Sr. Principal, GRC

HR Tech Job

Boulder (CO)

Hybrid

USD 196,498 - 287,400

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

HR Tech Job is looking for a cybersecurity expert to lead compliance initiatives within their Boulder, Colorado office. The role emphasizes strong leadership in developing cybersecurity frameworks and enhancing compliance with international standards.

The ideal candidate will possess a Bachelor's degree in Computer Engineering, complemented by extensive experience in cybersecurity governance and risk management. The position offers a salary range between $196,498 - $287,400 and benefits under the Workday Bonus Plan.

Qualifications

  • Bachelor's degree plus seven years of progressive experience in cybersecurity roles.
  • Experience in international compliance standards and facilitating audits.
  • Strong knowledge of legal commitments of SaaS organizations.

Responsibilities

  • Lead cybersecurity governance, risk, and compliance initiatives.
  • Develop and maintain cybersecurity compliance frameworks and procedures.
  • Conduct strategic analysis of controls and technical landscape for automation opportunities.

Skills

Cybersecurity compliance
Regulatory frameworks
Program/project management
Cloud computing
Security standards
Audit facilitation

Education

Bachelor's degree in Computer Engineering, Computer Science, or related field

Job description

Your work days are brighter here.

We’re obsessed with making hard work pay off, for our people, our customers, and the world around us. As a Fortune 500 company and a leading AI platform for managing people, money, and agents, we’re shaping the future of work so teams can reach their potential and focus on what matters most. The minute you join, you’ll feel it. Not just in the products we build, but in how we show up for each other. Our culture is rooted in integrity, empathy, and shared enthusiasm. We’re in this together, tackling big challenges with bold ideas and genuine care. We look for curious minds and courageous collaborators who bring sun‑drenched optimism and drive. Whether you're building smarter solutions, supporting customers, or creating a space where everyone belongs, you’ll do meaningful work with Workmates who’ve got your back. In return, we’ll give you the trust to take risks, the tools to grow, the skills to develop and the support of a company invested in you for the long haul. So, if you want to inspire a brighter work day for everyone, including yourself, you’ve found a match in Workday, and we hope to be a match for you too.

About the Team
About the Role

Contribute to Workday’s cybersecurity compliance posture by leading and executing critical Cybersecurity Governance, Risk, and Compliance (cGRC) initiatives. Develop and maintain cybersecurity compliance frameworks, policies, and procedures to ensure adherence to global regulatory compliance requirements, particularly Network and Information Security Directive (NIS2), Digital Operational Resilience Act (DORA), Security of Critical Infrastructure Act (SOCI), Cybersecurity Resilience Act (CRA). Enable and maintain Workday’s Public Sector offerings through certifications, continuous monitoring, consultation and deep stakeholder alignment. Act as a trusted advisor across Workday to help maintain and enhance customer’s trust through various global compliance programs including UK Public Sector Procurement Frameworks (G-Cloud and Back Office Software frameworks) and cybersecurity certification schemes like BSI C5 (Germany), IRAP (Australia), ENS (Spain). Conduct strategic analysis of Workday's control and technical landscape to identify automation opportunities for the GRC team, evaluate the potential of AI-driven efficiencies, and assess the ROI of GRC automation tools like OneTrust and TrustCloud. As part of the Shift‑Left initiative, leverage a deep understanding of Workday's SDLC, LaunchPad and Secure Development Engagement Lifecycle processes to integrate cybersecurity control requirements, ensuring streamlined audit readiness and driving process optimization. Position reports to the Workday's Boulder, CO office. May allow partial telecommuting.

Salary Range: $196,498 - $287,400

About You
Basic Qualifications
  • Bachelor's degree in Computer Engineering, Computer Science, Management Information Systems or related field plus seven (7) years, progressive, post‑baccalaureate work experience in the job offered or in a Sr. Principal, GRC-related occupation.
  • 7 years (84 months) of experience in EMEA cybersecurity standards and procurement frameworks including G-Cloud, Cyber Essentials Plus, Back Office Software, BSI C5, ENS, TISAX, EU Cloud Code of Conduct, and GDPR.
  • 7 years (84 months) of experience in international industry security and privacy compliance standards including ISO 27001, ISO 27017, ISO 27018, ISO 27701, SOC1 and SOC2+.
  • 7 years (84 months) of experience in facilitating and managing security and compliance audits (including customer onsite audits).
  • 7 years (84 months) of experience in industry‑specific regulatory compliance knowledge such as NIS2, DORA, and CRA.
  • 7 years (84 months) of experience in program/project management experience.
  • 7 years (84 months) of experience in cloud computing and Software as a Service, particularly risk models and controls related to these services.
  • 7 years (84 months) of experience in legal/operational commitments of SaaS organizations and the shared security responsibilities between customers and service providers; and
  • 7 years (84 months) of experience with capability to map nuances of individual product lines within a large organization and determine applicability to security certification and attesting frameworks.
Workday Pay Transparency Statement

