Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy
Jobs / Job page
Cybersecurity GRC - US Federal image - Rise Careers
Job details

Cybersecurity GRC - US Federal

Your work days are brighter here.

At Workday, it all began with a conversation over breakfast. When our founders met at a sunny California diner, they came up with an idea to revolutionize the enterprise software market. And when we began to rise, one thing that really set us apart was our culture. A culture which was driven by our value of putting our people first. And ever since, the happiness, development, and contribution of every Workmate is central to who we are. Our Workmates believe a healthy employee-centric, collaborative culture is the essential mix of ingredients for success in business. That’s why we look after our people, communities and the planet while still being profitable. Feel encouraged to shine, however that manifests: you don’t need to hide who you are. You can feel the energy and the passion, it's what makes us unique. Inspired to make a brighter work day for all and transform with us to the next stage of our growth journey? Bring your brightest version of you and have a brighter work day here.

At Workday, we value our candidates’ privacy and data security.  Workday will never ask candidates to apply to jobs through websites that are not Workday Careers. 

  

Please be aware of sites that may ask for you to input your data in connection with a job posting that appears to be from Workday but is not.

  

In addition, Workday will never ask candidates to pay a recruiting fee, or pay for consulting or coaching services, in order to apply for a job at Workday.

About the Team

The Workday’s National Security Group (NSG) is responsible for all aspects of cybersecurity and compliance for Workday’s US Department of Defense and Intelligence Community customer regions. The NSG Governance, Risk, Compliance (GRC) Team enables business agility while maintaining a strong security posture via intelligent risk-taking, optimized controls management, and iterative security governance. The NSG GRC team’s mission is to enable and maintain Workday’s National Security offerings through certification, continuous monitoring, consultation and deep stakeholder alignment. We act as a trusted advisor across Workday to help maintain and enhance our customer's trust.

About the Role

This role will support one or more direct or indirect contracts with the U.S. Federal Government which, due to federal government security requirements, mandates that all Workday personnel working on the contracts be United States citizens (naturalized or native).

This role will support one or more direct or indirect contracts with the U.S. Federal Government which, due to federal government security requirements, mandates that all Workday personnel working on the contracts be United States Citizens (naturalized or native).
The Cybersecurity GRC - Public Sector role is a critical part of Workday’s GRC function and will work as a key team member leading the design, implementation and assessment of Workday's US National Security offerings. You will play a vital role in ensuring continued compliance across public sector frameworks, assist in prioritizing future system changes and manage the audit lifecycle for the various DoD and IC programs. You will lead security and compliance related interactions with Workday's National Security customers and advise internal business partners on risk and compliance requirements related to the product development lifecycle and other strategic organizational initiatives.

About You

Basic Qualifications

  • 5+ years of experience in an equivalent governance, risk & compliance and/or related engineering role
  • 3+ years direct experience with the FedRAMP and RMF assessment and authorization processes
  • This position requires a TS/SCI with CI POLY security clearance. Applicants must already possess a valid and active TS/SCI with CI POLY security clearance.

Other Qualifications

  • A solid understanding of the FedRAMP Framework and DoD Impact levels IL4, IL5 and IL6
  • Bachelor's degree or equivalent experience
  • Experience prioritizing technical changes to a FedRAMP system and apply controls to ensure audit readiness and acceptability
  • Experience leading system design with engineering to provide technical guidance documentation
  • Experience designing federal SaaS cloud computing systems including source control management, logging & monitoring systems, FIPS encryption methods, access controls and vulnerability management
  • Strong communications skills (written and verbal) and attention to detail
  • Proven program/project management experience (especially audit management)
  • Ability to lead multiple projects and organize time effectively
  • Organized, adaptable, and able to gain support and consensus with cross-functional partners
  • CISA, CISSP, PMP, CIPP or other related certifications


Workday Pay Transparency Statement

The annualized base salary ranges for the primary location and any additional locations are listed below.  Workday pay ranges vary based on work location. As a part of the total compensation package, this role may be eligible for the Workday Bonus Plan or a role-specific commission/bonus, as well as annual refresh stock grants. Recruiters can share more detail during the hiring process. Each candidate’s compensation offer will be based on multiple factors including, but not limited to, geography, experience, skills, job duties, and business need, among other things. For more information regarding Workday’s comprehensive benefits, please click here.

Primary Location: USA.VA.McLean (Tyson's Corner)


 

Primary Location Base Pay Range: $111,600 USD - $167,500 USD


 

Additional US Location(s) Base Pay Range: $101,000 USD - $179,400 USD



Our Approach to Flexible Work
 

With Flex Work, we’re combining the best of both worlds: in-person time and remote. Our approach enables our teams to deepen connections, maintain a strong community, and do their best work. We know that flexibility can take shape in many ways, so rather than a number of required days in-office each week, we simply spend at least half (50%) of our time each quarter in the office or in the field with our customers, prospects, and partners (depending on role). This means you'll have the freedom to create a flexible schedule that caters to your business, team, and personal needs, while being intentional to make the most of time spent together. Those in our remote "home office" roles also have the opportunity to come together in our offices for important moments that matter.

Pursuant to applicable Fair Chance law, Workday will consider for employment qualified applicants with arrest and conviction records.

Workday is an Equal Opportunity Employer including individuals with disabilities and protected veterans.

Are you being referred to one of our roles? If so, ask your connection at Workday about our Employee Referral process!

Workday Glassdoor Company Review
4.2 Glassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star icon Glassdoor star icon
Workday DE&I Review
No rating Glassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star icon
CEO of Workday
Workday CEO photo
Aneel Bhusri | Carl Eschenbach
Approve of CEO

Average salary estimate

$139550 / YEARLY (est.)
min
max
$111600K
$167500K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

What You Should Know About Cybersecurity GRC - US Federal, Workday

At Workday, we're looking for a Cybersecurity GRC professional to join our National Security Group in McLean, VA. This role is crucial for supporting our U.S. Federal Government contracts, where compliance, risk management, and strong security posture are paramount. Here, you’ll play an integral part in designing, implementing, and assessing our US National Security offerings. Your expertise will help in maintaining compliance with public sector frameworks while advising on risk and compliance requirements across the product development lifecycle. With your strong background in governance, risk, and compliance, you’ll not only ensure our systems align with FedRAMP requirements but also lead security and compliance interactions with customers in the National Security domain. You'll collaborate closely with internal teams, prioritizing technical changes and managing the audit lifecycle for our various DoD and Intelligence Community programs. At Workday, we pride ourselves on our people-first culture, fostering an environment where you can bring your authentic self to work every day. If you’re ready to contribute to a great mission and be part of a company making a significant impact, then Workday is the right place for you.

Frequently Asked Questions (FAQs) for Cybersecurity GRC - US Federal Role at Workday
What are the responsibilities of a Cybersecurity GRC at Workday?

As a Cybersecurity GRC professional at Workday, you'll support U.S. Federal Government contracts by ensuring compliance with security standards and frameworks. You'll be integral in leading audits, implementing security measures, and advising internal teams on risk and compliance requirements during the product development lifecycle. Your role will also involve managing relationships with National Security customers to maintain and enhance their trust in Workday's services.

Join Rise to see the full answer
What qualifications do I need to apply for the Cybersecurity GRC position at Workday?

To qualify for the Cybersecurity GRC role at Workday, you should have at least 5 years of experience in governance, risk, and compliance or a related engineering role. A solid grasp of FedRAMP and RMF processes is essential, as well as a current TS/SCI with CI POLY security clearance. Candidates are also expected to hold a bachelor’s degree or equivalent and have knowledge of federal SaaS systems and audit management.

Join Rise to see the full answer
How does Workday support its Cybersecurity GRC professionals?

Workday is committed to its employees, including Cybersecurity GRC professionals, by fostering an employee-centric culture, providing opportunities for professional development, and ensuring a collaborative work environment. Flexible work arrangements, comprehensive benefits, and a focus on work-life balance support our teams in performing at their best while maintaining personal well-being.

Join Rise to see the full answer
What role does the Cybersecurity GRC play in Workday’s National Security Group?

