← All roles

WPP

Senior Technology Risk Analyst

Tech · ~6+ yrs (est.)

Location
United Kingdom
Opened
6 Jul 26
Closes
No date listed

This employer was not found on the gov.uk sponsor register. It may be listed under another legal name.

About the role

<div class="content-intro"><p><strong>WPP is the trusted growth partner for the world’s leading brands.&nbsp;</strong></p> <p><strong>We unite cutting-edge media intelligence and data solutions, world-class creativity, next-generation production, transformative enterprise solutions and expert strategic counsel in a single company – powered by exceptional talent and our agentic marketing platform, WPP Open, to help our clients navigate change, capture opportunity and deliver transformational growth.&nbsp;</strong><br><strong>&nbsp;</strong><br><strong>We work with the world's most valuable brands and have global reach across 100+ markets, with deep local expertise.</strong><br><strong>&nbsp;</strong><br><strong>Our people are the key to our success. We're committed to fostering a culture of creativity, belonging and continuous learning, attracting and developing the brightest talent, and providing exciting career opportunities that help our people grow.&nbsp;</strong><br><strong>&nbsp;</strong><br><strong>For more information, visit <a href="https://eur02.safelinks.protection.outlook.com/?url=http%3A%2F%2Fwpp.com%2F&amp;data=05%7C02%7CErica.Durr%40wpp.com%7C9bf4566a65bc46a48ac008de749116ea%7C150b5e663d884dee83f6ed149b727a00%7C0%7C0%7C639076363668176216%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&amp;sdata=Q9juosud56XGLThSFZ1NpPZd6FXpJPxV74OeRZWoh%2B4%3D&amp;reserved=0" target="_blank">WPP.com.</a></strong><br><strong>&nbsp;</strong></p></div><p>&nbsp;</p> <h1><span data-teams="true">Senior Technology Risk Analyst</span></h1> <ul> <li><strong>Department:</strong>&nbsp;Data &amp; Technology Solutions (DTS)</li> <li><strong>Reports To:</strong>&nbsp;SVP Security and Compliance</li> <li><strong>Location:</strong> [London/Hybrid 2 days a week in office]</li> <li><strong>Position Type:</strong>&nbsp;Full-Time</li> </ul> <hr> <h3><strong>Role Purpose</strong></h3> <p>The&nbsp;<strong>Senior Technology Risk Analyst</strong>&nbsp;is responsible for managing and continuously improving the Information Security Management System (ISMS) across Data &amp; Technology Solutions. You will ensure that security policies, controls, risks, exceptions, and governance processes are properly maintained, evidenced, reviewed, and acted upon.</p> <p>Reporting to the SVP Security and Compliance, you will provide the operational backbone for security governance across DTS. This is a&nbsp;<strong>hands-on</strong>&nbsp;Governance, Risk, and Compliance (GRC) role. You will collaborate across security, product, engineering, infrastructure, architecture, legal, risk, compliance, and delivery teams to transform security governance into a dynamic, working management system rather than a static documentation exercise.</p> <hr> <h3><strong>Key Responsibilities</strong></h3> <h4><strong>1. ISMS Ownership &amp; Operation</strong></h4> <ul> <li>Manage the day-to-day operation and continuous improvement of the DTS ISMS.</li> <li>Maintain the ISMS framework, documentation, control library, policies, standards, and procedures.</li> <li>Ensure the ISMS accurately reflects how DTS operates across products, platforms, infrastructure, data, and engineering.</li> <li>Support alignment with frameworks such as&nbsp;<strong>ISO 27001, SOC 2, GDPR, HIPAA</strong>&nbsp;(where applicable), and wider WPP security requirements.</li> <li>Ensure ISMS artefacts are version-controlled, approved, reviewed, and communicated appropriately.</li> <li>Maintain clear evidence of security governance activity, control operation, risk treatment, and management reviews.</li> </ul> <h4><strong>2. Policy Management &amp; Control Governance</strong></h4> <ul> <li>Own the lifecycle of DTS security and compliance policies, standards, procedures, and control documentation.</li> <li>Coordinate policy reviews with Security, Architecture, Infrastructure, Engineering, Product, Legal, Risk, and Enterprise Technology stakeholders.</li> <li>Ensure policies are practical, clear, enforceable, and aligned with DTS's operating reality.</li> <li>Track policy exceptions, waivers, compensating controls, and review dates.</li> <li>Ensure policy changes are communicated and seamlessly embedded into operational processes.</li> </ul> <h4><strong>3. Risk Review Board Operation</strong></h4> <ul> <li>Establish and continuously run the&nbsp;<strong>DTS Risk Review Board</strong>.</li> <li>Define the Board’s cadence, agenda, inputs, outputs, attendees, and escalation routes.