Workday pay ranges vary based on work location. As a part of the total compensation package, this role may be eligible for the Workday Bonus Plan or a role‑specific commission/bonus, as well as annual refresh stock grants. Recruiters can share more detail during the hiring process. Each candidate’s compensation offer will be based on multiple factors including, but not limited to, geography, experience, skills, job duties, and business need, among other things. For more information regarding Workday’s comprehensive benefits, please click here.

Primary Location

USA.CO.Boulder

Our Approach to Flexible Work

Workday uses a hybrid Flex Work Model. Most roles require at least 50% in‑person time each quarter in a Workday office or with customers, prospects, or partners, with specific expectations varying by role, team, country, and business needs.

Pursuant to applicable Fair Chance law, Workday will consider for employment qualified applicants with arrest and conviction records.

Workday is an Equal Opportunity Employer including individuals with disabilities and protected veterans.

Workday is committed to providing reasonable accommodations for qualified individuals during our application process, in order to perform one or more essential functions of their job, as well as regarding the use of AI tools for employment decision‑making to any degree. Please see below for more details including how to request an accommodation as a qualified veteran, due to a disability or for religious reasons, or as otherwise provided under applicable law.

Workday prohibits taking adverse action against any candidate or employee for reporting a possible violation of this policy, requesting one or more work accommodations, exercising a privacy right, or cooperating in an investigation in accordance with applicable law. Any employee who retaliates against a candidate or employee for doing so may be subject to disciplinary action, up to and including termination of employment, to the fullest extent allowable under applicable law.

If you require a reasonable accommodation, you should open a People Guide Request (current employees only), or you may email accommodations@workday.com, as far in advance as possible.

Additional Information

Are you being referred to one of our roles? If so, ask your connection at Workday about our Employee Referral process! At Workday, we value our candidates’ privacy and data security. Workday will never ask candidates to apply to jobs through websites that are not Workday Careers. Please be aware of sites that may ask for you to input your data in connection with a job posting that appears to be from Workday but is not. In addition, Workday will never ask candidates to pay a recruiting fee, or pay for consulting or coaching services, in order to apply for a job at Workday.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Principal Cybersecurity Engineer
Principal Cybersecurity Engineer

Workday • Reston (VA)

On-site
USD 184,800 - 300,000
Cybersecurity Engineer - US Federal
Cybersecurity Engineer - US Federal

Socket.dev • Reston (VA)

Hybrid
USD 130,000 - 195,000
Principal Cybersecurity Engineer
Principal Cybersecurity Engineer

Workday • Boulder (CO)

Hybrid
USD 176,000 - 264,000
Principal Cybersecurity Engineer - US Federal
Principal Cybersecurity Engineer - US Federal

Workday • Reston (VA)

On-site
USD 185,000 - 277,000
Principal Cybersecurity Engineer
Principal Cybersecurity Engineer

HR Tech Job • Reston (VA)

Hybrid
USD 184,000 - 278,000
Hybrid/flex schedule
Senior Program Manager, Security (Product Dev)
Senior Program Manager, Security (Product Dev)

Workday • Boulder (CO)

Hybrid
USD 150,000 - 225,000
Annual stock grants
Bonus plan
Flexible work
Cybersecurity Engineer - US Federal
Cybersecurity Engineer - US Federal

Workday • Reston (VA)

On-site
USD 130,000 - 195,000
Sr Software Development Engineer
Sr Software Development Engineer

Workday • Beaverton (OR)

Hybrid
USD 177,000 - 234,000
Senior Cybersecurity Engineer - Network Security (US Federal)
Senior Cybersecurity Engineer - Network Security (US Federal)

Workday • Reston (VA)

Hybrid
USD 159,000 - 240,000
Cybersecurity Engineer
Cybersecurity Engineer

Workday • Boulder (CO)

Hybrid
USD 124,000 - 186,000
Flexible work arrangements