Incident Coordinator/Cyber Incident Commander - US Federal

Sorry, this job was removed at 10:07 a.m. (CST) on Saturday, Mar 28, 2026
Be an Early Applicant
McLean, VA, USA
In-Office
Cloud • Fintech • HR Tech
The Role

Your work days are brighter here.

We’re obsessed with making hard work pay off, for our people, our customers, and the world around us. As a Fortune 500 company and a leading AI platform for managing people, money, and agents, we’re shaping the future of work so teams can reach their potential and focus on what matters most. The minute you join, you’ll feel it. Not just in the products we build, but in how we show up for each other. Our culture is rooted in integrity, empathy, and shared enthusiasm. We’re in this together, tackling big challenges with bold ideas and genuine care. We look for curious minds and courageous collaborators who bring sun-drenched optimism and drive. Whether you're building smarter solutions, supporting customers, or creating a space where everyone belongs, you’ll do meaningful work with Workmates who’ve got your back. In return, we’ll give you the trust to take risks, the tools to grow, the skills to develop and the support of a company invested in you for the long haul. So, if you want to inspire a brighter work day for everyone, including yourself, you’ve found a match in Workday, and we hope to be a match for you too.

About the Team

The Workday’s National Security Group (NSG) is responsible for all aspects of cybersecurity and compliance for Workday’s US Department of Defense and Intelligence Community customer regions. The NSG Governance, Risk, Compliance (GRC) Team enables business agility while maintaining a strong security posture via intelligent risk-taking, optimized controls management, and iterative security governance. The NSG GRC team’s mission is to enable and maintain Workday’s National Security offerings through certification, continuous monitoring, consultation and deep stakeholder alignment. We act as a trusted advisor across Workday to help maintain and enhance our customer's trust.

About the Role

This role will support one or more direct or indirect contracts with the U.S. Federal Government which, due to federal government security requirements, mandates that all Workday personnel working on the contracts be United States citizens (naturalized or native).

This critical role serves as the central point of command for all major cybersecurity incidents, outages, and customer-impacting events within Workday's highly regulated FedRAMP Moderate and IL4 environments. The Commander will lead the full incident lifecycle, from initial triage and containment through eradication and recovery. This involves making rapid, risk-based decisions under pressure, directing cross-functional responders (SOC, Engineering, SRE, Cloud teams), and driving resolution.

Key responsibilities include:

  • Communication & Compliance: Own all executive and customer communications. Ensure incident handling strictly adheres to compliance frameworks including FedRAMP, DoD IL4/IL5, and NIST 800-53.
  • Support CISA/JAB/DISA/Customer notifications and customer evidence requests.
  • Maintain IR playbooks, escalation paths, and communication templates.
  • Direct cross-functional teams through triage, containment, eradication, and recovery.
  • Validate evidence collection and maintain chain-of-custody as required.
  • Provide accurate, timely status updates during ongoing or high-severity incidents.
  • Communicate effectively with executives, legal, GRC, customer success, and partner teams.
  • Incident Command: Act as primary Incident Commander, owning the incident bridge, assigning tasks, and ensuring rapid progression toward resolution.
  • Documentation & Readiness: Produce official Incident Reports e.g. RCA, maintain IR playbooks, and lead post-incident reviews and readiness exercises to ensure continuous improvement.
  • Process & Quality Focus: Systematically track incident metrics (MTTD, MTTR) and drive organizational adoption of best practices learned from incident reviews.

About You

Required Qualifications:

  • Experience: 5–10 years in incident response, SOC, cybersecurity operations, or SRE/DevOps, including demonstrated experience leading complex incidents in cloud/SaaS environments.
  • Compliance Knowledge: Strong understanding of FedRAMP, DISA SRG, NIST 800-53 and IR best practices.
  • Technical Skills: Experience with EDR, SIEM, cloud forensics, and architectures (AWS/Azure/GCP, SaaS).
  • Core Competencies: Exceptional communication, crisis leadership, rapid triage, and the ability to remain calm and decisive under pressure. Strong emotional intelligence and cross-cultural communication skills to manage diverse, high-stress teams.

Preferred Qualifications:

  • Prior Incident Commander or CSIRT leadership experience.
  • Relevant certifications such as GCIH, GCIA, CISSP, or CCSP.
  • Experience supporting federal audits, 3PAOs, or highly regulated customer environments.
  • Proven ability to mentor junior team members and build long-term capabilities within the broader Security and Engineering organizations.


