Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy
Jobs / Job page
Senior Cybersecurity GRC - US Federal image - Rise Careers
Job details

Senior Cybersecurity GRC - US Federal - job 1 of 2

Your work days are brighter here.

At Workday, it all began with a conversation over breakfast. When our founders met at a sunny California diner, they came up with an idea to revolutionize the enterprise software market. And when we began to rise, one thing that really set us apart was our culture. A culture which was driven by our value of putting our people first. And ever since, the happiness, development, and contribution of every Workmate is central to who we are. Our Workmates believe a healthy employee-centric, collaborative culture is the essential mix of ingredients for success in business. That’s why we look after our people, communities and the planet while still being profitable. Feel encouraged to shine, however that manifests: you don’t need to hide who you are. You can feel the energy and the passion, it's what makes us unique. Inspired to make a brighter work day for all and transform with us to the next stage of our growth journey? Bring your brightest version of you and have a brighter work day here.

At Workday, we value our candidates’ privacy and data security.  Workday will never ask candidates to apply to jobs through websites that are not Workday Careers. 

  

Please be aware of sites that may ask for you to input your data in connection with a job posting that appears to be from Workday but is not.

  

In addition, Workday will never ask candidates to pay a recruiting fee, or pay for consulting or coaching services, in order to apply for a job at Workday.

About the Team

The Workday Cybersecurity Governance, Risk, Compliance & Trust (cGRCT) team enables business agility while maintaining a strong security posture via intelligent The Workday’s National Security Group (NSG) is responsible for all aspects of cybersecurity and compliance for Workday’s US Department of Defense and Intelligence Community customer regions. The NSG Governance, Risk, Compliance (GRC) Team enables business agility while maintaining a strong security posture via intelligent risk-taking, optimized controls management, and iterative security governance. The NSG GRC team’s mission is to enable and maintain Workday’s National Security offerings through certification, continuous monitoring, consultation and deep stakeholder alignment. We act as a trusted advisor across Workday to help maintain and enhance our customer's trust.

About the Role

This role will support one or more direct or indirect contracts with the U.S. Federal Government which, due to federal government security requirements, mandates that all Workday personnel working on the contracts be United States citizens (naturalized or native).

This role will support one or more direct or indirect contracts with the U.S. Federal Government which, due to federal government security requirements, mandates that all Workday personnel working on the contracts be United States Citizens (naturalized or native).
The Senior Cybersecurity GRC role is a critical part of Workday’s GRC function and will work as a key team member leading the design, implementation and assessment of Workday's US National Security offerings. You will play a vital role in ensuring continued compliance across public sector frameworks, assist in prioritizing future system changes and manage the audit lifecycle for the various DoD and IC programs. You will lead security and compliance related interactions with Workday's National Security customers and advise internal business partners on risk and compliance requirements related to the product development lifecycle and other strategic organizational initiatives.

About You

Basic Qualifications

  • 8+ years of experience in an equivalent governance, risk & compliance and/or related engineering role
  • 5+ years direct experience with the FedRAMP and RMF assessment and authorization processes
  • This position requires a TS/SCI with CI POLY security clearance. Applicants must already possess a valid and active TS/SCI with CI POLY security clearance.

Other Qualifications

  • A solid understanding of the FedRAMP Framework and DoD Impact levels IL4, IL5 and IL6
  • Bachelor's degree or equivalent experience
  • Experience prioritizing technical changes to a FedRAMP system and apply controls to ensure audit readiness and acceptability
  • Experience leading system design with engineering to provide technical guidance documentation
  • Experience designing federal SaaS cloud computing systems including source control management, logging & monitoring systems, FIPS encryption methods, access controls and vulnerability management
  • Strong communications skills (written and verbal) and attention to detail
  • Proven program/project management experience (especially audit management)
  • Ability to lead multiple projects and organize time effectively
  • Organized, adaptable, and able to gain support and consensus with cross-functional partners
  • CISA, CISSP, PMP, CIPP or other related certifications


Workday Pay Transparency Statement

The annualized base salary ranges for the primary location and any additional locations are listed below.  Workday pay ranges vary based on work location. As a part of the total compensation package, this role may be eligible for the Workday Bonus Plan or a role-specific commission/bonus, as well as annual refresh stock grants. Recruiters can share more detail during the hiring process. Each candidate’s compensation offer will be based on multiple factors including, but not limited to, geography, experience, skills, job duties, and business need, among other things. For more information regarding Workday’s comprehensive benefits, please click here.

