Sobre esta vaga de Head of Security Incident Management na WPP
WPP is the trusted growth partner for the world’s leading brands.
We unite cutting-edge media intelligence and data solutions, world-class creativity, next-generation production, transformative enterprise solutions and expert strategic counsel in a single company – powered by exceptional talent and our agentic marketing platform, WPP Open, to help our clients navigate change, capture opportunity and deliver transformational growth.
We work with the world's most valuable brands and have global reach across 100+ markets, with deep local expertise.
Our people are the key to our success. We're committed to fostering a culture of creativity, belonging and continuous learning, attracting and developing the brightest talent, and providing exciting career opportunities that help our people grow.
For more information, visit WPP.com.
Why we're hiring:
The Head of Security Incident Management is responsible for leading and maturing WPP's global Security Incident Management capability, providing strategic, operational, and technical leadership across the entire incident response lifecycle.
Reporting directly to the Director of Operational Security, this role owns the Security Incident Management function, including Security Incident Management Leads, Senior Security Incident Responders, and Security Incident Responders. The position ensures that security incidents are managed consistently, effectively, and in accordance with WPP policies, regulatory obligations, and operational standards.
The role evolves and scales incident response capabilities in alignment with WPP's Autonomic Security Operations (ASO) strategy and automation-first operating model. This includes oversight of people, process, technology, governance, service performance, and continuous improvement.
What you'll be doing:
- Own the end-to-end Security Incident Management capability across WPP.
- Lead and develop Security Incident Management Leads, Senior Security Incident Responders, and Security Incident Responders.
- Establish the strategic direction for incident response, aligned to Operational Security objectives and the wider ASO roadmap.
- Maintain overall accountability for the management of critical and major security incidents.
- Act as the senior escalation authority for Sev1 and Sev2 security incidents.
- Ensure appropriate incident governance, communication, decision-making, and stakeholder engagement throughout the incident lifecycle.
- Provide executive-level updates during significant cyber security incidents and crisis situations.
- Define and own the Security Incident Management strategy, roadmap, and maturity objectives.
- Develop a globally consistent incident response operating model across WPP.
- Establish and maintain incident response frameworks, methodologies, and standards.
- Drive adoption of intelligence-led and threat-informed response capabilities.
- Ensure incident management processes support regulatory, legal, client, and contractual obligations.
- Partner with Security Architecture, Security Technology & Visibility, Threat Intelligence, Detection Engineering, and Automation functions to continuously enhance response capability.
- Lead the transformation of Security Incident Management into an automation-first capability aligned to ASO principles.
- Partner with Automation & Process Engineering to automate investigation, triage, enrichment, containment, reporting, and evidence capture where appropriate.
- Drive reductions in manual effort, investigator workload, Mean Time to Detect (MTTD), and Mean Time to Respond (MTTR).
- Ensure incident management processes can consume automated intelligence, orchestration workflows, and agentic capabilities with appropriate human oversight.
- Sponsor operational innovation that improves quality, consistency, resilience, and scale.
- Lead strategic coordination during major cyber incidents, ransomware events, breaches, regulatory incidents, and business-critical security events.
- Coordinate Operational Security, Legal, Privacy, Enterprise Technology, Communications, Executive Leadership, and external partners.
- Oversee engagement with forensic providers, law enforcement, cyber insurance providers, and specialist third parties where required.
- Ensure effective recovery, lessons learned, and organisational improvement following major incidents.
- Own Security Incident Management policies, standards, procedures, playbooks, and operating documentation.
- Ensure incident response activities are auditable, measurable, and aligned to governance requirements.
- Chair incident review and service improvement forums.
- Oversee Root Cause Analysis (RCA) and Post Incident Review (PIR) programmes, ensuring actions are assigned, tracked, and completed.
- Support internal audit, client assurance, certification requirements, and regulatory reviews.
- Define and own Security Incident Management KPIs, KRIs, SLAs, and operational metrics.
- Provide regular reporting to Operational Security Leadership, Cyber Leadership, and executive stakeholders.
- Drive continual service improvement through data-led decision-making.
- Maintain visibility of incident trends, response effectiveness, control gaps, and organisational risk exposure.
- Ensure lessons learned are converted into measurable improvements across detection, response, vulnerability management, threat intelligence, and automation.
- Provide leadership, coaching, mentoring, and career development for personnel within the Security Incident Management function.
- Build and maintain a high-performing investigation and response culture.
- Establish competency frameworks, training plans, certification pathways, succession planning, and effective resource coverage.
- Foster collaboration across Detection Engineering & Response, Threat Intelligence & Knowledge Sharing, Automation & Process Engineering, Technology & Visibility, and Vulnerability Management.
What you'll need:
Essential
- Extensive experience leading enterprise-scale Security Incident Management or Incident Response functions.
- Demonstrable experience directing major cyber security incidents and crisis response activities.
- Strong understanding of modern incident response methodologies, operating models, and governance frameworks.
- Experience leading multidisciplinary cyber security teams in large, global organisations.
- Deep technical understanding of SIEM, SOAR, EDR/XDR, cloud security, identity security, email security, and digital forensics.
- Experience defining operational metrics, service management frameworks, and continual improvement programmes.
- Ability to communicate effectively with technical teams, executives, legal teams, regulators, clients, and external stakeholders.
- Proven experience building and maturing operational security capabilities.
Desirable
- Experience implementing automation-first or Autonomic Security Operations operating models.
- Experience working within highly regulated, global, or federated organisations.
- Familiarity with cyber crisis management and executive incident response.
- Relevant certifications such as CISSP, CISM, GCIH, GCFA, GCED, CGEIT, CRISC, or equivalent.
Who you'll be working with:
You will report directly to the Director of Operational Security and own the Security Incident Management function and its associated operating model. You will provide leadership across the Security Incident Management Leads, Senior Security Incident Responders and Security Incident Responders, while contributing as a member of the Operational Security Leadership Team. In this role, you will also play a key part in delivering WPP’s long-term Autonomic Security Operations strategy and wider operational transformation.
Who you are:
You're open: We are inclusive and collaborative; we encourage the free exchange of ideas; we respect and celebrate diverse views. We are open-minded: to new ideas, new partnerships, new ways of working.
You're optimistic: We believe in the power of creativity, technology and talent to create brighter futures or our people, our clients and our communities. We approach all that we do with conviction: to try the new and to seek the unexpected.
You're extraordinary: we are stronger together: through collaboration we achieve the amazing. We are creative leaders and pioneers of our industry; we provide extraordinary every day.
What we'll give you:
Passionate, inspired people – We aim to create a culture in which people can do extraordinary work.
Scale and opportunity – We offer the opportunity to create, influence and complete projects at a scale that is unparalleled in the industry.
Challenging and stimulating work – Unique work and the opportunity to join a group of creative problem solvers. Are you up for the challenge?
#LI-Hybrid
We believe the best work happens when we're together, fostering creativity, collaboration, and connection. That's why we’ve adopted a hybrid approach, with teams in the office around four days a week. If you require accommodations or flexibility, please discuss this with the hiring team during the interview process.
WPP is an equal opportunity employer and considers applicants for all positions without discrimination or regard to particular characteristics. We are committed to fostering a culture of respect in which everyone feels they belong and has the same opportunities to progress in their careers.