Workday Pay Transparency Statement

The annualized base salary ranges for the primary location and any additional locations are listed below.  Workday pay ranges vary based on work location. As a part of the total compensation package, this role may be eligible for the Workday Bonus Plan or a role-specific commission/bonus, as well as annual refresh stock grants. Recruiters can share more detail during the hiring process. Each candidate’s compensation offer will be based on multiple factors including, but not limited to, geography, experience, skills, job duties, and business need, among other things. For more information regarding Workday’s comprehensive benefits, please click here.

Primary Location: USA.VA.McLean (Tyson's Corner)


 

Primary Location Base Pay Range: $139,000 USD - $208,500 USD


 

Additional US Location(s) Base Pay Range: $125,800 USD - $223,400 USD


Our Approach to Flexible Work
 

With Flex Work, we’re combining the best of both worlds: in-person time and remote. Our approach enables our teams to deepen connections, maintain a strong community, and do their best work. We know that flexibility can take shape in many ways, so rather than a number of required days in-office each week, we simply spend at least half (50%) of our time each quarter in the office or in the field with our customers, prospects, and partners (depending on role). This means you'll have the freedom to create a flexible schedule that caters to your business, team, and personal needs, while being intentional to make the most of time spent together. Those in our remote "home office" roles also have the opportunity to come together in our offices for important moments that matter.

Pursuant to applicable Fair Chance law, Workday will consider for employment qualified applicants with arrest and conviction records.

Workday is an Equal Opportunity Employer including individuals with disabilities and protected veterans.

Are you being referred to one of our roles? If so, ask your connection at Workday about our Employee Referral process!

At Workday, we value our candidates’ privacy and data security.  Workday will never ask candidates to apply to jobs through websites that are not Workday Careers. 

  

Please be aware of sites that may ask for you to input your data in connection with a job posting that appears to be from Workday but is not.

  

In addition, Workday will never ask candidates to pay a recruiting fee, or pay for consulting or coaching services, in order to apply for a job at Workday.

Workday Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Workday and has not been reviewed or approved by Workday.

  • Healthcare Strength Health coverage is positioned as broad and well-supported, with multiple medical carrier options, virtual care access, and some locations offering onsite clinic/pharmacy services. Mental health support is described as notably strong, including therapy sessions and confidential support availability for household members.
  • Parental & Family Support Family-related benefits are portrayed as extensive, including paid bonding and caregiver leave alongside fertility, adoption, and surrogacy reimbursement. Added support like parenting resources, milk-shipping/lactation assistance during travel, and backup child/elder care is explicitly outlined.
  • Strong & Reliable Incentives Equity participation and savings-oriented programs are presented as meaningful components of total rewards, including an ESPP discount with a lookback feature. Additional programs like a student-loan pathway to earn the 401(k) match are included as financial-support enhancements.

Workday Insights

Similar Jobs

Zscaler Logo Zscaler

Senior Partner Marketing, Programs Manager

Cloud • Information Technology • Security • Software • Cybersecurity
Easy Apply
Remote or Hybrid
USA
8697 Employees
147K-210K Annually

Imprivata Logo Imprivata

Vice President, Sales - Commercial

Healthtech • Information Technology • Security • Software • Cybersecurity
Remote or Hybrid
United States
1372 Employees
420K-480K Annually

Bestow Logo Bestow

Director, Product Management (Underwriting)

Big Data • Fintech • Information Technology • Insurance • Software
Remote or Hybrid
US
160 Employees
225K-250K Annually

GRAIL Logo GRAIL

Client Integration Enablement Specialist (Clinical Informatics) #4783

Artificial Intelligence • Big Data • Healthtech • Machine Learning • Software • Biotech
Remote or Hybrid
USA
918 Employees
77K-95K Annually
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Pleasanton, CA
14,894 Employees
Year Founded: 2005

What We Do

Workday is a leading provider of enterprise cloud applications for finance, HR, and planning. Founded in 2005, Workday delivers financial management, human capital management, and analytics applications designed for the world’s largest companies, educational institutions, and government agencies. Organizations ranging from medium-sized businesses to Fortune 50 enterprises have selected Workday.

Similar Companies Hiring

Scotch Thumbnail
Artificial Intelligence • eCommerce • Fintech • Payments • Retail • Software • Analytics
US
35 Employees
Kepler  Thumbnail
Fintech • Software
New York, New York
6 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account