Jobs / United States / Workday INC
Vulnerability Management Analyst (US Federal)
Workday INC · 🇺🇸 USA.VA.Reston
Sponsorship verdict
Sponsorship possible
One solid signal, not two — worth applying, and worth asking about sponsorship early.
- Employer is on a government sponsor recordThe US Department of Labor certified 255 H-1B/E-3 labor condition applications for this employer between Oct 2025 and Jun 2026 (latest Jun 2026) — the step every H-1B hire needs first. USCIS also records 103 H-1B approvals in FY2023. Source: LCA disclosure data (US Department of Labor (OFLC)).
- The posting doesn’t mention sponsorshipSilence isn’t a refusal — ask the recruiter before investing much time.
- No salary bar for this routeH-1B has no fixed salary bar: the employer must pay at least the prevailing wage for the role and area. Cap-subject employers enter a lottery weighted by wage level. Source: https://www.federalregister.gov/documents/2025/12/29/2025-23853/weighted-selection-process-for-registrants-and-petitioners-seeking-to-file-cap-subject-h-1b, rules effective 2026-02-27.
- What Workday INC paid sponsored hires in similar roles3 certified filings for “Product Acceleration and Optimization Advisor” (Project Management Specialists) in CA: $126k–$138k, median $126k. Most were filed at wage level I (67%) — 1 lottery entry, ≈15% projected selection odds for cap-subject employers. Source: US Department of Labor LCA disclosure data (Oct 2025 – Jun 2026).
- Confirmed live todayWhen a source last listed this job as open.
US H-1B: cap-subject employers enter a lottery weighted by wage level — Level I gets 1 entry, Level IV gets 4 (DHS projected selection odds ≈15% at Level I to ≈61% at Level IV). Universities and non-profit research employers are cap-exempt. The $100,000 fee for new petitions from abroad is currently blocked by a court order (appeal pending).
A verdict summarises public evidence; it is not legal advice and never a guarantee — the employer and the immigration authority decide. Sign in to factor in where you can already work.
Or apply yourself on the official page →
Sponsor Radar — Workday INC
The US Department of Labor certified 255 H-1B/E-3 labor condition applications for this employer between Oct 2025 and Jun 2026 (latest Jun 2026) — the step every H-1B hire needs first. USCIS also records 103 H-1B approvals in FY2023. Source: LCA disclosure data (US Department of Labor (OFLC)).
Past sponsorship or register membership never guarantees sponsorship for this vacancy or for you. Full Sponsor Radar for Workday INC →
About the role
Your work days are brighter here. We’re obsessed with making hard work pay off, for our people, our customers, and the world around us. As a Fortune 500 company and a leading AI platform for managing people, money, and agents, we’re shaping the future of work so teams can reach their potential and focus on what matters most. The minute you join, you’ll feel it. Not just in the products we build, but in how we show up for each other. Our culture is rooted in integrity, empathy, and shared enthusiasm. We’re in this together, tackling big challenges with bold ideas and genuine care. We look for curious minds and courageous collaborators who bring sun-drenched optimism and drive. Whether you're building smarter solutions, supporting customers, or creating a space where everyone belongs, you’ll do meaningful work with Workmates who’ve got your back. In return, we’ll give you the trust to take risks, the tools to grow, the skills to develop and the support of a company invested in you for the long haul. So, if you want to inspire a brighter work day for everyone, including yourself, you’ve found a match in Workday, and we hope to be a match for you too. About the Team The Workday Government, Governance, Risk and Compliance (GRC) team works on compliance with US Government security frameworks such as FedRAMP, IL-4/5, CMMC, and others for our civilian and defense customers. The GRC team’s mission is to enable and maintain Workday Government’s offerings through certification, continuous monitoring, consultation and deep stakeholder alignment. About the Role This role will support one or more direct or indirect contracts with the U.S. Federal Government which, due to federal government security requirements, mandates that all Workday personnel working on the contracts be United States citizens (naturalized or native). This role will support one or more direct or indirect contracts with the U.S. Federal Government which, due to federal government security requirements, mandates that all Workday personnel working on the contracts be United States citizens (naturalized or native). The role requires strong organization and interpersonal skills, and the technical ability to understand, interpret and prioritize findings from commercial scan tools. The role also requires contributing to the Planning of Actions and Milestones (POAMs) and communicating status to the leadership team About You Responsibilities: • Analyze and organize scan results and prioritize vulnerabilities for remediation based on risk requirements. • Engage with engineering teams to track and report status and remediation timelines. • Support management of Planning of Actions and Milestones (POAMs) and monthly Continuous Monitoring (ConMon) • Support Annual Assessments for FedRAMP, IL-4/5 and CMMC • Assist in documenting policies and procedures (update SSPs, etc.) • Work with the larger GRC team to assist with leading the design, implementation and assessment of Workday's SaaS offering • Write scripts in Python to automate tasks Required Qualifications: • Outstanding communication and organization skills. • Self-driven, motivated professional with experience working with multiple stakeholders. • Ability to understand and interpret results from commercial scanning tools and provide related guidance for remediation. • Working knowledge in using scan tools such as Qualys, Tenable, Twistlock, Wiz, etc. • Working knowledge of FedRAMP, NIST 800-53 controls, IL4/5, and DoD SRG • Previous experience in managing POAMs for FedRAMP authorized environments. • Experience in cloud computing, with a major CSP like AWS, Google, or federal SaaS solution • Proficiency in using tools like Jira for managing tickets and tasks • Experience with documenting security and complian