Principal Program Manager

Workday
United States
Workplace: HybridFull timeUSD 170,600 - 255,800 annuallyFunction: Program & Project Management (PMO)Experience: 12+ yearsEducation: bachelorsSkills: ["Stakeholder management","Risk analysis","Cross-functional collaboration","Communication","Risk prioritization"]

Own and evolve the Cybersecurity third-party risk management (TPRM) program, including risk assessment methodology, vendor tiering, control expectations, continuous monitoring, and reporting. Lead principal-level risk assessments across the broader risk portfolio, translate risk into business impact, and drive remediation to closure. Partner with Security, Cloud Operations, IT, Legal, Procurement, Privacy, and ERM to manage and escalate risks, while establishing metrics, dashboards, and automation using GRC tooling and AI-enabled approaches.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
Workday
Workday
1 month ago

Principal Program Manager

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 35 days agoStatus: Live

Job Summary

Own and evolve the Cybersecurity third-party risk management (TPRM) program, including risk assessment methodology, vendor tiering, control expectations, continuous monitoring, and reporting. Lead principal-level risk assessments across the broader risk portfolio, translate risk into business impact, and drive remediation to closure. Partner with Security, Cloud Operations, IT, Legal, Procurement, Privacy, and ERM to manage and escalate risks, while establishing metrics, dashboards, and automation using GRC tooling and AI-enabled approaches.
Location: United States
Workplace: Hybrid
Employment Type: Full time
Job Function: Program & Project Management (PMO)
Seniority: Sr. Manager level

Key Responsibilities

  • •Own and evolve the Cybersecurity third-party security risk strategy, including assessment methodology, vendor tiering, control expectations, continuous monitoring, and reporting; mature the program for emerging risk domains and regulatory expectations.
  • •Lead risk assessments for critical and operationally significant third parties, including due diligence, ongoing monitoring, issue management, and exit planning.
  • •Perform principal-level risk assessment activities beyond third parties (security exception management, internal control reviews, cyber risk assessments) using qualitative/quantitative techniques to translate risk into business impact.
  • •Partner with Legal, Procurement, Privacy, ERM, and business owners to ensure risks are documented, accepted, mitigated, or escalated; communicate risk landscapes and prioritization to senior leadership.
  • •Establish and maintain risk and performance metrics/dashboards and Outcome-Driven Metrics (ODMs), refine initiatives with data-driven insights, and drive automation of repetitive processes.

Pay and Benefits

Salary: USD 170,600 - 255,800 annually
Equity and Bonus:Equity

Key Requirements

  • •12+ years experience in GRC, leading GRC initiatives, developing and maintaining GRC frameworks, and ensuring organizational compliance with laws and regulations.
  • •7+ years of experience implementing and managing modern GRC tools (ServiceNow GRC, OneTrust, Archer, LogicGate) to automate evidence collection and continuous control monitoring.
  • •B.S. or M.S. in Computer Science, Information Security, Management Information Systems (MIS), or a related technical field, or equivalent practical experience.
  • •Expert-level understanding of third-party risk management across the full lifecycle (intake, due diligence, vendor tiering, ongoing monitoring, remediation, exception/risk acceptance, exit planning) and ability to define and mature enterprise TPRM programs.
  • •Expert-level understanding of risk analysis methodologies (qualitative/quantitative, e.g., FAIR) and ability to translate technical/vendor risk into business impact to drive risk-based decisions.
Experience:12+ yearsGRCThird-party risk managementCybersecurityTPRM
Education:Bachelor's in Computer Science, Information Security, Management Information Systems (MIS) or related technical field
Skills:Stakeholder managementRisk analysisCross-functional collaborationCommunicationRisk prioritization
Certifications:CTPRPCRISCCISMCISACISSP
Tech Stack:ServiceNow GRCOneTrustArcherLogicGateN8nFAIRAI/MLAI-enabled toolingAutomationWorkflow-orchestration platforms

Company Brief

Workday
Provides cloud-based enterprise applications for human capital management, financial management, payroll, and analytics. Delivers unified HR and finance software suites to large organizations, enabling workforce planning, talent management, payroll, and financial reporting.
Industry: HR Tech
Company Size: Enterprise (1,001+ employees)
Revenue: USD 1B+
Growth: Public Company
Valuation: Public Company (Market Cap in USD)
Funding: IPO / Publicly Listed
Headquarters: Pleasanton, United States
Founded: 2005
WebsiteLinkedIn