Do what you love. Love what you do.
At Workday, we help the world’s largest organizations adapt to what’s next by bringing finance, HR, and planning into a single enterprise cloud. We work hard, and we’re serious about what we do. But we like to have fun, too. We put people first, celebrate diversity, drive innovation, and do good in the communities where we live and work.
About the Team
We are continuing to grow our Security Communications and Engagement team as we continue to tackle new responsibilities. This team plays a key role in ensuring that the security culture in Workday remains strong.
About the Role
Workday is looking for an experienced Information Security Training & Awareness Specialist to implement and maintain a security awareness and training program. You will be responsible for educating all employees and contractors on the key threats and risks they face in their jobs and how to defend against them.
As a member of the Security Communications and Engagement team reporting to the Director of Security Governance, you will combine your security knowledge with your knack for creativity to raise the overall security posture of Workday. This position will cover a broad set of activities, including drafting publications, crafting website content, creating timelines and infographics, and planning outreach, awareness, and educational events.
The role will require working cohesively with all teams within Workday and at all levels of the company. If you enjoy a meaningful, collaborative and fast paced environment, we want to meet you!
What you will do:
- Work with other security teams to understand and define security training requirements.
- Develop a training course catalogue and curriculum based on requirements.
- Develop training policies and playbooks for security communications and engagement.
- Develop and deliver targeted security content through various communication methods including intranet postings, training, roadshow, interactive activities, and presentations.
- Design and implement metrics to track the progress of information security awareness within a global context.
- Track completion of training to ensure 100% compliance and document exceptions.
- Recognise opportunities for improvement in areas of responsibility and either take initiative to implement changes or clearly communicate their findings, suggested solutions, and other relevant information to management.
- Support the Security Advocates program.
 
About You
What you should have:
- Bachelor’s degree or higher in a relevant field (information security, communications, marketing, and/or computer science).
- 8+ years’ experience in a security role of which at least 3 should be related to security training and awareness.
- Strong analytical and multi-tasking skills, writing proficiency and visual design skills, problem solving and decision-making skills.
- Outstanding communication and teamwork skills, including experience with international audiences.
- Knowledge of published security standards and frameworks (e.g. NIST CSF, OWASP top 10, ISO 27001, etc.).
- Basic understanding of a wide array of concepts within information security, specific to the reduction of risk through application of best practices.
What we hope you have:
- SSAP or similar certification
- Experience with security training platforms (e.g. Secure Code Warrior, Cofense, LivingSecurity, KnowBe4, etc.)
- Experience working with a large technology organisation
What we offer:
- Career & Capability Growth
- Wellness Program
- Pension
- Health Insurance & Dental Plan
- Employee Assistance Program
- Tax Saver Scheme
- Stock Schemes
- 27 Days Annual Leave
#LI-GS
 - Bachelor’s degree or higher in a relevant field (information security, communications, marketing, and/or computer science).
- 8+ years’ experience in a security role of which at least 3 should be related to security training and awareness.
- Strong analytical and multi-tasking skills, writing proficiency and visual design skills, problem solving and decision-making skills.
- Outstanding communication and teamwork skills, including experience with international audiences.
- Knowledge of published security standards and frameworks (e.g. NIST CSF, OWASP top 10, ISO 27001, etc.).
- Basic understanding of a wide array of concepts within information security, specific to the reduction of risk through application of best practices.