Every day, drivers get back on the road thanks to our client. As one of the largest names in the automotive collision repair industry, this organization has spent decades putting vehicles back together, and it is still growing fast across hundreds of locations in the U.S. and Canada. It does it with a culture built on teamwork, integrity, and giving people room to grow.
Behind that scale is a Workday environment that runs Finance and HR for a workforce in the thousands. Keeping it secure, compliant, and audit-ready is not a side task here. It is the whole job, and our client is looking for the person who owns it.
That's where you come in.
The Role
Our client is looking for a Workday Security Developer on a contract basis to take end-to-end ownership of Workday security across Financials and HCM. You will design the security model, harden access, and stand behind it when the auditors show up. This is a role for someone who makes the security design decisions, not just someone who works the ticket queue.
You will partner closely with internal audit, compliance, and risk, translating business risk into technical configuration and explaining your reasoning to people who do not live in Workday all day. If SOX controls, Segregation of Duties, and privileged access are the problems you like to solve, this is your kind of seat.
What You'll Own
- The security model. Design, build, test, and deploy Workday security groups (role based, user based, intersection, segment based, and more) across the Financials and HCM modules.
- Compliance and audit. Keep configurations aligned with SOX controls and internal audit standards, and produce the documentation and evidence that make audits go smoothly.
- Segregation of Duties. Analyze, implement, and monitor SOD matrices so conflicting access gets caught before it becomes risk.
- Privileged access. Define, restrict, and monitor high-risk and privileged access, including Workday administrative accounts, with clear protocols for emergency and temporary elevation.
- The access lifecycle. Run the User Access Request process end to end, from approvals and provisioning to timely de-provisioning, and use Kainos automated testing and compliance tooling to audit configurations and track control deficiencies.
What You Bring
- 5+ years of hands-on experience as a Workday Security Administrator or Developer, with a track record of owning security design decisions rather than just executing tickets.
- A strong background in corporate governance, SOX compliance, SOD analysis, and IT General Controls, ideally from a regulated or audit-heavy environment.
- Fluency across both Financials and HCM security domains, with the comfort to translate business risk into technical configuration.
- Experience partnering directly with internal audit, compliance, or risk teams, and communicating security posture to non-technical stakeholders.
- A methodical, documentation-first approach, because audit evidence and clear reporting matter as much as the configuration work itself.
- Bonus points for hands-on Kainos Smart Audit or Smart Shield experience, building SOD rulesets from the ground up, or carrying a Workday tenant through a full SOX audit cycle start to finish.
Why This Role, Why Now
Our client is scaling, and scale is exactly what turns access control from a checkbox into a real discipline. This is a chance to own Workday security at an organization that takes compliance seriously, work shoulder to shoulder with audit and risk leadership, and leave the environment measurably tighter than you found it. If you want your fingerprints on the security posture of a company this size, this is the engagement.
Sound Like You?
Apply here or reach out directly. If you know someone who lives and breathes Workday security, send them our way.
---
MMD Services Inc. is an equal opportunity employer. All applicants are considered for all positions without regard to race, religion, color, sex, gender, sexual orientation, pregnancy, age, national origin, ancestry, physical/mental disability, medical condition, military/veteran status, genetic information, marital status, ethnicity, alienage, or any other protected classification, in accordance with applicable federal, state, and local laws.