You will conduct third-party risk assessments, track control gaps and remediation to closure ... Working knowledge of security and risk frameworks such as NIST CSF, ISO 27001, SOC 2, PCI DSS, and ...
You will conduct third-party risk assessments, track control gaps and remediation to closure ... Working knowledge of security and risk frameworks such as NIST CSF, ISO 27001, SOC 2, PCI DSS, and ...
You will conduct third-party risk assessments, track control gaps and remediation to closure ... Working knowledge of security and risk frameworks such as NIST CSF, ISO 27001, SOC 2, PCI DSS, and ...
You will conduct third-party risk assessments, track control gaps and remediation to closure ... Working knowledge of security and risk frameworks such as NIST CSF, ISO 27001, SOC 2, PCI DSS, and ...
... PCI-DSS). Security Measures: Install, configure, and maintain security software and tools, such as firewalls, data encryption programs, and antivirus systems. Risk Assessment: Perform risk analyses ...
... PCI-DSS). Security Measures: Install, configure, and maintain security software and tools, such as firewalls, data encryption programs, and antivirus systems. Risk Assessment: Perform risk analyses ...
... PCI-DSS). • Security Measures: Install, configure, and maintain security software and tools, such as firewalls, data encryption programs, and antivirus systems. • Risk Assessment: Perform risk ...
... PCI-DSS). • Security Measures: Install, configure, and maintain security software and tools, such as firewalls, data encryption programs, and antivirus systems. • Risk Assessment: Perform risk ...
... PCI DSS, HIPAA, FedRAMP). Remediation and Collaboration: Collaborate with system owners, IT teams ... A minimum of 3-5 years of experience in cybersecurity, risk management, or security assessment ...
... PCI DSS, HIPAA, FedRAMP). Remediation and Collaboration: Collaborate with system owners, IT teams ... A minimum of 3-5 years of experience in cybersecurity, risk management, or security assessment ...
Security Assessor
Mclean, VA · On-site
... PCI DSS, HIPAA, FedRAMP). • Remediation and Collaboration: Collaborate with system owners, IT ... A minimum of 3-5 years of experience in cybersecurity, risk management, or security assessment ...
Security Assessor
Mclean, VA · On-site
... PCI DSS, HIPAA, FedRAMP). • Remediation and Collaboration: Collaborate with system owners, IT ... A minimum of 3-5 years of experience in cybersecurity, risk management, or security assessment ...
Senior IT Security Engineer
$92K - $126K/yr
... assessors during compliance audits and certification cycles, and direct remediation of audit ... risk management, governance, and compliance program across PCI DSS, SOC2, and ISO 27001. • A ...
New
Senior IT Security Engineer
$92K - $126K/yr
... assessors during compliance audits and certification cycles, and direct remediation of audit ... risk management, governance, and compliance program across PCI DSS, SOC2, and ISO 27001. • A ...
New
Senior Consultant - IT Governance, Risk & Compliance (GRC)
Ashburn, VA · On-site
$90K - $139K/yr
Perform regulatory and compliance gap assessments across frameworks such as HIPAA, PCI-DSS, SOX, ... Facilitate risk identification and prioritization workshops with client stakeholders across ...
Quick apply
Senior Consultant - IT Governance, Risk & Compliance (GRC)
Ashburn, VA · On-site
$90K - $139K/yr
Perform regulatory and compliance gap assessments across frameworks such as HIPAA, PCI-DSS, SOX, ... Facilitate risk identification and prioritization workshops with client stakeholders across ...
Senior Consultant - IT Governance, Risk & Compliance (GRC)
Ashburn, VA · On-site
$90K - $139K/yr
Perform regulatory and compliance gap assessments across frameworks such as HIPAA, PCI-DSS, SOX, ... Facilitate risk identification and prioritization workshops with client stakeholders across ...
Senior Consultant - IT Governance, Risk & Compliance (GRC)
Ashburn, VA · On-site
$90K - $139K/yr
Perform regulatory and compliance gap assessments across frameworks such as HIPAA, PCI-DSS, SOX, ... Facilitate risk identification and prioritization workshops with client stakeholders across ...
CYBER SECURITY
Virginia Beach, VA · On-site
... Security (PCI DSS), Threat Monitoring, Threat Detection, Incident Response, Vulnerability Assessment, Risk Analysis, SIEM Tools, Network Security, Web Application Security, Endpoint Security ...
CYBER SECURITY
Virginia Beach, VA · On-site
... Security (PCI DSS), Threat Monitoring, Threat Detection, Incident Response, Vulnerability Assessment, Risk Analysis, SIEM Tools, Network Security, Web Application Security, Endpoint Security ...
