Back to jobs
New

Product Security Engineer - Federal

USA - Remote

About Ping Identity: 

At Ping Identity, we believe in making digital experiences both secure and seamless for all users, without compromise. We call this digital freedom. And it's not just something we provide our customers. It's something that inspires our company. People don't come here to join a culture that's built on digital freedom. They come to cultivate it. 

Our intelligent, cloud identity platform lets people shop, work, bank, and interact wherever and however they want. Without friction. Without fear. 

While protecting digital identities is at the core of our technology, protecting individual identities is at the core of our culture. We champion every identity. One of our core values, Respect Individuality, reminds us to celebrate differences so you are empowered to bring your authentic self to work. 

We're headquartered in Denver, Colorado and we have offices and employees around the globe. We serve the largest, most demanding enterprises worldwide, including more than half of the Fortune 100. At Ping Identity, we're changing the way people and businesses think about cybersecurity, digital experiences, and identity and access management. 

Job Summary:

As a Product Security Engineer working in our Federal accounts, you will gain invaluable experience at a visionary identity security company. The position requires a passion for application security, solving both technical and organizational challenges, with the ability to work in a challenging, distributed and Infrastructure-as-Code development environment, excellent communications skills, and attention to the latest security best practices.

This role focuses on product security (application security) for Ping’s identity platform. Product Security Engineers partner closely with engineering teams to review code, identify vulnerabilities, and improve the security posture of production software across Ping’s revenue-generating products.

We are particularly interested in engineers who developed a passion for security and transitioned into application security or DevSecOps roles. Candidates with a background in software engineering, platform engineering, or DevOps who now focus on security are strongly encouraged to apply.

Responsibilities:

  • Own multiple Security Engineering assignments working with Ping Identity products, processes, and tooling
  • Assist in proposing, developing, and improving Secure Software Development Lifecycle (SSDLC) practices alongside global, high-performance product engineering teams
  • Work with the product teams to perform security design/code reviews and vulnerability assessment and management in an agile environment
  • Perform application security tasks including threat modeling, developer code reviews, consulting, static code analysis, dynamic runtime fuzzing, building custom tools, and automation and exploit development
  • Assist the Federal presales, support, and customer success teams responding to prospect, customer, and field questions related to product and industry security
  • Engage with third-party security consultants for independent security assessments, bug bounties, and penetration testing of the product

Required Qualifications:

  • Ability to meet U.S. citizenship and residency eligibility requirements associated with supporting FedRAMP-regulated environments.
  • 2+ years of application security experience across areas such as API Security, Web Application Security, Enterprise Application Security, and Mobile Application Security
  • 3+ years of developing commercial software products
  • Hands-on experience working with Secure Software Development Lifecycle (SSDLC) security tooling, such as source code scanning tools (SAST) and third-party dependency or software composition analysis (SCA)
  • Strong understanding of modern authentication and identity standards, including OAuth 2.0, OpenID Connect (OIDC), and SAML
  • Ability to review application code for security vulnerabilities, ideally in Java or Go
  • Experience identifying and mitigating vulnerabilities aligned with OWASP Top 10
  • Familiarity with cloud-native application environments, including Google Cloud Platform (GCP) or AWS, and containerized platforms such as Docker and Kubernetes
  • Understanding of networking protocols and modern data center architecture
  • Exceptional problem-solving skills, curiosity about the inner workings of systems, and strong attention to detail and documentation

Preferred Qualifications:

  • Experience in security and compliance for FedRAMP solutions, including understanding of NIST, DoD, and related security standards
  • Security certifications such as CISSP, CSSLP, GIAC, or OSCP
  • Experience with Linux environments, administration, security, internals
  • Experience with identity and access management (e.g. OAuth 2.0, OpenID Connect, SAML 2.0, Active Directory, 2FA/MFA, LDAP, SCIM, FAPI, OpenBanking)
  • Experience with CI/CD in Federal or US government cloud deployment (e.g., AWS GovCloud, Azure, or GCP)
  • Experience with Infrastructure as Code (IaC) tools such as Terraform, CloudFormation, or Ansible
  • Experience in vulnerability management measurement, reporting, and remediation

Salary Range: $133,060-$175,000
In accordance with Colorado’s Equal Pay for Equal Work Act (SB 19-085) the approximate compensation range for this role in Colorado is listed above. Final compensation for this role will be determined by various factors, such as knowledge, skills, and abilities.

Life at Ping:

We believe in and facilitate a flexible, collaborative work environment. We’re growing quickly, but remain true to the innovative, can-do startup values that got us here. Most importantly, we keep hiring talented, smart, fun, and genuinely nice people because that’s who we want to succeed with every day. 

Here are just a few of the things that make Ping special:

  • A company culture that empowers you to do your best work.
  • Employee Resource Groups that create a sense of belonging for everyone.
  • Regular company and team bonding events.
  • Competitive benefits and perks.
  • Global volunteering and community initiatives

Our Benefits: 

  • Generous PTO & Holiday Schedule 
  • Parental Leave
  • Progressive Healthcare Options
  • Retirement Programs
  • Opportunity for Education Reimbursement 
  • Commuter Offset (Specific locations) 

Ping is the collective sum of all our individual experiences, backgrounds and influences and we pride ourselves in growing and learning together. We are committed to building an inclusive and diverse environment where everyone’s individuality is respected and everyone has an Identity. In recruiting for new colleagues, we welcome the unique contributions you can bring and encourage you to be your best self.

We are an Equal Opportunity/Affirmative Action employer.  All qualified applicants will receive consideration for employment without regard to race, color, religion, sex including sexual orientation and gender identity, national origin, disability, protected Veteran Status, or any other characteristic protected by applicable federal, state, or local law.

Create a Job Alert

Interested in building your career at Ping Identity? Get future opportunities sent straight to your email.

Apply for this job

*

indicates a required field

Phone
Resume/CV*

Accepted file types: pdf, doc, docx, txt, rtf

Cover Letter

Accepted file types: pdf, doc, docx, txt, rtf


Select...
Select...
Select...

You understand and agree that as part of the application process Ping Identity may provide certain non-public information that is and must be kept confidential. You agree not to disclose any non-public information required to do so by law.

Select...

By submitting your application, resume, and/or other personal information through this site, you agree that Ping Identity may use your personal information in accordance with Ping Identity's Privacy Statement. Please review and acknowledge that you have read and agree to the Privacy Statement.

Select...
How did you hear about us? *

Voluntary Self-Identification

For government reporting purposes, we ask candidates to respond to the below self-identification survey. Completion of the form is entirely voluntary. Whatever your decision, it will not be considered in the hiring process or thereafter. Any information that you do provide will be recorded and maintained in a confidential file.

As set forth in Ping Identity’s Equal Employment Opportunity policy, we do not discriminate on the basis of any protected group status under any applicable law.

Select...
Select...
Race & Ethnicity Definitions

If you believe you belong to any of the categories of protected veterans listed below, please indicate by making the appropriate selection. As a government contractor subject to the Vietnam Era Veterans Readjustment Assistance Act (VEVRAA), we request this information in order to measure the effectiveness of the outreach and positive recruitment efforts we undertake pursuant to VEVRAA. Classification of protected categories is as follows:

A "disabled veteran" is one of the following: a veteran of the U.S. military, ground, naval or air service who is entitled to compensation (or who but for the receipt of military retired pay would be entitled to compensation) under laws administered by the Secretary of Veterans Affairs; or a person who was discharged or released from active duty because of a service-connected disability.

A "recently separated veteran" means any veteran during the three-year period beginning on the date of such veteran's discharge or release from active duty in the U.S. military, ground, naval, or air service.

An "active duty wartime or campaign badge veteran" means a veteran who served on active duty in the U.S. military, ground, naval or air service during a war, or in a campaign or expedition for which a campaign badge has been authorized under the laws administered by the Department of Defense.

An "Armed forces service medal veteran" means a veteran who, while serving on active duty in the U.S. military, ground, naval or air service, participated in a United States military operation for which an Armed Forces service medal was awarded pursuant to Executive Order 12985.

Select...

Voluntary Self-Identification of Disability

Form CC-305
Page 1 of 1
OMB Control Number 1250-0005
Expires 04/30/2026

Why are you being asked to complete this form?

We are a federal contractor or subcontractor. The law requires us to provide equal employment opportunity to qualified people with disabilities. We have a goal of having at least 7% of our workers as people with disabilities. The law says we must measure our progress towards this goal. To do this, we must ask applicants and employees if they have a disability or have ever had one. People can become disabled, so we need to ask this question at least every five years.

Completing this form is voluntary, and we hope that you will choose to do so. Your answer is confidential. No one who makes hiring decisions will see it. Your decision to complete the form and your answer will not harm you in any way. If you want to learn more about the law or this form, visit the U.S. Department of Labor’s Office of Federal Contract Compliance Programs (OFCCP) website at www.dol.gov/ofccp.

How do you know if you have a disability?

A disability is a condition that substantially limits one or more of your “major life activities.” If you have or have ever had such a condition, you are a person with a disability. Disabilities include, but are not limited to:

  • Alcohol or other substance use disorder (not currently using drugs illegally)
  • Autoimmune disorder, for example, lupus, fibromyalgia, rheumatoid arthritis, HIV/AIDS
  • Blind or low vision
  • Cancer (past or present)
  • Cardiovascular or heart disease
  • Celiac disease
  • Cerebral palsy
  • Deaf or serious difficulty hearing
  • Diabetes
  • Disfigurement, for example, disfigurement caused by burns, wounds, accidents, or congenital disorders
  • Epilepsy or other seizure disorder
  • Gastrointestinal disorders, for example, Crohn's Disease, irritable bowel syndrome
  • Intellectual or developmental disability
  • Mental health conditions, for example, depression, bipolar disorder, anxiety disorder, schizophrenia, PTSD
  • Missing limbs or partially missing limbs
  • Mobility impairment, benefiting from the use of a wheelchair, scooter, walker, leg brace(s) and/or other supports
  • Nervous system condition, for example, migraine headaches, Parkinson’s disease, multiple sclerosis (MS)
  • Neurodivergence, for example, attention-deficit/hyperactivity disorder (ADHD), autism spectrum disorder, dyslexia, dyspraxia, other learning disabilities
  • Partial or complete paralysis (any cause)
  • Pulmonary or respiratory conditions, for example, tuberculosis, asthma, emphysema
  • Short stature (dwarfism)
  • Traumatic brain injury
Select...

PUBLIC BURDEN STATEMENT: According to the Paperwork Reduction Act of 1995 no persons are required to respond to a collection of information unless such collection displays a valid OMB control number. This survey should take about 5 minutes to complete.