System Owner-boundary Compliance Owner - US Federal

Workday Workday · Enterprise · McLean, VA

This role is a System Owner for Workday's US Federal Government contracts, focusing on compliance boundaries like FedRAMP and DoD ILs. The role involves cross-functional ownership of system health, security posture, risk mitigation, and compliance control assurance. It also requires future-proofing the system by assessing the impact of AI/ML capabilities and new product SKUs, ensuring safe and secure integration, and optimizing cloud costs. The position requires deep experience with US Government compliance frameworks and the ability to drive large-scale architectural and security roadmaps.

What you'd actually do

  1. Holistic Boundary Ownership: Serve as the single point of accountability for the overall health and compliance status of the assigned boundary.
  2. Risk Aggregation and Mitigation: Identify, document, and socialize systemic, long-term risks related to architecture, technical debt, and control decay within your specific boundary.
  3. System Health & Security Posture: Define and monitor long-term health metrics for the boundary, integrating data from SOC rules, Vulnerability Management, Incident Response, and Configuration Management to assess overall systemic risk.
  4. Compliance Control Assurance: Ensure all compliance controls relevant to the boundary (e.g., NIST 800-53 controls) are implemented, continuously monitored, and architecturally sustainable.
  5. AI and New SKU Readiness: Proactively assess the impact of Artificial Intelligence (AI) features, machine learning models, and new Product SKUs coming into the environment. Define the necessary architectural modifications and compliance controls to safely and securely integrate these future capabilities into the boundary.

Skills

Required

  • Experience in Security Engineering, Security Architecture, or a Compliance-focused role within a cloud or SaaS environment
  • Direct experience with U.S. Government compliance frameworks such as FedRAMP (Moderate/High), DoD IL4/IL5/IL6, NIST RMF, or ICD-503
  • Ability to own and drive large-scale, multi-year architectural and security roadmaps for a single, complex system

Nice to have

  • Experience with AI/ML capabilities and their integration into compliant systems
  • Cloud cost optimization
  • Cross-functional leadership and stakeholder management

What the JD emphasized

  • United States citizens
  • Fedramp Moderate, IL4, Top Secret
  • US Government compliance frameworks such as FedRAMP (Moderate/High), DoD IL4/IL5/IL6, NIST RMF, or ICD-503
  • multi-year architectural and security roadmaps