Workday

Workday

Program Manager, Cybersecurity Risk

USA.VA.Reston

Sponsorship not specifiedDetected 1 day ago
Machine LearningCybersecurityPenetration TestingComplianceProcurementHRISCommunicationCollaborationMentoringCISSP

About the role

  • You will conduct third-party risk assessments, track control gaps and remediation to closure, monitor high-risk vendors, and support broader cyber risk assessment activities.
  • You will partner with business units and stakeholders to identify and assess security issues and gaps, communicate impact, and help drive remediation actions and timelines.
  • The Cybersecurity Risk team is responsible for cybersecurity risk assessments, security exception management, TPRM, and partner eco-system security.

Responsibilities

  • Third-Party Risk Assessments: Conduct security risk assessments for third parties - including cloud service providers, SaaS platforms, technology partners, and infrastructure providers - across the third-party lifecycle (intake, due diligence, ongoing monitoring, and offboarding).
  • Issue and Remediation Management: Identify, document, track, and drive remediation of control gaps and security risks through remediation, exception, or formal risk acceptance, and escalate when risks or remediation efforts are insufficient or delayed.
  • Cross-Functional Collaboration: Partner with Legal, Procurement, Security, Privacy, and business owners to ensure third-party risks are appropriately documented, communicated, accepted, or mitigated.
  • Documentation and Reporting: Maintain accurate third-party records, assessment results, and issues within the system of record, and support preparation of metrics, dashboards, and management reporting.
  • Broader Risk Support: Support principal-level risk assessment activities as needed - including security exception reviews and internal control assessments - working under the direction of the Principal Program Manager.
  • Continuous Improvement: Contribute to the maturation of TPRM processes, procedures, and best practices, and support other risk, governance, and program activities as needed.
  • Our approach enables our teams to deepen connections, maintain a strong community, and do their best work.

Requirements

  • 5+ years of experience in governance, risk, and compliance (GRC), including third-party / vendor risk management.
  • 2+ years of experience conducting security or third-party risk assessments across the vendor lifecycle.
  • Bachelor's degree in a relevant discipline such as Information Security, Computer Science, Risk Management, Business, or a related field, or equivalent practical experience.
  • Working knowledge of security and risk frameworks such as NIST CSF, ISO 27001, SOC 2, PCI DSS, and SIG.
  • Familiarity with GRC / TPRM platforms and security-ratings services (e.g., OneTrust, Archer, ServiceNow, Vanta, BitSight, SecurityScorecard, RiskRecon).
  • Ability to review and interpret technical assurance evidence (e.g., SOC 2 Type II reports, penetration testing results) to evaluate vendor control effectiveness.
  • Understanding of qualitative risk analysis and the ability to translate risk into clear business impact.
  • Strong written and verbal communication skills, with the ability to work with both technical and non-technical stakeholders.
  • We know that flexibility can take shape in many ways, so rather than a number of required days in-office each week, we simply spend at least half (50%) of our time each quarter in the office or in the field with our customers, prospects, and partners (depending on role).

Nice to have

  • some hands-on automation experience such as scripting or low-code / no-code workflow tools used to streamline risk assessments and reporting.
  • Workday Pay Transparency Statement
  • Recruiters can share more detail during the hiring process.
  • Each candidate's compensation offer will be based on multiple factors including, but not limited to, geography, experience, skills, job duties, and business need, among other things.
  • Certifications such as CRISC, CISA, CISSP, or CISM preferred.
  • Nice to have: some hands-on automation experience such as scripting or low-code / no-code workflow tools used to streamline risk assessments and reporting.

Skills

  • Your work days are brighter here.

Compensation

  • $110,100 USD - $165,100 USD
  • $99,600 USD - $176,900 USD
  • In addition, Workday will never ask candidates to pay a recruiting fee, or pay for consulting or coaching services, in order to apply for a job at Workday.

Benefits

  • Our Approach to Flexible Work
  • This means you'll have the freedom to create a flexible schedule that caters to your business, team, and personal needs, while being intentional to make the most of time spent together.
  • Those in our remote "home office" roles also have the opportunity to come together in our offices for important moments that matter.

Equal opportunity

  • Workday is an Equal Opportunity Employer including individuals with disabilities and protected veterans.
  • If you require assistance or an accommodation at any point, please email accommodations@workday.com.

This listing is sourced directly from Workday's careers page and normalized into a canonical job model.