> Markdown version of [/jobs/ext/1862245-workday-security-analyst-ii](https://www.wearedevelopers.com/jobs/ext/1862245-workday-security-analyst-ii). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # WORKDAY SECURITY ANALYST II - **Company:** Moffitt Cancer Center - **Location:** Tampa, FL, United States - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Cyber Security, System Configuration, Data Security, Identity and Access Management, Information Security Management, IT Management, Regression Testing, Security Assertion Markup Language (SAML), User Provisioning Software, Enterprise Software Applications, Workday Security, Information Technology, EIB, SailPoint, Workday - **Published:** July 31, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=8b295b17e5a19f0e ## About the Role * Bachelor's Degree: Information Security, Computer Science, Risk Management, or a related field * Minimum of 3 years of experience in IT governance, risk, and compliance (GRC). * Preferred 2 years of experience with Workday security and SailPoint access control. * Knowledge of security frameworks and regulatory compliance (e.g., SOX). * Experience configuring, maintaining, and auditing Workday security, including domains, business processes, and security groups. * Hands-on experience with user provisioning, deprovisioning, and access management in Workday. * Experience performing security impact assessments for configuration changes and enhancements. * Managing role-based access controls and segration of duties monitoring. * Troubleshooting SSO/SAML authentication and access issues. * Conducting security reviews, risk assessments, and remediation planning. * Experience handling security incidents, escalations, and break/fix support. * Partnering with HR, Financials and Supply Chain customers for issue resolution. * Experience monitoring integration and EIB access to ensure data security. * Building security audit reports and dashboards. * Supporting Workday releases, feature adoption, and security regression testing. * Documenting change controls, and approvals for security updates. * Partnering with stakeholders to prioritize and execute security enhancements. Certification: * Workday Security (within 9 months of hire/job change) * CISSP (Certified Information System Security) or CISM (Certified Information Security Manager) preferred ## Description * The Security Analyst II is responsible for maintaining and supporting the organization's Workday security infrastructure, ensuring secure and efficient access management for all users. This role focuses on day-to-day operational security activities, including user provisioning through Workday and SailPoint, managing security groups, maintaining role-based access controls, domain security policies and business process security policies. * The analyst supports the full security life cycle by configuring security in Workday, performing routine audits, responding to security incidents, and maintaining accurate documentation. By ensuring compliance with internal policies and regulatory requirements, the Analyst helps safeguard sensitive HR and financial data while enabling seamless business operations. * The analyst supports Workday's infrastructure through governance, sustains continuous policy improvements, and keeps the organization audit-ready. This role will help shape our security framework as we launch Workday and enforce the policies after go-live. * This role focuses on developing, maintaining, and monitoring security governance frameworks, including security policies and audit procedures. The analyst partners with HR, IT, and Internal Audit teams to perform regular security audits, document controls, and support internal and external audits. The role also proactively identifies risks, recommends process improvements, and contributes to the overall security strategy, ensuring the Workday environment remains secure, compliant, and well-governed. Please note: This role is not a contract position and offers long-term career growth, benefits, and the opportunity to contribute to the ongoing evolution of the organization's Workday ecosystem. Responsibilities: * Demonstrate proof of security controls during internal and external audits. * Provision and deprovision access in Workday. * Monitor segragation of duties * Collaborate with IT and business customers on security-impacting changes. * Document change controls for security changes made. * Support Workday releases with a focus on security impacts and security regression testing. * Drive continuous improvement in security governance processes. * Educate business leaders on security policies * Contribute to any discussions and decisions concerning enterprise application security. * Monitor emerging threats and recommend proactive security enhancements. * Proactively stay up to date on Workday releases involving security. * Champion security feature adoption where beneficial. * Develop and enforce Workday security governance policies. * Perform security audits, assessments, and readiness for internal and external compliance requirements. * Monitor system activity and ensure policy compliance. * Lead audit readiness efforts and maintain documentation. * Review security roles and access controls for adherence to policy. * Develop and maintain awareness of divisional and data security and comply with policies and procedures. * Ensure alignment of security practices with organizational goals and regulatory standards. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Destigmatizing the Workplace: Building Real Inclusion](https://www.wearedevelopers.com/videos/1492-destigmatizing-the-workplace-building-real-inclusion) - [Maturity assessment for technicians or how I learned to love OWASP SAMM](https://www.wearedevelopers.com/videos/351-maturity-assessment-for-technicians-or-how-i-learned-to-love-owasp-samm) - [WeAreDevelopers LIVE - How DevRel Makes Tech More Human](https://www.wearedevelopers.com/videos/2149-wearedevelopers-live-how-devrel-makes-tech-more-human) - [Securing Your Web Application Pipeline From Intruders](https://www.wearedevelopers.com/videos/53-securing-your-web-application-pipeline-from-intruders) - [The Future of Employee Wellbeing: Benefits, Trust & Performance](https://www.wearedevelopers.com/videos/1808-the-future-of-employee-wellbeing-benefits-trust-performance) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Data Analyst Salary in the UK](https://www.wearedevelopers.com/magazine/278-data-analyst-salary-in-the-uk) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology)