Overview
You lead and mature WPP’s global Security Incident Management capability, guiding strategy, operations, and technical execution across the incident lifecycle. You will manage a global team, partner with Security Architecture, Threat Intelligence, and Automation, and escalate Sev1/Sev2 incidents at the executive level. Your remit includes governance, metrics, and continuous improvement to align with the ASO strategy. This role offers influence over incident response at scale and a chance to shape an automation-first security posture. You help protect clients, data, and brand integrity in a dynamic, regulated environment.
Responsibilities
- Own end-to-end Security Incident Management capability across WPP
- Develop and lead Security Incident Management Leads and Responders
- Set strategic direction for incident response aligned to Operational Security objectives and ASO roadmap
- Hold accountability for major incidents and act as senior escalation authority for Sev1/Sev2
- Ensure governance, communication, and stakeholder engagement throughout incident lifecycles
- Provide executive updates during cyber incidents and crises
- Define and own incident management strategy, roadmap, and maturity objectives
- Create globally consistent incident response operating model and frameworks
- Drive intelligence-led and threat-informed response capabilities
- Automate investigation, triage, enrichment, containment, reporting, and evidence capture where appropriate
- Reduce manual effort, improve MTTD/MTTR, and incorporate automated intelligence
- Coordinate with Legal, Privacy, Communications, and external partners during major events
- Oversee RCA and PIR processes, post-incident improvements, and audits
- Define KPIs, KRIs, SLAs, and reporting to leadership
- Foster a high-performing, collaborative incident response culture
- Ensure training, certification pathways, and succession planning for the team
Key requirements
- Extensive experience leading enterprise-scale Security Incident Management or Incident Response
- Proven track record directing major cyber security incidents and crisis response
- Strong understanding of incident response methodologies, operating models, and governance
- Experience leading multidisciplinary cyber security teams in global organizations
- Deep technical knowledge of SIEM, SOAR, EDR/XDR, cloud, identity, email security, and digital forensics
- Experience defining operational metrics and continual improvement programs
- Excellent communication with technical teams, executives, legal, regulators, and clients
- Proven ability to build and mature operational security capabilities
- strategic thinking
- leadership and coaching
- stakeholder management
- SIEM
- SOAR
- EDR/XDR
…
