This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
As the system owner for our federal information system, you will be responsible for the lifecycle of our information systems. This is a high-impact role that will provide cross-functional ownership, stewardship, and focus for our compliance boundaries (e.g., Fedramp Moderate, IL4, Top Secret). While individual teams will focus on their respective functions (Security Operations, GRC, Engineering) this role will span all teams and boundaries and act as a focal point for the Federal business.
Job Responsibility
Boundary Health, Risk & Cross-Functional Stewardship: Serve as the single point of accountability for the overall health and compliance status of the assigned boundary
Risk Aggregation and Mitigation: Identify, document, and socialize systemic, long-term risks related to architecture, technical debt, and control decay within your specific boundary
System Health & Security Posture: Define and monitor long-term health metrics for the boundary, integrating data from SOC rules, Vulnerability Management, Incident Response, and Configuration Management to assess overall systemic risk
Compliance Control Assurance: Ensure all compliance controls relevant to the boundary (e.g., NIST 800-53 controls) are implemented, continuously monitored, and architecturally sustainable
Compliance Artifact Tracking: Track, prioritize and raise exceptions for the creation, maintenance, and audit readiness of all necessary compliance artifacts for the assigned boundary (e.g., System Security Plan (SSP), POA&Ms, Control Implementation Details)
Future-Proofing & Strategic Planning: Proactively assess the impact of Artificial Intelligence (AI) features, machine learning models, and new Product SKUs coming into the environment
Own the strategic direction for reducing the long-term vulnerability surface area within the boundary
Collaborate with the Engineering team to analyze and optimize cloud infrastructure costs within the boundary
Interface with core Workday engineering and product teams as well as Security teams to ensure base product capabilities are designed to be compliant and deployable within your restricted government environment
Requirements
7+ years of experience in Security Engineering, Security Architecture, or a Compliance-focused role within a cloud or SaaS environment
5+ years of direct experience with U.S. Government compliance frameworks such as FedRAMP (Moderate/High), DoD IL4/IL5/IL6, NIST RMF, or ICD-503
Proven ability to own and drive large-scale, multi-year architectural and security roadmaps for a single, complex system
Deep understanding of cloud architecture AWS, Azure, GCP and how security controls are implemented at scale
Excellent communication skills with the ability to articulate complex, multi-faceted technical risk across all domains (architecture, operations, cost) to executive leadership