</li> <li>Prepare comprehensive risk packs, dashboards, decision logs, and action trackers.</li> <li>Ensure risks are presented clearly, consistently, and with appropriate supporting evidence.</li> <li>Track decisions, owners, due dates, mitigations, exceptions, and residual risks.</li> <li>Escalate risks exceeding agreed thresholds to the SVP Security and Compliance, DTS leadership, the CISO office, or other appropriate forums.</li> </ul> <h4><strong>4. Risk Register Management</strong></h4> <ul> <li>Own and maintain the central DTS security and compliance risk register.</li> <li>Capture, assess, categorise, and maintain security, compliance, privacy, operational resilience, third-party, and technology risks.</li> <li>Ensure all risks have clear descriptions, owners, likelihood/impact ratings, inherent risk scores, mitigations, residual risk scores, treatment plans, and target dates.</li> <li>Partner with risk owners to ensure mitigations are realistic, funded, and actively progressed.</li> <li>Track overdue risk actions and escalate insufficient progress.</li> <li>Produce regular risk reporting for DTS leadership and wider WPP governance forums.</li> </ul> <h4><strong>5. Control Assurance &amp; Evidence Management</strong></h4> <ul> <li>Support ongoing assurance activity by ensuring controls are consistently evidenced, tested, and reviewed.</li> <li>Maintain control evidence for ISO 27001, SOC 2, client assurance, internal audits, and other compliance needs.</li> <li>Coordinate evidence collection from Engineering, Infrastructure, Security, Product, HR, Legal, and Enterprise Technology.</li> <li>Identify gaps between documented controls and actual operating practices, tracking remediation plans.</li> </ul> <h4><strong>6. Compliance Support &amp; Audit Readiness</strong></h4> <ul> <li>Support DTS compliance obligations (ISO 27001, SOC 2, HIPAA, GDPR-related controls, and client-specific requirements).</li> <li>Help prepare for internal/external audits, client reviews, security questionnaires, and due diligence exercises.</li> <li>Maintain an organized, always-ready evidence library and audit trail.</li> <li>Support management reviews required by ISO 27001 and other governance frameworks.</li> </ul> <h4><strong>7. Exception, Waiver &amp; Remediation Tracking</strong></h4> <ul> <li>Manage the formal process for security exceptions, policy waivers, risk acceptances, and remediation plans.</li> <li>Ensure exceptions are documented, reviewed, approved, time-bound, and assigned to accountable owners.</li> <li>Track compensating controls, monitor residual risk, and manage the renewal/escalation of expired exceptions.</li> </ul> <h4><strong>8. Third-Party &amp; Supplier Risk Support</strong></h4> <ul> <li>Help assess security and compliance risks associated with vendors, partners, tools, platforms, and managed services.</li> <li>Maintain supplier risk records and coordinate with Procurement, Legal, CISO, Enterprise Technology, and Product teams.</li> <li>Ensure third-party risk is appropriately integrated into the DTS risk register and Risk Review Board.</li> </ul> <h4><strong>9. Security Governance Reporting</strong></h4> <ul> <li>Produce clear, reliable, and actionable governance dashboards and reports for the SVP Security and Compliance and DTS leadership.</li> <li>Translate complex governance and technical data into clear business language, highlighting trends, overdue actions, and material risks.</li> </ul> <h4><strong>10. Stakeholder Engagement &amp; Culture</strong></h4> <ul> <li>Foster a collaborative and practical security governance culture across DTS.</li> <li>Coach risk owners on how to describe, assess, treat, and monitor risks.</li> <li>Ensure risk processes support business delivery rather than becoming bureaucratic overhead.</li> </ul> <hr> <h3><strong>Key Accountabilities</strong></h3> <p>The ISMS and Risk Officer will be directly accountable for:</p> <ul> <li>Effective operation, accuracy, and maintenance of the DTS Senior Technology Risk Analyst.</li> <li>Continuous, disciplined operation of the DTS Risk Review Board.</li> <li>Up-to-date, approved, and realistic security policies, standards, and control documentation.</li> <li>Structured tracking of risks, exceptions, waivers, and remediation plans.</li> <li>Audit-ready evidence management and reliable governance reporting to leadership.</li> </ul> <hr> <h3><strong>Skills &amp; Experience</strong></h3> <p><strong>Required:</strong></p> <ul> <li>Proven experience in&nbsp;<strong>information security governance, risk management, compliance, audit, or ISMS operation</strong>.</li> <li>Strong working knowledge of&nbsp;<strong>ISO 27001</strong>&nbsp;and practical ISMS management.