
Risk Manager
Posted Sep 15

Posted Sep 15
This is a fully remote position, open to applicants in United Kingdom.
• Oversee the identification, assessment, treatment, monitoring, and reporting of information security and business risks throughout Ping Identity.
• Collaborate with stakeholders from Enterprise Security, Engineering, Product, Legal, Privacy, People Team, Sales, Customer Success, and Finance.
• Integrate enterprise risk management with the ISMS, BCMS, AIMS, control environment, customer assurance capabilities, and audit preparedness.
• Conduct enterprise-wide, business-unit, project, technology, and third-party risk evaluations.
• Maintain risk registers, risk statements, treatment plans, action owners, due dates, and escalation procedures.
• Establish and oversee risk appetite, tolerance indicators, key risk indicators, and management reporting.
• Provide guidance to senior leaders and control owners regarding risk acceptance, mitigation, compensating controls, residual risk, and escalation processes.
• Enhance control design, quality of evidence, remediation effectiveness, and the relationship between controls and significant risks.
• Sustain and enhance the ISMS, BCMS, and AIMS risk components, including policies, standards, procedures, methodologies, mappings, and governance records.
• Coordinate risk-related contributions to audits, customer assurance activities, regulatory requests, and security questionnaires.
• Manage third-party and supplier risk activities.
• Establish governance routines, workflows, playbooks, service levels, and escalation processes.
• Monitor remediation and risk treatment commitments, reporting on trends, dependencies, and residual exposures.
• Utilize operational data and metrics to identify systemic issues and enhance program performance.
• Serve as an escalation point for complex or ambiguous risk issues.
• Contribute to the GRC and Information Security team capabilities through coaching, knowledge sharing, and ongoing improvements.
• Proven experience leading information security risk assessments and treatment programs within a complex, technology-driven organization.
• Familiarity with recognized compliance frameworks and standards such as ISO 27001, SOC 2, ISO 27017, ISO 27018, NIST, HIPAA, or similar.
• Deep understanding of security and technology risks across systems, networks, applications, cloud services, identity platforms, and business processes.
• Experience with AWS, GCP, or Azure, along with the capability to translate technical issues into business risks.
• Knowledge of risk registers, risk acceptance, exception management, remediation tracking, control validation, and residual-risk reporting.
• Experience collaborating with internal and external auditors, control owners, executive stakeholders, and cross-functional delivery teams.
• Background in third-party or supplier risk management, including due diligence, contractual risk considerations, and ongoing oversight.
• Excellent written and verbal communication skills.
• Strong judgment, prioritization, analytical thinking, and problem-solving abilities.
• Capacity to challenge constructively, influence without direct authority, and build trust while maintaining appropriate risk discipline.
• Proficient in using metrics, data, and operational reporting to enhance risk visibility and program effectiveness.
• Flexible, collaborative work environment.
• Company culture that empowers employees to perform at their best.
• Employee Resource Groups.
• Regular company and team bonding events.
• Competitive benefits and perks.
• Global volunteering and community initiatives.
• Generous PTO & Holiday Schedule.
• Parental Leave.
• Progressive Healthcare Options.
• Retirement Programs.
• Opportunity for Education Reimbursement.
• Commuter Offset (specific locations).
Horizon Connect @ Wall BCBSNJ
Experian
Ignition
Experian
Get handpicked remote jobs straight to your inbox weekly.