{"absolute_url":"https://job-boards.greenhouse.io/wpp/jobs/8580459002","data_compliance":[{"type":"gdpr","requires_consent":false,"requires_processing_consent":false,"requires_retention_consent":false,"retention_period":null,"demographic_data_consent_applies":false}],"internal_job_id":6427226002,"location":{"name":"São Paulo, Sao Paulo, Brazil"},"metadata":null,"id":8580459002,"updated_at":"2026-06-19T07:27:20-04:00","requisition_id":"10560","title":"Technical Security Governance Lead - Identity","company_name":"WPP","first_published":"2026-06-11T09:01:29-04:00","language":"en","application_deadline":null,"content":"\u0026lt;div class=\u0026quot;content-intro\u0026quot;\u0026gt;\u0026lt;p\u0026gt;\u0026lt;strong\u0026gt;WPP is the trusted growth partner for the world’s leading brands.\u0026amp;nbsp;\u0026lt;/strong\u0026gt;\u0026lt;/p\u0026gt;\n\u0026lt;p\u0026gt;\u0026lt;strong\u0026gt;We unite cutting-edge media intelligence and data solutions, world-class creativity, next-generation production, transformative enterprise solutions and expert strategic counsel in a single company – powered by exceptional talent and our agentic marketing platform, WPP Open, to help our clients navigate change, capture opportunity and deliver transformational growth.\u0026amp;nbsp;\u0026lt;/strong\u0026gt;\u0026lt;br\u0026gt;\u0026lt;strong\u0026gt;\u0026amp;nbsp;\u0026lt;/strong\u0026gt;\u0026lt;br\u0026gt;\u0026lt;strong\u0026gt;We work with the world\u0026#39;s most valuable brands and have global reach across 100+ markets, with deep local expertise.\u0026lt;/strong\u0026gt;\u0026lt;br\u0026gt;\u0026lt;strong\u0026gt;\u0026amp;nbsp;\u0026lt;/strong\u0026gt;\u0026lt;br\u0026gt;\u0026lt;strong\u0026gt;Our people are the key to our success. We\u0026#39;re committed to fostering a culture of creativity, belonging and continuous learning, attracting and developing the brightest talent, and providing exciting career opportunities that help our people grow.\u0026amp;nbsp;\u0026lt;/strong\u0026gt;\u0026lt;br\u0026gt;\u0026lt;strong\u0026gt;\u0026amp;nbsp;\u0026lt;/strong\u0026gt;\u0026lt;br\u0026gt;\u0026lt;strong\u0026gt;For more information, visit \u0026lt;a href=\u0026quot;https://eur02.safelinks.protection.outlook.com/?url=http%3A%2F%2Fwpp.com%2F\u0026amp;amp;data=05%7C02%7CErica.Durr%40wpp.com%7C9bf4566a65bc46a48ac008de749116ea%7C150b5e663d884dee83f6ed149b727a00%7C0%7C0%7C639076363668176216%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C\u0026amp;amp;sdata=Q9juosud56XGLThSFZ1NpPZd6FXpJPxV74OeRZWoh%2B4%3D\u0026amp;amp;reserved=0\u0026quot; target=\u0026quot;_blank\u0026quot;\u0026gt;WPP.com.\u0026lt;/a\u0026gt;\u0026lt;/strong\u0026gt;\u0026lt;br\u0026gt;\u0026lt;strong\u0026gt;\u0026amp;nbsp;\u0026lt;/strong\u0026gt;\u0026lt;/p\u0026gt;\u0026lt;/div\u0026gt;\u0026lt;p\u0026gt;\u0026lt;span style=\u0026quot;text-decoration: underline;\u0026quot;\u0026gt;\u0026lt;strong\u0026gt;Why we\u0026#39;re hiring:\u0026lt;/strong\u0026gt;\u0026lt;/span\u0026gt;\u0026lt;/p\u0026gt;\n\u0026lt;p\u0026gt;The Technical Security Governance Lead is responsible for leading one or more technical security governance domains within Digital Security \u0026amp;amp; Risk Management (DSRM). The role defines enforceable security guardrails and minimum baselines, monitors security posture and exposure, and provides independent oversight and challenge to Enterprise Technology (ET), DT\u0026amp;amp;S engineering teams, and business-managed technology owners.\u0026lt;/p\u0026gt;\n\u0026lt;p\u0026gt;This role focuses on risk, exposure, and control effectiveness—ensuring that technical security risks are consistently identified, assessed, escalated, and reported—without designing, building, configuring, or operating technology platforms.