CYBER SECURITY
Virginia Beach, VA · On-site
... Security (PCI DSS), Threat Monitoring, Threat Detection, Incident Response, Vulnerability Assessment, Risk Analysis, SIEM Tools, Network Security, Web Application Security, Endpoint Security ...
CYBER SECURITY
Virginia Beach, VA · On-site
... Security (PCI DSS), Threat Monitoring, Threat Detection, Incident Response, Vulnerability Assessment, Risk Analysis, SIEM Tools, Network Security, Web Application Security, Endpoint Security ...
The ideal candidate will have a strong understanding of regulatory frameworks such as PCI-DSS ... Able to manage risk assessments and security briefings to advise them of critical issues that may ...
The ideal candidate will have a strong understanding of regulatory frameworks such as PCI-DSS ... Able to manage risk assessments and security briefings to advise them of critical issues that may ...
Cybersecurity and Risk Analyst
Arlington, VA · On-site
$110K - $183K/yr
Vulnerability Assessment & Risk Evaluation * Conduct vulnerability assessments across systems ... PCI-DSS). * Contribute to incident response readiness, business continuity, and disaster recovery ...
Cybersecurity and Risk Analyst
Arlington, VA · On-site
$110K - $183K/yr
Vulnerability Assessment & Risk Evaluation * Conduct vulnerability assessments across systems ... PCI-DSS). * Contribute to incident response readiness, business continuity, and disaster recovery ...
Cybersecurity and Risk Analyst
Arlington, VA · On-site
$110K - $183K/yr
Vulnerability Assessment & Risk Evaluation * Conduct vulnerability assessments across systems ... PCI-DSS). * Contribute to incident response readiness, business continuity, and disaster recovery ...
Cybersecurity and Risk Analyst
Arlington, VA · On-site
$110K - $183K/yr
Vulnerability Assessment & Risk Evaluation * Conduct vulnerability assessments across systems ... PCI-DSS). * Contribute to incident response readiness, business continuity, and disaster recovery ...
Cybersecurity and Risk Analyst
Arlington, VA · On-site
$110K - $183K/yr
Vulnerability Assessment & Risk Evaluation * Conduct vulnerability assessments across systems ... PCI-DSS). * Contribute to incident response readiness, business continuity, and disaster recovery ...
Cybersecurity and Risk Analyst
Arlington, VA · On-site
$110K - $183K/yr
Vulnerability Assessment & Risk Evaluation * Conduct vulnerability assessments across systems ... PCI-DSS). * Contribute to incident response readiness, business continuity, and disaster recovery ...
Evaluate adherence to standards such as GDPR, HIPAA, PCI DSS, and SOX through detailed compliance assessments. * Risk Assessment and Mitigation: Conduct risk assessments to identify and prioritize ...
Evaluate adherence to standards such as GDPR, HIPAA, PCI DSS, and SOX through detailed compliance assessments. * Risk Assessment and Mitigation: Conduct risk assessments to identify and prioritize ...
Collaborate with internal teams (engineering, product, compliance, risk, and operations) and ... Ensure all payment solutions adhere to PCI-DSS compliance standards, regulatory requirements, and ...
Collaborate with internal teams (engineering, product, compliance, risk, and operations) and ... Ensure all payment solutions adhere to PCI-DSS compliance standards, regulatory requirements, and ...
Cybersecurity and Risk Analyst
Arlington, VA · On-site
$120K - $135K/yr
The analyst conducts vulnerability assessments, risk evaluations, and red team/threat simulation ... PCI-DSS). * Contribute to incident response readiness, business continuity, and disaster recovery ...
Quick apply
Cybersecurity and Risk Analyst
Arlington, VA · On-site
$120K - $135K/yr
The analyst conducts vulnerability assessments, risk evaluations, and red team/threat simulation ... PCI-DSS). * Contribute to incident response readiness, business continuity, and disaster recovery ...
The analyst conducts vulnerability assessments, risk evaluations, and red team/threat simulation ... PCI-DSS). * Contribute to incident response readiness, business continuity, and disaster recovery ...
The analyst conducts vulnerability assessments, risk evaluations, and red team/threat simulation ... PCI-DSS). * Contribute to incident response readiness, business continuity, and disaster recovery ...
Cybersecurity and Risk Analyst
Arlington, VA · On-site
$120K - $135K/yr
The analyst conducts vulnerability assessments, risk evaluations, and red team/threat simulation ... PCI-DSS). * Contribute to incident response readiness, business continuity, and disaster recovery ...