The Cybersecurity GRC role is key to ensuring compliance and maintaining a strong security posture for Workday's offerings in the National Security sector. This includes engaging with Federal Government customers, leading audit processes, evaluating risk management strategies, and ensuring adherence to established regulatory frameworks, all of which are essential for sustaining trust and security.

Join Rise to see the full answer
Can you describe the team culture for the Cybersecurity GRC at Workday?

The team culture for the Cybersecurity GRC at Workday is collaborative and deeply supportive, embodying the company's values of transparency and inclusivity. With a focus on innovation and employee engagement, team members are encouraged to share ideas, collaborate on projects, and pursue professional growth while aligning with Workday’s mission to enhance cybersecurity solutions for our customers.

Join Rise to see the full answer
Common Interview Questions for Cybersecurity GRC - US Federal
What is your experience with FedRAMP and RMF processes in your previous roles?

Be sure to highlight specific projects where you applied your expertise with FedRAMP and RMF. Describe your involvement in assessments, authorizations, or ongoing monitoring, and explain how these experiences prepared you for the Cybersecurity GRC position.

Join Rise to see the full answer
How do you prioritize risk management initiatives within a compliance framework?

Discuss your approach to assessing risks, including tools or methodologies you employ. Explain how you balance compliance with operational needs and how you communicate prioritization to stakeholders, ensuring alignment with both security and business objectives.

Join Rise to see the full answer
Can you give an example of how you've successfully managed a compliance audit?

Share a detailed narrative about a specific audit you managed, outlining your steps from preparation to follow-up. Emphasize your communication with stakeholders throughout the process and any challenges you encountered and overcame.

Join Rise to see the full answer
What strategies do you employ to maintain stakeholder engagement in compliance activities?

Talk about the importance of clear communication and regular updates. Describe how you foster cooperation by educating stakeholders on compliance significance and collaborating on compliance-related initiatives.

Join Rise to see the full answer
Describe your experience with developing and implementing security controls.

Provide examples of security controls you have developed and implemented, discussing the rationale behind your choices and how they align with regulatory requirements. Highlight any positive outcomes from these implementations.

Join Rise to see the full answer
How do you stay updated on cybersecurity regulations and compliance standards?

Mention specific resources like industry publications, professional organizations, or training programs that you engage with regularly. Emphasize your commitment to continuous learning and adapting to new regulations.

Join Rise to see the full answer
What is your approach to handling non-compliance issues?

Discuss a structured approach that includes identifying the root cause of non-compliance, evaluating the risks involved, and implementing corrective actions. Provide an example if applicable.

Join Rise to see the full answer
Can you explain the role of continuous monitoring in cybersecurity compliance?

Explain that continuous monitoring is crucial for maintaining ongoing security posture and compliance by tracking changes to the environment and identifying potential vulnerabilities in real-time. Discuss tools and methodologies you have used.

Join Rise to see the full answer
How do you ensure that your team understands their compliance-related responsibilities?

Emphasize the importance of training and clear communication of expectations. Discuss your methods for conveying accountability and providing resources for team members to understand their roles in compliance.

Join Rise to see the full answer
What do you consider the biggest challenges facing cybersecurity GRC professionals today?

Identify key challenges such as the fast-paced evolution of threats, regulatory changes, and technologies. Discuss strategies you employ to overcome these challenges, focusing on adaptability and proactive engagement.

Join Rise to see the full answer
Similar Jobs
Photo of the Rise User
Posted 14 days ago

Join Workday as a Business System Analyst to drive system improvements for our finance team and enhance operational efficiency.

Photo of the Rise User
Posted 14 days ago

Join Workday as a Product Manager to lead our innovative design system, fostering collaboration across teams to create exceptional user experiences.

Photo of the Rise User
Armis Security Hybrid Tel Aviv-Yafo, Tel Aviv District, Israel
Posted 8 days ago

Join Armis as a Network & Security Engineer and play a pivotal role in safeguarding our global IT infrastructure.

Posted 12 days ago

As a Manufacturing Digital Solutions Support Analyst at Toyota, you'll empower teams with the expertise they need to implement innovative digital solutions on the shop floor.

Join UChicago Medicine as an Inpatient Orders Analyst - Associate in a remote role and help advance healthcare through technology.

Join Climate Arc as a DevOps Engineer and help build a data-driven foundation for transitioning to a sustainable future.

Photo of the Rise User
Posted 11 days ago

Join Northern Trust as a Senior IT Auditor - Cyber to lead critical audit projects in a hybrid work environment.

Photo of the Rise User
Posted 22 hours ago

Join Peraton as a Cyberspace Intelligence Analyst, where you will play a vital role in supporting national security through advanced cyber operations at Fort Meade, MD.

Photo of the Rise User
Wix Remote Dublin, Ireland
Posted 13 days ago
Inclusive & Diverse
Rise from Within
Mission Driven
Diversity of Opinions
Maternity Leave
Paternity Leave
Family Coverage (Insurance)
Medical Insurance
Dental Insurance
Vision Insurance
Mental Health Resources
Life insurance
Disability Insurance
Health Savings Account (HSA)
Flexible Spending Account (FSA)
401K Matching

As a Senior DevOps Engineer at DeviantArt, you'll architect and maintain a robust infrastructure for a leading online art community, focusing on high availability and reactive mitigation strategies.

Photo of the Rise User
Posted 19 hours ago

Join Carta as a Junior Salesforce Admin and help streamline contract processes in their innovative financial technology environment.

Workday brings finance, HR, and planning into one system, making it possible for enterprises of all sizes to shed their disparate systems and build better businesses. We serve over 7,900 of the world’s largest companies, educational institutions, ...

252 jobs
MATCH
VIEW MATCH
FUNDING
SENIORITY LEVEL REQUIREMENT
TEAM SIZE
EMPLOYMENT TYPE
Full-time, hybrid
DATE POSTED
April 13, 2025

Subscribe to Rise newsletter

Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!
LATEST ACTIVITY
Photo of the Rise User
52 people applied to Security Analyst Jr at DEUNA
Photo of the Rise User
Someone from OH, Pickerington just viewed Senior Business Analyst (Salesforce) at Protolabs
Photo of the Rise User
13 people applied to Cyber security analyst at Optimiza
H
Someone from OH, Akron just viewed Brand Marketing Manager at Huntington
R
Someone from OH, Hamilton just viewed Forklift Operator Warehouse at Ryder
Photo of the Rise User
Someone from OH, Cincinnati just viewed Ad Ops Specialist, Display at System1
Photo of the Rise User
Someone from OH, Cincinnati just viewed FQHC Billing & Collections Manager at OhioGuidestone
Photo of the Rise User
Someone from OH, Cleveland just viewed Enrollment Specialist- Remote at Adtalem Global Education
o
Someone from OH, Dayton just viewed Marketing and Communications Specialist at osu
Photo of the Rise User
Someone from OH, Columbus just viewed Construction Coordinator at Meijer
T
11 people applied to Intern-Tech at TDS Telecom
Photo of the Rise User
Someone from OH, Steubenville just viewed Legal & Compliance Internship at Smiths Group
Photo of the Rise User
Someone from OH, Warren just viewed Senior Front-End Developer at Worldly
Photo of the Rise User
62 people applied to SOC Analyst I at Epsilon
Photo of the Rise User
Someone from OH, Tiffin just viewed Game Operations Specialist at Genius Sports
u
Someone from OH, Loveland just viewed Customer Service Agent - Part Time at uhaul
Photo of the Rise User
Someone from OH, Cleveland just viewed HR Manager at Shearer's Foods
Photo of the Rise User
Someone from OH, Columbus just viewed Mid Level, System Administrator - (ETS) at Delivery Hero
Photo of the Rise User
Someone from OH, Mason just viewed Inside Sales Co-Op at VEGA Americas
Photo of the Rise User
Someone from OH, Sandusky just viewed Director of IT at Kyo
Photo of the Rise User
Someone from OH, Delaware just viewed Practice Group Manager at LifeStance Health