[![Image]() Meet Jobicy Copilot — free AI autofill for job applications + remote job alerts ›](#)   [All remote jobs](https://jobicy.com/jobs.md)Open role[![Ping Identity logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/09/63e8d5a6-221.png)](https://jobicy.com/company/ping-identity.md)Remote opportunity at[Ping Identity](https://jobicy.com/company/ping-identity.md)

# Cyber Security Engineer II

Review the role, location requirements, compensation details, and application process before deciding whether this opportunity fits your next career move.

[Apply for this job](#job-application)[View company](https://jobicy.com/company/ping-identity.md)Share11 Sep 2026Published26Listing views1Application actions11 Oct 2026Apply before  Opportunity details

## About this role.

AI SummaryPing Identity is seeking a Cyber Security Engineer II to strengthen enterprise and SaaS security through automation, configuration hardening, detection engineering, and incident response. The role leads incident-response playbooks, coordinates multidisciplinary investigations, assesses system changes, and delivers reliable security engineering solutions. It requires hands-on experience with SIEM and SOAR tooling, cloud platforms such as AWS or GCP, endpoint detection and response, and Kubernetes/Docker environments. The engineer will participate in a weekly on-call rotation and collaborate across teams to advance the security roadmap. Golang, reverse engineering, and threat-intelligence integration are beneficial differentiators.

## Role DNA

A quick view of the complexity, pace, ownership and collaboration implied by the job description.

### Job Complexity

4/5EasyHard

### Pace & Pressure

4/5RelaxedFast-paced

### Autonomy Level

4/5GuidedFull ownership

### Communication Load

4/5IndependentCollaborative

AI insightThis is a mid-level security engineering role combining operational incident response with engineering design, automation, cloud security, and cross-functional leadership. The on-call requirement and responsibility for leading response playbooks increase both technical breadth and operational pressure.

## Salary analysis

Estimated compensation compared with the broader US market for similar roles.

Estimated job medianHighly competitive$145,000US market range$120k–$170k0$187k

AI insightNo actual salary is disclosed. These figures are estimated annual USD base-pay benchmarks for a US-market Cyber Security Engineer II with cloud security, SIEM/SOAR automation, incident response, and on-call responsibilities; actual UK compensation may differ materially.

## Core skills

Skills and capabilities most closely associated with this opportunity.

[Incident Response](https://jobicy.com/jobs?search_keywords=Incident%20Response.md)[Security Automation](https://jobicy.com/jobs?search_keywords=Security%20Automation.md)[SOAR](https://jobicy.com/jobs?search_keywords=SOAR.md)[SIEM](https://jobicy.com/jobs?search_keywords=SIEM.md)[Google Chronicle](https://jobicy.com/jobs?search_keywords=Google%20Chronicle.md)[YARA-L](https://jobicy.com/jobs?search_keywords=YARA-L.md)[AWS](https://jobicy.com/jobs?search_keywords=AWS.md)[GCP](https://jobicy.com/jobs?search_keywords=GCP.md)[Kubernetes](https://jobicy.com/jobs?search_keywords=Kubernetes.md)[Endpoint Detection and Response](https://jobicy.com/jobs?search_keywords=Endpoint%20Detection%20and%20Response.md)

Sample interview questionsDescribe an incident-response playbook you designed or significantly improved.I would explain the triggering conditions, ownership model, evidence-collection steps, escalation paths, containment actions, communications plan, and post-incident review. I would also describe how I tested the playbook through tabletop exercises or real incidents and used lessons learned to reduce response time.

How would you automate a recurring security operations workflow?

I would first map the current process and identify deterministic, high-volume steps such as enrichment, triage, ticket creation, or containment. I would implement the workflow through SOAR tooling or maintainable scripts with logging, error handling, access controls, approval gates for impactful actions, and metrics to measure quality and time saved.

What is your approach to building useful SIEM detections in a cloud environment?

I start with relevant threat scenarios and validate that the required telemetry is complete, normalized, and retained. I then create behavior-focused detections, tune them against expected activity, document investigation guidance, and continuously improve rules using incident findings and threat-intelligence inputs.

How do Kubernetes and container technologies affect incident response?

