Vulnerability Management Analyst - US Federal

WorkdayMcLean, VA
9dHybrid

About The Position

Your work days are brighter here. We’re obsessed with making hard work pay off, for our people, our customers, and the world around us. As a Fortune 500 company and a leading AI platform for managing people, money, and agents, we’re shaping the future of work so teams can reach their potential and focus on what matters most. The minute you join, you’ll feel it. Not just in the products we build, but in how we show up for each other. Our culture is rooted in integrity, empathy, and shared enthusiasm. We’re in this together, tackling big challenges with bold ideas and genuine care. We look for curious minds and courageous collaborators who bring sun-drenched optimism and drive. Whether you're building smarter solutions, supporting customers, or creating a space where everyone belongs, you’ll do meaningful work with Workmates who’ve got your back. In return, we’ll give you the trust to take risks, the tools to grow, the skills to develop and the support of a company invested in you for the long haul. So, if you want to inspire a brighter work day for everyone, including yourself, you’ve found a match in Workday, and we hope to be a match for you too. About the Team Workday has launched Workday Government, a new wholly owned subsidiary dedicated to serving the U.S. Government, to address its specific needs and accelerate modernization efforts. The Governance, Risk and Compliance (GRC) team works on compliance with US Government security frameworks including FedRAMP, IL-4, CMMC, and others for our civilian and defense customers. About the Role This role will support one or more direct or indirect contracts with the U.S. Federal Government which, due to federal government security requirements, mandates that all Workday personnel working on the contracts be United States citizens (naturalized or native). The GRC team is seeking a Vulnerability Management Analyst who will work with system owners and engineering teams to remediate issues. The role requires strong organization and interpersonal skills, and the technical ability to understand, interpret and prioritize findings from commercial scan tools. The role also requires contributing to the Planning of Actions and Milestones (POAMs) and communicating status to the leadership team.

Requirements

  • Outstanding communication and organization skills.
  • Self-driven, motivated professional with experience working with multiple stakeholders.
  • Strong ability to understand and interpret results from commercial scanning tools and provide related guidance for remediation.
  • Strong ability to manage complex datasets in spreadsheets.
  • Previous experience in managing POAMs for FedRAMP authorized environments.
  • Working knowledge of security standards like FedRAMP, DoD IL-4/5, NIST 800-171, NIST 800-53 and the Risk Management Framework (RMF).
  • Experience in cloud computing, preferably with a major hyperscaler like AWS, Google, etc.
  • Proficiency in using tools like Jira for managing tickets and tasks.

Nice To Haves

  • Relevant industry certifications (e.g., Security+, CEH, CISSP).
  • Previous experience as an assessor, Information Systems Security Engineer (ISSE) with a 3PAO or Cloud Services Provider (CSP).
  • Previous experience with US Federal Government defense or civilian agencies.
  • Ability to write simple scripts (e.g. Python) to improve productivity.

Responsibilities

  • Analyze and organize scan results and prioritize vulnerabilities for remediation based on risk requirements.
  • Establish strong relationships with engineering teams to track and report status and remediation timelines.
  • Contribute to the Planning of Actions and Milestones (POAMs).
  • Support Continuous Monitoring (ConMon) and participate in audit activities related to vulnerability management.
  • Report status to leadership teams.

Stand Out From the Crowd

Upload your resume and get instant feedback on how well it matches this job.

Upload and Match Resume

What This Job Offers

Job Type

Full-time

Career Level

Mid Level

Education Level

No Education Listed

Number of Employees

5,001-10,000 employees

© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service