Risk Manager
Ping Identity Corporation is an active enterprise identity-security company offering the Ping Identity Platform for customer, B2B, workforce, and AI-agent identity use cases.
Maintainer signals as of 9/2/2026
Funding history
Investors
Projects
About Ping Identity Corporation
Ping Identity develops and operates identity and access management and identity-security products, including identity verification, identity management, authentication, authorization, threat protection, fraud prevention, and orchestration. Its offerings support multi-tenant SaaS, dedicated-tenant SaaS, self-managed software, and FedRAMP High deployments.
Skills
Candidate Availability
Required and preferred rules are kept separate and reflect the wording in the original posting.
About the Role
You will lead and improve the information security risk management lifecycle, from identification and assessment through treatment, acceptance, monitoring, and reporting. You will maintain risk registers and governance records, advise stakeholders on mitigation and residual risk, oversee third-party risk activities, support audits and customer assurance, and use metrics to improve programme performance.
Requirements
- Experience leading information security risk assessments and treatment programmes in a complex technology-led organisation
- Knowledge of ISO 27001, SOC 2, ISO 27017, ISO 27018, NIST, HIPAA, or similar frameworks
- Understanding of security and technology risks across systems, networks, applications, cloud services, identity platforms, and business processes
- Experience with AWS, GCP, or Azure
- Experience with risk registers, risk acceptance, exception management, remediation tracking, control validation, and residual-risk reporting
- Experience working with auditors, control owners, executive stakeholders, and cross-functional delivery teams
- Experience with third-party or supplier risk management
- Written and verbal communication skills
- Analytical thinking and problem-solving skills
- Experience using metrics, data, and operational reporting
Responsibilities
- Run and improve the information security risk management lifecycle
- Conduct enterprise, business-unit, project, technology, and third-party risk assessments
- Maintain risk registers, treatment plans, action owners, due dates, and escalation paths
- Define and monitor risk appetite, tolerance indicators, key risk indicators, and management reporting
- Advise leaders and control owners on risk acceptance, mitigation, compensating controls, and escalation
- Improve control design, evidence quality, remediation effectiveness, and control-to-risk connections
- Maintain ISMS, BCMS, and AIMS risk components and governance records
- Coordinate risk-related audit, customer assurance, regulatory, and security-questionnaire inputs
- Oversee supplier risk due diligence, treatment, monitoring, issue management, and exceptions
- Establish risk governance routines, workflows, playbooks, service levels, and escalation processes
- Track remediation commitments and report risk trends, dependencies, and residual exposure
- Use metrics to identify systemic issues and improve risk management effectiveness
- Escalate complex risk matters and support documented decisions
- Coach and share knowledge with GRC and information security colleagues
Benefits
- Generous PTO and holiday schedule
- Parental leave
- Progressive healthcare options
- Retirement programs
- Education reimbursement
- Commuter offset for specific locations
- Employee Resource Groups
- Regular company and team bonding events
- Global volunteering and community initiatives
