The Workday Security Lead & Architect is a senior technical role responsible for the architecture, governance, and strategic direction of security across the Workday platform. This position serves as the primary Workday Security subject matter expert, owning the overall security model and ensuring security solutions are scalable, sustainable, compliant, and aligned with organizational policies and business needs. The role combines deep hands-on Workday security expertise with architectural and technical leadership, partnering across functional, technical, Information Security, and Internal Audit teams to manage risk and enable appropriate access. The position provides technical direction to Workday Security Administrators and Tier 1 Security Support and serves as the escalation point for complex security issues. This position may be eligible for remote work. However, St. Jude requires all remote employees to: Travel to our Memphis campus for the interview process and/or orientation, if selected Travel to Memphis to work on-site for one week per quarter, or as requested based on business needs, if hired. By applying, you acknowledge and agree to these travel requirements as a condition of employment. This position is remote within approved U.S. locations. Due to state-specific employment regulations, we are unable to consider applicants currently residing in California for remote work; however, candidates based in California who are willing to relocate to an approved location may be considered. Key Responsibilities: Security Architecture & Governance: Own the overall Workday security architecture and security configuration model, including domain security policies, business process security policies, security groups, role-based access, and constrained security. Establish and maintain Workday security architecture standards, design principles, policies, procedures, and technical documentation to support consistent administration, knowledge transfer, and audit readiness. Lead the design and implementation of new and complex security roles, security groups, and access models using least privilege and role-based access principles. Provide architectural review and consultation for security changes across Workday functional areas, integrations, reporting, and emerging capabilities, ensuring designs are scalable, maintainable, compliant, and aligned with the broader Workday architecture. Collaborate with Workday program leadership and senior governance forums as needed to communicate security risks, recommendations, and decisions. Risk, Audit & Compliance: Own the Workday security risk and control strategy, including Segregation of Duties (SoD), Privileged/Sensitive Access (SA), and User Activity monitoring, as well as the design and ongoing effectiveness of preventative and detective controls. Provide leadership and subject matter expertise for internal and external audits involving Workday security and access. Partner with Internal Audit, Information Security, functional teams, and other stakeholders to evaluate findings, determine appropriate remediation, and oversee resolution of security-related risks. Own the strategy, roadmap, and continued evolution of Kainos SmartAudit and other Workday security monitoring and compliance capabilities. Establish standards and oversight for periodic access reviews and security certifications, ensuring appropriate governance, documentation, and remediation. Maintain audit-ready security documentation and evidence supporting organizational control and compliance requirements. Ensure security architecture and practices appropriately protect sensitive and regulated data, including PII and PHI. Security Strategy & Delivery: Lead security impact assessments for Workday R1/R2 releases, new capabilities, projects, integrations, and functional changes; identify required security changes, risks, dependencies, and remediation. Provide security architecture and design leadership throughout the lifecycle of Workday initiatives, from requirements and solution design through testing and deployment. Design, configure, test, and implement complex Workday security solutions across domain and business process security, security groups, intersection security, integration security, and other advanced configurations. Lead security-related projects and initiatives, coordinating activities across functional, technical, audit, and Information Security stakeholders. Technical Leadership & Security Operations: Serve as the senior Workday Security subject matter expert and escalation point for complex security issues, troubleshooting, and design decisions. Perform hands-on Workday security administration and complex technical work while providing technical direction, coaching, and knowledge transfer to Workday Security Administrators, Tier 1 Security Support, and other team members supporting Workday security. Oversee the effectiveness and consistency of Workday security administration, ensuring operational activities align with established architecture, standards, and controls. Identify opportunities for continuous improvement, automation, standardization, and simplification of Workday security processes and controls. Minimum Education and/or Training: Bachelor's degree in computer science, data science, information science, business, or related field required. Master's degree preferred. Minimum Experience: Minimum