The IT Application Security Analyst is responsible for contributing to the design, implementation, administration, and governance of security access across enterprise applications. This role partners with IT and business stakeholders to develop scalable role-based security solutions that enable business operations while maintaining compliance with security, audit and regulatory requirements.
The role collaborates closely with functional and technical teams to design, implement, and maintain secure access models, support organizational changes, and promote security best practices across the application portfolio.
ESSENTIAL DUTIES AND RESPONSIBILITIES:
- Contribute to design, implementation, and maintain role-based security models and access controls across enterprise applications.
- Collaborate with IT business partners to analyze security requirements and implement secure access solutions.
- Develop, modify, and maintain security roles, profiles, permission structures, and authorization frameworks aligned with business processes and compliance requirements.
- Evaluate security requests and recommend solutions that balance operational efficiency, security, audit and regulatory requirements.
- Identify and mitigate Segregation of Duties (SoD) conflicts and excessive access risks.
- Analyze application security reports and audit findings to identify improvement opportunities.
- Troubleshoot and resolve user access issues, security-related incidents, and authorization challenges.
- Support periodic audits by gathering evidence, validating access controls, and coordinating remediation activities.
- Serve as a primary resource for security administration and configuration.
- Assess the security impacts of organizational changes, enhancements, and new functionality.
- Support projects, testing initiatives, and production deployments by providing security guidance and configuration expertise.
SUPERVISORY RESPONSIBILITIES:
This role has no direct people leadership responsibilities.
KEY SUCCESS INDICATORS/ATTRIBUTES:
- Demonstrate intermediate to advanced level knowledge of Workday Technology.
- Strong analytical, critical thinking, and problem-solving skills.
- Demonstrate excellent interpersonal, technical, organizational skills and be detail oriented.
- Ability to prioritize and multi-task in a fast paced, changing environment.
- Demonstrate peer mentoring, and interpersonal skills.
- Demonstrate ability to work independently with general supervision.
- Ability to self-motivate, set goals, and meet deadlines.
- Ability to identify deficiencies and take corrective action.
- Ability to maintain professionalism when interacting with internal and external customers. Proficient personal computer skills with MS Office (Word, Excel, Power Point, Outlook).
- Commitment and adherence to the Firm’s Core Values.
EDUCATION AND/OR EXPERIENCE:
- Bachelor’s degree in information technology, Information Systems, Cybersecurity, Business Technology, or equivalent experience.
- 3-7 years of experience supporting application security, access management, or enterprise business applications.
- Experience designing and administering role-based security models and access controls.
- Experience partnering with technical teams and business stakeholders to implement security solutions.
- Strong understanding of security governance, audit controls, access management, and compliance requirements.
- Experience administering Workday security including Security Groups, Domain Security Policies, and Business Process Security Policies.
- Experience supporting ERP, HCM, Financial, Payroll, Recruiting, or other enterprise business applications.
- Experience with identity and access management technologies, single sign-on solutions, and security governance processes.
- Experience supporting audits, access certifications, and Segregation of Duties programs.
CERTIFICATES AND/OR LICENSES:
- Workday Pro Security Certification (strongly preferred)