasm. We’re in this together, tackling big challenges with bold ideas and genuine care. We look for curious minds and courageous collaborators who bring sun-drenched optimism and drive. Whether you're building smarter solutions, supporting customers, or creating a space where everyone belongs, you’ll do meaningful work with Workmates who’ve got your back. In return, we’ll give you the trust to take risks, the tools to grow, the skills to develop and the support of a company invested in you for the long haul. So, if you want to inspire a brighter work day for everyone, including yourself, you’ve found a match in Workday, and we hope to be a match for you too. About the Team The Workday Cybersecurity Governance, Risk, Compliance & Trust (cGRCT) team enables business agility while maintaining a strong security posture via intelligent The Workday’s National Security Group (NSG) is responsible for all aspects of cybersecurity and compliance for Workday’s US Department of Defense and Intelligence Community customer regions. The NSG Governance, Risk, Compliance (GRC) Team enables business agility while maintaining a strong security posture via intelligent risk-taking, optimized controls management, and iterative security governance. The NSG GRC team’s mission is to enable and maintain Workday’s National Security offerings through certification, continuous monitoring, consultation and deep stakeholder alignment. We act as a trusted advisor across Workday to help maintain and enhance our customer's trust. About the Role As the system owner for our federal information system, you will be responsible for the lifecycle of our information systems. This is a high-impact role that will provide cross-functional ownership, stewardship, and focus for our compliance boundaries (e.g., Fedramp Moderate, IL4, Top Secret). While individual teams will focus on their respective functions (Security Operations, GRC, Engineering) this role will span all teams and boundaries and act as a focal point for the Federal business. The boundary's scope is wide-ranging, covering security, system health, compliance risks, cost/unit economics, incident/on-call trends, and future roadmaps (e.g., AI/ML capabilities or SKUs). To effectively address these complex issues, the System Owner must engage and coordinate the appropriate cross-functional experts from Security, Engineering, Product, Finance, and GRC. You will own the long-term trajectory, risk posture, and architectural runway of your assigned boundary, ensuring it is secure, efficient, and ready for future demands.

Requirements

  • 7+ years of experience in Security Engineering, Security Architecture, or a Compliance-focused role within a cloud or SaaS environment.
  • 5+ years of direct experience with U.S. Government compliance frameworks such as FedRAMP (Moderate/High), DoD IL4/IL5/IL6, NIST RMF, or ICD-503.
  • Proven ability to own and drive large-scale, multi-year architectural and security roadmaps for a single, complex system.
  • Deep understanding of cloud architecture AWS, Azure, GCP and how security controls are implemented at scale.
  • Experience integrating future technologies (e.g., AI/ML systems) into regulated, high-security environments.
  • Excellent communication skills with the ability to articulate complex, multi-faceted technical risk across all domains (architecture, operations, cost) to executive leadership.

Responsibilities

  • Boundary Health, Risk & Cross-Functional Stewardship Holistic Boundary Ownership: Serve as the single point of accountability for the overall health and compliance status of the assigned boundary.
  • Risk Aggregation and Mitigation: Identify, document, and socialize systemic, long-term risks related to architecture, technical debt, and control decay within your specific boundary.
  • System Health & Security Posture: Define and monitor long-term health metrics for the boundary, integrating data from SOC rules, Vulnerability Management, Incident Response, and Configuration Management to assess overall systemic risk.
  • Compliance Control Assurance: Ensure all compliance controls relevant to the boundary (e.g., NIST 800-53 controls) are implemented, continuously monitored, and architecturally sustainable.
  • Compliance Artifact Tracking: Track, prioritize and raise exceptions for the creation, maintenance, and audit readiness of all necessary compliance artifacts for the assigned boundary (e.g., System Security Plan (SSP), POA&Ms, Control Implementation Details).
  • Future-Proofing & Strategic Planning AI and New SKU Readiness: Proactively assess the impact of Artificial Intelligence (AI) features, machine learning models, and new Product SKUs coming into the environment.
  • Define the necessary architectural modifications and compliance controls to safely and securely integrate these future capabilities into the boundary.
  • Vulnerability Trajectory Ownership: Own the strategic direction for reducing the long-term vulnerability surface area within the boundary, guiding functional teams on architectural dependencies and risk prioritization unique to your system.
  • Cloud Cost Efficiency: Collaborate with the Engineering team to analyze and optimize cloud infrastructure costs within the boundary, ensuring security requirements are met in the most fiscally responsible manner.
  • Core Workday Product and Technology: Interface with core Workday engineering and product teams as well as Security teams to ensure base product capabilities are designed to be compliant and deployable within your restricted government environment.

Stand Out From the Crowd

Upload your resume and get instant feedback on how well it matches this job.

Upload and Match Resume

What This Job Offers

Job Type

Full-time

Career Level

Mid Level

Education Level

No Education Listed

Number of Employees

5,001-10,000 employees

© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service