Program Development and Implementation (Strategy & Framework) – GRC Risk Management

Posted 4 hours ago
$130.7K - $232.2K / year

Are you applying to the internship?

Job Description

IT Risk Manager, BT Risk Management | Workday

The Tone:
This is a full-time role at Workday, located in Pleasanton, CA for the primary location, with options for other US locations. Workday builds a leading AI platform for managing people, money, and agents, focused on shaping the future of work. This role is crucial for developing and implementing a new, formal BT Risk Management Program, ensuring Workday’s Business Technology maintains secure and reliable systems, and driving proactive risk management across the organization.

The TL;DR
• Role: Full Time
• Location: Hybrid – Pleasanton, CA
• Pay: $130,700–$232,200 yearly
• Team: BT Risk Management, within the BT Strategy & Operations team
• Mission: To design, formalize, and implement a comprehensive BT Risk Management Program, ensuring secure and reliable systems through risk assessment, mitigation, and compliance efforts.

What You’ll Actually Do
• Program Development: Assist with the design and formalization of a new, comprehensive BT Risk Management Program, clarifying roles, responsibilities, and a standardized framework.
• Compliance Enhancement: Review and enhance the BT compliance strategy, including controls and procedures, aligning with industry trends and upcoming regulatory activity.
• Risk Assessment & Mitigation: Lead projects to establish and perform a risk assessment process for BT technology and manage remediation actions for identified issues.
• Strategic Partnerships: Cultivate and maintain strong, effective partnerships with BT leaders and cross-functional partners to foster a collaborative and supportive environment.
• Continuous Improvement: Define, implement, and track outcome-driven metrics to measure the effectiveness of risk management and refine programs using data-driven insights.

The Must-Haves
• Background: Bachelor’s degree in Business Administration, Law, Finance, Information Security, or a related discipline, or equivalent practical experience. Career level implies Senior-level expertise in GRC, internal audits, regulatory compliance, and risk assessment methodologies.
• Experience: 8+ years experience in GRC, developing and implementing GRC policies and procedures; 8+ years experience conducting internal audits and managing regulatory compliance; 8+ years experience in risk assessment methodologies, control frameworks, and regulatory requirements.
• Skills: Strong knowledge of internal controls, audit procedures, and compliance regulations. Successful record of implementing and improving operational processes pertaining to risk management, regulatory compliance, incident response planning, and security technologies.
• Bonus: Experience designing federal SaaS cloud computing systems; experience with Intelligence, DOD, and other federal programs; familiarity with privacy principles and regulations including GDPR, HIPAA; experience with industry compliance standards such as ISO 27001, SOC1, SOC2; CISA, PMP, CIPP, or other related certifications.

Related Jobs

Zions Bancorporation
Posted 4 hours ago In-person - Midvale, Utah, United States Information Technology