Workday

Program Manager, Cybersecurity Risk

Workday$110K — $165K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 5+ years of experience in governance, risk, and compliance (GRC), focusing on third-party/vendor risk management.
  • 2+ years of experience conducting security assessments across the vendor lifecycle.
  • Bachelor’s degree in Information Security, Computer Science, Risk Management, or a related field, or equivalent experience.
  • Solid understanding of third-party risk management processes, including due diligence and ongoing monitoring.
  • Working knowledge of security frameworks like NIST CSF, ISO 27001, and SOC 2.
  • Familiarity with GRC/TPRM platforms and security-rating services like OneTrust and ServiceNow.
  • Strong communication skills to engage technical and non-technical stakeholders.

Responsibilities

  • Conduct third-party risk assessments for various vendor types throughout their lifecycle.
  • Identify, track, and drive remediation of security risks and control gaps.
  • Monitor high-risk vendors for compliance and risk indicators.
  • Collaborate with legal, procurement, and other stakeholders to manage risks effectively.
  • Maintain records of assessments and produce metrics and reports.
  • Support broader risk assessment initiatives as guided by senior management.
  • Contribute to the improvement of TPRM processes and best practices.

Benefits

  • Flexible work arrangements allowing a mix of in-office and remote work.
  • Opportunity for career development and involvement in process maturation.
  • Potential participation in the Workday Bonus Plan and stock grants.
  • Access to comprehensive benefits package, including health and wellness programs.
  • Support for flexible schedules to cater to personal and business needs.
Full Job Description

About the Team

The Cybersecurity Risk team is responsible for cybersecurity risk assessments, security exception management, TPRM, and partner eco-system security.

About the Role

As a Program Manager on the Cybersecurity Risk team, you will be a hands-on execution partner within our third-party risk management (TPRM) program, working closely with the Principal Program Manager to assess and manage security risk across our vendor and partner ecosystem. You will conduct third-party risk assessments, track control gaps and remediation to closure, monitor high-risk vendors, and support broader cyber risk assessment activities. You will partner with business units and stakeholders to identify and assess security issues and gaps, communicate impact, and help drive remediation actions and timelines.

Responsibilities:-

  • Third-Party Risk Assessments: Conduct security risk assessments for third parties — including cloud service providers, SaaS platforms, technology partners, and infrastructure providers — across the third-party lifecycle (intake, due diligence, ongoing monitoring, and offboarding).

  • Issue and Remediation Management: Identify, document, track, and drive remediation of control gaps and security risks through remediation, exception, or formal risk acceptance, and escalate when risks or remediation efforts are insufficient or delayed.

  • Ongoing Monitoring: Monitor critical and high-risk vendors for control changes, risk signals, remediation progress, and ongoing compliance concerns.

  • Cross-Functional Collaboration: Partner with Legal, Procurement, Security, Privacy, and business owners to ensure third-party risks are appropriately documented, communicated, accepted, or mitigated.

  • Documentation and Reporting: Maintain accurate third-party records, assessment results, and issues within the system of record, and support preparation of metrics, dashboards, and management reporting.

  • Broader Risk Support: Support principal-level risk assessment activities as needed — including security exception reviews and internal control assessments — working under the direction of the Principal Program Manager.

  • Continuous Improvement: Contribute to the maturation of TPRM processes, procedures, and best practices, and support other risk, governance, and program activities as needed.

About You

Basic Qualifications

  • 5+ years of experience in governance, risk, and compliance (GRC), including third-party / vendor risk management.

  • 2+ years of experience conducting security or third-party risk assessments across the vendor lifecycle.

  • Bachelor’s degree in a relevant discipline such as Information Security, Computer Science, Risk Management, Business, or a related field, or equivalent practical experience.

Other Qualifications

  • Solid understanding of third-party / vendor risk management across the lifecycle — intake, due diligence, ongoing monitoring, issue remediation, and off-boarding.

  • Working knowledge of security and risk frameworks such as NIST CSF, ISO 27001, SOC 2, PCI DSS, and SIG.

  • Familiarity with GRC / TPRM platforms and security-ratings services (e.g., OneTrust, Archer, ServiceNow, Vanta, BitSight, SecurityScorecard, RiskRecon).

  • Ability to review and interpret technical assurance evidence (e.g., SOC 2 Type II reports, penetration testing results) to evaluate vendor control effectiveness.

  • Understanding of qualitative risk analysis and the ability to translate risk into clear business impact.

  • Awareness of AI/ML vendor risk and how AI-enabled services are assessed, monitored, and governed.

  • Strong written and verbal communication skills, with the ability to work with both technical and non-technical stakeholders.

  • Strong attention to detail and the ability to manage multiple assessments and competing priorities in a fast-paced environment.

  • Certifications such as CRISC, CISA, CISSP, or CISM preferred.

  • Nice to have: some hands-on automation experience such as scripting or low-code / no-code workflow tools used to streamline risk assessments and reporting.


Workday Pay Transparency Statement

The annualized base salary ranges for the primary location and any additional locations are listed below.  Workday pay ranges vary based on work location. As a part of the total compensation package, this role may be eligible for the Workday Bonus Plan or a role-specific commission/bonus, as well as annual refresh stock grants. Recruiters can share more detail during the hiring process. Each candidate’s compensation offer will be based on multiple factors including, but not limited to, geography, experience, skills, job duties, and business need, among other things. For more information regarding Workday’s comprehensive benefits, please .

Primary Location: USA.VA.RestonPrimary Location Base Pay Range: $110,100 USD - $165,100 USD


 

Additional US Location(s) Base Pay Range: $99,600 USD - $176,900 USD



Our Approach to Flexible Work
 

With Flex Work, we’re combining the best of both worlds: in-person time and remote. Our approach enables our teams to deepen connections, maintain a strong community, and do their best work. We know that flexibility can take shape in many ways, so rather than a number of required days in-office each week, we simply spend at least half (50%) of our time each quarter in the office or in the field with our customers, prospects, and partners (depending on role). This means you'll have the freedom to create a flexible schedule that caters to your business, team, and personal needs, while being intentional to make the most of time spent together. Those in our remote "home office" roles also have the opportunity to come together in our offices for important moments that matter.

About Workday

Workday, Inc. is a provider of enterprise cloud applications for finance and human resources. The Company delivers financial management, human capital management and analytics applications designed for various companies, educational institutions and government agencies. As part of its applications, the Company provides embedded analytics that capture the content and context of everyday business events, facilitating informed decision-making from wherever users are working. Its applications include Workday Financial Management, Workday Human Capital Management (HCM) and Other Applications. It also provides open, standards-based Web-services application programming interfaces, and pre-built packaged integrations and connectors. Workday, Inc. is headquartered in Pleasanton, California.
Learn more about Workday
Size
15,932 employees
Market Cap
$42.2 billion
Industry
Net Income
-$282.4 million
Founded
2005
5 Year Trend
+26.7%
Revenue
$4.3 billion
NASDAQ

Similar Jobs

More Jobs at Workday

More Information Technology Jobs

Find similar Program Manager, Cybersecurity Risk jobs: