Workday company logo

System Owner-Boundary Compliance Owner - US Federal at Workday

WorkdayVerified

Get jobs like this by email

First name, email, subscribe.

Job Details

Status
Active
Posted
May 26, 2026
Expires
Aug 24, 2026
Work style
Remote

Share with someone qualified

About the Role

Your work days are brighter here.

We’re obsessed with making hard work pay off, for our people, our customers, and the world around us. As a Fortune 500 company and a leading AI platform for managing people, money, and agents, we’re shaping the future of work so teams can reach their potential and focus on what matters most. The minute you join, you’ll feel it. Not just in the products we build, but in how we show up for each other. Our culture is rooted in integrity, empathy, and shared enthusiasm. We’re in this together, tackling big challenges with bold ideas and genuine care. We look for curious minds and courageous collaborators who bring sun-drenched optimism and drive. Whether you're building smarter solutions, supporting customers, or creating a space where everyone belongs, you’ll do meaningful work with Workmates who’ve got your back. In return, we’ll give you the trust to take risks, the tools to grow, the skills to develop and the support of a company invested in you for the long haul. So, if you want to inspire a brighter work day for everyone, including yourself, you’ve found a match in Workday, and we hope to be a match for you too.

About the Team

The Workday Cybersecurity Governance, Risk, Compliance & Trust (cGRCT) team enables business agility while maintaining a strong security posture via intelligent The Workday’s National Security Group (NSG) is responsible for all aspects of cybersecurity and compliance for Workday’s US Department of Defense and Intelligence Community customer regions. The NSG Governance, Risk, Compliance (GRC) Team enables business agility while maintaining a strong security posture via intelligent risk-taking, optimized controls management, and iterative security governance. The NSG GRC team’s mission is to enable and maintain Workday’s National Security offerings through certification, continuous monitoring, consultation and deep stakeholder alignment. We act as a trusted advisor across Workday to help maintain and enhance our customer's trust.

About the Role

This role will support one or more direct or indirect contracts with the U.S. Federal Government which, due to federal government security requirements, mandates that all Workday personnel working on the contracts be United States citizens (naturalized or native).

As the system owner for our federal information system, you will be responsible for the lifecycle of our information systems. This is a high-impact role that will provide cross-functional ownership, stewardship, and focus for our compliance boundaries (e.g., Fedramp Moderate, IL4, Top Secret). While individual teams will focus on their respective functions (Security Operations, GRC, Engineering) this role will span all teams and boundaries and act as a focal point for the Federal business.


The boundary's scope is wide-ranging, covering security, system health, compliance risks, cost/unit economics, incident/on-call trends, and future roadmaps (e.g., AI/ML capabilities or SKUs). To effectively address these complex issues, the System Owner must engage and coordinate the appropriate cross-functional experts from Security, Engineering, Product, Finance, and GRC. You will own the long-term trajectory, risk posture, and architectural runway of your assigned boundary, ensuring it is secure, efficient, and ready for future demands.

Key Responsibilities
1. Boundary Health, Risk & Cross-Functional Stewardship

  • Holistic Boundary Ownership: Serve as the single point of accountability for the overall health and compliance status of the assigned boundary.
  • Risk Aggregation and Mitigation: Identify, document, and socialize systemic, long-term risks related to architecture, technical debt, and control decay within your specific boundary.
  • System Health & Security Posture: Define and monitor long-term health metrics for the boundary, integrating data from SOC rules, Vulnerability Management, Incident Response, and Configuration Management to assess overall systemic risk.
  • Compliance Control Assurance: Ensure all compliance controls relevant to the boundary (e.g., NIST 800-53 controls) are implemented, continuously monitored, and architecturally sustainable.
  • Compliance Artifact Tracking: Track, prioritize and raise exceptions for the creation, maintenance, and audit readiness of all necessary compliance artifacts for the assigned boundary (e.g., System Security Plan (SSP), POA&Ms, Control Implementation Details).

2. Future-Proofing & Strategic Planning

  • AI and New SKU Readiness: Proactively assess the impact of Artificial Intelligence (AI) features, machine learning models, and new Product SKUs coming into the environment. Define the necessary architectural modifications and compliance controls to safely and securely integrate these future capabilities into the boundary.
  • Vulnerability Trajectory Ownership: Own the strategic direction for reducing the long-term vulnerability surface area within the boundary, guiding functional teams on architectural dependencies and risk prioritization unique to your system.
  • Cloud Cost Efficiency: Collaborate with the Engineering team to analyze and optimize cloud infrastructure costs within the boundary, ensuring security requirements are met in the most fiscally responsible manner.
  • Core Workday Product and Technology: Interface with core Workday engineering and product teams as well as Security teams to ensure base product capabilities are designed to be compliant and deployable within your restricted government environment.

About You

Basic Qualifications

  • 7+ years of experience in Security Engineering, Security Architecture, or a Compliance-focused role within a cloud or SaaS environment.
  • 5+ years of direct experience with U.S. Government compliance frameworks such as FedRAMP (Moderate/High), DoD IL4/IL5/IL6, NIST RMF, or ICD-503.
  • Proven ability to own and drive large-scale, multi-year architectural and security roadmaps for a single, complex system.
  • Deep understanding of cloud architecture AWS, Azure, GCP and how security controls are implemented at scale.
  • Experience integrating future technologies (e.g., AI/ML systems) into regulated, high-security environments.
  • Excellent communication skills with the ability to articulate complex, multi-faceted technical risk across all domains (architecture, operations, cost) to executive leadership.


Workday Pay Transparency Statement

The annualized base salary ranges for the primary location and any additional locations are listed below. Workday pay ranges vary based on work location. As a part of the total compensation package, this role may be eligible for the Workday Bonus Plan or a role-specific commission/bonus, as well as annual refresh stock grants. Recruiters can share more detail during the hiring process. Each candidate’s compensation offer will be based on multiple factors including, but not limited to, geography, experience, skills, job duties, and business need, among other things. For more information regarding Workday’s comprehensive benefits, please click here.

Primary Location: USA.VA.RestonPrimary Location Base Pay Range: $144,500 USD - $216,700 USDAdditional US Location(s) Base Pay Range: $130,700 USD - $232,200 USD



Our Approach to Flexible Work

With Flex Work, we’re combining the best of both worlds: in-person time and remote. Our approach enables our teams to deepen connections, maintain a strong community, and do their best work. We know that flexibility can take shape in many ways, so rather than a number of required days in-office each week, we simply spend at least half (50%) of our time each quarter in the office or in the field with our customers, prospects, and partners (depending on role). This means you'll have the freedom to create a flexible schedule that caters to your business, team, and personal needs, while being intentional to make the most of time spent together. Those in our remote "home office" roles also have the opportunity to come together in our offices for important moments that matter.

Pursuant to applicable Fair Chance law, Workday will consider for employment qualified applicants with arrest and conviction records.

Workday is an Equal Opportunity Employer including individuals with disabilities and protected veterans.


At Workday, we are committed to providing an accessible and inclusive hiring experience where all candidates can fully demonstrate their skills. If you require assistance or an accommodation at any point, please email
accommodations@workday.com.

Are you being referred to one of our roles? If so, ask your connection at Workday about our Employee Referral process!

At Workday, we value our candidates’ privacy and data security. Workday will never ask candidates to apply to jobs through websites that are not Workday Careers.

Please be aware of sites that may ask for you to input your data in connection with a job posting that appears to be from Workday but is not.

In addition, Workday will never ask candidates to pay a recruiting fee, or pay for consulting or coaching services, in order to apply for a job at Workday.

CV Match Tool

Check if your CV matches this job before applying

This job accepts direct applications - no recruiter in between. Posted 4w ago.

Apply on Company Site

More Jobs in USA.VA.Reston

Remote Jobs in USA.VA.Reston

Remote roles tied to the same location.

Articles You May Like

  • Best Cybersecurity Certifications in 2026 You Should Have to Land a Job

    AI and Automation Jun 9, 2026

    Cybersecurity certifications are more popular than ever, but many professionals are chasing the wrong credentials for their career goals. In 2026, the smartest move isn't collecting certificates; it's choosing the one that aligns with the job you actually want. From Security+ and CISSP to CCSP, CISM, OSCP, and GIAC, here's what matters most before you invest your time and money.

  • How to Become an AI Engineer in 2026

    Career Advice Jun 7, 2026

    AI engineering in 2026 is no longer just about learning Python or training machine learning models. Companies want people who can build real AI systems, integrate them into products, evaluate their performance, and ensure reliability. Here’s why most beginners are preparing the wrong way, and what to focus on instead.

  • ChatGPT Skills for Jobs in 2026

    AI and Automation Jun 6, 2026

    As ChatGPT becomes a must-have workplace tool in 2026, many job seekers are focusing on the wrong skills. In this article, I explain why employers care less about memorized prompts and more about AI workflow thinking, the ability to use ChatGPT to research, analyze, verify, organize, and produce real business outcomes.

  • Why AI Skills Are Becoming the New Career Filter

    AI and Automation Jun 4, 2026

    AI is no longer just a bonus skill. In 2026, employers are looking for workers who can use AI to improve real work, not just generate quick answers. This article explains why prompt writing is only the beginning — and why skills like workflow design, AI evaluation, data judgment, risk awareness, and domain expertise are becoming essential for career growth.

  • Countries Best for Remote Workers in 2026

    Career Advice May 7, 2026

    With 56 countries now competing for remote workers, the decision isn't about finding the "best" destination, it's about understanding where your income level, tax situation, and work style actually align.

Related Jobs

More jobs in Cyber Security that are worth reviewing next.

Recently Posted Jobs

Fresh openings users can continue browsing from here.