远程工作雷达

风险经理

Risk Manager

开发工程限定地区(需当地身份)
公司pingidentity
薪资未公开
工作地点UK - Remote
地域资格限定地区(需当地身份)
时区要求无特别要求
用工类型未标注
发布时间昨天
数据来源Greenhouse
前往企业招聘页投递 →
注意地域限制:该职位明确限定在 UK - Remote 招聘。如果你是位于中国大陆的求职者,通常需要当地工作身份才能投递,或需与雇主确认是否接受独立合同(Contractor)形式合作。

关于 Ping Identity:

在 Ping Identity,我们相信为所有用户打造安全且无缝的数字体验,而无需妥协。我们称之为数字自由。这不仅是提供给客户的服务,更是激励我们公司的力量。人们来到这里,不是为了加入一个建立在数字自由之上的文化,而是为了培育它。

我们的智能云身份平台让人们可以随时随地购物、工作、银行交易和互动,毫无摩擦,毫无恐惧。

虽然保护数字身份是我们的技术核心,但保护个人身份是我们的文化核心。我们支持每一个身份。我们的核心价值观之一“尊重个性”提醒我们去庆祝差异,让你能够带着真实的自我来上班。

我们总部位于科罗拉多州丹佛市,并在全球设有办公室和员工。我们为全球最大的、最苛刻的企业客户提供服务,包括超过一半的财富100强企业。在 Ping Identity,我们正在改变人们和企业对网络安全、数字体验以及身份和访问管理的思考方式。

作为风险经理,你将负责识别、评估、处理、监控和报告 Ping Identity 内部的信息安全和业务风险。你将帮助确保风险决策一致、基于证据、清晰传达,并与公司的目标、风险偏好和客户信任承诺保持一致。

你将与企业安全、工程、产品、法律、隐私、人力资源、销售、客户成功和财务等各个利益相关方合作,以维护并持续改进 Ping Identity 的风险管理实践和支持性治理。你的工作将连接企业风险管理与信息安全管理系统(ISMS)、业务连续性管理系统(BCMS)、人工智能管理系统(AIMS)、控制环境、客户保证能力和审计准备度。

你将在强大的风险监督与务实执行之间取得平衡,帮助组织理解其最重要的风险,做出明智的权衡,并跟踪风险处理直至可衡量的解决。你还将通过明确的治理流程、有用的指标、有效的利益相关者参与和持续改进,为可扩展的运营模式做出贡献。

你将:

  • 运行并持续改进信息安全
查看英文原文

About Ping Identity:

At Ping Identity, we believe in making digital experiences both secure and seamless for all users, without compromise. We call this digital freedom. And it's not just something we provide our customers. It's something that inspires our company. People don't come here to join a culture that's built on digital freedom. They come to cultivate it.

Our intelligent, cloud identity platform lets people shop, work, bank, and interact wherever and however they want. Without friction. Without fear.

While protecting digital identities is at the core of our technology, protecting individual identities is at the core of our culture. We champion every identity. One of our core values, Respect Individuality, reminds us to celebrate differences so you are empowered to bring your authentic self to work.

We're headquartered in Denver, Colorado and we have offices and employees around the globe. We serve the largest, most demanding enterprises worldwide, including more than half of the Fortune 100. At Ping Identity, we're changing the way people and businesses think about cybersecurity, digital experiences, and identity and access management.

As Risk Manager, you will lead the identification, assessment, treatment, monitoring, and reporting of information security and business risks across Ping Identity. You will help ensure that risk decisions are consistent, evidence-based, clearly communicated, and aligned with the company’s objectives, risk appetite, and customer trust commitments.

You will partner with stakeholders across Enterprise Security, Engineering, Product, Legal, Privacy, People Team, Sales, Customer Success, and Finance to maintain and continuously improve Ping Identity’s risk management practices and supporting governance. Your work will connect enterprise risk management with the Information Security Management System (ISMS), Business Continuity Management System (BCMS), AI Management System (AIMS), control environment, customer assurance capability, and audit readiness.

You will balance strong risk oversight with pragmatic execution, helping the organisation understand its most material risks, make informed trade-offs, and track risk treatment through to measurable resolution. You will also contribute to a scalable operating model through clear governance routines, useful metrics, effective stakeholder engagement, and continuous improvement.

What You’ll Do

You will:

  • Run and continuously improve the information security risk management lifecycle, including risk identification, assessment, prioritisation, treatment, acceptance, monitoring, and reporting.
  • Run enterprise, business-unit, project, technology, and third-party risk assessments, ensuring risks are evaluated consistently and documented with clear business context.
  • Maintain risk registers, risk statements, treatment plans, action owners, due dates, and escalation paths, ensuring material risks remain visible and actively managed.
  • Define and monitor risk appetite, tolerance indicators, key risk indicators, and management reporting that support timely decision-making by security and business leadership.
  • Advise senior leaders and control owners on risk acceptance, mitigation options, compensating controls, residual risk, and escalation requirements.
  • Partner with control owners and business stakeholders to improve control design, evidence quality, remediation effectiveness, and the connection between controls and material risks.
  • Maintain and improve the ISMS, BCMS, and AIMS risk components, including policies, standards, procedures, risk methodologies, control mappings, and governance records.
  • Coordinate risk-related inputs to internal and external audits, customer assurance activities, regulatory requests, and security questionnaires.
  • Oversee third-party and supplier risk activities, including inherent risk assessments, due diligence, risk treatment, ongoing monitoring, issue management, and exception handling.
  • Establish governance routines, workflows, playbooks, service levels, and escalation processes that improve risk visibility, consistency, and operational efficiency.
  • Track remediation and risk treatment commitments, challenge weak or overdue actions, and provide clear reporting on trends, dependencies, and residual exposure.
  • Use operational data and metrics to identify systemic issues, improve programme performance, and demonstrate the effectiveness of risk management activities.
  • Act as an escalation point for complex or ambiguous risk matters and help stakeholders reach practical, defensible, and appropriately documented decisions.
  • Contribute to the development of GRC and Information Security team capability through coaching, knowledge sharing, and continuous improvement.

What We’re Looking For

You have:

  • Demonstrable experience leading information security risk assessments and treatment programmes in a complex, technology-led organisation.
  • Experience with and understanding of recognised compliance frameworks and standards such as ISO 27001, SOC 2, ISO 27017, ISO 27018, NIST, HIPAA, or similar, and their relationship with enterprise risk.
  • Strong understanding of security and technology risks across systems, networks, applications, cloud services, identity platforms, and business processes.
  • Experience working with cloud environments such as AWS, GCP, or Azure and the ability to translate technical issues into business risk.
  • Experience with risk registers, risk acceptance, exception management, remediation tracking, control validation, and residual-risk reporting.
  • Experience working with internal and external auditors, control owners, executive stakeholders, and cross-functional delivery teams.
  • Experience with third-party or supplier risk management, including due diligence, contractual risk considerations, and ongoing oversight.
  • Strong written and verbal communication skills, with the ability to tailor risk narratives for technical teams, auditors, executives, customers, and other stakeholders.
  • Strong judgement, prioritisation, analytical thinking, and problem-solving skills, especially in ambiguous or cross-functional situations.
  • The ability to challenge constructively, influence without direct authority, and build trust while maintaining appropriate risk discipline.
  • Experience using metrics, data, and operational reporting to improve risk visibility and programme effectiveness.

Bonus Points If You Have

  • Experience developing enterprise risk reporting, key risk indicators, risk appetite statements, or risk committee materials.
  • Experience leading customer assurance or security questionnaire programmes.
  • Experience with GRC, risk, audit, or compliance platforms and workflow automation.
  • Experience improving risk assessment, evidence collection, control testing, or reporting through automation.
  • Experience working in a SaaS, cloud, identity, or software development environment.
  • Relevant certifications such as CISSP, CISM, CISA, CRISC, CGEIT, ISO 27001 Lead Implementer, or ISO 27001 Lead Auditor.
  • Experience partnering closely with Legal, Sales, Privacy, Engineering, Product, Finance, and Procurement on security and compliance risks.

Life at Ping:

We believe in and facilitate a flexible, collaborative work environment. We’re growing quickly, but remain true to the innovative, can-do startup values that got us here. Most importantly, we keep hiring talented, smart, fun, and genuinely nice people because that’s who we want to succeed with every day.

Here are just a few of the things that make Ping special:

  • A company culture that empowers you to do your best work.
  • Employee Resource Groups that create a sense of belonging for everyone.
  • Regular company and team bonding events.
  • Competitive benefits and perks.
  • Global volunteering and community initiatives

Our Benefits:

  • Generous PTO & Holiday Schedule
  • Parental Leave
  • Progressive Healthcare Options
  • Retirement Programs
  • Opportunity for Education Reimbursement
  • Commuter Offset (Specific locations)

Ping is the collective sum of all our individual experiences, backgrounds and influences and we pride ourselves in growing and learning together. We are committed to building an inclusive and diverse environment where everyone’s individuality is respected and everyone has an Identity. In recruiting for new colleagues, we welcome the unique contributions you can bring and encourage you to be your best self.

We are an Equal Opportunity/Affirmative Action employer.  All qualified applicants will receive consideration for employment without regard to race, color, religion, sex including sexual orientation and gender identity, national origin, disability, protected Veteran Status, or any other characteristic protected by applicable federal, state, or local law.

本页面信息整理自 Greenhouse,版权归原发布方所有。职位可能随时关闭,投递请以原始页面为准。 本站只做信息聚合展示,不参与招聘流程,也不向求职者收取任何费用。

该公司其他在招职位

客户成功经理

pingidentityUK - Remote2 天前
市场运营限定地区(需当地身份)

← 返回全部职位