Data Privacy and Security Counsel (US Federal)
Reston, VA - USA
Job Summary
Your work days are brighter here.
Were obsessed with making hard work pay off for our people our customers and the world around us. As a Fortune 500 company and a leading AI platform for managing people money and agents were shaping the future of work so teams can reach their potential and focus on what matters most. The minute you join youll feel it. Not just in the products we build but in how we show up for each other. Our culture is rooted in integrity empathy and shared enthusiasm. Were in this together tackling big challenges with bold ideas and genuine care. We look for curious minds and courageous collaborators who bring sun-drenched optimism and drive. Whether youre building smarter solutions supporting customers or creating a space where everyone belongs youll do meaningful work with Workmates whove got your return well give you the trust to take risks the tools to grow the skills to develop and the support of a company invested in you for the long haul. So if you want to inspire a brighter work day for everyone including yourself youve found a match in Workday and we hope to be a match for you too.
About the Team
Your work matters here. At Workday Government we focus on outcomes that serve a larger mission. Our work supports U.S. federal agencies as they modernize and transform the full employee lifecycle experience and finance operationsso they can operate with greater clarity accountability and trust. As a Fortune 500 company and a proven enterprise cloud platform Workday brings modern technology responsible AI and secure infrastructure to some of the most complex environments in the world. The work isnt theoretical. Its operational. Its high-impact. And it demands rigor integrity and long-term thinking.From day one youll be part of a team that values collaboration follow-through and doing the right thingespecially when the stakes are high. Our culture is grounded in integrity respect and shared responsibility. We challenge each other to think clearly act thoughtfully and build solutions that stand up to real-world demands. Here curiosity is matched with accountability. Ambition is paired with trust. Youll have the space to do your best work the support to keep growing and the backing of a company committed to long-term investment in both its people and the federal mission.
If youre looking to apply your experience to meaningful mission-driven workalongside colleagues who take pride in building things that lastyoull find that opportunity at Workday Government.
About the Role
This role will support one or more direct or indirect contracts with the U.S. Federal Government which due to federal government security requirements mandates that all Workday personnel working on the contracts be United States citizens (naturalized or native).
This role may require a security clearance at the TS/SCI w/CI Poly level. Applicants must have the ability to obtain and maintain a U.S. government issued security clearance. An active TS/SCI w/CI Poly is preferred.
Employees may be required to be on site at client locations in the DC MD and VA (DMV) area.
Responsibilities include
Serve as lead counsel on data privacy and cybersecurity matters and advise business product and engineering teams on compliance obligations across the data lifecycle
Own the legal strategy for achieving and maintaining FedRAMP authorization and partner with security compliance and engineering teams throughout the assessment and Authority to Operate (ATO) process
Advise on requirements associated with Department of Defense (DoD) Cloud Computing Security Requirements Guide (SRG) Impact Levels (IL2 IL4 IL5 and IL6) including data segregation personnel screening and physical/logical separation requirements
Draft review and negotiate contracts data processing agreements and government contract vehicles (including FAR/DFARS clauses) that reflect current federal state and international privacy and security law
Monitor and interpret emerging legal and regulatory developments in privacy and cybersecurity law including CMMC NIST 800-53 NIST 800-171 FISMA and state and international privacy statutes and translate them into practical guidance
Lead incident response efforts for data breaches and security incidents coordinating with security communications and outside counsel to manage legal risk and notification obligations
Act as a trusted advisor to executive leadership on data governance risk management and the legal implications of new products features and government contracting opportunities
About You
You are a seasoned data privacy and cybersecurity attorney who thrives at the intersection of law technology and national security compliance. You bring deep hands-on experience guiding organizations through FedRAMP authorization and DoD Impact Level accreditation and you are comfortable translating complex technical security requirements into clear legal and business guidance. You are a pragmatic risk-manager who can move quickly in a fast-paced environment while maintaining rigorous attention to regulatory detail and you enjoy building scalable processes that let compliance and business goals move forward seamlessly.
Basic Qualifications:
J.D. Degree and active membership in at least one state bar
8 years of experience as a practicing attorney with a substantial focus on data privacy and cybersecurity law
Demonstrated experience advising on or supporting FedRAMP authorization processes (Low Moderate or High)
Direct experience with Department of Defense Impact Levels (IL2 through IL6) and the DoD Cloud Computing SRG
Strong working knowledge of U.S. federal privacy and security frameworks including FISMA NIST 800-53 NIST 800-171 and CMMC
Other Qualifications:
Experience advising cloud service providers or government contractors on compliance with federal acquisition regulations (FAR/DFARS) related to data security
Familiarity with state federal and international privacy laws (e.g. CCPA/CPRA state privacy statutes GDPR) and their intersection with government contracting requirements
Experience leading or supporting data breach and security incident response including regulatory notification analysis
Excellent contract drafting and negotiation skills particularly for data processing agreements security addenda and government contract vehicles
Ability to communicate complex legal and technical concepts clearly to both technical and non-technical stakeholders
Strong project management skills with the ability to manage multiple compliance workstreams simultaneously
Active or the ability to obtain a security clearance is a plus
Workday Pay Transparency Statement
The annualized base salary ranges for the primary location and any additional locations are listed below. Workday pay ranges vary based on work location. As a part of the total compensation package this role may be eligible for the Workday Bonus Plan or a role-specific commission/bonus as well as annual refresh stock grants. Recruiters can share more detail during the hiring process. Each candidates compensation offer will be based on multiple factors including but not limited to geography experience skills job duties and business need among other things. For more information regarding Workdays comprehensive benefits please click here.
Primary Location:
Our Approach to Flexible Work
With Flex Work were combining the best of both worlds: in-person time and remote. Our approach enables our teams to deepen connections maintain a strong community and do their best work. We know that flexibility can take shape in many ways so rather than a number of required days in-office each week we simply spend at least half (50%) of our time each quarter in the office or in the field with our customers prospects and partners (depending on role). This means youll have the freedom to create a flexible schedule that caters to your business team and personal needs while being intentional to make the most of time spent together. Those in our remote home office roles also have the opportunity to come together in our offices for important moments that matter.
Pursuant to applicable Fair Chance law Workday will consider for employment qualified applicants with arrest and conviction records.
Workday is an Equal Opportunity Employer including individuals with disabilities and protected veterans.
Workday is committed to providing reasonable accommodations for qualified individuals during our application process in order to perform one or more essential functions of their job as well as regarding the use of AI tools for employment decision-making to any degree. Please see below for more details including how to request an accommodation as a qualified veteran due to a disability or for religious reasons or as otherwise provided under applicable law.
Workday prohibits taking adverse action against any candidate or employee for reporting a possible violation of this policy requesting one or more work accommodations exercising a privacy right or cooperating in an investigation in accordance with applicable law. Any employee who retaliates against a candidate or employee for doing so may be subject to disciplinary action up to and including termination of employment to the fullest extent allowable under applicable law.
If you require a reasonable accommodation you may email as far in advance as possible.
Are you being referred to one of our roles If so ask your connection at Workday about our Employee Referral process!
At Workday we value our candidates privacy and data security. Workday will never ask candidates to apply to jobs through websites that are not Workday Careers.
Please be aware of sites that may ask for you to input your data in connection with a job posting that appears to be from Workday but is not.
In addition Workday will never ask candidates to pay a recruiting fee or pay for consulting or coaching services in order to apply for a job at Workday.