Head of Security Incident Management

Company: WPP
Apply for the Head of Security Incident Management
Location: London
Job Description:

Overview

You lead and mature WPP’s global Security Incident Management capability, guiding strategy, operations, and technical execution across the incident lifecycle. You will manage a global team, partner with Security Architecture, Threat Intelligence, and Automation, and escalate Sev1/Sev2 incidents at the executive level. Your remit includes governance, metrics, and continuous improvement to align with the ASO strategy. This role offers influence over incident response at scale and a chance to shape an automation-first security posture. You help protect clients, data, and brand integrity in a dynamic, regulated environment.

Responsibilities

  • Own end-to-end Security Incident Management capability across WPP
  • Develop and lead Security Incident Management Leads and Responders
  • Set strategic direction for incident response aligned to Operational Security objectives and ASO roadmap
  • Hold accountability for major incidents and act as senior escalation authority for Sev1/Sev2
  • Ensure governance, communication, and stakeholder engagement throughout incident lifecycles
  • Provide executive updates during cyber incidents and crises
  • Define and own incident management strategy, roadmap, and maturity objectives
  • Create globally consistent incident response operating model and frameworks
  • Drive intelligence-led and threat-informed response capabilities
  • Automate investigation, triage, enrichment, containment, reporting, and evidence capture where appropriate
  • Reduce manual effort, improve MTTD/MTTR, and incorporate automated intelligence
  • Coordinate with Legal, Privacy, Communications, and external partners during major events
  • Oversee RCA and PIR processes, post-incident improvements, and audits
  • Define KPIs, KRIs, SLAs, and reporting to leadership
  • Foster a high-performing, collaborative incident response culture
  • Ensure training, certification pathways, and succession planning for the team

Key requirements

  • Extensive experience leading enterprise-scale Security Incident Management or Incident Response
  • Proven track record directing major cyber security incidents and crisis response
  • Strong understanding of incident response methodologies, operating models, and governance
  • Experience leading multidisciplinary cyber security teams in global organizations
  • Deep technical knowledge of SIEM, SOAR, EDR/XDR, cloud, identity, email security, and digital forensics
  • Experience defining operational metrics and continual improvement programs
  • Excellent communication with technical teams, executives, legal, regulators, and clients
  • Proven ability to build and mature operational security capabilities
  • strategic thinking
  • leadership and coaching
  • stakeholder management
  • SIEM
  • SOAR
  • EDR/XDR

…

Posted: October 1st, 2026