Hiring.Camp

Vulnerability Management Analyst (US Federal)

Workday

·

Yesterday

Location
USA.VA.Reston, United States of America
Type
Full-time
Department
Management
Source
Workday

Description

Your work days are brighter here.

We’re obsessed with making hard work pay off, for our people, our customers, and the world around us. As a Fortune 500 company and a leading AI platform for managing people, money, and agents, we’re shaping the future of work so teams can reach their potential and focus on what matters most. The minute you join, you’ll feel it. Not just in the products we build, but in how we show up for each other. Our culture is rooted in integrity, empathy, and shared enthusiasm. We’re in this together, tackling big challenges with bold ideas and genuine care. We look for curious minds and courageous collaborators who bring sun-drenched optimism and drive. Whether you're building smarter solutions, supporting customers, or creating a space where everyone belongs, you’ll do meaningful work with Workmates who’ve got your back. In return, we’ll give you the trust to take risks, the tools to grow, the skills to develop and the support of a company invested in you for the long haul. So, if you want to inspire a brighter work day for everyone, including yourself, you’ve found a match in Workday, and we hope to be a match for you too.

About the Team

The Workday Government, Governance, Risk and Compliance (GRC) team works on compliance with US Government security frameworks such as FedRAMP, IL-4/5, CMMC, and others for our civilian and defense customers. The GRC team’s mission is to enable and maintain Workday Government’s offerings through certification, continuous monitoring, consultation and deep stakeholder alignment.

About the Role

This role will support one or more direct or indirect contracts with the U.S. Federal Government which, due to federal government security requirements, mandates that all Workday personnel working on the contracts be United States citizens (naturalized or native).

This role will support one or more direct or indirect contracts with the U.S. Federal Government which, due to federal government security requirements, mandates that all Workday personnel working on the contracts be United States citizens (naturalized or native).


The role requires strong organization and interpersonal skills, and the technical ability to understand, interpret and prioritize findings from commercial scan tools. The role also requires contributing to the Planning of Actions and Milestones (POAMs) and communicating status to the leadership team


About You

Responsibilities:

  • Analyze and organize scan results and prioritize vulnerabilities for remediation based on risk requirements.
  • Engage with engineering teams to track and report status and remediation timelines.
  • Support management of Planning of Actions and Milestones (POAMs) and monthly Continuous Monitoring (ConMon)
  • Support Annual Assessments for FedRAMP, IL-4/5 and CMMC
  • Assist in documenting policies and procedures (update SSPs, etc.)
  • Work with the larger GRC team to assist with leading the design, implementation and assessment of Workday's SaaS offering
  • Write scripts in Python to automate tasks

Required Qualifications:


  • Outstanding communication and organization skills.
  • Self-driven, motivated professional with experience working with multiple stakeholders.
  • Ability to understand and interpret results from commercial scanning tools and provide related guidance for remediation.
  • Working knowledge in using scan tools such as Qualys, Tenable, Twistlock, Wiz, etc.
  • Working knowledge of FedRAMP, NIST 800-53 controls, IL4/5, and DoD SRG
  • Previous experience in managing POAMs for FedRAMP authorized environments.
  • Experience in cloud computing, with a major CSP like AWS, Google, or federal SaaS solution
  • Proficiency in using tools like Jira for managing tickets and tasks
  • Experience with documenting security and compliance policies and procedures
  • Working proficiency in Python for minor scripting and automation



Preferred Qualifications:


  • Relevant industry certifications (e.g., Security+, CEH, CISSP).
  • Previous experience with using Git, SDKs/APIs 
  • Previous experience with a 3PAO, as a Security Controls Assessor (SCA).
  • Previous experience with commercial Cloud Service Providers (CSPs).
  • Experience in system design engineering to provide technical security guidance documentation
  • Experience in implementing POAM related automation
  • Knowledge of GRC tools  (e.g., Xacta, Vanta, RegScale, ServiceNow, Archer)


Workday Pay Transparency Statement

The annualized base salary ranges for the primary location and any additional locations are listed below.  Workday pay ranges vary based on work location. As a part of the total compensation package, this role may be eligible for the Workday Bonus Plan or a role-specific commission/bonus, as well as annual refresh stock grants. Recruiters can share more detail during the hiring process. Each candidate’s compensation offer will be based on multiple factors including, but not limited to, geography, experience, skills, job duties, and business need, among other things. For more information regarding Workday’s comprehensive benefits, please click here.

