Manager, Cyber Security
As a Ping Cyber Security Manager, you will be responsible for Running the day-to-day operational delivery of the Cyber Security Engineering team. You will help ensure the team has the capacity, structure, processes, and capabilities needed to protect our enterprise systems, including our Software-as-a-Service business areas. This role will take ownership of operational coordination, team execution, incident readiness, prioritisation, on-call operations, and continuous improvement across CSE.
You will provide direction across incident response, security automation, detection engineering, secure configuration, and operational security improvements. This role requires a strong technical background, proven Incident Response experience, sound operational judgement, and the ability to turn security priorities into sustainable ways of working for the team.
This role would be well suited to an experienced security leader with a background in Security Operations, Security Engineering, Incident Response, or Site Reliability Engineering who is looking to manage and mature a high-performing cyber security engineering function.
You will:
Run and coordinate the day-to-day operational activities of the Cyber Security Engineering team
Build operational capacity across the team by improving planning, prioritisation, delegation, and delivery practices
Develop and mature team capabilities across incident response, detection engineering, automation, and security operations
Lead, coach, and support members of the Cyber Security Engineering team
Run and mature incident response processes, including the design, development, and implementation of incident response playbooks
Support incident response coordination across multi-disciplinary teams
Provide technical and operational leadership in the assessment of system design, change, and operational risk
Participate in and improve the team’s weekly on-call rotation, including escalation, response quality, handover, and operational readiness
Lead the design, development, and implementation of engineered security solutions that are reliable, maintainable, and scalable
Guide and support detection engineering activities across enterprise and SaaS environments
Identify operational gaps, risks, and areas of the business that require security improvement, then translate them into clear, workable solutions
Influence and align the team’s operational priorities with the wider CSE vision, roadmap, and strategy
Collaborate cross-functionally to support delivery of roadmap items, projects, and security improvements
Partner with engineering, infrastructure, product, and operations teams to improve security outcomes across Ping
Requirements
Experience leading or managing day-to-day security operations, security engineering, incident response, or technical operations teams
Strong background in operational delivery, including prioritisation, planning, delegation, and continuous improvement
Experience building team capacity, improving operational processes, and developing technical capabilities within a security function
Required Incident Response experience, including coordination of complex incidents involving multiple teams
Experience with automation within Security Orchestration and Automation tooling, as well as bespoke scripting automation
Experience with Security Information and Event Management systems, ideally Google Chronicle and YARA-L
Strong understanding of cloud environments, preferably AWS and GCP
Experience working with container technologies, notably Kubernetes and Docker, in development and incident response contexts
Experience deploying, operating, or utilising Endpoint Detection and Response tools
Experience leading cross-functional projects and influencing teams outside of direct reporting lines
Ability to communicate operational priorities, technical risk, and delivery trade-offs clearly to technical and non-technical audiences
Strong judgement, ownership, and decision-making during security incidents and operational escalations
Participation in the team’s on-call rotation is required for this position
You have an advantage if:
You have experience building or leading a Security Operations Centre, Cyber Security Engineering, Detection Engineering, or technical operations function
You have experience defining operating models, team roadmaps, operational maturity plans, or capability development plans
You have experience utilising and integrating threat intelligence into security systems