They require responders to understand ephemeral workloads, orchestration events, image provenance, service accounts, and cluster audit logs. I would preserve relevant logs and artifacts quickly, scope affected namespaces and identities, contain suspicious workloads carefully, and investigate whether the issue originated from an image, configuration, credential, or deployment pipeline.

How do you communicate security risk and remediation priorities to engineering partners?

I communicate the affected asset, realistic attack path, business impact, evidence, and a prioritized remediation recommendation in clear technical and non-technical terms. I collaborate on an achievable plan, define ownership and deadlines, and verify the control is effective after implementation.

About Ping Identity:

At Ping Identity, we believe in making digital experiences both secure and seamless for all users, without compromise. We call this digital freedom. And it’s not just something we provide our customers. It’s something that inspires our company. People don’t come here to join a culture that’s built on digital freedom. They come to cultivate it.

Our intelligent, cloud identity platform lets people shop, work, bank, and interact wherever and however they want. Without friction. Without fear.

While protecting digital identities is at the core of our technology, protecting individual identities is at the core of our culture. [We champion every identity.](https://www.pingidentity.com/en/company/championing-every-identity.html) One of our core values, Respect Individuality, reminds us to celebrate differences so you are empowered to bring your authentic self to work.

We’re headquartered in Denver, Colorado and we have offices and employees around the globe. We serve the largest, most demanding enterprises worldwide, including more than half of the Fortune 100. At Ping Identity, we’re changing the way people and businesses think about cybersecurity, digital experiences, and identity and access management.

As a Ping Cyber Security Engineer II, you will be involved with every facet of our enterprise systems, including our Software-as-a-Service business areas. You will be responsible for helping to build out and deploy security automation, harden security configuration, provide incident response, and more within the Cyber Security Engineering team. Cyber Security Engineers are expected to have a broad understanding of security principles, and be able to communicate and support other teams in the design and deployment of security and robust systems. This role would be well suited to an experienced Security Operations Centre analyst, or Site Reliability Engineer looking to transition into Security Engineering.

You will:

* Lead the design, develop, and implementation of incident response playbooks
* Perform incident response and coordination
* Lead in the assessment of system design and change
* Be part of a weekly on-call rotation
* Lead the design, develop, and implement engineered solutions that are reliable and maintainable
* Support in detection engineering
* Identify areas of the business that require security improvement and translate that into a workable solution
* Influence and align the team’s vision and strategy
* Collaborate cross functionality to support delivery of roadmap items and projects

Requirements

* Experienced with automation within Security Orchestration and Automation Tooling, as well as, bespoke scripting automation
* Experienced with Security Information and Event Management (SIEM) Systems, ideally, Google Chronicle, and YARA-L
* Strong understanding of Cloud (preferred AWS/GCP)
* Experienced working with container technologies, notably, Kubernetes and Docker in a development and incident response context
* Experienced deploying and utilising Endpoint Detection and Response tools
* Experienced leading cross functional projects
* Conducted and coordinated Incident Response involving multi-disciplinary teams

You have an advantage if:

* Golang development and public development projects
* Knowledge of Reverse Engineering
* Threat Intelligence utilisation and integration into security systems

Life at Ping:

We believe in and facilitate a flexible, collaborative work environment. We’re growing quickly, but remain true to the innovative, can-do startup values that got us here. Most importantly, we keep hiring talented, smart, fun, and genuinely nice people because that’s who we want to succeed with every day.

Here are just a few of the things that make Ping special:

* A company culture that empowers you to do your best work.
* Employee Resource Groups that create a sense of belonging for everyone.
* Regular company and team bonding events.
* Competitive benefits and perks.
* Global volunteering and community initiatives

Our Benefits:

* Generous PTO & Holiday Schedule
* Parental Leave
* Progressive Healthcare Options
* Retirement Programs
* Opportunity for Education Reimbursement
* Commuter Offset (Specific locations)

Ping is the collective sum of all our individual experiences, backgrounds and influences and we pride ourselves in growing and learning together. We are committed to building an inclusive and diverse environment where everyone’s individuality is respected and everyone has an Identity. In recruiting for new colleagues, we welcome the unique contributions you can bring and encourage you to be your best self.

We are an Equal Opportunity/Affirmative Action employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex including sexual orientation and gender identity, national origin, disability, protected Veteran Status, or any other characteristic protected by applicable federal, state, or local law.