Primary Location: USA.VA.Reston


 

Primary Location Base Pay Range: $0 USD - $0 USD


 

Additional US Location(s) Base Pay Range: $ USD - $ USD



Our Approach to Flexible Work
 

With Flex Work, we’re combining the best of both worlds: in-person time and remote. Our approach enables our teams to deepen connections, maintain a strong community, and do their best work. We know that flexibility can take shape in many ways, so rather than a number of required days in-office each week, we simply spend at least half (50%) of our time each quarter in the office or in the field with our customers, prospects, and partners (depending on role). This means you'll have the freedom to create a flexible schedule that caters to your business, team, and personal needs, while being intentional to make the most of time spent together. Those in our remote "home office" roles also have the opportunity to come together in our offices for important moments that matter.

Pursuant to applicable Fair Chance law, Workday will consider for employment qualified applicants with arrest and conviction records.

Workday is an Equal Opportunity Employer including individuals with disabilities and protected veterans.


Workday is committed to providing reasonable accommodations for qualified individuals during our application process, in order to perform one or more essential functions of their job, as well as regarding the use of AI tools for employment decision-making to any degree. Please see below for more details including how to request an accommodation as a qualified veteran, due to a disability or for religious reasons, or as otherwise provided under applicable law.


Workday prohibits taking adverse action against any candidate or employee for reporting a possible violation of this policy, requesting one or more work accommodations, exercising a privacy right, or cooperating in an investigation in accordance with applicable law. Any employee who retaliates against a candidate or employee for doing so may be subject to disciplinary action, up to and including termination of employment, to the fullest extent allowable under applicable law.


If you require a reasonable accommodation, you may email [email protected], as far in advance as possible.


Are you being referred to one of our roles? If so, ask your connection at Workday about our Employee Referral process!

At Workday, we value our candidates’ privacy and data security.  Workday will never ask candidates to apply to jobs through websites that are not Workday Careers. 

  

Please be aware of sites that may ask for you to input your data in connection with a job posting that appears to be from Workday but is not.

  

In addition, Workday will never ask candidates to pay a recruiting fee, or pay for consulting or coaching services, in order to apply for a job at Workday.

Skills

PythonAWSGitJiraWorkdayServiceNowComplianceCISSP

Similar Jobs

24

Vulnerability Management Analyst

Inetum·Madrid, MD·Hybrid

6d ago

Vulnerability Management Analyst

TheStaffed·Remote

1w ago

Vulnerability Management Analyst

Abacus Technology·Hanscom AFB, MA

3w ago

Vulnerability Management Analyst

Nabancard·Remote work MI, US·Remote

4w ago

Vulnerability Management Analyst

Hapag-Lloyd·Chennai, India·Hybrid

9mo ago

Vulnerability Management Analyst

Decisionpointcorp·US·Remote

1y+ ago

Senior Vulnerability Management Analyst (CrowdStrike)

METRO/MAKRO·Pune, Maharashtra

2d ago

IT Vulnerability Management Lead / Senior Security Analyst

August Schell·Bethesda, MD·Hybrid, Onsite

1w ago

Lead Information Security Analyst, Vulnerability and External Attack Surface Management (T & I) (Telework/Hybrid)

Cbcrc·Montreal - MRC, Canada +1·Remote, Hybrid, Onsite

1w ago

Information Security Analyst, Vulnerability Management

bet365·Manchester, England·Hybrid

2w ago

Information Security Analyst, Vulnerability Management

bet365·Stoke-on-Trent, England·Hybrid

2w ago

Vulnerability Management Analyst- CIO- BPL

Barclays·Canary Wharf, 1 Churchill Place

3w ago

Federal Cloud Vulnerability Management Analyst (US REMOTE)

motorolasolutions·Chicago, IL +6

4w ago

Federal Cloud Vulnerability Management Analyst (US REMOTE)

Motorola Solutions·Chicago, IL +6

4w ago

Senior Vulnerability Management Analyst

Income Insurance Limited·Singapore, SG

1mo ago

Senior Analyst, Vulnerability Management and Vulnerability Operations (VulnOps)

Edwards·India-Pune

1mo ago

Information Security Analyst (Vulnerability Management)

Jda·BYDS Dallas, US·Remote, Hybrid, Onsite

1mo ago

Senior Cybersecurity Analyst – Vulnerability Management

Digital Realty Global·LONDON, GB·Onsite

2mo ago

Threat and Vulnerability Management Analyst

Centrica·UK - Windsor - Millstream, UK +1·Hybrid

3mo ago

Vulnerability Management Analyst & Automation specialist

Euroclear·Poland, PL

5mo ago

Senior Vulnerability Management Analyst

SailPoint is·US

6mo ago

Cloud Vulnerability Management Analyst

Rockwell Automation·Mexico Mexico City +3·Hybrid

1y+ ago

Cloud Vulnerability Management Analyst

Rockwellautomation·Mexico Mexico City +3·Hybrid

1y+ ago

Security Vulnerability Management Analyst

Qmulos·Washington, DC

1y+ ago