requirement: 5+ progressive years of IT experience including strong database design, data architecture and data transform processes. Experience in data architecture and design. Some experience with data governance including implementation of a data governance framework. Experience with leading industrial tools for data lake, big data, or ETL. Some experience and knowledge in Master Data Management and Data Dictionary Standards. Experience providing technical guidance and mentorship within Data Engineering. Proven performance in earlier role/comparable role. Highly Preferred Experience: 5+ years of hands-on Workday Security experience, including demonstrated experience in a senior, lead, or architectural capacity. Workday Security certification. Deep expertise across the Workday security framework, including domain and business process security, security groups, SoD, intersection/segment/contextual security, integration security (ISU/ISSG), and data privacy/sensitive access. Demonstrated experience designing scalable security solutions and assessing security impacts across Workday implementations, enhancements, releases, integrations, and functional areas. Experience supporting security audits, access reviews, compliance activities, and remediation, with strong knowledge of least privilege, role-based access, SoD, and security risk management principles. Preferred Experience: Experience supporting Workday security within healthcare or another highly regulated environment. Experience with Kainos SmartAudit or similar Workday security governance and compliance tools. Broad experience across multiple Workday functional areas such as HCM, Financials, Supply Chain, PRISM, Adaptive Planning, Payroll, Time Tracking, Absence, and Reporting. Experience with SSO/SAML, authentication, ServiceNow/ITIL processes, and technical leadership or mentoring. Special Skills, Knowledge and Abilities: Strong analytical and problem-solving skills with demonstrated ability to troubleshoot complex security and access issues. Strong communication and collaboration skills with the ability to translate complex security concepts, work across organizational boundaries, and influence decisions without direct authority. Ability to think critically, draw insights and connect the dots. Openness to change and adapting to changing times with resilience and flexibility. Able to draw insights from different sets of data and quickly understand why issues are happening. Solves problems quickly by identifying the root causes. Encourages others to see the opportunities ahead amidst changing circumstances even when the details have not been finalized. Remains calm in challenging and uncertain times by focusing on the end goals and solving problems. Defuses any unforeseen developments and problems by leveraging data analysis and insights. Maintains focus on goals. Drives engagement and ownership for group to deliver ambitious results and solutions. Skills in prioritizing and addressing needs from multiple customers/stakeholders with a focus on efficient, responsive, high quality/fit-for-purpose delivery. Ability to take accountability for work outcomes and proactively account for interdependencies across adjacent work areas. Thinks holistically and plans for interdependencies and impact of work and processes with other teams within and outside of IT. Always focused on quality, costs, sustainability from a complete ownership mindset and approach. Demonstrates a strong collaborative style with emotional empathy and is able to work/ negotiate through challenging situations Compensation In recognition of certain U.S. state and municipal pay transparency laws, St. Jude is including a reasonable estimate of the compensation range for this role. This is an estimate offered in good faith and a specific salary offer takes into account factors that are considered in making compensation decisions including but not limited to skill sets, experience and training, licensure and certifications, and other business and organizational needs. It is not typical for an individual to be hired at or near the top of the salary range and compensation decisions are dependent on the facts and circumstances of each case. A reasonable estimate of the current salary range is $94,640 - $169,520 per year for the role of Workday Security Lead & Architect. Explore our exceptional benefits ! We are committed to a human-centered hiring experience. Technology may support portions of our process, but recruiting decisions involve human review and engagement. Learn more about our approach to AI . St. Jude is an Equal Opportunity Employer No Search Firms St. Jude Children's Research Hospital does not accept unsolicited assistance from search firms for employment opportunities. Please do not call or email. All resumes submitted by search firms to any employee or other representative at St. Jude via email, the internet or in any form and/or method without a valid written search agreement in place and approved by HR will result in no fee being paid in the event the candidate is hired by St. Jude.
Lead Enterprise Architect / FEAF-Certified Architect- FCC
TechSur Solutions
Lead IT Enterprise Security Architect
Honeywell
Technical Lead Chief Security Architect / Engineer
9th Way Insignia
Solution Architect / Technical Lead - DOI
TechSur Solutions
Lead Solutions Architect - DERMS
Gevernova
Lead Enterprise Architect
Humana