Primary Location: USA.VA.McLean (Tyson's Corner)


 

Primary Location Base Pay Range: $139,000 USD - $208,500 USD


 

Additional US Location(s) Base Pay Range: $125,800 USD - $223,400 USD



Our Approach to Flexible Work
 

With Flex Work, we’re combining the best of both worlds: in-person time and remote. Our approach enables our teams to deepen connections, maintain a strong community, and do their best work. We know that flexibility can take shape in many ways, so rather than a number of required days in-office each week, we simply spend at least half (50%) of our time each quarter in the office or in the field with our customers, prospects, and partners (depending on role). This means you'll have the freedom to create a flexible schedule that caters to your business, team, and personal needs, while being intentional to make the most of time spent together. Those in our remote "home office" roles also have the opportunity to come together in our offices for important moments that matter.

Pursuant to applicable Fair Chance law, Workday will consider for employment qualified applicants with arrest and conviction records.

Workday is an Equal Opportunity Employer including individuals with disabilities and protected veterans.

Are you being referred to one of our roles? If so, ask your connection at Workday about our Employee Referral process!

Workday Glassdoor Company Review
4.2 Glassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star icon Glassdoor star icon
Workday DE&I Review
No rating Glassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star icon
CEO of Workday
Workday CEO photo
Aneel Bhusri | Carl Eschenbach
Approve of CEO

Average salary estimate

$173750 / YEARLY (est.)
min
max
$139000K
$208500K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

What You Should Know About Senior Cybersecurity GRC - US Federal, Workday

At Workday, we’re happy to announce an exciting opportunity for a Senior Cybersecurity GRC in our McLean, VA office, where you’ll be part of a vibrant team driven by a culture of innovation and collaboration. Our Cybersecurity Governance, Risk, Compliance & Trust (cGRCT) team plays a pivotal role in balancing business agility with robust security measures. You’ll be a key player in designing and implementing Workday's National Security offerings to ensure compliance with various public sector frameworks. Your expertise will include guiding both our clients in the U.S. Federal Government and internal partners on risk and compliance throughout the product development lifecycle. Here, we prioritize a work culture that values your individuality and fosters professional growth, all while maintaining a strong commitment to community and the planet. If you are passionate about cybersecurity and thrive in a collaborative environment, come join our mission to maintain a trusted relationship with our clients and drive Workday’s growth journey forward.

Frequently Asked Questions (FAQs) for Senior Cybersecurity GRC - US Federal Role at Workday
What are the key responsibilities of the Senior Cybersecurity GRC role at Workday?

The Senior Cybersecurity GRC role at Workday encompasses a wide array of responsibilities including leading the design, implementation, and assessment of Workday's US National Security offerings. This involves ensuring compliance with federal frameworks, managing audit lifecycles for various DoD and Intelligence Community programs, and advising internal partners on risk and compliance requirements throughout the product development process.

Join Rise to see the full answer
What qualifications are required for the Senior Cybersecurity GRC position at Workday?

To qualify for the Senior Cybersecurity GRC position at Workday, candidates should have a minimum of 8 years of experience in governance, risk, and compliance roles, along with at least 5 years of experience with FedRAMP and RMF assessment processes. A current TS/SCI with CI POLY security clearance is required, and a solid understanding of the FedRAMP Framework and DoD Impact Levels is vital.

Join Rise to see the full answer
What skills are essential for success in the Senior Cybersecurity GRC role at Workday?

Essential skills for success in the Senior Cybersecurity GRC role include strong communication abilities, attention to detail, and proven project management experience, particularly in audit management. Candidates will benefit from their expertise in leading multiple projects simultaneously, organizing effectively, and achieving consensus with cross-functional partners.

Join Rise to see the full answer
How does Workday support professional development for the Senior Cybersecurity GRC role?

At Workday, we champion professional growth and support our Workmates through ongoing training, mentorship opportunities, and access to resources that cultivate their expertise. In the Senior Cybersecurity GRC role, you will have opportunities to participate in training on compliance standards, attend industry conferences, and engage with a network of professionals to foster your career advancement.

Join Rise to see the full answer
What unique benefits does Workday offer for the Senior Cybersecurity GRC position?

Workday offers a unique array of benefits for Senior Cybersecurity GRC team members, including flexibility in work schedules, comprehensive health coverage, and performance bonuses. Our approach to flexible work enables you to maintain a healthy work-life balance, while our commitment to community engagement provides opportunities for fulfilling experiences outside of work.

Join Rise to see the full answer
Common Interview Questions for Senior Cybersecurity GRC - US Federal
Can you explain the importance of compliance in the Senior Cybersecurity GRC role?

Compliance is paramount in the Senior Cybersecurity GRC role as it ensures that all processes align with federal regulations and security standards. When explaining its importance, highlight how compliance fosters trust with clients and helps mitigate risks associated with cybersecurity threats.

Join Rise to see the full answer
What experience do you have with FedRAMP and RMF processes?

In your response, showcase any direct experience you have with FedRAMP and RMF assessment processes, including specific projects or achievements. Emphasize how you’ve applied this knowledge to enhance security measures or lead successful compliance projects.

Join Rise to see the full answer
How do you prioritize tasks in a multifaceted GRC environment?

Share your strategies for prioritizing tasks, such as utilizing project management tools or frameworks. Emphasize your ability to remain organized under pressure while maintaining clear communication with stakeholders about project timelines and expectations.

Join Rise to see the full answer
Describe a time when you managed an audit lifecycle effectively.

When answering, provide a detailed example of an audit you managed, highlighting your role in ensuring preparation, execution, and wrap-up stages. Focus on metrics or outcomes that demonstrate your ability to successfully navigate complex audit processes.

Join Rise to see the full answer
What methods do you use for keeping up-to-date with cybersecurity regulations?

Describe your proactive approach to staying informed about cybersecurity regulations, such as following industry news, attending relevant workshops, or participating in professional networks. Highlight your commitment to lifelong learning in this rapidly evolving field.

Join Rise to see the full answer
How would you approach leading interactions with National Security customers?

Discuss your interpersonal skills and how you would approach building strong relationships with National Security customers. Mention your focus on understanding their unique needs while providing clarity on compliance requirements.

Join Rise to see the full answer
What strategies do you use to communicate complex compliance information to non-technical stakeholders?

Illustrate your ability to simplify complex compliance information by using relatable analogies and clear language. Mention techniques you use to ensure engagement, such as visual aids or interactive discussions, to enhance understanding.

Join Rise to see the full answer
Can you detail your experience in designing security frameworks for federal systems?

Here, you can detail your hands-on experience designing security frameworks, emphasizing your familiarity with specific compliance standards and technical specifications. Include examples that demonstrate how your designs enhanced security postures.

Join Rise to see the full answer
What do you believe are the most significant risks facing cybersecurity in government contracts?

Discuss what you perceive as the top risks, such as insider threats, data breaches, or non-compliance with regulatory standards. Also, share your thoughts on how effective governance, risk management, and compliance can mitigate these risks.

Join Rise to see the full answer
Why do you want to work for Workday in this role?

Express your admiration for Workday’s culture and commitment to employee development. Mention specific aspects of the Senior Cybersecurity GRC role that excite you, such as the opportunity to work with cutting-edge technologies within the National Security sector.

Join Rise to see the full answer
Similar Jobs
Photo of the Rise User

Join Workday as a Strategic Account Executive to leverage your sales expertise in promoting the innovative Contract Intelligence platform powered by Evisort AI.

Photo of the Rise User
Workday Remote IND.Chennai
Posted 13 days ago

Join Workday as a Product Manager to shape the future of employee feedback and engagement in a hybrid working environment.

Photo of the Rise User
Posted 3 days ago

Join Rentokil Initial as an Epicor Functional Analyst where you'll optimize business processes using your Epicor expertise in a hybrid working environment.

Posted 9 days ago

John Deere seeks an experienced Microsoft Office 365 SME to provide expert guidance and manage innovative solutions for their remote teams.

Photo of the Rise User
Posted 9 days ago

Join i3 as a Mid Level Cybersecurity Engineer, where you will protect systems from cyber threats while ensuring their compliance with DoD requirements.

Photo of the Rise User

Take the lead in information security governance as a Senior Security Engineer at Stone Tech, working in a collaborative and innovative environment.

Photo of the Rise User
Posted 11 days ago
Inclusive & Diverse
Collaboration over Competition
Growth & Learning
Mission Driven
Transparent & Candid

As a Senior Site Reliability Engineer at Coinbase, you'll drive the deployment and optimization of AI solutions while maintaining security and collaboration across teams in a remote setting.

Join the University of Texas at Austin as an Enterprise Application Support Manager, where your leadership will enhance user experience with enterprise applications.

Photo of the Rise User
Posted 3 days ago

Join CeLeen as a Linux System Administrator and contribute to essential services for the Department of Energy in a fast-paced environment.

Photo of the Rise User
Rise from Within
Mission Driven
Diversity of Opinions
Work/Life Harmony
Maternity Leave
Paternity Leave
401K Matching
Paid Holidays
Paid Sick Days
Paid Time-Off
Paid Volunteer Time
Health Savings Account (HSA)
Flexible Spending Account (FSA)
Family Coverage (Insurance)
Medical Insurance
Mental Health Resources

Lead Okta's Identity & Access Management security strategy as an Enterprise Security Architect to protect and enhance enterprise security.

Workday brings finance, HR, and planning into one system, making it possible for enterprises of all sizes to shed their disparate systems and build better businesses. We serve over 7,900 of the world’s largest companies, educational institutions, ...

292 jobs
MATCH
Calculating your matching score...
FUNDING
SENIORITY LEVEL REQUIREMENT
TEAM SIZE
EMPLOYMENT TYPE
Full-time, hybrid
DATE POSTED
April 13, 2025

Subscribe to Rise newsletter

Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!