SlipstreamJobsFresh Startup & VC-Backed Jobs

Risk Manager

Ping Identity - Remote - Remote - posted 2026-09-15

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Ping Identity is seeking a Risk Manager to lead the identification, assessment, treatment, monitoring, and reporting of information security and business risks across the organization. This role sits at the intersection of enterprise risk management, information security, governance, and compliance, partnering with stakeholders across Security, Engineering, Product, Legal, Privacy, People, Sales, Customer Success, and Finance. You will own the information security risk management lifecycle, including risk identification, assessment, prioritization, treatment, acceptance, monitoring, and reporting. Key responsibilities include running enterprise, business-unit, project, technology, and third-party risk assessments; maintaining risk registers and treatment plans; defining and monitoring risk appetite and key risk indicators; advising senior leaders on risk acceptance and mitigation options; and coordinating risk inputs to internal and external audits, customer assurance activities, and regulatory requests. You will also oversee third-party and supplier risk activities, establish governance routines and workflows, track remediation commitments, use operational data to improve programme performance, and serve as an escalation point for complex risk matters. The role includes contributing to the development of GRC and Information Security team capability through coaching and knowledge sharing. Ping Identity is a cloud identity platform company headquartered in Denver, Colorado, serving more than half of the Fortune 100. The company operates with a flexible, collaborative work environment and values innovation, inclusivity, and digital freedom. REQUIREMENTS: - Demonstrable experience leading information security risk assessments and treatment programmes in a complex, technology-led organization - Experience with and understanding of recognized compliance frameworks and standards such as ISO 27001, SOC 2, ISO 27017, ISO 27018, NIST, HIPAA, or similar, and their relationship with enterprise risk - Strong understanding of security and technology risks across systems, networks, applications, cloud services, identity platforms, and business processes - Experience working with cloud environments such as AWS, GCP, or Azure and the ability to translate technical issues into business risk - Experience with risk registers, risk acceptance, exception management, remediation tracking, control validation, and residual-risk reporting - Experience working with internal and external auditors, control owners, executive stakeholders, and cross-functional delivery teams - Experience with third-party or supplier risk management, including due diligence, contractual risk considerations, and ongoing oversight - Strong written and verbal communication skills, with the ability to tailor risk narratives for technical teams, auditors, executives, customers, and other stakeholders - Strong judgement, prioritization, analytical thinking, and problem-solving skills, especially in ambiguous or cross-functional situations - The ability to challenge constructively, influence without direct authority, and build trust while maintaining appropriate risk discipline - Experience using metrics, data, and operational reporting to improve risk visibility and programme effectiveness BONUS QUALIFICATIONS: - Experience developing enterprise risk reporting, key risk indicators, risk appetite statements, or risk committee materials - Experience leading customer assurance or security questionnaire programmes - Experience with GRC, risk, audit, or compliance platforms and workflow automation - Experience improving risk assessment, evidence collection, control testing, or reporting through automation - Experience working in a SaaS, cloud, identity, or software development environment - Relevant certifications such as CISSP, CISM, CISA, CRISC, CGEIT, ISO 27001 Lead Implementer, or ISO 27001 Lead Auditor - Experience partnering closely with Legal, Sales, Privacy, Engineering, Product, Finance, and Procurement on security and compliance risks

Similar roles