About the job
Workstate is seeking a Senior Security Engineer to help drive the transition to a multi-tenant platform. This role sits within the Governance, Risk, and Compliance (GRC) team and focuses on closing SOX compliance gaps in the current access control framework. The consultant will also influence the development and oversight of role-based access control (RBAC) for Workstate’s clients.
This is a remote position open to candidates based in Colombia or Argentina. Candidates must have the legal right to work in their country of residence.
What You Will Do
- Lead the migration of access control systems from single-tenant to multi-tenant, ensuring compliance and security are integrated from the start.
- Serve as a principal contributor to the Role Discovery and Governance Program by analyzing and documenting over 200 platform roles for SOX compliance.
- Work closely with GRC, Security, Engineering, and Product teams to build and maintain a centralized Role Catalog that defines all access permissions.
- Document business justifications, ownership, and usage patterns for each role to reduce ambiguity and support future RBAC migrations.
- Help design and implement a formal governance process for the entire role lifecycle, including creation, modification, deprecation, and regular access reviews.
- Assess current roles to find opportunities for simplification and consolidation, recommending the removal of unnecessary or inactive roles.
- Partner with business process owners and engineering teams to align process and control changes with multi-tenancy and compliance requirements.
- Support SOX audits by collaborating with internal and external auditors, assisting with control testing, and helping resolve any identified issues.
