About the RoleThis role will support one or more direct or indirect contracts with the U.S. Federal Government which, due to federal government security requirements, mandates that all Workday personnel working on the contracts be United States citizens (naturalized or native). The SOC Lead will provide technical and operational leadership for the Cyber Defense Security Operations Center supporting U.S. Government SaaS deployments, including air-gapped environments. This role is responsible for overseeing 24x7 monitoring operations, incident response coordination, escalation management, and continuous improvement of SOC processes and capabilities.
You will lead a team of SOC Analysts, ensure high-quality investigations, oversee detection engineering collaboration, and drive automation initiatives leveraging platforms such as Splunk and SOAR technologies (e.g., Tines). You will also interface with Red, Blue, Purple Teams and Threat Intelligence to maintain an integrated cyber defense posture.
This position requires a balance of operational leadership, deep technical expertise, and the ability to communicate risk effectively to leadership.
About YouThis role may require a security clearance at the TS/SCI level. Applicants must have the ability to obtain and maintain a U.S. government issued security clearance.Basic Qualifications
- 10+ years of experience in cybersecurity operations, incident response, or threat detection
- 5+ years of experience leading or mentoring security operations personnel
- Deep experience operating and tuning SIEM platforms such as Splunk
- Experience managing incident response lifecycle activities aligned to NIST SP 800-61r3
- Experience supporting secure cloud environments and/or air-gapped networks
- Bachelor's degree in Cybersecurity, Computer Science, Engineering, or equivalent experience
Other Qualifications
- Strong understanding of adversary TTPs and MITRE ATT&CK framework
- Experience with SOAR platforms (e.g., Tines) and security automation
- Proven ability to manage escalations and high-severity incidents
- Experience developing KPIs, SLAs, and operational metrics
- Strong critical thinking and decision-making skills under pressure
- Ability to coordinate cross-functional teams (Red, Blue, Engineering, Compliance)
- Excellent written and verbal communication skills
- Experience building and improving SOC playbooks and runbooks
- Certifications meeting DoD 8570 requirements
Workday Pay Transparency StatementThe annualized base salary ranges for the primary location and any additional locations are listed below. Workday pay ranges vary based on work location. As a part of the total compensation package, this role may be eligible for the Workday Bonus Plan or a role-specific commission/bonus, as well as annual refresh stock grants. Recruiters can share more detail during the hiring process. Each candidate's compensation offer will be based on multiple factors including, but not limited to, geography, experience, skills, job duties, and business need, among other things. For more information regarding Workday's comprehensive benefits, please click here.
Primary Location: USA.VA.Reston
Primary Location Base Pay Range: $184,800 USD - $277,200 USD
Additional US Location(s) Base Pay Range: $167,200 USD - $300,000 USD
Our Approach to Flexible WorkWith Flex Work, we're combining the best of both worlds: in-person time and remote. Our approach enables our teams to deepen connections, maintain a strong community, and do their best work. We know that flexibility can take shape in many ways, so rather than a number of required days in-office each week, we simply
spend at least half (50%) of our time each quarter in the office or in the field with our customers, prospects, and partners (depending on role). This means you'll have the freedom to create a flexible schedule that caters to your business, team, and personal needs, while being intentional to make the most of time spent together. Those in our remote "home office" roles also have the opportunity to come together in our offices for important moments that matter.