\u0026lt;/p\u0026gt;\n\u0026lt;p\u0026gt;\u0026lt;span style=\u0026quot;text-decoration: underline;\u0026quot;\u0026gt;\u0026lt;strong\u0026gt;What you\u0026#39;ll be doing:\u0026lt;/strong\u0026gt;\u0026lt;/span\u0026gt;\u0026lt;/p\u0026gt;\n\u0026lt;p\u0026gt;\u0026lt;strong\u0026gt;Technical Security Governance\u0026lt;/strong\u0026gt;\u0026lt;/p\u0026gt;\n\u0026lt;ul\u0026gt;\n\u0026lt;li\u0026gt;Define and maintain technical governance guardrails, minimum baselines, and posture expectations for assigned domains.\u0026lt;/li\u0026gt;\n\u0026lt;li\u0026gt;Translate enterprise policies, standards, and risk appetite into clear and actionable technical expectations for execution teams.\u0026lt;/li\u0026gt;\n\u0026lt;li\u0026gt;Define exception criteria, escalation thresholds, and evidence requirements to ensure governance is auditable and defensible.\u0026lt;/li\u0026gt;\n\u0026lt;li\u0026gt;Provide independent challenge to remediation plans and risk acceptances where residual risk remains unacceptable.\u0026lt;/li\u0026gt;\n\u0026lt;/ul\u0026gt;\n\u0026lt;p\u0026gt;\u0026lt;strong\u0026gt;Compliance Monitoring\u0026lt;/strong\u0026gt;\u0026lt;/p\u0026gt;\n\u0026lt;ul\u0026gt;\n\u0026lt;li\u0026gt;Support audit readiness by ensuring evidence requirements are defined, traceable, and consistently produced by execution owners.\u0026lt;/li\u0026gt;\n\u0026lt;li\u0026gt;Contribute technical governance input to ISO/SOC and internal assurance activities, including control operation validation where required.\u0026lt;/li\u0026gt;\n\u0026lt;li\u0026gt;Identify recurring compliance gaps and drive corrective actions through agreed remediation plans and escalation routes.\u0026lt;/li\u0026gt;\n\u0026lt;/ul\u0026gt;\n\u0026lt;p\u0026gt;\u0026lt;strong\u0026gt;Collaboration and Stakeholder Engagement\u0026lt;/strong\u0026gt;\u0026lt;/p\u0026gt;\n\u0026lt;ul\u0026gt;\n\u0026lt;li\u0026gt;Partner with Enterprise Technology, DT\u0026amp;amp;S engineering, and business-managed technology owners to embed governance expectations into delivery workflows.\u0026lt;/li\u0026gt;\n\u0026lt;li\u0026gt;Work closely with Risk Management, Client Assurance \u0026amp;amp; Vendor Risk, and BISOs to ensure consistent risk visibility and business context.\u0026lt;/li\u0026gt;\n\u0026lt;li\u0026gt;Communicate expectations clearly and pragmatically, enabling delivery teams to move quickly within defined boundaries.\u0026lt;/li\u0026gt;\n\u0026lt;/ul\u0026gt;\n\u0026lt;h4\u0026gt;Continuous Improvement\u0026lt;/h4\u0026gt;\n\u0026lt;ul\u0026gt;\n\u0026lt;li\u0026gt;Identify opportunities to improve governance processes, automation, and reporting to reduce friction and improve risk outcomes.\u0026lt;/li\u0026gt;\n\u0026lt;li\u0026gt;Stay informed on emerging threats and technical risk trends and incorporate relevant changes into governance expectations.\u0026lt;/li\u0026gt;\n\u0026lt;li\u0026gt;Drive maturity improvements across domains through measurable targets and iterative uplift plans.\u0026lt;/li\u0026gt;\n\u0026lt;/ul\u0026gt;\n\u0026lt;p\u0026gt;\u0026lt;strong\u0026gt;Domain Related Responsibilities - Identity\u0026lt;/strong\u0026gt;\u0026lt;/p\u0026gt;\n\u0026lt;ul\u0026gt;\n\u0026lt;li\u0026gt;Define identity guardrails including authentication strength, privileged access controls, and identity-based risk thresholds.\u0026lt;/li\u0026gt;\n\u0026lt;li\u0026gt;Monitor identity posture signals (e.g., MFA coverage, privileged access hygiene, risky access paths) and escalate systemic weaknesses.\u0026lt;/li\u0026gt;\n\u0026lt;li\u0026gt;Ensure identity governance is treated as a primary attack-vector control domain across cloud, endpoint, and product environments.\u0026lt;/li\u0026gt;\n\u0026lt;/ul\u0026gt;\n\u0026lt;p\u0026gt;\u0026lt;span style=\u0026quot;text-decoration: underline;\u0026quot;\u0026gt;\u0026lt;strong\u0026gt;What you\u0026#39;ll need:\u0026lt;/strong\u0026gt;\u0026lt;/span\u0026gt;\u0026lt;/p\u0026gt;\n\u0026lt;p\u0026gt;\u0026lt;strong\u0026gt;Essential\u0026lt;/strong\u0026gt;\u0026lt;/p\u0026gt;\n\u0026lt;ul\u0026gt;\n\u0026lt;li\u0026gt;Fluent English – reading, writing and conversation skills.\u0026lt;/li\u0026gt;\n\u0026lt;li\u0026gt;Demonstrable experience in technical security governance, security assurance, or risk-based security oversight in a global environment\u0026lt;/li\u0026gt;\n\u0026lt;li\u0026gt;Strong understanding of cybersecurity policies, standards, and frameworks (e.g., ISO 27001, NIST CSF).\u0026lt;/li\u0026gt;\n\u0026lt;li\u0026gt;Strong understanding of cloud security, vulnerability management, identity risk, and modern attack paths and exposure management.\u0026lt;/li\u0026gt;\n\u0026lt;li\u0026gt;Experience working with global engineering and operations teams\u0026lt;/li\u0026gt;\n\u0026lt;li\u0026gt;Excellent analytical, problem-solving, and critical thinking skills.\u0026lt;/li\u0026gt;\n\u0026lt;li\u0026gt;Strong communication and interpersonal skills, with the ability to collaborate effectively across teams.\u0026lt;/li\u0026gt;\n\u0026lt;li\u0026gt;Ability to communicate risk and technical posture clearly to senior stakeholders and non-technical audiences.\u0026lt;/li\u0026gt;\n\u0026lt;/ul\u0026gt;\n\u0026lt;p\u0026gt;\u0026lt;strong\u0026gt;Nice-to-Have\u0026lt;/strong\u0026gt;\u0026lt;/p\u0026gt;\n\u0026lt;ul\u0026gt;\n\u0026lt;li\u0026gt;Certifications such as CISSP, Azure, AWS, GCP or other related to the domain.\u0026lt;/li\u0026gt;\n\u0026lt;li\u0026gt;Familiarity with posture and detection tooling (e.g., CNAPP/CSPM, EDR, vulnerability scanning, identity telemetry) and evidence management approaches.\u0026lt;/li\u0026gt;\n\u0026lt;li\u0026gt;Working knowledge of agile methodologies.\u0026lt;/li\u0026gt;\n\u0026lt;li\u0026gt;Experience in multinational, multicultural and matrixed companies.\u0026lt;/li\u0026gt;\n\u0026lt;li\u0026gt;Bachelor\u0026#39;s degree in Information Security, Computer Science or a related field\u0026lt;/li\u0026gt;\n\u0026lt;/ul\u0026gt;\n\u0026lt;p\u0026gt;\u0026lt;strong\u0026gt;Key Behaviour\u0026#39;s \u0026amp;amp; Competencies\u0026lt;/strong\u0026gt;\u0026lt;/p\u0026gt;\n\u0026lt;ul\u0026gt;\n\u0026lt;li\u0026gt;Experience operating in decentralised or federated organisations — holding companies, media groups, professional services firms, or global technology businesses — where governance relies on influence rather than control.\u0026lt;/li\u0026gt;\n\u0026lt;li\u0026gt;Demonstrated ability to build governance programmes from the ground up, including posture measurement frameworks, KPI/KRI design, and executive risk reporting.\u0026lt;/li\u0026gt;\n\u0026lt;li\u0026gt;Broad technical security knowledge across multiple domains — enough to lead a specialist team, provide credible challenge, and recognise when you are being given an incomplete picture.\u0026lt;/li\u0026gt;\n\u0026lt;li\u0026gt;Strong executive communication skills — able to translate complex risk and posture data into clear, honest narratives for senior and non-technical audiences.\u0026lt;/li\u0026gt;\n\u0026lt;li\u0026gt;Experience governing across multiple regions and regulatory environments, with familiarity with GDPR and other major data protection frameworks.\u0026lt;/li\u0026gt;\n\u0026lt;li\u0026gt;Familiarity with client data obligations and the reputational and commercial stakes that come with them.\u0026lt;/li\u0026gt;\n\u0026lt;/ul\u0026gt;\n\u0026lt;div\u0026gt;\u0026lt;strong\u0026gt;Applicants are asked to submit their application in English.