> Markdown version of [/jobs/ext/124496-senior-workday-security-consultant](https://www.wearedevelopers.com/jobs/ext/124496-senior-workday-security-consultant). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Workday Security Consultant - **Company:** OpenKyber LLC - **Location:** United States (Remote available) - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Cyber Security, Data Dictionary, Information Leak Prevention, Identity and Access Management, Systems Development Life Cycle, Systems Architecture, Software Vulnerability Management, Data Logging, Workday Security - **Published:** May 13, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=8f2ef063779c4286 ## About the Role Do you have experience in Stakeholder management?, * 6+ years of experience in Security Assessment & Authorization (SA&A) within government, para-government, or regulated environments. * 6+ years of hands-on experience developing: Security Categorization Reports (SCAR), Security Requirements Traceability Matrices (SRTM), Security Concept of Operations (CONOPS), Security Assessment Reports (SAR), Threat and Risk Assessments (TRA). * Strong knowledge of security frameworks, compliance standards, and risk management methodologies. * Experience reviewing enterprise and COTS-based system architectures for security compliance. * Proven ability to support ATO/IATO processes and security audits. * Strong stakeholder management and consulting skills. * Bilingual in English and French. ## Description Role: Business Consultant IT Security Location: Ottawa, ON - Canada" [Hybrid - 2-3 days/week to onsite is must], The Business Consultant IT Security will act as a trusted security consultant, providing expert advisory and hands-on support across Security Assessment & Authorization (SA&A) initiatives. The role focuses on guiding project teams through complex security compliance requirements, shaping security architecture decisions, and ensuring successful attainment of Authority to Operate (ATO). This position requires strong stakeholder engagement, risk-based decision-making, and the ability to translate security frameworks into practical implementation within enterprise and COTS-based environments. Day to Day Job Duties: * Conduct technical research and provide expert guidance on Security Assessment & Authorization (SA&A) requirements. * Collaborate with project teams and Life Cycle Application Manager (LCAM) through weekly meetings to track SA&A progress. * Support security evidence collection and develop formal risk and compliance documentation. * Develop and refine SA&A artefacts including CONOPS, SCAR, PoAM, data dictionaries, and security control questionnaires. * Advise project teams on implementation and prioritization of tailored security controls. * Define and validate security processes across SDLC, including: Vulnerability Management, Identity and Access Management (IAM), Audit and Logging, Incident Response, Data Loss Prevention (DLP). * Review system architecture for compliance with Enterprise Architecture (EA) and CIA (Confidentiality, Integrity, Availability) requirements. * Assess documentation, questionnaires, and evidence ahead of IATO and ATO approvals. * Identify gaps or deficiencies in implemented security controls and recommend remediation actions. * Prepare and package documentation for IATO/ATO submissions. * Participate in SA&A governance meetings, sprint ceremonies, and cross-functional discussions. ## Related Videos - [Parquet, Delta, Iceberg & Ducklake - An introduction for developers](https://www.wearedevelopers.com/videos/100075-parquet-delta-iceberg-ducklake-an-introduction-for-developers) - [Crypto-secure Data Management with In-Database Blockchain](https://www.wearedevelopers.com/videos/632-crypto-secure-data-management-with-in-database-blockchain) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) - [Build Delightful Mobile Experiences with Kotlin, Realm, and Atlas Device Sync](https://www.wearedevelopers.com/videos/694-build-delightful-mobile-experiences-with-kotlin-realm-and-atlas-device-sync) ## Related Articles - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing)