Technical Security Governance Lead - Cloud, Vulnerability Management
WPP is the trusted growth partner for the world’s leading brands.
We unite cutting-edge media intelligence and data solutions, world-class creativity, next-generation production, transformative enterprise solutions and expert strategic counsel in a single company – powered by exceptional talent and our agentic marketing platform, WPP Open, to help our clients navigate change, capture opportunity and deliver transformational growth.
We work with the world's most valuable brands and have global reach across 100+ markets, with deep local expertise.
Our people are the key to our success. We're committed to fostering a culture of creativity, belonging and continuous learning, attracting and developing the brightest talent, and providing exciting career opportunities that help our people grow.
For more information, visit WPP.com.
Why we're hiring:
We are looking for a Technical Security Governance Lead – Cloud & Vulnerability Management to help shape and strengthen the security posture of one of the world’s largest technology and creative ecosystems.
This role is responsible for leading security governance across our cloud and vulnerability management domains. You will define enforceable technical guardrails, minimum baselines, and remediation expectations across global cloud platforms, workloads, identities, and infrastructure.
As a strategic lead, you will provide independent oversight and collaborative challenge to engineering, infrastructure, and product teams—ensuring technical risks are consistently identified, prioritized, and remediated at scale. This is an opportunity to bring clarity, challenge, and strategic oversight to complex technical environments, focusing on overall posture, risk reduction, and governance discipline rather than operational day-to-day patching.
What you'll be doing:
Technical Security Governance & Assurance
- Define and maintain technical governance guardrails, baselines, and posture expectations across cloud and vulnerability domains.
- Translate enterprise policy and risk appetite into actionable, practical technical standards for engineering and product teams.
- Provide independent challenge and strategic oversight where remediation plans or accepted risks exceed WPP's tolerance.
- Support compliance monitoring by partnering with product security to align technical evidence with audits, ISO, SOC, and internal assurance programs.
Cloud Security Governance
- Define mandatory cloud guardrails across multi-cloud environments, focusing on key areas such as identity, logging, encryption, secrets management, and network segmentation.
- Govern multi-cloud posture and monitor systemic control gaps across global tenants, workloads, and environments.
- Define acceptable cloud exposure principles and blast-radius containment strategies to minimize real-world impact.
- Collaborate with platform and infrastructure teams to review architecture, identify exposure, and improve cloud security maturity.
Vulnerability Management Governance
- Own and govern the vulnerability lifecycle across infrastructure, endpoints, cloud workloads, containers, applications, and APIs.
- Define modern, risk-based prioritization models using asset criticality, exposure context, and intelligence sources (e.g., CVSS, EPSS).
- Establish remediation SLAs and expectation models, actively challenging backlog growth and SLA breaches while governing the exception process.
- Validate remediation effectiveness and drive consistency in how global teams address and reduce critical exposures.
Collaboration & Stakeholder Engagement
- Partner closely with Platform Engineering, Infrastructure, Product Security, and Risk teams to maintain aligned risk visibility.
- Enable engineering teams to build securely and move quickly within defined guardrails.
- Help improve how technical risk and security trends are measured, prioritized, and communicated to leadership.
What you'll need:
Experience & Qualifications:
- 5+ years of experience in cloud security, vulnerability management, or technical security governance.
- Strong hands-on or governance knowledge of major cloud platforms (AWS, GCP, and Microsoft Azure).
- Deep understanding of:
- Cloud Native Application Protection Platforms (CNAPP) and Cloud Security Posture Management (CSPM).
- Vulnerability lifecycle management and modern risk-based prioritization.
- Cloud identity, access models, and modern attack paths.
- Strong communication and stakeholder engagement skills, with the ability to influence and challenge engineering and security teams in a matrixed organization.
- Education & Certifications: Bachelor’s degree in Information Security, Computer Science, or a related field (or equivalent experience). CISSP, CISM, CCSP, or CISA certifications are highly desirable.
Personal Attributes:
- Strategic & Impact-Focused: Ability to align technical security initiatives with global business goals.
- Proactive Leader: A strong sense of ownership and accountability, with the confidence to drive corrective action.
- Adaptable & Collaborative: Culturally aware and capable of working effectively with diverse, global teams in a fast-paced environment.
Who you are:
You're open_:_ We are inclusive and collaborative; we encourage the free exchange of ideas; we respect and celebrate diverse views. We are open-minded: to new ideas, new partnerships, new ways of working.
You're optimistic_:_ We believe in the power of creativity, technology and talent to create brighter futures or our people, our clients and our communities. We approach all that we do with conviction: to try the new and to seek the unexpected.
You're extraordinary: we are stronger together: through collaboration we achieve the amazing. We are creative leaders and pioneers of our industry; we provide extraordinary every day.
What we'll give you:
Passionate, inspired people – We aim to create a culture in which people can do extraordinary work.
Scale and opportunity – We offer the opportunity to create, influence and complete projects at a scale that is unparalleled in the industry.
Challenging and stimulating work – Unique work and the opportunity to join a group of creative problem solvers. Are you up for the challenge?
#LI-Hybrid
We believe the best work happens when we're together, fostering creativity, collaboration, and connection. That's why we’ve adopted a hybrid approach, with teams in the office around four days a week. If you require accommodations or flexibility, please discuss this with the hiring team during the interview process.
WPP is an equal opportunity employer and considers applicants for all positions without discrimination or regard to particular characteristics. We are committed to fostering a culture of respect in which everyone feels they belong and has the same opportunities to progress in their careers.