</li> <li>Familiarity with&nbsp;<strong>SOC 2, GDPR, HIPAA</strong>, cloud security, SaaS platforms, and enterprise security controls.</li> <li>Experience maintaining risk registers, policy frameworks, control libraries, and audit evidence repositories.</li> <li>Experience running or supporting risk committees, governance forums, or control review boards.</li> <li>Excellent technical writing skills (policies, standards, risk statements, and governance reports).</li> <li>Ability to collaborate with technical teams and translate technical issues into business risk/compliance language.</li> <li>Strong organizational skills, high attention to detail, and a constructive yet persistent approach to driving action.</li> </ul> <p><strong>Preferred:</strong></p> <ul> <li>Experience operating within a complex, matrixed, enterprise environment is highly valued.</li> </ul> <hr> <h3><strong>Leadership Expectations</strong></h3> <ul> <li><strong>Disciplined &amp; Reliable:</strong>&nbsp;Bring structure, order, and high standards of documentation to risk and compliance processes.</li> <li><strong>Pragmatic &amp; Delivery-Aware:</strong>&nbsp;Build trust with technical teams by making governance useful, proportionate, and aligned with delivery.</li> <li><strong>Proactive:</strong>&nbsp;Follow through persistently on actions, dates, and evidence, and escalate bottlenecks clearly.</li> <li><strong>Collaborative:</strong>&nbsp;Support the SVP Security and Compliance in building a mature, transparent, and well-governed security function.</li> </ul> <hr> <h3><strong>Success Measures</strong></h3> <ul> <li>A current, well-maintained DTS ISMS with zero "reactive" compliance rushes.</li> <li>Security policies and standards reviewed, updated, and communicated on schedule.</li> <li>The Risk Review Board operating systematically with clear actions and high leadership engagement.</li> <li>DTS risk register actively used by leadership to drive risk-based decisions.</li> <li>Audit and certification evidence organized so there are "fewer surprises" during external audits and client reviews.</li> <li>Security governance fully embedded as a natural part of daily DTS operations.</li> </ul> <p><span style="text-decoration: underline;"><strong>Who you are:</strong></span></p> <p><strong>You're open<em>:</em> </strong>We are inclusive and collaborative; we encourage the free exchange of ideas; we respect and celebrate diverse views. We are open-minded: to new ideas, new partnerships, new ways of working.</p> <p><strong>You're optimistic<em>:</em></strong> <span id="628d56ad5d8a35dab853e65d9daa237c" class="editor-module-hl-green-solid">We believe</span> in the power of creativity, technology and talent to create brighter futures or our people, our clients and our communities. We approach all that we do with conviction: to try the new and to seek the unexpected.</p> <p><strong>You're extraordinary:</strong> we are stronger together: through collaboration we achieve the amazing. We are creative leaders and pioneers of our industry; we provide extraordinary every day.</p> <p><span style="text-decoration: underline;"><strong>What we'll give you:</strong></span></p> <p><strong>Passionate, inspired people</strong> – We aim to create a culture in which people can do extraordinary work.</p> <p><strong>Scale and opportunity</strong> – We offer the opportunity to create, influence and complete projects at a scale that is unparalleled in the industry.</p> <p><strong>Challenging and stimulating work</strong> – Unique work and the opportunity to join a group of creative problem solvers. Are you up for the challenge?</p> <p><span style="color: rgb(236, 240, 241);">#LI-Hybrid&nbsp;</span></p><div class="content-conclusion"><p><strong>We believe the best work happens when we're together, fostering creativity, collaboration, and connection. That's why we’ve adopted a hybrid approach, with teams in the office around four days a week. If you require accommodations or flexibility, please discuss this with the hiring team during the interview process.</strong></p> <p><strong>WPP is an equal opportunity employer and considers applicants for all positions without discrimination or regard to particular characteristics. We are committed to fostering a culture of respect in which everyone feels they belong and has the same opportunities to progress in their careers.</strong></p> <h4><strong>Please read our Privacy Notice (<a href="https://www.wpp.com/en/careers/wpp-privacy-policy-for-recruitment">https://www.wpp.com/en/careers/wpp-privacy-policy-for-recruitment</a>) for more information on how we process the information you provide.</strong></h4></div>
Apply on the employer's site