Sysco logo
Sysco

Connecting the world to share food and care for one another

Senior Analyst, Workday Functional Security

Security AnalystSecurity AnalystFull TimeRemoteSeniorTeam 10,001+Since 1969H1B SponsorCompany SiteLinkedIn

Location

United States

Posted

8 days ago

Salary

$88.5K - $132.7K / year

Seniority

Senior

Job Description

Senior Analyst, Workday Functional Security

Sysco

Role Description The Senior Workday Functional Security Analyst is responsible for establishing, maintaining, and evolving the functional security framework for Workday HCM. This role serves as the primary advisor on security design, access strategy, risk management, compliance requirements, and security impacts associated with business process, organizational, and regulatory changes. The position partners with HRIS, Shared Services, Internal Audit, and business stakeholders to ensure Workday security supports business objectives while maintaining appropriate controls, governance, and scalability. The role serves as the primary liaison between business requirements and technical security execution, providing consultation, decision support, reporting, and security expertise across the global Workday. Duties and Responsibilities - Serve as the primary functional security advisor for Workday by providing consultative guidance on access requests, evaluating business requirements, and recommending security approaches aligned to established standards, risk considerations, and business objectives. - Design, maintain, and optimize Workday security roles, access models, and functional security frameworks to support a scalable global operating model. - Serve as a functional security consultant to HRIS functional teams, supporting HRIS owned stakeholder engagements by evaluating security impacts associated with new business processes, organizational changes, system enhancements, and projects. - Conduct access reviews, segregation of duties assessments, and compliance-related security activities to identify and mitigate risk. - Develop and maintain security documentation, standards, procedures, training materials, and knowledge resources. - Create and analyze security reporting, metrics, dashboards, and audit support documentation for leadership, compliance, and business stakeholders. - Support investigation and resolution of complex security-related issues, access concerns, and escalations. - Partner with technical security resources, Workday consultants, and external partners to support security enhancements and continuous improvement initiatives. Qualifications - Bachelor’s degree in information technology, computer science, business or equivalent education/experience/training. Experience Required - Minimum of five (5) years of experience supporting Human Resources Information Systems (HRIS), Workday HCM, security administration, business process configuration, or related functional support activities. - Demonstrated experience evaluating business requirements and translating them into security, process, or technology solutions. - Experience supporting security audits, access reviews, compliance initiatives, governance activities, or risk assessments. - Experience partnering with business stakeholders and providing consultation on system functionality, security impacts, and operational processes. - Demonstrated analytical and problem-solving skills with the ability to evaluate complex issues and recommend solutions. Experience Preferred - Experience supporting Workday Security in a global organization. - Experience with role-based security design, business process security policies, and security framework development. - Experience supporting SOX, privacy, audit, compliance, or internal controls programs. - Experience supporting large-scale HR technology environments and global deployments. Licenses/Certifications Preferred - Workday Pro Security, Workday Pro HCM, Workday Security Administration Certification, Compliance, Audit, or Risk related certifications preferred. Skills and Abilities - Strong understanding of Workday security concepts including security groups, role assignments, domain security policies, business process security policies, constrained and unconstrained security, and intersection security. - Ability to assess business requirements and determine appropriate security solutions while balancing compliance, risk, and operational needs. - Strong understanding of HR business processes and how security impacts user experience, data access, workflow execution, and compliance requirements. - Ability to analyze complex security issues and provide practical recommendations. - Strong stakeholder management and influencing skills. - Experience presenting recommendations and findings to leaders and business partners. - Strong documentation, communication, and organizational skills. - Ability to work independently and manage competing priorities. - Demonstrated capability to operate in ambiguous situations and provide decision support. - High degree of integrity and attention to confidentiality. Benefits - For information on Sysco’s Benefits, please visit SyscoBenefits.com . Company Description Sysco is the global leader in foodservice distribution. With over 71,000 colleagues and a fleet of over 13,000 vehicles, Sysco operates approximately 333 distribution facilities worldwide and serves more than 700,000 customer locations. We offer our colleagues the opportunity to grow personally and professionally, to contribute to the success of a dynamic organization, and to serve others in a manner that exceeds their expectations. We’re looking for talented, hard-working individuals to join our team. Come grow with us and let us show you why Sysco is at the heart of food and service.

Related Job Pages

More Security Analyst Jobs

Virtru logo

Security Governance, Risk & Compliance (GRC) Analyst

Virtru

Respect the people. Respect the data. Virtru equips you to protect your data anywhere and everywhere it's shared.

Full TimeRemoteTeam 51-200Since 2012H1B No Sponsor

• Manage and implement complex controls frameworks for large systems, consisting of Cloud infrastructure and Software as a Service (SaaS) services (GCP, AWS, GitHub, Okta, etc). • Design and develop automation solutions for evidence collection across Cloud infrastructure, endpoints, and SaaS services. • Conduct risk assessments across business units and processes. Identify risk findings and recommend remediation and risk mitigation strategies. • Participate in incident response (IR) activities, providing risk analysis and remediation support as needed. • Assist or implement automated controls to support risk mitigation efforts across various business units with stakeholders. • Incorporate CMMC certification into Virtru’s slate of compliance assessments and ongoing monitoring activities (FedRAMP, SOC 2, PCI). • Facilitate the third-party vendor on-boarding and annual review process by evaluating the security of current and prospective partners. • Enhance the team with your individualism, spirit, and love of learning.

District Of Columbia + 1 moreAll locations: District Of Columbia | Washington
$130K - $170K / year
Cherokee Federal logo

Cybersecurity Analyst

Cherokee Federal

Building. Solving. Serving.

Full TimeRemoteTeam 5,001-10,000Since 1969H1B No Sponsor

• Monitor and analyze security events utilizing Splunk Enterprise Security (ES). • Build, maintain, and tune Splunk searches, correlation rules, alerts, and dashboards. • Conduct incident response activities from detection through containment, eradication, recovery, and closure. • Investigate endpoint security incidents utilizing Microsoft Defender for Endpoint. • Perform endpoint policy management and incident investigations. • Assess AWS cloud security telemetry utilizing GuardDuty, Security Hub, and related cloud security services. • Identify threats, vulnerabilities, suspicious activity, and cloud misconfigurations. • Execute alert triage, incident scoping, and escalation activities according to established playbooks. • Recommend updates and improvements to operational procedures and incident response playbooks. • Support threat hunting activities and detection engineering initiatives aligned to MITRE ATT&CK methodologies. • Perform phishing investigations, alert enrichment, and forensic review activities. • Conduct root cause analysis and document corrective actions following security incidents. • Track incidents and operational tasks utilizing case management systems. • Participate in tabletop exercises and operational readiness activities. • Collaborate with Security Operations teams, Incident Response personnel, and federal stakeholders. • Prepare reports and communicate findings to technical and non-technical audiences. • Perform other job-related duties as assigned.

United States
$153K - $160K / year
Deutsche Telekom IT Solutions logo

Security Analyst

Deutsche Telekom IT Solutions

As Hungary’s most attractive employer in 2025 (according to Randstad’s representative survey), Deutsche Telekom IT Solutions is a subsidiary of the Deutsche Telekom Group. The company provides a wide portfolio of IT and telecommunications services with more than 5300 employees. We have hundreds of large customers, corporations in Germany and in other European countries. DT-ITS received the Best in Educational Cooperation award from HIPA in 2019, acknowledged as the Most Ethical Multinational Company in 2019. The company continuously develops its four sites in Budapest, Debrecen, Pécs and Szeged and is looking for skilled IT professionals to join its team.

Full TimeRemoteTeam 5,001-10,000

Role Description You don’t want to cry when you hear about WannaCry? Loki isn’t only a German firegod to you? You know what Meltdown/Spectre are, maybe you even know what cryptojacking is? Then the following position is for you! If you join us, your daily tasks will be as follows: - Detection, analysis and management of security incidents - Making and evaluating reports - Monitoring the customer’s environment - Tracking IT security issues (vulnerabilities, 0day exploits, malware) and making/fitting the rules for detecting them in the client's environment - Change and incident management - Analysis of malicious code in sandbox Qualifications - If you love to learn and you have a need for continuous development - If you know network models (OSI, TCP/IP) - If you know how operating systems work (Windows, Linux) - You speak English on business level - You are fluent in Hungarian - It's not a problem if you have to spend about one-third of your working hours in shifts - You have basic knowledge of script languages: python, bash, JS and so on - You are familiar with the logs of security systems: proxy, AV, WAF, IDS, Webserver, DNS - You've done PCAP analysis Benefits - Please be informed that our remote working possibility is only available within Hungary due to European taxation regulation. Company Description As Hungary’s most attractive employer in 2025 (according to Randstad’s representative survey), Deutsche Telekom IT Solutions is a subsidiary of the Deutsche Telekom Group. The company provides a wide portfolio of IT and telecommunications services with more than 5300 employees. We have hundreds of large customers, corporations in Germany and in other European countries. DT-ITS received the Best in Educational Cooperation award from HIPA in 2019, acknowledged as the Most Ethical Multinational Company in 2019. The company continuously develops its four sites in Budapest, Debrecen, Pécs and Szeged and is looking for skilled IT professionals to join its team.

Hungary
CMG Financial logo

Senior IT GRC Analyst

CMG Financial

Based in San Ramon, California, CMG Financial is a privately held banking and mortgage firm with operations in most U.S. states. An equal housing lender, CMG Fi

Role Description The Senior IT GRC Analyst leads policy development and audit execution within CMG's IT Governance, Risk, and Compliance program, with particular emphasis on CMG's upcoming SOC 2 readiness effort. This role works closely with the GRC team and the broader IT department to plan and execute audit engagements, maintain the policy framework, and manage auditor relationships. The Senior IT GRC Analyst operates with a high degree of autonomy and is expected to navigate ambiguity in a regulated environment. - Lead CMG's SOC 2 readiness assessment, including scope definition, gap analysis, and control design, in partnership with the IT GRC Manager. - Serve as a point of contact during audit engagements and regulatory exams. - Develop, maintain, and update IT policies, standards, and procedures to align with NIST CSF and other applicable regulatory requirements. - Plan and execute audit activities, including scheduling, control walkthroughs, evidence gathering, and findings documentation. - Identify control gaps, coordinate remediation planning with control owners, tracking findings and remediation status through the risk register. - Provide guidance to other GRC team members and IT leadership on audit and policy matters. - Research regulatory and framework changes relevant to mortgage lending and financial services, and translate them into policy updates. - Contribute to the ongoing development and improvement of GRC processes and tooling. Qualifications - Bachelor's degree in Information Technology, Cybersecurity, or a related field (equivalent experience considered). - 5+ years of experience in IT audit, compliance, or GRC in an enterprise IT environment. - Demonstrated experience managing SOC 2 audit cycles (Type I or Type II) from scoping through remediation. - Direct experience in financial services, mortgage lending, or related regulated industries, with working knowledge of applicable regulations (GLBA, CFPB, NYDFS). - Strong working knowledge of relevant IT compliance frameworks, such as NIST CSF, ISO 27001, or SOX. - Strong policy writing and documentation skills. - Ability to work independently amid ambiguity, exercising sound judgment on scope and prioritization. - Excellent written and verbal communication skills, with the ability to explain technical and compliance matters to varied audiences. - Relevant certifications preferred: CISA, CRISC, or GRCP. Requirements - Direct Reports: N/A Benefits - This role is a remote position that is currently allocated for candidates within geographic regions that do not currently require base wage disclosure. - The compensation range for this position will be provided upon request. - Due to their geographic location, residents of the states of CA & CO, and for NY are excluded from this role at this time. Physical and Environmental Conditions This role operates in an ADA compliant office environment, utilizing typical office equipment and tasks including computer work. The position may involve partial stationary positions and moving throughout the day. Flexibility to work overtime to meet project deadlines is required.

United States