×
Register Here to Apply for Jobs or Post Jobs. X

Sr. Principal, GRC

Job in Boulder, Boulder County, Colorado, 80301, USA
Listing for: HR Tech Job
Full Time position
Listed on 2026-07-07
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security, Data Security, IT Consultant
Salary/Wage Range or Industry Benchmark: 196498 - 287400 USD Yearly USD 196498.00 287400.00 YEAR
Job Description & How to Apply Below

Your work days are brighter here.

We’re obsessed with making hard work pay off, for our people, our customers, and the world around us. As a Fortune 500 company and a leading AI platform for managing people, money, and agents, we’re shaping the future of work so teams can reach their potential and focus on what matters most. The minute you join, you’ll feel it. Not just in the products we build, but in how we show up for each other.

Our culture is rooted in integrity, empathy, and shared enthusiasm. We’re in this together, tackling big challenges with bold ideas and genuine care. We look for curious minds and courageous collaborators who bring sun‑drenched optimism and drive. Whether you're building smarter solutions, supporting customers, or creating a space where everyone belongs, you’ll do meaningful work with Workmates who’ve got your back.

In return, we’ll give you the trust to take risks, the tools to grow, the skills to develop and the support of a company invested in you for the long haul. So, if you want to inspire a brighter work day for everyone, including yourself, you’ve found a match in Workday, and we hope to be a match for you too.

About

the Team About the Role

Contribute to Workday’s cybersecurity compliance posture by leading and executing critical Cybersecurity Governance, Risk, and Compliance (cGRC) initiatives. Develop and maintain cybersecurity compliance frameworks, policies, and procedures to ensure adherence to global regulatory compliance requirements, particularly Network and Information Security Directive (NIS2), Digital Operational Resilience Act (DORA), Security of Critical Infrastructure Act (SOCI), Cybersecurity Resilience Act (CRA). Enable and maintain Workday’s Public Sector offerings through certifications, continuous monitoring, consultation and deep stakeholder alignment.

Act as a trusted advisor across Workday to help maintain and enhance customer’s trust through various global compliance programs including UK Public Sector Procurement Frameworks (G-Cloud and Back Office Software frameworks) and cybersecurity certification schemes like BSI C5 (Germany), IRAP (Australia), ENS (Spain). Conduct strategic analysis of Workday's control and technical landscape to identify automation opportunities for the GRC team, evaluate the potential of AI-driven efficiencies, and assess the ROI of GRC automation tools like One Trust and Trust Cloud.

As part of the Shift‑Left initiative, leverage a deep understanding of Workday's SDLC, Launch Pad and Secure Development Engagement Lifecycle processes to integrate cybersecurity control requirements, ensuring streamlined audit readiness and driving process optimization. Position reports to the Workday's Boulder, CO office. May allow partial telecommuting.

Salary Range: $196,498 - $287,400

About You Basic Qualifications
  • Bachelor's degree in Computer Engineering, Computer Science, Management Information Systems or related field plus seven (7) years, progressive, post‑baccalaureate work experience in the job offered or in a Sr. Principal, GRC-related occupation.
  • 7 years (84 months) of experience in EMEA cybersecurity standards and procurement frameworks including G-Cloud, Cyber Essentials Plus, Back Office Software, BSI C5, ENS, TISAX, EU Cloud Code of Conduct, and GDPR.
  • 7 years (84 months) of experience in international industry security and privacy compliance standards including ISO 27001, ISO 27017, ISO 27018, ISO 27701, SOC1 and SOC2+.
  • 7 years (84 months) of experience in facilitating and managing security and compliance audits (including customer onsite audits).
  • 7 years (84 months) of experience in industry‑specific regulatory compliance knowledge such as NIS2, DORA, and CRA.
  • 7 years (84 months) of experience in program/project management experience.
  • 7 years (84 months) of experience in cloud computing and Software as a Service, particularly risk models and controls related to these services.
  • 7 years (84 months) of experience in legal/operational commitments of SaaS organizations and the shared security responsibilities between customers and service providers; and
  • 7 years (84 months) of experience with capability to map nuances of…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary