Program Manager, Cybersecurity Compliance
Workday unites HR and finance on one AI-first platform to help elevate humans and supercharge work to keep business moving forever forward.
At Workday, it all began with a conversation over breakfast. When our founders met at a sunny California diner, they came up with an idea to revolutionize the enterprise software market. One thing that really set us apart was our culture, driven by our value of putting our people first. The happiness, development, and contribution of every Workmate is central to who we are. Our Workmates believe a healthy employee-centric, collaborative culture is essential for success in business. That’s why we look after our people, communities, and the planet while still being profitable. Feel encouraged to shine, however that manifests: you don’t need to hide who you are.
About the Team
Cybersecurity Governance, Risk, Compliance, and Trust (cGRCT) is dedicated to maintaining, enhancing, and protecting trust in Workday. Every cGRCT workmate contributes by building and managing programs designed to protect the confidentiality, integrity, and availability (CIA) of our customers’ most sensitive data. The cGRCT team serves as a trusted advisor across Workday to help maintain and enhance trust for our customers and prospects.
Within cGRCT, the Cybersecurity Compliance team focuses on leading Workday’s various compliance programs, control frameworks, third-party audits, and overall certification strategy. As a member of the Cybersecurity Compliance team, you'll play a key role in supporting our business partners and engaging directly with customers and prospects on cybersecurity matters.
About the Role
The Program Manager, Cybersecurity Compliance is an important part of Workday’s compliance function and will be responsible for working with Workday customers and prospects that are conducting audits and assessments of Workday controls and processes. This individual will specifically help facilitate audits and assessments of Workday’s internal controls, policies, and procedures that govern Workday’s security posture. This includes, but is not limited to, the intake, preparation, assignment, review, and completion of privacy and information security questionnaires as well as full audit engagements for Workday’s global customers and prospects. This role will also interface with Workday's independent third-party auditors, partner implementers, and vendors in association with contractual and regulatory projects.
About You
Basic Qualifications
* 5+ years of experience in an equivalent technology compliance related role
* Exceptional communication and presentation skills with an ability to articulate complex security concepts clearly and concisely to both technical and non-technical audiences
* Extensive experience facilitating and managing security and compliance audits; industry-specific regulatory compliance knowledge, a plus
* Demonstrated program/project management experience; ability to juggle multiple projects and organize time effectively
Other Qualifications
* Familiarity with Cloud Computing and Software as a Service, particularly risk models and controls related to these services; familiarity with industry compliance standards such as SOC1 (SSAE18), SOC2, ISO27001
* Strong executive presence with the capability to speak articulately to technical and operational processes
* Successful record of implementing and improving operational processes; can drive program efficiency and high customer satisfaction
* Keen attention to detail and accuracy
* Strong communications skills, both written and oral
* Proven ability to think critically while maintaining operational efficiency
* Organized, responsive, and able to gain support and consensus with cross-functional stakeholders
* CISA or other relevant certifications a strong plus
* University level degree
Our Approach to Flexible Work
With Flex Work, we’re combining the best of both worlds: in-person time and remote. Our approach enables our teams to deepen connections, maintain a strong community, and do their best work. We know that flexibility can take shape in many ways, so rather than a number of required days in-office each week, we simply spend at least half (50%) of our time each quarter in the office or in the field with our customers, prospects, and partners (depending on role). This means you'll have the freedom to create a flexible schedule that caters to your business, team, and personal needs, while being intentional to make the most of time spent together.
#J-18808-Ljbffr