System Owner-boundary Compliance Owner - US Federal

Workday Workday · Enterprise · USA.VA.Reston

This role is a System Owner for compliance boundaries within Workday's US Federal Government contracts. The primary focus is on managing the lifecycle, security, and compliance of information systems, including assessing the impact of future AI/ML capabilities. The role requires deep experience with US Government compliance frameworks and cross-functional coordination.

What you'd actually do

  1. Holistic Boundary Ownership: Serve as the single point of accountability for the overall health and compliance status of the assigned boundary.
  2. Risk Aggregation and Mitigation: Identify, document, and socialize systemic, long-term risks related to architecture, technical debt, and control decay within your specific boundary.
  3. System Health & Security Posture: Define and monitor long-term health metrics for the boundary, integrating data from SOC rules, Vulnerability Management, Incident Response, and Configuration Management to assess overall systemic risk.
  4. Compliance Control Assurance: Ensure all compliance controls relevant to the boundary (e.g., NIST 800-53 controls) are implemented, continuously monitored, and architecturally sustainable.
  5. AI and New SKU Readiness: Proactively assess the impact of Artificial Intelligence (AI) features, machine learning models, and new Product SKUs coming into the environment. Define the necessary architectural modifications and compliance controls to safely and securely integrate these future capabilities into the boundary.

Skills

Required

  • Security Engineering
  • Security Architecture
  • Compliance-focused role
  • cloud or SaaS environment
  • U.S. Government compliance frameworks
  • FedRAMP
  • DoD IL4/IL5/IL6
  • NIST RMF
  • ICD-503
  • own and drive large-scale, multi-year architectural and security roadmaps

Nice to have

  • System Owner
  • cross-functional ownership
  • stewardship
  • compliance boundaries
  • Security Operations
  • GRC
  • Engineering
  • Product
  • Finance
  • risk posture
  • architectural runway
  • technical debt
  • control decay
  • Vulnerability Management
  • Incident Response
  • Configuration Management
  • NIST 800-53 controls
  • System Security Plan (SSP)
  • POA&Ms
  • Control Implementation Details
  • new Product SKUs
  • vulnerability surface area
  • cloud infrastructure costs
  • core Workday engineering and product teams
  • restricted government environment

What the JD emphasized

  • U.S. Federal Government
  • United States citizens
  • Fedramp Moderate, IL4, Top Secret
  • AI/ML capabilities
  • FedRAMP (Moderate/High), DoD IL4/IL5/IL6, NIST RMF, or ICD-503
  • architectural and security roadmaps