Show more

[Apply now >](https://jobicy.com/jobs/153056-cyber-security-engineer-ii.md)

>  Annual salary information is not provided for this position. Explore salary ranges for similar roles in our [Salary Directory ›](https://jobicy.com/salaries.md)

*

![Upload CV](data:image/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHdpZHRoPSI2NSIgaGVpZ2h0PSI2NSIgZmlsbD0ibm9uZSIgeG1sbnM6dj0iaHR0cHM6Ly92ZWN0YS5pby9uYW5vIj48ZyBjbGlwLXBhdGg9InVybCgjQSkiPjxwYXRoIGQ9Ik0wIDBINjVWNjVIMFYwWiIgZmlsbD0iIzAyOWFlYiIvPjxnIGZpbGw9IiNmZmYiIHN0cm9rZT0iI2ZmZiIgc3Ryb2tlLXdpZHRoPSIyIj48cGF0aCBkPSJNMzMuMDQ5IDE1LjQ1NGExLjQzIDEuNDMgMCAwIDAtMi4wOTcgMGwtNy41NzkgOC4xNDdhMS4zOCAxLjM4IDAgMCAwIC4wOSAxLjk3MyAxLjQ0IDEuNDQgMCAwIDAgMi4wMDgtLjA4OGw1LjEwOS01LjQ5MnYyMC42MWExLjQxIDEuNDEgMCAwIDAgMS40MjEgMS4zOTdjLjc4NSAwIDEuNDIxLS42MjUgMS40MjEtMS4zOTd2LTIwLjYxbDUuMTA5IDUuNDkyYTEuNDQgMS40NCAwIDAgMCAyLjAwOC4wODggMS4zOCAxLjM4IDAgMCAwIC4wOS0xLjk3M2wtNy41NzktOC4xNDZ6TTE2Ljc2OSAzOC40YzAtLjc3My0uNjItMS40LTEuMzg1LTEuNFMxNCAzNy42MjcgMTQgMzguNHYuMTAybC4yMTUgNi4yMjljLjIyMyAxLjY4LjcwMSAzLjA5NSAxLjgxMyA0LjIxOHMyLjUxIDEuNjA3IDQuMTcyIDEuODMzYzEuNi4yMTggMy42MzYuMjE4IDYuMTYuMjE4aDExLjI4bDYuMTYtLjIxOGMxLjY2Mi0uMjI2IDMuMDYxLS43MDkgNC4xNzItMS44MzNzMS41ODktMi41MzggMS44MTMtNC4yMThDNTAgNDMuMTEzIDUwIDQxLjA1NSA1MCAzOC41MDNWMzguNGMwLS43NzMtLjYyLTEuNC0xLjM4NS0xLjRzLTEuMzg1LjYyNy0xLjM4NSAxLjRsLS4xOSA1Ljk1OGMtLjE4MiAxLjM3LS41MTUgMi4wOTUtMS4wMjYgMi42MTJzLTEuMjI4Ljg1My0yLjU4MyAxLjAzOGMtMS4zOTUuMTktMy4yNDMuMTkzLTUuODkzLjE5M0gyNi40NjJjLTIuNjUgMC00LjQ5OC0uMDAzLTUuODkzLS4xOTMtMS4zNTUtLjE4NC0yLjA3Mi0uNTIxLTIuNTgzLTEuMDM4cy0uODQ0LTEuMjQyLTEuMDI2LTIuNjEyYy0uMTg3LTEuNDEtLjE5MS0zLjI3OS0uMTkxLTUuOTU4eiIvPjwvZz48L2c+PGRlZnM+PGNsaXBQYXRoIGlkPSJBIj48cGF0aCBmaWxsPSIjZmZmIiBkPSJNMCAwaDY1djY1SDB6Ii8+PC9jbGlwUGF0aD48L2RlZnM+PC9zdmc+)

### Upload your resume now

To unlock remote work opportunities and be discovered by global employers.

This job listing has been manually reviewed by the Jobicy Trust & Safety Team for compliance with our posting guidelines, including verification of the company's legitimacy, accuracy of job details, clarity of remote work policy, and absence of misleading or fraudulent content.

Next step

## Apply now.

Follow the employer’s application method and review Jobicy’s safety guidance before sharing personal information.

