At a Glance
- Tasks: Lead risk management initiatives to protect digital identities and ensure business continuity.
- Company: Join Ping Identity, a leader in secure digital experiences and innovative technology.
- Benefits: Enjoy generous PTO, flexible work, healthcare options, and education reimbursement.
- Other info: Collaborative culture with opportunities for growth and community involvement.
- Why this job: Make a real impact on cybersecurity while working in a dynamic, inclusive environment.
- Qualifications: Experience in information security risk assessments and strong communication skills required.
The predicted salary is between 72000 - 88000 £ per year.
About Ping Identity: At Ping Identity, we believe in making digital experiences both secure and seamless for all users, without compromise. We call this digital freedom. And it's not just something we provide our customers. It's something that inspires our company. People don't come here to join a culture that's built on digital freedom. They come to cultivate it. Our intelligent, cloud identity platform lets people shop, work, bank, and interact wherever and however they want. Without friction. Without fear.
While protecting digital identities is at the core of our technology, protecting individual identities is at the core of our culture. We champion every identity. One of our core values, Respect Individuality, reminds us to celebrate differences so you are empowered to bring your authentic self to work. We're headquartered in Denver, Colorado and we have offices and employees around the globe. We serve the largest, most demanding enterprises worldwide, including more than half of the Fortune 100. At Ping Identity, we're changing the way people and businesses think about cybersecurity, digital experiences, and identity and access management.
As Risk Manager, you will lead the identification, assessment, treatment, monitoring, and reporting of information security and business risks across Ping Identity. You will help ensure that risk decisions are consistent, evidence-based, clearly communicated, and aligned with the company’s objectives, risk appetite, and customer trust commitments. You will partner with stakeholders across Enterprise Security, Engineering, Product, Legal, Privacy, People Team, Sales, Customer Success, and Finance to maintain and continuously improve Ping Identity’s risk management practices and supporting governance. Your work will connect enterprise risk management with the Information Security Management System (ISMS), Business Continuity Management System (BCMS), AI Management System (AIMS), control environment, customer assurance capability, and audit readiness. You will balance strong risk oversight with pragmatic execution, helping the organisation understand its most material risks, make informed trade-offs, and track risk treatment through to measurable resolution. You will also contribute to a scalable operating model through clear governance routines, useful metrics, effective stakeholder engagement, and continuous improvement.
What You’ll Do
- Run and continuously improve the information security risk management lifecycle, including risk identification, assessment, prioritisation, treatment, acceptance, monitoring, and reporting.
- Run enterprise, business-unit, project, technology, and third-party risk assessments, ensuring risks are evaluated consistently and documented with clear business context.
- Maintain risk registers, risk statements, treatment plans, action owners, due dates, and escalation paths, ensuring material risks remain visible and actively managed.
- Define and monitor risk appetite, tolerance indicators, key risk indicators, and management reporting that support timely decision-making by security and business leadership.
- Advise senior leaders and control owners on risk acceptance, mitigation options, compensating controls, residual risk, and escalation requirements.
- Partner with control owners and business stakeholders to improve control design, evidence quality, remediation effectiveness, and the connection between controls and material risks.
- Maintain and improve the ISMS, BCMS, and AIMS risk components, including policies, standards, procedures, risk methodologies, control mappings, and governance records.
- Coordinate risk-related inputs to internal and external audits, customer assurance activities, regulatory requests, and security questionnaires.
- Oversee third-party and supplier risk activities, including inherent risk assessments, due diligence, risk treatment, ongoing monitoring, issue management, and exception handling.
- Establish governance routines, workflows, playbooks, service levels, and escalation processes that improve risk visibility, consistency, and operational efficiency.
- Track remediation and risk treatment commitments, challenge weak or overdue actions, and provide clear reporting on trends, dependencies, and residual exposure.
- Use operational data and metrics to identify systemic issues, improve programme performance, and demonstrate the effectiveness of risk management activities.
- Act as an escalation point for complex or ambiguous risk matters and help stakeholders reach practical, defensible, and appropriately documented decisions.
- Contribute to the development of GRC and Information Security team capability through coaching, knowledge sharing, and continuous improvement.
What We’re Looking For
- Demonstrable experience leading information security risk assessments and treatment programmes in a complex, technology-led organisation.
- Experience with and understanding of recognised compliance frameworks and standards such as ISO 27001, SOC 2, ISO 27017, ISO 27018, NIST, HIPAA, or similar, and their relationship with enterprise risk.
- Strong understanding of security and technology risks across systems, networks, applications, cloud services, identity platforms, and business processes.
- Experience working with cloud environments such as AWS, GCP, or Azure and the ability to translate technical issues into business risk.
- Experience with risk registers, risk acceptance, exception management, remediation tracking, control validation, and residual-risk reporting.
- Experience working with internal and external auditors, control owners, executive stakeholders, and cross-functional delivery teams.
- Experience with third-party or supplier risk management, including due diligence, contractual risk considerations, and ongoing oversight.
- Strong written and verbal communication skills, with the ability to tailor risk narratives for technical teams, auditors, executives, customers, and other stakeholders.
- Strong judgement, prioritisation, analytical thinking, and problem-solving skills, especially in ambiguous or cross-functional situations.
- The ability to challenge constructively, influence without direct authority, and build trust while maintaining appropriate risk discipline.
- Experience using metrics, data, and operational reporting to improve risk visibility and programme effectiveness.
Bonus Points If You Have
- Experience developing enterprise risk reporting, key risk indicators, risk appetite statements, or risk committee materials.
- Experience leading customer assurance or security questionnaire programmes.
- Experience with GRC, risk, audit, or compliance platforms and workflow automation.
- Experience improving risk assessment, evidence collection, control testing, or reporting through automation.
- Experience working in a SaaS, cloud, identity, or software development environment.
- Relevant certifications such as CISSP, CISM, CISA, CRISC, CGEIT, ISO 27001 Lead Implementer, or ISO 27001 Lead Auditor.
- Experience partnering closely with Legal, Sales, Privacy, Engineering, Product, Finance, and Procurement on security and compliance risks.
Life at Ping: We believe in and facilitate a flexible, collaborative work environment. We’re growing quickly, but remain true to the innovative, can-do startup values that got us here. Most importantly, we keep hiring talented, smart, fun, and genuinely nice people because that’s who we want to succeed with every day.
Here are just a few of the things that make Ping special:
- A company culture that empowers you to do your best work.
- Employee Resource Groups that create a sense of belonging for everyone.
- Regular company and team bonding events.
- Competitive benefits and perks.
- Global volunteering and community initiatives.
Our Benefits:
- Generous PTO & Holiday Schedule
- Parental Leave
- Progressive Healthcare Options
- Retirement Programs
- Opportunity for Education Reimbursement
- Commuter Offset (Specific locations)
Ping is the collective sum of all our individual experiences, backgrounds and influences and we pride ourselves in growing and learning together. We are committed to building an inclusive and diverse environment where everyone’s individuality is respected and everyone has an Identity. In recruiting for new colleagues, we welcome the unique contributions you can bring and encourage you to be your best self. We are an Equal Opportunity/Affirmative Action employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex including sexual orientation and gender identity, national origin, disability, protected Veteran Status, or any other characteristic protected by applicable federal, state, or local law.
Risk Manager employer: Ping Identity
Ping Identity is an exceptional employer that fosters a collaborative and innovative work culture, perfect for those passionate about cutting-edge technology in AI and security. Employees benefit from comprehensive growth opportunities, competitive compensation, and a supportive environment that encourages creativity and teamwork, all while working in a vibrant location that promotes a healthy work-life balance.
StudySmarter Expert Advice🤫
We think this is how you could land Risk Manager
✨Join Compliance Communities
Get involved in compliance and risk communities — both online and offline. Look for forums, LinkedIn groups, or even local meetups where compliance pros hang out. You never know who might drop a job opportunity your way!
✨Attend Industry Conferences
Keep an eye out for compliance and risk management conferences and workshops in your area. These events are a goldmine for networking, and they often have job boards or recruiters on-site looking for new talent. Plus, it’s a chance to learn what's trending in the field.
✨Leverage Your University Career Services
If you’ve recently graduated or are still studying, head over to your university's career services. Many companies, including those in compliance, actively recruit fresh talent through these services, so make sure you tap into that resource.
✨Showcase Your Knowledge Online
Start writing articles or blog posts about compliance topics that interest you. Share them on platforms like LinkedIn to demonstrate your knowledge and passion. This not only builds your presence in the field but can also catch the attention of companies like Ping Identity looking for candidates who are engaged and informed.
We think you need these skills to ace Risk Manager
Some tips for your application 🫡
Show Your Understanding of Compliance:In the compliance-risk field, it's super important to showcase your understanding of regulations and risk management frameworks. Highlight any relevant coursework, certifications (like ICA or AML), or even projects that demonstrate your knowledge and commitment to this area. We want to see how you can navigate this complex landscape!
Quantify Your Achievements:When detailing your experience, try to quantify your achievements. For example, if you've previously worked on a project that improved compliance metrics or reduced risk exposure, give us the numbers! This data-driven approach really stands out to hiring managers in compliance-risk roles.
Tailor Your CV to Reflect Relevant Skills:Make sure your CV highlights skills that are particularly relevant to compliance, like attention to detail, analytical thinking, and report writing. Ensure these are easy to spot – consider using bullet points to break down your responsibilities and achievements for maximum impact!
Craft a Motivating Cover Letter:In your cover letter, let us know why you’re excited about the compliance-risk role at Ping Identity. Share what motivates you about compliance, and how you believe you can contribute to our mission. This is your chance to showcase not only your skills but also your passion for this important field!
How to prepare for a job interview at Ping Identity
✨Master the Regulations
Brush up on key compliance regulations relevant to the industry you're applying to. Familiarising yourself with specific laws and frameworks used in your field will give you an edge during technical questions. Show that you’re not just aware of them but can also apply them—think real-life scenarios!
✨Show Your Analytical Skills
Compliance roles really focus on analytical skills, so be prepared for case studies or situational questions during the interview. We've got to demonstrate how we approach risk assessments or compliance audits, possibly drawing on examples from past experiences or university projects. Bring some thoughtful case scenarios to discuss!
✨Know Your Tools
Get comfortable with commonly used compliance software and tools. Familiarity with platforms like RSA or MetricStream can really impress during your interview, as it shows you're ready to hit the ground running. If you’ve had any experience with them, make sure to highlight that!
✨Align with Company Culture
Since it's a full-time position, show your long-term commitment and interest in the company’s mission and values. Dive into how your ethics and professional philosophy align with Ping Identity’s stance on compliance. A shared vision can really resonate with interviewers looking for fit as much as skill!