- Location
- CSCS TX, United States of America
- Type
- Full-time
- Department
- IT
- Education
- Master
- Visa
- Not sponsored
- Source
- Workday
Description
Service Center
CSCS TXPOSITION SUMMARY:
The Workday Security Analyst is a specialized technical role within the Workday Center of Excellence (COE), responsible for the day-to-day configuration, administration, and ongoing governance of Workday security. This individual is a hands-on practitioner of the Workday security model — administering role-based access control (RBAC), domain and business process security policies, security group configurations, and user provisioning across the enterprise Workday environment.
The Security Analyst collaborates with the Internal Security. Audit, Risk, and Legal teams to ensure the Workday platform operates in full compliance with enterprise security standards, regulatory requirements, and audit expectations. This role requires deep Workday security expertise combined with the ability to engage directly with business teams — translating complex access and governance requirements into precise, well-documented Workday security configurations that protect sensitive HR and Finance data without impeding business operations.
ESSENTIAL DUTIES:
Security Configuration & Role Administration
Configure and maintain Workday security groups across all types — intersection, role-based, user-based, and segment-based — ensuring access is aligned to the principle of least privilege and supports clean separation of duties (SoD), in accordance with standards.
Maintain domain security policy configurations, business process security policies, and configurable security for all Workday functional areas including HCM, Payroll, Finance, and Reporting.
Administer segment-based security to appropriately restrict access to sensitive worker, compensation, and financial data across organizational structures.
Collaborate with functional COE teams (HCM, Finance, Integrations, Reporting) to evaluate security implications of new configurations, business process changes, and integration deployments before promotion to production, escalating findings as needed.
User Provisioning & Access Administration
Administer Workday user provisioning — including new hire access setup, role assignments, role transfers, and termination access removal — in coordination with HR operations and Technology identity management teams.
Support the Workday Integration System User (ISU) and Integration System Security Group (ISSG) framework, ensuring integration service accounts follow least-privilege standards and are properly documented and reviewed.
Support the ongoing maintenance of Workday’s Identity and Access Management configurations, including SSO, multi-factor authentication enforcement, and session management settings.
Participate in regular user access reviews and entitlement certification exercises in coordination with Internal Audit and Risk teams — identifying over-provisioned access, SoD violations, and orphaned accounts requiring remediation and escalating findings for disposition.
Process and fulfill security access requests submitted through the Technology service management system, applying appropriate validation and approval workflow standards before granting access.
Audit, Risk & Compliance Support
Perform Workday security risk assessments for proposed configuration changes, new feature adoptions, and third-party integration onboarding — identifying security gaps and recommending mitigating controls before implementation.
Maintain audit-ready documentation of the Workday security model — including security group matrices, domain policy configurations, SoD conflict matrices, and access change logs — ensuring evidence is organized, version-controlled, and available on demand.
Monitor Workday security audit logs and configurable security activity reports to detect anomalous access patterns, unauthorized activity, or configuration drift — escalating findings as appropriate.
Support the COE in responding to Internal Audit, Risk, and Legal inquiries related to Workday security — providing accurate documentation, evidence packages, and configuration details as directed.
Assist in preparing evidence and documentation required for SOX ITGC, GDPR, CCPA, HIPAA, or other applicable compliance audits.
Security Maintenance, Testing & Release Readiness
Perform impact assessments for Workday bi-annual feature releases, evaluating security-related changes, new domain security policies, and modified business process security configurations — and coordinating testing to validate no unintended access is introduced.
Execute security regression testing for all COE platform changes, validating that configuration deployments do not introduce unintended access grants, privilege escalations, or security policy breaks.
Maintain Workday security configurations across all tenant environments (sandbox, implementation, production), ensuring environment-specific security policies reflect appropriate access controls and data masking standards.
Troubleshoot end-user access issues reported through the help desk or COE support channels — diagnosing root causes within the Workday security model and implementing precise, minimal-footprint corrections.
Support COE change management processes by reviewing non-security configuration changes for security impact prior to production promotion.
Business Partnership & Security Enablement
Develop effective working relationships with business stakeholders across HR, Finance, Payroll, and Procurement — translating access requirements into compliant, well-documented Workday security configurations that enable productivity without compromising data integrity.
Support alignment of Workday security configurations with enterprise security policies, threat models, and identity governance frameworks.
Maintain security-related end-user guidance, including access request procedures, role description documentation, and security awareness materials tailored to Workday users.
Stay current on Workday security release notes, Community advisories, and best practices.
SKILLS & COMPETENCIES:
Technical Skills
Workday Security Model: Strong working knowledge of Workday role-based access control, domain security policies, business process security policies, segment-based security, and configurable security across HCM, Finance, Payroll, and Reporting functional areas.
Identity & Access Management: Hands-on experience with Workday SSO (SAML 2.0, OKTA), OAuth 2.0, ISU/ISSG administration, and integration with enterprise IAM platforms.
Separation of Duties: Working knowledge of SoD conflict frameworks, access certification processes, and entitlement review methodologies in a Workday context.
Audit & Compliance: Practical experience supporting SOX ITGC, GDPR, CCPA, or HIPAA compliance obligations in a Workday or enterprise SaaS platform environment.
Workday Reporting: Ability to build and maintain Workday security audit reports, configurable security reports, and access review dashboards to support ongoing governance monitoring.
Documentation: Demonstrated ability to produce and maintain clear, structured security documentation — role catalogs, SoD matrices, policy configurations, and audit evidence packages.
Business & Interpersonal Competencies
Ability to translate complex Workday security concepts into clear, accessible language for business stakeholders, auditors, and non-technical partners.
High attention to detail with a methodical, risk-aware mindset — understands that security misconfigurations can have significant regulatory and operational consequences.
Collaborative team player with experience working with all stakeholders.
Proactive self-starter who stays current on Workday platform changes and security developments.
EDUCATION, EXPERIENCE, AND OTHER REQUIREMENTS:
3–5+ years of hands-on experience administering and configuring Workday security, including working knowledge of domain security policies, business process security policies, security group design, and user provisioning in a large, complex Workday tenant.
Demonstrated experience supporting SOX, GDPR, CCPA, HIPAA, or equivalent regulatory compliance requirements as they apply to Workday platform access controls and data governance.
Experience in the preparation of security evidence, access review coordination, and audit finding remediation.
Familiarity with Workday IAM capabilities including SSO, OAuth 2.0, MFA enforcement, and Integration System User (ISU) management.
Experience working in a Workday COE or enterprise SaaS security administration role, with exposure to multi-tenant environment management (sandbox, implementation, production).
Bachelor’s degree in Information Security, Computer Science, Information Systems, or a related field.
CERTIFICATIONS, LICENSURES, AND LANGUAGE SKILLS (If needed):
Workday Pro Certification in Security (strongly preferred)
Workday Pro Certification in HCM or Financial Management (a plus)
CISSP, CISM, CRISC, or equivalent information security certification (a plus)
PHYSICAL REQUIREMENTS:
Position requires little to moderate physical activity. Handling of average weight objects up to 15 pounds; occasional standing or walking; frequently at a keyboard, workstation, or desk.
WORK ENVIRONMENT:
Work is typically in a normal office administrative environment involving minimal exposure to physical risks. Hybrid / remote-eligible schedule available.
Caliber uses E-Verify to confirm the identity and employment eligibility of all new hires.
Must be eligible to work in the U.S. with no restrictions.