Base Career helps you apply smarter for this job.
Key skills for this role
You will:
Run and continuously improve the information security risk management lifecycle, including risk identification, assessment, prioritisation, treatment, acceptance, monitoring, and reporting.
Run enterprise, business-unit, project, technology, and third-party risk assessments, ensuring risks are evaluated consistently and documented with clear business context.
Maintain risk registers, risk statements, treatment plans, action owners, due dates, and escalation paths, ensuring material risks remain visible and actively managed.
Define and monitor risk appetite, tolerance indicators, key risk indicators, and management reporting that support timely decision-making by security and business leadership.
Advise senior leaders and control owners on risk acceptance, mitigation options, compensating controls, residual risk, and escalation requirements.
Partner with control owners and business stakeholders to improve control design, evidence quality, remediation effectiveness, and the connection between controls and material risks.
Maintain and improve the ISMS, BCMS, and AIMS risk components, including policies, standards, procedures, risk methodologies, control mappings, and governance records.
Coordinate risk-related inputs to internal and external audits, customer assurance activities, regulatory requests, and security questionnaires.
Oversee third-party and supplier risk activities, including inherent risk assessments, due diligence, risk treatment, ongoing monitoring, issue management, and exception handling.
Establish governance routines, workflows, playbooks, service levels, and escalation processes that improve risk visibility, consistency, and operational efficiency.
Track remediation and risk treatment commitments, challenge weak or overdue actions, and provide clear reporting on trends, dependencies, and residual exposure.
Use operational data and metrics to identify systemic issues, improve programme performance, and demonstrate the effectiveness of risk management activities.
Skip the repetitive application forms
Install the Base Career Chrome Extension and autofill job applications across major job boards with your profile.
Trusted by over 500,000 job seekers on Base Career
More from this employer
Denver, USA
Denver, USA
Denver, USA
Austin, USA
London, GBR
Austin, USA
Paris, USA
London, GBR
Act as an escalation point for complex or ambiguous risk matters and help stakeholders reach practical, defensible, and appropriately documented decisions.
Contribute to the development of GRC and Information Security team capability through coaching, knowledge sharing, and continuous improvement.
You have:
Demonstrable experience leading information security risk assessments and treatment programmes in a complex, technology-led organisation.
Experience with and understanding of recognised compliance frameworks and standards such as ISO 27001, SOC 2, ISO 27017, ISO 27018, NIST, HIPAA, or similar, and their relationship with enterprise risk.
Strong understanding of security and technology risks across systems, networks, applications, cloud services, identity platforms, and business processes.
Experience working with cloud environments such as AWS, GCP, or Azure and the ability to translate technical issues into business risk.
Experience with risk registers, risk acceptance, exception management, remediation tracking, control validation, and residual-risk reporting.
Experience working with internal and external auditors, control owners, executive stakeholders, and cross-functional delivery teams.
Experience with third-party or supplier risk management, including due diligence, contractual risk considerations, and ongoing oversight.
Strong written and verbal communication skills, with the ability to tailor risk narratives for technical teams, auditors, executives, customers, and other stakeholders.
Strong judgement, prioritisation, analytical thinking, and problem-solving skills, especially in ambiguous or cross-functional situations.
The ability to challenge constructively, influence without direct authority, and build trust while maintaining appropriate risk discipline.
Experience using metrics, data, and operational reporting to improve risk visibility and programme effectiveness.
Experience developing enterprise risk reporting, key risk indicators, risk appetite statements, or risk committee materials.
Experience leading customer assurance or security questionnaire programmes.
Experience with GRC, risk, audit, or compliance platforms and workflow automation.
Experience improving risk assessment, evidence collection, control testing, or reporting through automation.
Experience working in a SaaS, cloud, identity, or software development environment.
Relevant certifications such as CISSP, CISM, CISA, CRISC, CGEIT, ISO 27001 Lead Implementer, or ISO 27001 Lead Auditor.
Experience partnering closely with Legal, Sales, Privacy, Engineering, Product, Finance, and Procurement on security and compliance risks.
Life at Ping:
We believe in and facilitate a flexible, collaborative work environment. We’re growing quickly, but remain true to the innovative, can-do startup values that got us here. Most importantly, we keep hiring talented, smart, fun, and genuinely nice people because that’s who we want to succeed with every day.
Here are just a few of the things that make Ping special:
A company culture that empowers you to do your best work.
Employee Resource Groups that create a sense of belonging for everyone.
Regular company and team bonding events.
Competitive benefits and perks.
Global volunteering and community initiatives
Our Benefits:
Generous PTO & Holiday Schedule
Parental Leave
Progressive Healthcare Options
Retirement Programs
Opportunity for Education Reimbursement
Commuter Offset (Specific locations)
Ping is the collective sum of all our individual experiences, backgrounds and influences and we pride ourselves in growing and learning together. We are committed to building an inclusive and diverse environment where everyone’s individuality is respected and everyone has an Identity. In recruiting for new colleagues, we welcome the unique contributions you can bring and encourage you to be your best self.
We are an Equal Opportunity/Affirmative Action employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex including sexual orientation and gender identity, national origin, disability, protected Veteran Status, or any other characteristic protected by applicable federal, state, or local law.
Identity security platform enabling enterprises to protect digital identities and deliver frictionless, secure access across applications.
Visit company websiteJobs and hiring trendsManager
Remote
Apply faster on company sites with our extension.