Wpp
Wpp23h ago
New

Head of Security Incident Management

United KingdomUnited Kingdom·Londonexecutive
OperationsManagement
0 views0 saves0 applied

Quick Summary

Key Responsibilities

Own the end-to-end Security Incident Management capability across WPP. Lead and develop Security Incident Management Leads, Senior Security Incident Responders, and Security Incident Responders.

Technical Tools
OperationsManagement

The Head of Security Incident Management is responsible for leading and maturing WPP's global Security Incident Management capability, providing strategic, operational, and technical leadership across the entire incident response lifecycle.

Reporting directly to the Director of Operational Security, this role owns the Security Incident Management function, including Security Incident Management Leads, Senior Security Incident Responders, and Security Incident Responders. The position ensures that security incidents are managed consistently, effectively, and in accordance with WPP policies, regulatory obligations, and operational standards.

The role evolves and scales incident response capabilities in alignment with WPP's Autonomic Security Operations (ASO) strategy and automation-first operating model. This includes oversight of people, process, technology, governance, service performance, and continuous improvement.

 

Responsibilities

~3 min read
  • Own the end-to-end Security Incident Management capability across WPP.
  • Lead and develop Security Incident Management Leads, Senior Security Incident Responders, and Security Incident Responders.
  • Establish the strategic direction for incident response, aligned to Operational Security objectives and the wider ASO roadmap.
  • Maintain overall accountability for the management of critical and major security incidents.
  • Act as the senior escalation authority for Sev1 and Sev2 security incidents.
  • Ensure appropriate incident governance, communication, decision-making, and stakeholder engagement throughout the incident lifecycle.
  • Provide executive-level updates during significant cyber security incidents and crisis situations.
  • Define and own the Security Incident Management strategy, roadmap, and maturity objectives.
  • Develop a globally consistent incident response operating model across WPP.
  • Establish and maintain incident response frameworks, methodologies, and standards.
  • Drive adoption of intelligence-led and threat-informed response capabilities.
  • Ensure incident management processes support regulatory, legal, client, and contractual obligations.
  • Partner with Security Architecture, Security Technology & Visibility, Threat Intelligence, Detection Engineering, and Automation functions to continuously enhance response capability.
  • Lead the transformation of Security Incident Management into an automation-first capability aligned to ASO principles.
  • Partner with Automation & Process Engineering to automate investigation, triage, enrichment, containment, reporting, and evidence capture where appropriate.
  • Drive reductions in manual effort, investigator workload, Mean Time to Detect (MTTD), and Mean Time to Respond (MTTR).
  • Ensure incident management processes can consume automated intelligence, orchestration workflows, and agentic capabilities with appropriate human oversight.
  • Sponsor operational innovation that improves quality, consistency, resilience, and scale.
  • Lead strategic coordination during major cyber incidents, ransomware events, breaches, regulatory incidents, and business-critical security events.
  • Coordinate Operational Security, Legal, Privacy, Enterprise Technology, Communications, Executive Leadership, and external partners.
  • Oversee engagement with forensic providers, law enforcement, cyber insurance providers, and specialist third parties where required.
  • Ensure effective recovery, lessons learned, and organisational improvement following major incidents.
  • Own Security Incident Management policies, standards, procedures, playbooks, and operating documentation.
  • Ensure incident response activities are auditable, measurable, and aligned to governance requirements.
  • Chair incident review and service improvement forums.
  • Oversee Root Cause Analysis (RCA) and Post Incident Review (PIR) programmes, ensuring actions are assigned, tracked, and completed.
  • Support internal audit, client assurance, certification requirements, and regulatory reviews.
  • Define and own Security Incident Management KPIs, KRIs, SLAs, and operational metrics.
  • Provide regular reporting to Operational Security Leadership, Cyber Leadership, and executive stakeholders.
  • Drive continual service improvement through data-led decision-making.
  • Maintain visibility of incident trends, response effectiveness, control gaps, and organisational risk exposure.
  • Ensure lessons learned are converted into measurable improvements across detection, response, vulnerability management, threat intelligence, and automation.
  • Provide leadership, coaching, mentoring, and career development for personnel within the Security Incident Management function.
  • Build and maintain a high-performing investigation and response culture.
  • Establish competency frameworks, training plans, certification pathways, succession planning, and effective resource coverage.
  • Foster collaboration across Detection Engineering & Response, Threat Intelligence & Knowledge Sharing, Automation & Process Engineering, Technology & Visibility, and Vulnerability Management.

 

  • Extensive experience leading enterprise-scale Security Incident Management or Incident Response functions.
  • Demonstrable experience directing major cyber security incidents and crisis response activities.
  • Strong understanding of modern incident response methodologies, operating models, and governance frameworks.
  • Experience leading multidisciplinary cyber security teams in large, global organisations.
  • Deep technical understanding of SIEM, SOAR, EDR/XDR, cloud security, identity security, email security, and digital forensics.
  • Experience defining operational metrics, service management frameworks, and continual improvement programmes.
  • Ability to communicate effectively with technical teams, executives, legal teams, regulators, clients, and external stakeholders.
  • Proven experience building and maturing operational security capabilities.
  • Experience implementing automation-first or Autonomic Security Operations operating models.
  • Experience working within highly regulated, global, or federated organisations.
  • Familiarity with cyber crisis management and executive incident response.
  • Relevant certifications such as CISSP, CISM, GCIH, GCFA, GCED, CGEIT, CRISC, or equivalent.

 

Who you'll be working with:

You will report directly to the Director of Operational Security and own the Security Incident Management function and its associated operating model. You will provide leadership across the Security Incident Management Leads, Senior Security Incident Responders and Security Incident Responders, while contributing as a member of the Operational Security Leadership Team. In this role, you will also play a key part in delivering WPP’s long-term Autonomic Security Operations strategy and wider operational transformation.

 

What We Offer

~1 min read

Location & Eligibility

Where is the job
London, United Kingdom
On-site at the office
Who can apply
GB

Listing Details

Posted
September 23, 2026
First seen
September 23, 2026
Last seen
September 23, 2026

Posting Health

Days active
0
Repost count
0
Trust Level
67%
Scored at
September 23, 2026

Signal breakdown

freshnesssource trustcontent trustemployer trust
Newsletter

Stay ahead of the market

Get the latest job openings, salary trends, and hiring insights delivered to your inbox every week.

A
B
C
D
Join 12,000+ marketers

No spam. Unsubscribe at any time.

WppHead of Security Incident Management