Incident CoordinatorCyber Incident Commander US Federal

Workday

Not Interested
Bookmark
Report This Job

profile Job Location:

McLean, MD - USA

profile Monthly Salary: Not Disclosed
Posted on: Yesterday
Vacancies: 1 Vacancy

Job Summary

Your work days are brighter here.

Were obsessed with making hard work pay off for our people our customers and the world around us. As a Fortune 500 company and a leading AI platform for managing people money and agents were shaping the future of work so teams can reach their potential and focus on what matters most. The minute you join youll feel it. Not just in the products we build but in how we show up for each other. Our culture is rooted in integrity empathy and shared enthusiasm. Were in this together tackling big challenges with bold ideas and genuine care. We look for curious minds and courageous collaborators who bring sun-drenched optimism and drive. Whether youre building smarter solutions supporting customers or creating a space where everyone belongs youll do meaningful work with Workmates whove got your return well give you the trust to take risks the tools to grow the skills to develop and the support of a company invested in you for the long haul. So if you want to inspire a brighter work day for everyone including yourself youve found a match in Workday and we hope to be a match for you too.

About the Team

The Workdays National Security Group (NSG) is responsible for all aspects of cybersecurity and compliance for Workdays US Department of Defense and Intelligence Community customer regions. The NSG Governance Risk Compliance (GRC) Team enables business agility while maintaining a strong security posture via intelligent risk-taking optimized controls management and iterative security governance. The NSG GRC teams mission is to enable and maintain Workdays National Security offerings through certification continuous monitoring consultation and deep stakeholder alignment. We act as a trusted advisor across Workday to help maintain and enhance our customers trust.

About the Role

This role will support one or more direct or indirect contracts with the U.S. Federal Government which due to federal government security requirements mandates that all Workday personnel working on the contracts be United States citizens (naturalized or native).

This critical role serves as the central point of command for all major cybersecurity incidents outages and customer-impacting events within Workdays highly regulated FedRAMP Moderate and IL4 environments. The Commander will lead the full incident lifecycle from initial triage and containment through eradication and recovery. This involves making rapid risk-based decisions under pressure directing cross-functional responders (SOC Engineering SRE Cloud teams) and driving resolution.


Key responsibilities include:

  • Communication & Compliance: Own all executive and customer communications. Ensure incident handling strictly adheres to compliance frameworks including FedRAMP DoD IL4/IL5 and NIST 800-53.
  • Support CISA/JAB/DISA/Customer notifications and customer evidence requests.
  • Maintain IR playbooks escalation paths and communication templates.
  • Direct cross-functional teams through triage containment eradication and recovery.
  • Validate evidence collection and maintain chain-of-custody as required.
  • Provide accurate timely status updates during ongoing or high-severity incidents.
  • Communicate effectively with executives legal GRC customer success and partner teams.
  • Incident Command: Act as primary Incident Commander owning the incident bridge assigning tasks and ensuring rapid progression toward resolution.
  • Documentation & Readiness: Produce official Incident Reports e.g. RCA maintain IR playbooks and lead post-incident reviews and readiness exercises to ensure continuous improvement.
  • Process & Quality Focus: Systematically track incident metrics (MTTD MTTR) and drive organizational adoption of best practices learned from incident reviews.

About You

Required Qualifications:

  • Experience: 510 years in incident response SOC cybersecurity operations or SRE/DevOps including demonstrated experience leading complex incidents in cloud/SaaS environments.
  • Compliance Knowledge: Strong understanding of FedRAMP DISA SRG NIST 800-53 and IR best practices.
  • Technical Skills: Experience with EDR SIEM cloud forensics and architectures (AWS/Azure/GCP SaaS).
  • Core Competencies: Exceptional communication crisis leadership rapid triage and the ability to remain calm and decisive under pressure. Strong emotional intelligence and cross-cultural communication skills to manage diverse high-stress teams.

Preferred Qualifications:

  • Prior Incident Commander or CSIRT leadership experience.
  • Relevant certifications such as GCIH GCIA CISSP or CCSP.
  • Experience supporting federal audits 3PAOs or highly regulated customer environments.
  • Proven ability to mentor junior team members and build long-term capabilities within the broader Security and Engineering organizations.


Workday Pay Transparency Statement

The annualized base salary ranges for the primary location and any additional locations are listed below. Workday pay ranges vary based on work location. As a part of the total compensation package this role may be eligible for the Workday Bonus Plan or a role-specific commission/bonus as well as annual refresh stock grants. Recruiters can share more detail during the hiring process. Each candidates compensation offer will be based on multiple factors including but not limited to geography experience skills job duties and business need among other things. For more information regarding Workdays comprehensive benefits please click here.

Primary Location: (Tysons Corner)


Primary Location Base Pay Range: $139000 USD - $208500 USD


Additional US Location(s) Base Pay Range: $125800 USD - $223400 USD



Our Approach to Flexible Work

With Flex Work were combining the best of both worlds: in-person time and remote. Our approach enables our teams to deepen connections maintain a strong community and do their best work. We know that flexibility can take shape in many ways so rather than a number of required days in-office each week we simply spend at least half (50%) of our time each quarter in the office or in the field with our customers prospects and partners (depending on role). This means youll have the freedom to create a flexible schedule that caters to your business team and personal needs while being intentional to make the most of time spent together. Those in our remote home office roles also have the opportunity to come together in our offices for important moments that matter.

Pursuant to applicable Fair Chance law Workday will consider for employment qualified applicants with arrest and conviction records.

Workday is an Equal Opportunity Employer including individuals with disabilities and protected veterans.

Are you being referred to one of our roles If so ask your connection at Workday about our Employee Referral process!

At Workday we value our candidates privacy and data security. Workday will never ask candidates to apply to jobs through websites that are not Workday Careers.

Please be aware of sites that may ask for you to input your data in connection with a job posting that appears to be from Workday but is not.

In addition Workday will never ask candidates to pay a recruiting fee or pay for consulting or coaching services in order to apply for a job at Workday.


Required Experience:

IC

Your work days are brighter here.Were obsessed with making hard work pay off for our people our customers and the world around us. As a Fortune 500 company and a leading AI platform for managing people money and agents were shaping the future of work so teams can reach their potential and focus on w...
View more view more

Key Skills

  • Analysis
  • ABB
  • Information Technology Sales
  • Import & Export
  • Interventional Cardiology
  • Manual Testing

About Company

Company Logo

Seamlessly manage your people, money, and agents on an open, unified platform with AI at the core. It’s a new work day.

View Profile View Profile