Workday

Vulnerability Management Analyst (US Federal)

Workday$100K — $120K *
Education, Government & Non-Profit
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Outstanding communication and organizational skills.
  • Self-driven with experience managing multiple stakeholders.
  • Ability to interpret results from commercial scanning tools for remediation guidance.
  • Familiarity with scan tools like Qualys, Tenable, and Twistlock.
  • Knowledge of FedRAMP, NIST 800-53, IL4/5, and DoD SRG requirements.
  • Experience managing POAMs in FedRAMP environments.
  • Cloud computing experience with major providers like AWS or Google.
  • Proficiency in Python for task automation.

Responsibilities

  • Analyze scan results and prioritize vulnerabilities for remediation.
  • Engage with engineering teams to track and report remediation timelines.
  • Manage Planning of Actions and Milestones (POAMs) and Continuous Monitoring (ConMon).
  • Support Annual Assessments for compliance frameworks like FedRAMP and CMMC.
  • Document and update security policies and System Security Plans (SSPs).
  • Collaborate with the GRC team on compliance design and assessments.
  • Write and improve scripts in Python for automation tasks.

Benefits

  • Flexible work schedule supporting remote and in-office balance.
  • Culture fostering connections and community engagement.
  • Opportunities for growth and collaboration with varied teams.
  • Participation in Workday’s Bonus Plan and annual stock grants.
  • Comprehensive benefits package including health and wellness programs.
Full Job Description
About the Team
The Workday Government, Governance, Risk and Compliance (GRC) team works on compliance with US Government security frameworks such as FedRAMP, IL-4/5, CMMC, and others for our civilian and defense customers. The GRC team's mission is to enable and maintain Workday Government's offerings through certification, continuous monitoring, consultation and deep stakeholder alignment.

About the Role

This role will support one or more direct or indirect contracts with the U.S. Federal Government which, due to federal government security requirements, mandates that all Workday personnel working on the contracts be United States citizens (naturalized or native).

This role will support one or more direct or indirect contracts with the U.S. Federal Government which, due to federal government security requirements, mandates that all Workday personnel working on the contracts be United States citizens (naturalized or native).

The role requires strong organization and interpersonal skills, and the technical ability to understand, interpret and prioritize findings from commercial scan tools. The role also requires contributing to the Planning of Actions and Milestones (POAMs) and communicating status to the leadership team

About You

Responsibilities:
  • Analyze and organize scan results and prioritize vulnerabilities for remediation based on risk requirements.
  • Engage with engineering teams to track and report status and remediation timelines.
  • Support management of Planning of Actions and Milestones (POAMs) and monthly Continuous Monitoring (ConMon)
  • Support Annual Assessments for FedRAMP, IL-4/5 and CMMC
  • Assist in documenting policies and procedures (update SSPs, etc.)
  • Work with the larger GRC team to assist with leading the design, implementation and assessment of Workday's SaaS offering
  • Write scripts in Python to automate tasks


Required Qualifications:

  • Outstanding communication and organization skills.
  • Self-driven, motivated professional with experience working with multiple stakeholders.
  • Ability to understand and interpret results from commercial scanning tools and provide related guidance for remediation.
  • Working knowledge in using scan tools such as Qualys, Tenable, Twistlock, Wiz, etc.
  • Working knowledge of FedRAMP, NIST 800-53 controls, IL4/5, and DoD SRG
  • Previous experience in managing POAMs for FedRAMP authorized environments.
  • Experience in cloud computing, with a major CSP like AWS, Google, or federal SaaS solution
  • Proficiency in using tools like Jira for managing tickets and tasks
  • Experience with documenting security and compliance policies and procedures
  • Working proficiency in Python for minor scripting and automation


PreferredQualifications:

  • Relevant industry certifications (e.g., Security+, CEH, CISSP).
  • Previous experience with using Git, SDKs/APIs
  • Previous experience with a 3PAO, as a Security Controls Assessor (SCA).
  • Previous experience with commercial Cloud Service Providers (CSPs).
  • Experience in system design engineering to provide technical security guidance documentation
  • Experience in implementing POAM related automation
  • Knowledge of GRC tools (e.g., Xacta, Vanta, RegScale, ServiceNow, Archer)


Workday Pay Transparency Statement

The annualized base salary ranges for the primary location and any additional locations are listed below. Workday pay ranges vary based on work location. As a part of the total compensation package, this role may be eligible for the Workday Bonus Plan or a role-specific commission/bonus, as well as annual refresh stock grants. Recruiters can share more detail during the hiring process. Each candidate's compensation offer will be based on multiple factors including, but not limited to, geography, experience, skills, job duties, and business need, among other things. For more information regarding Workday's comprehensive benefits, please click here.

Primary Location: USA.VA.Reston

Primary Location Base Pay Range: $0 USD - $0 USD

Additional US Location(s) Base Pay Range: $ USD - $ USD

Our Approach to Flexible Work

With Flex Work, we're combining the best of both worlds: in-person time and remote. Our approach enables our teams to deepen connections, maintain a strong community, and do their best work. We know that flexibility can take shape in many ways, so rather than a number of required days in-office each week, we simply spend at least half (50%) of our time each quarter in the office or in the field with our customers, prospects, and partners (depending on role). This means you'll have the freedom to create a flexible schedule that caters to your business, team, and personal needs, while being intentional to make the most of time spent together. Those in our remote "home office" roles also have the opportunity to come together in our offices for important moments that matter.

Are you being referred to one of our roles? If so, ask your connection at Workday about our Employee Referral process!

About Workday

Workday, Inc. is a provider of enterprise cloud applications for finance and human resources. The Company delivers financial management, human capital management and analytics applications designed for various companies, educational institutions and government agencies. As part of its applications, the Company provides embedded analytics that capture the content and context of everyday business events, facilitating informed decision-making from wherever users are working. Its applications include Workday Financial Management, Workday Human Capital Management (HCM) and Other Applications. It also provides open, standards-based Web-services application programming interfaces, and pre-built packaged integrations and connectors. Workday, Inc. is headquartered in Pleasanton, California.
Learn more about Workday
Size
15,932 employees
Market Cap
$42.2 billion
Industry
Net Income
-$282.4 million
Founded
2005
5 Year Trend
+26.7%
Revenue
$4.3 billion
NASDAQ

Similar Jobs

More Jobs at Workday

More Education, Government & Non-Profit Jobs

Find similar Vulnerability Management Analyst (US Federal) jobs: