Application & Development Security Lead

Company: WPP
Apply for the Application & Development Security Lead
Location: London
Job Description:

Overview

In this role, you help shape secure-by-design governance for software across WPP’s vast technology ecosystem. You’ll partner with engineering, product and platform teams to embed security into development lifecycles and governance across cloud-native environments, APIs, and AI-enabled apps. Your work has global reach, improving visibility into software security risks and strengthening software supply chains to enable secure innovation. You will influence how security supports rapid, scalable product development within a creative, collaborative culture.

Pay / Benefits

  • hybrid work model
  • inclusive and collaborative culture
  • equal opportunity employer
  • opportunity to work at scale
  • challenging and stimulating work

Responsibilities

  • Define and evolve secure software development standards, guardrails and governance practices
  • Partner with engineering and product teams to embed security into development lifecycles and delivery processes
  • Improve visibility and management of software security risks, including vulnerabilities, insecure coding trends and dependency risks
  • Strengthen governance of software supply chains, open-source dependencies and SBOM practices
  • Support development of secure CI/CD pipelines through controls such as code scanning, secrets detection and release governance
  • Help shape WPP’s approach to securing AI-enabled applications, including areas like prompt injection resilience, agent controls and data protection
  • Provide insight, reporting and challenge to ensure software security risks are understood, prioritized and effectively managed
  • Drive continuous improvements in software security maturity across the organization

Key requirements

  • Experience in application security, software security, DevSecOps, software assurance or technical security governance
  • Strong understanding of Secure SDLC, application security and modern software development practices
  • Knowledge of CI/CD security, cloud-native environments and software supply chain risk
  • Experience working closely with engineering teams to improve security outcomes
  • Strong stakeholder management and communication skills with the ability to influence technical and non-technical audiences
  • Pragmatic approach to balancing security, risk and delivery
  • Stakeholder management
  • Effective communication with both technical and non-technical audiences
  • Collaborative mindset and openness to new ideas
  • CI/CD security
  • Secure SDLC and modern software development practices
  • Software supply chain risk and SBOM

Posted: September 14th, 2026