Vulnerability Management Analyst (US Federal)

Workday•Reston, VA
•Hybrid

About The Position

This role will support one or more direct or indirect contracts with the U.S. Federal Government which, due to federal government security requirements, mandates that all Workday personnel working on the contracts be United States citizens (naturalized or native). The role requires strong organization and interpersonal skills, and the technical ability to understand, interpret and prioritize findings from commercial scan tools. The role also requires contributing to the Planning of Actions and Milestones (POAMs) and communicating status to the leadership team.

Requirements

  • Outstanding communication and organization skills.
  • Self-driven, motivated professional with experience working with multiple stakeholders.
  • Ability to understand and interpret results from commercial scanning tools and provide related guidance for remediation.
  • Working knowledge in using scan tools such as Qualys, Tenable, Twistlock, Wiz, etc.
  • Working knowledge of FedRAMP, NIST 800-53 controls, IL4/5, and DoD SRG.
  • Previous experience in managing POAMs for FedRAMP authorized environments.
  • Experience in cloud computing, with a major CSP like AWS, Google, or federal SaaS solution.
  • Proficiency in using tools like Jira for managing tickets and tasks.
  • Experience with documenting security and compliance policies and procedures.
  • Working proficiency in Python for minor scripting and automation.

Nice To Haves

  • Relevant industry certifications (e.g., Security+, CEH, CISSP).
  • Previous experience with using Git, SDKs/APIs.
  • Previous experience with a 3PAO, as a Security Controls Assessor (SCA).
  • Previous experience with commercial Cloud Service Providers (CSPs).
  • Experience in system design engineering to provide technical security guidance documentation.
  • Experience in implementing POAM related automation.
  • Knowledge of GRC tools (e.g., Xacta, Vanta, RegScale, ServiceNow, Archer).

Responsibilities

  • Analyze and organize scan results and prioritize vulnerabilities for remediation based on risk requirements.
  • Engage with engineering teams to track and report status and remediation timelines.
  • Support management of Planning of Actions and Milestones (POAMs) and monthly Continuous Monitoring (ConMon).
  • Support Annual Assessments for FedRAMP, IL-4/5 and CMMC.
  • Assist in documenting policies and procedures (update SSPs, etc.).
  • Work with the larger GRC team to assist with leading the design, implementation and assessment of Workday's SaaS offering.
  • Write scripts in Python to automate tasks.

Benefits

  • Workday Bonus Plan or a role-specific commission/bonus
  • Annual refresh stock grants
  • Comprehensive benefits
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service