WPP
Senior Technology Risk Analyst
Tech · ~6+ yrs (est.)
- Location
- United Kingdom
- Opened
- 6 Jul 26
- Closes
- No date listed
UK visa sponsorship
This employer was not found on the gov.uk sponsor register. It may be listed under another legal name.
About the role
<div class="content-intro"><p><strong>WPP is the trusted growth partner for the world’s leading brands. </strong></p>
<p><strong>We unite cutting-edge media intelligence and data solutions, world-class creativity, next-generation production, transformative enterprise solutions and expert strategic counsel in a single company – powered by exceptional talent and our agentic marketing platform, WPP Open, to help our clients navigate change, capture opportunity and deliver transformational growth. </strong><br><strong> </strong><br><strong>We work with the world's most valuable brands and have global reach across 100+ markets, with deep local expertise.</strong><br><strong> </strong><br><strong>Our people are the key to our success. We're committed to fostering a culture of creativity, belonging and continuous learning, attracting and developing the brightest talent, and providing exciting career opportunities that help our people grow. </strong><br><strong> </strong><br><strong>For more information, visit <a href="https://eur02.safelinks.protection.outlook.com/?url=http%3A%2F%2Fwpp.com%2F&data=05%7C02%7CErica.Durr%40wpp.com%7C9bf4566a65bc46a48ac008de749116ea%7C150b5e663d884dee83f6ed149b727a00%7C0%7C0%7C639076363668176216%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&sdata=Q9juosud56XGLThSFZ1NpPZd6FXpJPxV74OeRZWoh%2B4%3D&reserved=0" target="_blank">WPP.com.</a></strong><br><strong> </strong></p></div><p> </p>
<h1><span data-teams="true">Senior Technology Risk Analyst</span></h1>
<ul>
<li><strong>Department:</strong> Data & Technology Solutions (DTS)</li>
<li><strong>Reports To:</strong> SVP Security and Compliance</li>
<li><strong>Location:</strong> [London/Hybrid 2 days a week in office]</li>
<li><strong>Position Type:</strong> Full-Time</li>
</ul>
<hr>
<h3><strong>Role Purpose</strong></h3>
<p>The <strong>Senior Technology Risk Analyst</strong> is responsible for managing and continuously improving the Information Security Management System (ISMS) across Data & Technology Solutions. You will ensure that security policies, controls, risks, exceptions, and governance processes are properly maintained, evidenced, reviewed, and acted upon.</p>
<p>Reporting to the SVP Security and Compliance, you will provide the operational backbone for security governance across DTS. This is a <strong>hands-on</strong> Governance, Risk, and Compliance (GRC) role. You will collaborate across security, product, engineering, infrastructure, architecture, legal, risk, compliance, and delivery teams to transform security governance into a dynamic, working management system rather than a static documentation exercise.</p>
<hr>
<h3><strong>Key Responsibilities</strong></h3>
<h4><strong>1. ISMS Ownership & Operation</strong></h4>
<ul>
<li>Manage the day-to-day operation and continuous improvement of the DTS ISMS.</li>
<li>Maintain the ISMS framework, documentation, control library, policies, standards, and procedures.</li>
<li>Ensure the ISMS accurately reflects how DTS operates across products, platforms, infrastructure, data, and engineering.</li>
<li>Support alignment with frameworks such as <strong>ISO 27001, SOC 2, GDPR, HIPAA</strong> (where applicable), and wider WPP security requirements.</li>
<li>Ensure ISMS artefacts are version-controlled, approved, reviewed, and communicated appropriately.</li>
<li>Maintain clear evidence of security governance activity, control operation, risk treatment, and management reviews.</li>
</ul>
<h4><strong>2. Policy Management & Control Governance</strong></h4>
<ul>
<li>Own the lifecycle of DTS security and compliance policies, standards, procedures, and control documentation.</li>
<li>Coordinate policy reviews with Security, Architecture, Infrastructure, Engineering, Product, Legal, Risk, and Enterprise Technology stakeholders.</li>
<li>Ensure policies are practical, clear, enforceable, and aligned with DTS's operating reality.</li>
<li>Track policy exceptions, waivers, compensating controls, and review dates.</li>
<li>Ensure policy changes are communicated and seamlessly embedded into operational processes.</li>
</ul>
<h4><strong>3. Risk Review Board Operation</strong></h4>
<ul>
<li>Establish and continuously run the <strong>DTS Risk Review Board</strong>.</li>
<li>Define the Board’s cadence, agenda, inputs, outputs, attendees, and escalation routes.</li>