Keep exploring

## Related remote jobs.

Matched by job category10 related opportunities[Cybersecurity](https://jobicy.com/categories/cybersecurity.md) [Browse all jobs](https://jobicy.com/jobs.md)
*
![Stripe logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2020/10/WRILS-201011073943-272457.png)
Stripe  Sep 11

### [Abuse Research Engineer](https://jobicy.com/jobs/153053-abuse-research-engineer.md)

Who we are About Stripe Stripe is a financial infrastructure platform for businesses. Millions of companies—from the world’s largest enterprises to the most ambitious startups—use Stripe to accept payments, grow…

*
![Luna Physical Therapy logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2026/07/fcb34e841928-221.webp)
Luna Physical Therapy  Sep 11

### [Director , Information Security and IT](https://jobicy.com/jobs/153041-director-information-security-and-it.md)

Luna is seeking a Director of Information Security & IT to lead the strategy, execution, and continuous evolution of the company’s enterprise technology and information security programs. Reporting to the…

*
![CertiK logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2021/03/Jobicy-210308091023-955845.jpg)
CertiK  Sep 10

### [Blockchain Security Expert Intern – AI Track](https://jobicy.com/jobs/152979-blockchain-security-expert-intern-ai-track.md)

About the Company Founded in 2018 by professors of Yale University and Columbia University, CertiK is a pioneer in blockchain security, utilizing best-in-class AI technology to secure and monitor blockchain…

*
![CertiK logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2021/03/Jobicy-210308091023-955845.jpg)
CertiK  Sep 10

### [Blockchain Security Expert – Security Audit Track](https://jobicy.com/jobs/152975-blockchain-security-expert-security-audit-track.md)

About You You’re a self-starter. You believe in tackling the most important problems, even if they are the most difficult problems. You’re comfortable with the unknown and understand that #startuplife…

*
![CertiK logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2021/03/Jobicy-210308091023-955845.jpg)
CertiK  Sep 10

### [Blockchain Security Expert – Chain Security Evaluation Track](https://jobicy.com/jobs/152970-blockchain-security-expert-chain-security-evaluation-track.md)

About You You’re a self-starter who thrives on tackling the toughest and most meaningful problems, even if they are the most difficult problems. You’re comfortable with the unknown and understand…

*
![Synthesia logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2026/06/c69aad11-221.webp)
Synthesia  Sep 10

### [SecOps Security Engineer (Staff-level, L6)](https://jobicy.com/jobs/152968-secops-security-engineer-staff-level-l6.md)

Synthesia is the world’s leading AI video platform for business, used by over 90% of the Fortune 100. Founded in 2017, the company is headquartered in London, with offices and…

*
![CertiK logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2021/03/Jobicy-210308091023-955845.jpg)
CertiK  Sep 10

### [Blockchain Security Expert – Anti Defect Track](https://jobicy.com/jobs/152966-blockchain-security-expert-anti-defect-track.md)

About the Company Founded in 2018 by professors of Yale University and Columbia University, CertiK is a pioneer in blockchain security, utilizing best-in-class AI technology to secure and monitor blockchain…

*
![Fortive logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2026/06/08ee6cc3-221.webp)
Fortive  Sep 10

### [Chief Information Security Officer](https://jobicy.com/jobs/149008-chief-information-security-officer.md)

Position Summary The Chief Information Security Officer (CISO) owns enterprise security strategy, risk management, and compliance for the FAL Group of companies under Fortive (Accruent, Gordian, and ServiceChannel) all of…

*
![Vercel logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/06/a6aded72-221.png)
Vercel  Sep 9

### [Security Engineer, Cloud](https://jobicy.com/jobs/152929-security-engineer-cloud.md)

About Vercel: Vercel is the agentic infrastructure company. We free people and agents to ship what’s next. For more than a decade, Vercel has shaped how the web is built….

*
![Tremendous logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/01/c2bd8be5-221.jpeg)
Tremendous  Sep 9

### [Head of Security](https://jobicy.com/jobs/152862-head-of-security.md)

Tremendous is the global platform built for businesses to send payouts—gift cards and money—to anyone, anywhere, instantly. We’re trusted by 20,000+ organizations, from startups to giants like Atlassian, MIT, and…