\u0026lt;/strong\u0026gt;\u0026lt;/div\u0026gt;\n\u0026lt;div\u0026gt;\u0026amp;nbsp;\u0026lt;/div\u0026gt;\n\u0026lt;p\u0026gt;\u0026lt;span style=\u0026quot;text-decoration: underline;\u0026quot;\u0026gt;\u0026lt;strong\u0026gt;Who you are:\u0026lt;/strong\u0026gt;\u0026lt;/span\u0026gt;\u0026lt;/p\u0026gt;\n\u0026lt;p\u0026gt;\u0026lt;strong\u0026gt;You\u0026#39;re open\u0026lt;em\u0026gt;:\u0026lt;/em\u0026gt; \u0026lt;/strong\u0026gt;We are inclusive and collaborative; we encourage the free exchange of ideas; we respect and celebrate diverse views. We are open-minded: to new ideas, new partnerships, new ways of working.\u0026lt;/p\u0026gt;\n\u0026lt;p\u0026gt;\u0026lt;strong\u0026gt;You\u0026#39;re optimistic\u0026lt;em\u0026gt;:\u0026lt;/em\u0026gt;\u0026lt;/strong\u0026gt; \u0026lt;span id=\u0026quot;628d56ad5d8a35dab853e65d9daa237c\u0026quot; class=\u0026quot;editor-module-hl-green-solid\u0026quot;\u0026gt;We believe\u0026lt;/span\u0026gt; in the power of creativity, technology and talent to create brighter futures or our people, our clients and our communities. We approach all that we do with conviction: to try the new and to seek the unexpected.\u0026lt;/p\u0026gt;\n\u0026lt;p\u0026gt;\u0026lt;strong\u0026gt;You\u0026#39;re extraordinary:\u0026lt;/strong\u0026gt; we are stronger together: through collaboration we achieve the amazing. We are creative leaders and pioneers of our industry; we provide extraordinary every day.\u0026lt;/p\u0026gt;\n\u0026lt;p\u0026gt;\u0026amp;nbsp;\u0026lt;/p\u0026gt;\n\u0026lt;p\u0026gt;\u0026lt;span style=\u0026quot;text-decoration: underline;\u0026quot;\u0026gt;\u0026lt;strong\u0026gt;What we\u0026#39;ll give you:\u0026lt;/strong\u0026gt;\u0026lt;/span\u0026gt;\u0026lt;/p\u0026gt;\n\u0026lt;p\u0026gt;\u0026lt;strong\u0026gt;Passionate, inspired people\u0026lt;/strong\u0026gt; –\u0026amp;nbsp;We aim to create a culture in which people can do extraordinary work.\u0026lt;/p\u0026gt;\n\u0026lt;p\u0026gt;\u0026lt;strong\u0026gt;Scale and opportunity\u0026lt;/strong\u0026gt; – We offer the opportunity to create, influence and complete projects at a scale that is unparalleled in the industry.\u0026lt;/p\u0026gt;\n\u0026lt;p\u0026gt;\u0026lt;strong\u0026gt;Challenging and stimulating work\u0026lt;/strong\u0026gt; – Unique work and the opportunity to join a group of creative problem solvers. Are you up for the challenge?\u0026lt;/p\u0026gt;\n\u0026lt;p\u0026gt;\u0026lt;span style=\u0026quot;color: rgb(236, 240, 241);\u0026quot;\u0026gt;#LI-Hybrid\u0026amp;nbsp;\u0026lt;/span\u0026gt;\u0026lt;/p\u0026gt;\u0026lt;div class=\u0026quot;content-conclusion\u0026quot;\u0026gt;\u0026lt;p\u0026gt;\u0026lt;strong\u0026gt;We believe the best work happens when we\u0026#39;re together, fostering creativity, collaboration, and connection. That\u0026#39;s why we’ve adopted a hybrid approach, with teams in the office around four days a week. If you require accommodations or flexibility, please discuss this with the hiring team during the interview process.\u0026lt;/strong\u0026gt;\u0026lt;/p\u0026gt;\n\u0026lt;p\u0026gt;\u0026lt;strong\u0026gt;WPP is an equal opportunity employer and considers applicants for all positions without discrimination or regard to particular characteristics. We are committed to fostering a culture of respect in which everyone feels they belong and has the same opportunities to progress in their careers.\u0026lt;/strong\u0026gt;\u0026lt;/p\u0026gt;\n\u0026lt;h4\u0026gt;\u0026lt;strong\u0026gt;Please read our Privacy Notice (\u0026lt;a href=\u0026quot;https://www.wpp.com/en/careers/wpp-privacy-policy-for-recruitment\u0026quot;\u0026gt;https://www.wpp.com/en/careers/wpp-privacy-policy-for-recruitment\u0026lt;/a\u0026gt;) for more information on how we process the information you provide.\u0026lt;/strong\u0026gt;\u0026lt;/h4\u0026gt;\u0026lt;/div\u0026gt;","departments":[{"id":4060815002,"name":"Legal \u0026 Compliance","child_ids":[],"parent_id":null}],"offices":[{"id":4034699002,"name":"Brazil","location":null,"child_ids":[4009079002],"parent_id":4036712002}],"ai_disclaimer":null,"include_ai_disclaimer":null,"ai_opt_out_request_url":null}