Head of Security Incident Management

WPP · London

  • Senior
  • Full-time
  • Posted 2026-09-23
  • Confirmed live on 25 September 2026

Apply at WPP

Job description

WPP is the trusted growth partner for the world’s leading brands.

We unite cutting-edge media intelligence and data solutions, world-class creativity, next-generation production, transformative enterprise solutions and expert strategic counsel in a single company – powered by exceptional talent and our agentic marketing platform, WPP Open, to help our clients navigate change, capture opportunity and deliver transformational growth.

We work with the world's most valuable brands and have global reach across 100+ markets, with deep local expertise.

Our people are the key to our success. We're committed to fostering a culture of creativity, belonging and continuous learning, attracting and developing the brightest talent, and providing exciting career opportunities that help our people grow.

For more information, visit WPP.com.

Why we're hiring:

The Head of Security Incident Management is responsible for leading and maturing WPP's global Security Incident Management capability, providing strategic, operational, and technical leadership across the entire incident response lifecycle.

Reporting directly to the Director of Operational Security, this role owns the Security Incident Management function, including Security Incident Management Leads, Senior Security Incident Responders, and Security Incident Responders. The position ensures that security incidents are managed consistently, effectively, and in accordance with WPP policies, regulatory obligations, and operational standards.

The role evolves and scales incident response capabilities in alignment with WPP's Autonomic Security Operations (ASO) strategy and automation-first operating model. This includes oversight of people, process, technology, governance, service performance, and continuous improvement.

What you'll be doing:

• Own the end-to-end Security Incident Management capability across WPP.

• Lead and develop Security Incident Management Leads, Senior Security Incident Responders, and Security Incident Responders.

• Establish the strategic direction for incident response, aligned to Operational Security objectives and the wider ASO roadmap.

• Maintain overall accountability for the management of critical and major security incidents.

• Act as the senior escalation authority for Sev1 and Sev2 security incidents.

• Ensure appropriate incident governance, communication, decision-making, and stakeholder engagement throughout the incident lifecycle.

• Provide executive-level updates during significant cyber security incidents and crisis situations.

• Define and own the Security Incident Management strategy, roadmap, and maturity objectives.

• Develop a globally consistent incident response operating model across WPP.

• Establish and maintain incident response frameworks, methodologies, and standards.

• Drive adoption of intelligence-led and threat-informed response capabilities.

• Ensure incident management processes support regulatory, legal, client, and contractual obligations.

• Partner with Security Architecture, Security Technology & Visibility, Threat Intelligence, Detection Engineering, and Automation functions to continuously enhance response capability.

• Lead the transformation of Security Incident Management into an automation-first capability aligned to ASO principles.

• Partner with Automation & Process Engineering to automate investigation, triage, enrichment, containment, reporting, and evidence capture where appropriate.

• Drive reductions in manual effort, investigator workload, Mean Time to Detect (MTTD), and Mean Time to Respond (MTTR).

• Ensure incident management processes can consume automated intelligence, orchestration workflows, and agentic capabilities with appropriate human oversight.

• Sponsor operational innovation that improves quality, consistency, resilience, and scale.

• Lead strategic coordination during major cyber incidents, ransomware events, breaches, regulatory incidents, and business-critical security events.

• Coordinate Operational Security, Legal, Privacy, Enterprise Technology, Communications, Executive Leadership, and external partners.

• Oversee engagement with forensic providers, law enforcement, cyber insurance providers, and specialist third parties where required.

• Ensure effective recovery, lessons learned, and organisational improvement following major incidents.

• Own Security Incident Management policies, standards, procedures, playbooks, and operating documentation.

• Ensure incident response activities are auditable, measurable, and aligned to governance requirements.

• Chair incident review and service improvement forums.

• Oversee Root Cause Analysis (RCA) and Post Incident Review (PIR) programmes, ensuring actions are assigned, tracked, and completed.

• Support internal audit, client assurance, certification requirements, and regulatory reviews.

• Define and own Security Incident Management KPIs, KRIs, SLAs, and operational metrics.

• Provide regul

Prepare for the interview

Nothing collected for this employer yet. The Blind 75 is what technical screens draw from; practise it here, with a coach, in Java or Python.

More at WPP

All open software jobs