About the Role
As a Staff Business Systems Analyst – Workday Security & ITGC Lead, you will be the system administrator and technical owner responsible for Workday security architecture, tenant configurations, business process engineering, and key reporting infrastructure. This deeply technical, hands-on role ensures system-level changes and business processes adhere to strict security and SOX standards.
Responsibilities
- Architect, configure, and maintain Workday security models, ensuring alignment with security and compliance controls.
- Manage and audit Workday integration system users, API service accounts, and elevated access permissions.
- Design, build, and maintain Workday Key Reports (IPEs) for financial and operational controls.
- Act as the technical gatekeeper for Workday tenant configuration changes and updates.
- Design, operationalize, and maintain IT Automated Controls (ITACs) and system-enforced validation rules.
- Serve as the primary technical liaison for internal and external audits, leading walkthroughs and demonstrating technical configurations.
- Perform technical root-cause analysis for control failures and design remediation plans.
- Apply AI/LLM tooling to streamline systems evidence collection and audit documentation.
- Partner with cross-functional teams and mentor other BSAs on Workday configuration and compliance.
Requirements
- Bachelor's degree in Information Technology, Computer Science, Management Information Systems, Accounting, or equivalent practical experience.
- 7+ years in business systems analysis, IT systems administration, or IT compliance.
- 4+ years of direct, hands-on experience configuring and administering Workday.
- Proven proficiency in configuring Workday Security and developing advanced Custom Reports and Calculated Fields.
- Practical experience managing ITGC domains, including logical access provisioning, privileged access reviews, and service account management.
- Demonstrated experience independently leading ITGC and ITAC technical walkthroughs with external audit teams.
- Strong understanding of how business process configurations map to system controls and risk mitigation.
- Proven track record of performing exposure analysis, lookback assessments, and technical remediation.
- Experience or practical interest in utilizing AI/LLM automation tools.
- Relevant certifications strongly preferred (e.g., Workday Pro Security, Workday Pro Reporting, CISA, CISSP).
Skills
- Workday Security
- Workday tenant configurations
- Workday business process engineering
- Workday reporting infrastructure
- Workday security architecture
- Domain policies
- Business process security
- Constraint groups
- Segmented security
- Service account governance
- SOX ITGC
- Logical access reviews
- Key Reporting (IPEs)
- Custom reports
- Calculated fields
- Change management
- SDLC protocols
- IT Automated Controls (ITACs)
- Job monitoring
- Root-cause analysis
- AI/LLM tooling
- Data governance
- Auditability standards
Location
- Austin, Texas
Work Type
- Full-time
Experience Level
- 7+ years
- 4+ years
Education Level
- Bachelor's degree
Salary/Compensations
- 127,680.00 - 175,560.00 USD Annual
Benefits
- Equity Compensation
- Bonus Incentive Compensation
About the Company
- Procore is committed to offering competitive, fair, and commensurate compensation.
Equal Opportunity
- Procore will consider for employment all qualified applicants, including those with arrest or conviction records, in accordance with the requirements of applicable federal, state, and local laws, including the City of Los Angeles’ Fair Chance Initiative for Hiring Ordinance, the Los Angeles County Fair Chance Ordinance for Employers, and the California Fair Chance Act.
- A criminal history may have a direct, adverse, and negative relationship on the following job duties, potentially resulting in the withdrawal of the conditional offer of employment: 1. appropriately managing, accessing, and handling confidential information including proprietary and trade secret information, as well as accessing Procore's information technology systems and platforms; 2. interacting with and occasionally having unsupervised contact with internal/external customers, stakeholders, and/or colleagues; and 3. exercising sound judgment.