<li>Prepare comprehensive risk packs, dashboards, decision logs, and action trackers.</li>
<li>Ensure risks are presented clearly, consistently, and with appropriate supporting evidence.</li>
<li>Track decisions, owners, due dates, mitigations, exceptions, and residual risks.</li>
<li>Escalate risks exceeding agreed thresholds to the SVP Security and Compliance, DTS leadership, the CISO office, or other appropriate forums.</li>
</ul>
<h4><strong>4. Risk Register Management</strong></h4>
<ul>
<li>Own and maintain the central DTS security and compliance risk register.</li>
<li>Capture, assess, categorise, and maintain security, compliance, privacy, operational resilience, third-party, and technology risks.</li>
<li>Ensure all risks have clear descriptions, owners, likelihood/impact ratings, inherent risk scores, mitigations, residual risk scores, treatment plans, and target dates.</li>
<li>Partner with risk owners to ensure mitigations are realistic, funded, and actively progressed.</li>
<li>Track overdue risk actions and escalate insufficient progress.</li>
<li>Produce regular risk reporting for DTS leadership and wider WPP governance forums.</li>
</ul>
<h4><strong>5. Control Assurance & Evidence Management</strong></h4>
<ul>
<li>Support ongoing assurance activity by ensuring controls are consistently evidenced, tested, and reviewed.</li>
<li>Maintain control evidence for ISO 27001, SOC 2, client assurance, internal audits, and other compliance needs.</li>
<li>Coordinate evidence collection from Engineering, Infrastructure, Security, Product, HR, Legal, and Enterprise Technology.</li>
<li>Identify gaps between documented controls and actual operating practices, tracking remediation plans.</li>
</ul>
<h4><strong>6. Compliance Support & Audit Readiness</strong></h4>
<ul>
<li>Support DTS compliance obligations (ISO 27001, SOC 2, HIPAA, GDPR-related controls, and client-specific requirements).</li>
<li>Help prepare for internal/external audits, client reviews, security questionnaires, and due diligence exercises.</li>
<li>Maintain an organized, always-ready evidence library and audit trail.</li>
<li>Support management reviews required by ISO 27001 and other governance frameworks.</li>
</ul>
<h4><strong>7. Exception, Waiver & Remediation Tracking</strong></h4>
<ul>
<li>Manage the formal process for security exceptions, policy waivers, risk acceptances, and remediation plans.</li>
<li>Ensure exceptions are documented, reviewed, approved, time-bound, and assigned to accountable owners.</li>
<li>Track compensating controls, monitor residual risk, and manage the renewal/escalation of expired exceptions.</li>
</ul>
<h4><strong>8. Third-Party & Supplier Risk Support</strong></h4>
<ul>
<li>Help assess security and compliance risks associated with vendors, partners, tools, platforms, and managed services.</li>
<li>Maintain supplier risk records and coordinate with Procurement, Legal, CISO, Enterprise Technology, and Product teams.</li>
<li>Ensure third-party risk is appropriately integrated into the DTS risk register and Risk Review Board.</li>
</ul>
<h4><strong>9. Security Governance Reporting</strong></h4>
<ul>
<li>Produce clear, reliable, and actionable governance dashboards and reports for the SVP Security and Compliance and DTS leadership.</li>
<li>Translate complex governance and technical data into clear business language, highlighting trends, overdue actions, and material risks.</li>
</ul>
<h4><strong>10. Stakeholder Engagement & Culture</strong></h4>
<ul>
<li>Foster a collaborative and practical security governance culture across DTS.</li>
<li>Coach risk owners on how to describe, assess, treat, and monitor risks.</li>
<li>Ensure risk processes support business delivery rather than becoming bureaucratic overhead.</li>
</ul>
<hr>
<h3><strong>Key Accountabilities</strong></h3>
<p>The ISMS and Risk Officer will be directly accountable for:</p>
<ul>
<li>Effective operation, accuracy, and maintenance of the DTS Senior Technology Risk Analyst.</li>
<li>Continuous, disciplined operation of the DTS Risk Review Board.</li>
<li>Up-to-date, approved, and realistic security policies, standards, and control documentation.</li>
<li>Structured tracking of risks, exceptions, waivers, and remediation plans.</li>
<li>Audit-ready evidence management and reliable governance reporting to leadership.</li>
</ul>
<hr>
<h3><strong>Skills & Experience</strong></h3>
<p><strong>Required:</strong></p>
<ul>
<li>Proven experience in <strong>information security governance, risk management, compliance, audit, or ISMS operation</strong>.</li>
<li>Strong working knowledge of <strong>ISO 27001</strong> and practical ISMS management.</li>
