Program Manager, Cybersecurity Risk
Listed on 2026-07-23
-
IT/Tech
Cybersecurity, Information Security & Data Protection
Your work days are brighter here.
We’re obsessed with making hard work pay off, for our people, our customers, and the world around us. As a Fortune 500 company and a leading AI platform for managing people, money, and agents, we’re shaping the future of work so teams can reach their potential and focus on what matters most. The minute you join, you’ll feel it. Not just in the products we build, but in how we show up for each other.
Our culture is rooted in integrity, empathy, and shared enthusiasm. We’re in this together, tackling big challenges with bold ideas and genuine care. We look for curious minds and courageous collaborators who bring sun-drenched optimism and drive. Whether you're building smarter solutions, supporting customers, or creating a space where everyone belongs, you’ll do meaningful work with Workmates who’ve got your back.
In return, we’ll give you the trust to take risks, the tools to grow, the skills to develop and the support of a company invested in you for the long haul. So, if you want to inspire a brighter work day for everyone, including yourself, you’ve found a match in Workday, and we hope to be a match for you too.
the Team
The Cybersecurity Risk team is responsible for cybersecurity risk assessments, security exception management, TPRM, and partner eco-system security.
About the RoleAs a Program Manager on the Cybersecurity Risk team, you will be a hands‑on execution partner within our third‑party risk management (TPRM) program, working closely with the Principal Program Manager to assess and manage security risk across our vendor and partner ecosystem. You will conduct third‑party risk assessments, track control gaps and remediation to closure, monitor high‑risk vendors, and support broader cyber risk assessment activities.
You will partner with business units and stakeholders to identify and assess security issues and gaps, communicate impact, and help drive remediation actions and timelines.
- Third‑Party Risk Assessments:
Conduct security risk assessments for third parties — including cloud service providers, SaaS platforms, technology partners, and infrastructure providers — across the third‑party lifecycle (intake, due diligence, ongoing monitoring, and off‑boarding). - Issue and Remediation Management:
Identify, document, track, and drive remediation of control gaps and security risks through remediation, exception, or formal risk acceptance, and elevate when risks or remediation efforts are insufficient or delayed. - Ongoing Monitoring:
Monitor critical and high‑risk vendors for control changes, risk signals, remediation progress, and ongoing compliance concerns. - Cross‑Functional
Collaboration:
Partner with Legal, Procurement, Security, Privacy, and business owners to ensure third‑party risks are appropriately documented, communicated, accepted, or mitigated. - Documentation and Reporting:
Maintain accurate third‑party records, assessment results, and issues within the system of record, and support preparation of metrics, dashboards and management reporting. - Broader Risk Support:
Support principal‑level risk assessment activities as needed — including security exception reviews and internal control assessments — working under the direction of the Principal Program Manager. - Continuous Improvement:
Contribute to the maturation of TPRM processes, procedures, and best practices, and support other risk, governance, and program activities as needed.
- 5+ years of experience in governance, risk, and compliance (GRC), including third‑party / vendor risk management.
- 2+ years of experience conducting security or third‑party risk assessments across the vendor lifecycle.
- Bachelor’s degree in a relevant discipline such as Information Security, Computer Science, Risk Management, Business, or a related field, or equivalent practical experience.
- Solid understanding of third‑party / vendor risk management across the lifecycle — intake, due diligence, ongoing monitoring, issue remediation, and off‑boarding.
- Working knowledge of security and risk frameworks such as NIST CSF, ISO 27001, SOC 2, PCI DSS, and SIG.
- Familiarity with GRC /…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).