Cybersecurity and Risk Analyst
Arlington, VA · On-site
$120K - $135K/yr
The analyst conducts vulnerability assessments, risk evaluations, and red team/threat simulation ... PCI-DSS). * Contribute to incident response readiness, business continuity, and disaster recovery ...
Pci Dss Risk Assessment information
What is a PCI DSS risk assessment?
What are the key skills and qualifications needed to thrive as a PCI DSS Risk Assessor, and why are they important?
Is PCI compliance legitimate?
Who can perform a PCI DSS assessment?
What does a PCI compliance specialist do?
What is the difference between Pci Dss Risk Assessment vs Pci Dss Compliance Analyst?
| Aspect | Pci Dss Risk Assessment | Pci Dss Compliance Analyst |
|---|---|---|
| Primary Focus | Identifying and evaluating security risks related to PCI DSS requirements | Ensuring ongoing compliance with PCI DSS standards and policies |
| Responsibilities | Risk identification, vulnerability assessment, mitigation planning | Policy implementation, audit preparation, compliance documentation |
| Required Skills | Risk management, security assessment, knowledge of PCI DSS | Compliance auditing, documentation, regulatory knowledge |
| Work Environment | Security teams, risk management departments | Compliance teams, audit departments |
While both roles involve PCI DSS standards, the Pci Dss Risk Assessment focuses on identifying and evaluating security risks, whereas the Pci Dss Compliance Analyst concentrates on maintaining compliance and preparing for audits. Understanding these differences helps organizations assign the right responsibilities to ensure security and compliance.
Does PCI DSS require risk assessments?
What are some common challenges faced during PCI DSS risk assessments, and how can they be addressed?
- No Experience Information Security Analyst
- Temporary Ciso
- Contract Model Risk Governance
- Internship Insider Threat Investigator
- Internship Visa Sponsorship Available Cyber Security
- From Home Nist Cybersecurity Framework
- Manager Servicenow Grc
- Internship Nist Cybersecurity Framework
- Information Security Governance
- Risk Management Framework

Full-time
This job post has expired today. Applications are no longer accepted.
Workday rating
7.6
Based on 12 frontline employees who took The Breakroom Quiz
156th of 246 rated software companies
Job description
We're obsessed with making hard work pay off, for our people, our customers, and the world around us. As a Fortune 500 company and a leading AI platform for managing people, money, and agents, we're shaping the future of work so teams can reach their potential and focus on what matters most. The minute you join, you'll feel it. Not just in the products we build, but in how we show up for each other. Our culture is rooted in integrity, empathy, and shared enthusiasm. We're in this together, tackling big challenges with bold ideas and genuine care. We look for curious minds and courageous collaborators who bring sun-drenched optimism and drive. Whether you're building smarter solutions, supporting customers, or creating a space where everyone belongs, you'll do meaningful work with Workmates who've got your back. In return, we'll give you the trust to take risks, the tools to grow, the skills to develop and the support of a company invested in you for the long haul. So, if you want to inspire a brighter work day for everyone, including yourself, you've found a match in Workday, and we hope to be a match for you too.
About the Team
The Cybersecurity Risk team is responsible for cybersecurity risk assessments, security exception management, TPRM, and partner eco-system security.
About the Role
As a Program Manager on the Cybersecurity Risk team, you will be a hands-on execution partner within our third-party risk management (TPRM) program, working closely with the Principal Program Manager to assess and manage security risk across our vendor and partner ecosystem. You will conduct third-party risk assessments, track control gaps and remediation to closure, monitor high-risk vendors, and support broader cyber risk assessment activities. You will partner with business units and stakeholders to identify and assess security issues and gaps, communicate impact, and help drive remediation actions and timelines.
Responsibilities:-
- Third-Party Risk Assessments: Conduct security risk assessments for third parties - including cloud service providers, SaaS platforms, technology partners, and infrastructure providers - across the third-party lifecycle (intake, due diligence, ongoing monitoring, and offboarding).
- Issue and Remediation Management: Identify, document, track, and drive remediation of control gaps and security risks through remediation, exception, or formal risk acceptance, and escalate when risks or remediation efforts are insufficient or delayed.
- Ongoing Monitoring: Monitor critical and high-risk vendors for control changes, risk signals, remediation progress, and ongoing compliance concerns.
- Cross-Functional Collaboration: Partner with Legal, Procurement, Security, Privacy, and business owners to ensure third-party risks are appropriately documented, communicated, accepted, or mitigated.
- Documentation and Reporting: Maintain accurate third-party records, assessment results, and issues within the system of record, and support preparation of metrics, dashboards, and management reporting.
- Broader Risk Support: Support principal-level risk assessment activities as needed - including security exception reviews and internal control assessments - working under the direction of the Principal Program Manager.
- Continuous Improvement: Contribute to the maturation of TPRM processes, procedures, and best practices, and support other risk, governance, and program activities as needed.
About You
Basic Qualifications
- 5+ years of experience in governance, risk, and compliance (GRC), including third-party / vendor risk management.
- 2+ years of experience conducting security or third-party risk assessments across the vendor lifecycle.
- Bachelor's degree in a relevant discipline such as Information Security, Computer Science, Risk Management, Business, or a related field, or equivalent practical experience.
Other Qualifications
- Solid understanding of third-party / vendor risk management across the lifecycle - intake, due diligence, ongoing monitoring, issue remediation, and off-boarding.
- Working knowledge of security and risk frameworks such as NIST CSF, ISO 27001, SOC 2, PCI DSS, and SIG.
- Familiarity with GRC / TPRM platforms and security-ratings services (e.g., OneTrust, Archer, ServiceNow, Vanta, BitSight, SecurityScorecard, RiskRecon).
- Ability to review and interpret technical assurance evidence (e.g., SOC 2 Type II reports, penetration testing results) to evaluate vendor control effectiveness.
- Understanding of qualitative risk analysis and the ability to translate risk into clear business impact.
- Awareness of AI/ML vendor risk and how AI-enabled services are assessed, monitored, and governed.
- Strong written and verbal communication skills, with the ability to work with both technical and non-technical stakeholders.
- Strong attention to detail and the ability to manage multiple assessments and competing priorities in a fast-paced environment.
- Certifications such as CRISC, CISA, CISSP, or CISM preferred.
- Nice to have: some hands-on automation experience such as scripting or low-code / no-code workflow tools used to streamline risk assessments and reporting.
Workday Pay Transparency Statement
The annualized base salary ranges for the primary location and any additional locations are listed below. Workday pay ranges vary based on work location. As a part of the total compensation package, this role may be eligible for the Workday Bonus Plan or a role-specific commission/bonus, as well as annual refresh stock grants. Recruiters can share more detail during the hiring process. Each candidate's compensation offer will be based on multiple factors including, but not limited to, geography, experience, skills, job duties, and business need, among other things. For more information regarding Workday's comprehensive benefits, please click here.
Primary Location: USA.VA.Reston
Primary Location Base Pay Range: $110,100 USD - $165,100 USD
Additional US Location(s) Base Pay Range: $99,600 USD - $176,900 USD
Our Approach to Flexible Work
With Flex Work, we're combining the best of both worlds: in-person time and remote. Our approach enables our teams to deepen connections, maintain a strong community, and do their best work. We know that flexibility can take shape in many ways, so rather than a number of required days in-office each week, we simply spend at least half (50%) of our time each quarter in the office or in the field with our customers, prospects, and partners (depending on role). This means you'll have the freedom to create a flexible schedule that caters to your business, team, and personal needs, while being intentional to make the most of time spent together. Those in our remote "home office" roles also have the opportunity to come together in our offices for important moments that matter.
Pursuant to applicable Fair Chance law, Workday will consider for employment qualified applicants with arrest and conviction records.
Workday is an Equal Opportunity Employer including individuals with disabilities and protected veterans.
At Workday, we are committed to providing an accessible and inclusive hiring experience where all candidates can fully demonstrate their skills. If you require assistance or an accommodation at any point, please email accommodations@workday.com.
Are you being referred to one of our roles? If so, ask your connection at Workday about our Employee Referral process!
At Workday, we value our candidates' privacy and data security. Workday will never ask candidates to apply to jobs through websites that are not Workday Careers.
Please be aware of sites that may ask for you to input your data in connection with a job posting that appears to be from Workday but is not.
In addition, Workday will never ask candidates to pay a recruiting fee, or pay for consulting or coaching services, in order to apply for a job at Workday.
About Workday
Sourced by ZipRecruiter
Workday's journey began with a transformative idea generated during a breakfast conversation between its founders in sunny California. What set us apart from the start was our people-centric culture, driven by the core value of prioritizing our employees. At Workday, the happiness, growth, and contributions of every team member are at the heart of who we are. Our collaborative and employee-focused culture is the key ingredient for our business success. We not only care for our people but also for the communities and the environment, all while maintaining profitability. Embrace your uniqueness, as we encourage our Workmates to shine brightly in their authentic selves. Our passion and energy make us distinct, and we are inspired to create a brighter workday for everyone.
Industry
Software development
Company size
10,000+ Employees
Headquarters location
Pleasanton, CA, US
Year founded
2005