<li>Familiarity with <strong>SOC 2, GDPR, HIPAA</strong>, cloud security, SaaS platforms, and enterprise security controls.</li>
<li>Experience maintaining risk registers, policy frameworks, control libraries, and audit evidence repositories.</li>
<li>Experience running or supporting risk committees, governance forums, or control review boards.</li>
<li>Excellent technical writing skills (policies, standards, risk statements, and governance reports).</li>
<li>Ability to collaborate with technical teams and translate technical issues into business risk/compliance language.</li>
<li>Strong organizational skills, high attention to detail, and a constructive yet persistent approach to driving action.</li>
</ul>
<p><strong>Preferred:</strong></p>
<ul>
<li>Experience operating within a complex, matrixed, enterprise environment is highly valued.</li>
</ul>
<hr>
<h3><strong>Leadership Expectations</strong></h3>
<ul>
<li><strong>Disciplined & Reliable:</strong> Bring structure, order, and high standards of documentation to risk and compliance processes.</li>
<li><strong>Pragmatic & Delivery-Aware:</strong> Build trust with technical teams by making governance useful, proportionate, and aligned with delivery.</li>
<li><strong>Proactive:</strong> Follow through persistently on actions, dates, and evidence, and escalate bottlenecks clearly.</li>
<li><strong>Collaborative:</strong> Support the SVP Security and Compliance in building a mature, transparent, and well-governed security function.</li>
</ul>
<hr>
<h3><strong>Success Measures</strong></h3>
<ul>
<li>A current, well-maintained DTS ISMS with zero "reactive" compliance rushes.</li>
<li>Security policies and standards reviewed, updated, and communicated on schedule.</li>
<li>The Risk Review Board operating systematically with clear actions and high leadership engagement.</li>
<li>DTS risk register actively used by leadership to drive risk-based decisions.</li>
<li>Audit and certification evidence organized so there are "fewer surprises" during external audits and client reviews.</li>
<li>Security governance fully embedded as a natural part of daily DTS operations.</li>
</ul>
<p><span style="text-decoration: underline;"><strong>Who you are:</strong></span></p>
<p><strong>You're open<em>:</em> </strong>We are inclusive and collaborative; we encourage the free exchange of ideas; we respect and celebrate diverse views. We are open-minded: to new ideas, new partnerships, new ways of working.</p>
<p><strong>You're optimistic<em>:</em></strong> <span id="628d56ad5d8a35dab853e65d9daa237c" class="editor-module-hl-green-solid">We believe</span> in the power of creativity, technology and talent to create brighter futures or our people, our clients and our communities. We approach all that we do with conviction: to try the new and to seek the unexpected.</p>
<p><strong>You're extraordinary:</strong> we are stronger together: through collaboration we achieve the amazing. We are creative leaders and pioneers of our industry; we provide extraordinary every day.</p>
<p><span style="text-decoration: underline;"><strong>What we'll give you:</strong></span></p>
<p><strong>Passionate, inspired people</strong> – We aim to create a culture in which people can do extraordinary work.</p>
<p><strong>Scale and opportunity</strong> – We offer the opportunity to create, influence and complete projects at a scale that is unparalleled in the industry.</p>
<p><strong>Challenging and stimulating work</strong> – Unique work and the opportunity to join a group of creative problem solvers. Are you up for the challenge?</p>
<p><span style="color: rgb(236, 240, 241);">#LI-Hybrid </span></p><div class="content-conclusion"><p><strong>We believe the best work happens when we're together, fostering creativity, collaboration, and connection. That's why we’ve adopted a hybrid approach, with teams in the office around four days a week. If you require accommodations or flexibility, please discuss this with the hiring team during the interview process.</strong></p>
<p><strong>WPP is an equal opportunity employer and considers applicants for all positions without discrimination or regard to particular characteristics. We are committed to fostering a culture of respect in which everyone feels they belong and has the same opportunities to progress in their careers.</strong></p>
<h4><strong>Please read our Privacy Notice (<a href="https://www.wpp.com/en/careers/wpp-privacy-policy-for-recruitment">https://www.wpp.com/en/careers/wpp-privacy-policy-for-recruitment</a>) for more information on how we process the information you provide.</strong></h4></div>
Apply on the employer's site