Technical Security Governance Lead - Cloud, Vulnerability Management
Quick Summary
Technical Security Governance & Assurance Define and maintain technical governance guardrails, baselines, and posture expectations across cloud and vulnerability domains.
5+ years of experience in cloud security, vulnerability management, or technical security governance. Strong hands-on or governance knowledge of major cloud platforms (AWS, GCP, and Microsoft Azure).
Why we're hiring:
We are looking for a Technical Security Governance Lead – Cloud & Vulnerability Management to help shape and strengthen the security posture of one of the world’s largest technology and creative ecosystems.
This role is responsible for leading security governance across our cloud and vulnerability management domains. You will define enforceable technical guardrails, minimum baselines, and remediation expectations across global cloud platforms, workloads, identities, and infrastructure.
As a strategic lead, you will provide independent oversight and collaborative challenge to engineering, infrastructure, and product teams—ensuring technical risks are consistently identified, prioritized, and remediated at scale. This is an opportunity to bring clarity, challenge, and strategic oversight to complex technical environments, focusing on overall posture, risk reduction, and governance discipline rather than operational day-to-day patching.
What you'll be doing:
Technical Security Governance & Assurance
- Define and maintain technical governance guardrails, baselines, and posture expectations across cloud and vulnerability domains.
- Translate enterprise policy and risk appetite into actionable, practical technical standards for engineering and product teams.
- Provide independent challenge and strategic oversight where remediation plans or accepted risks exceed WPP's tolerance.
- Support compliance monitoring by partnering with product security to align technical evidence with audits, ISO, SOC, and internal assurance programs.
Cloud Security Governance
- Define mandatory cloud guardrails across multi-cloud environments, focusing on key areas such as identity, logging, encryption, secrets management, and network segmentation.
- Govern multi-cloud posture and monitor systemic control gaps across global tenants, workloads, and environments.
- Define acceptable cloud exposure principles and blast-radius containment strategies to minimize real-world impact.
- Collaborate with platform and infrastructure teams to review architecture, identify exposure, and improve cloud security maturity.
Vulnerability Management Governance
- Own and govern the vulnerability lifecycle across infrastructure, endpoints, cloud workloads, containers, applications, and APIs.
- Define modern, risk-based prioritization models using asset criticality, exposure context, and intelligence sources (e.g., CVSS, EPSS).
- Establish remediation SLAs and expectation models, actively challenging backlog growth and SLA breaches while governing the exception process.
- Validate remediation effectiveness and drive consistency in how global teams address and reduce critical exposures.
Collaboration & Stakeholder Engagement
-
- Partner closely with Platform Engineering, Infrastructure, Product Security, and Risk teams to maintain aligned risk visibility.
- Enable engineering teams to build securely and move quickly within defined guardrails.
- Help improve how technical risk and security trends are measured, prioritized, and communicated to leadership.
What you'll need:
Experience & Qualifications:
- 5+ years of experience in cloud security, vulnerability management, or technical security governance.
- Strong hands-on or governance knowledge of major cloud platforms (AWS, GCP, and Microsoft Azure).
- Deep understanding of:
- Cloud Native Application Protection Platforms (CNAPP) and Cloud Security Posture Management (CSPM).
- Vulnerability lifecycle management and modern risk-based prioritization.
- Cloud identity, access models, and modern attack paths.
- Strong communication and stakeholder engagement skills, with the ability to influence and challenge engineering and security teams in a matrixed organization.
- Education & Certifications: Bachelor’s degree in Information Security, Computer Science, or a related field (or equivalent experience). CISSP, CISM, CCSP, or CISA certifications are highly desirable.
Personal Attributes:
-
- Strategic & Impact-Focused: Ability to align technical security initiatives with global business goals.
- Proactive Leader: A strong sense of ownership and accountability, with the confidence to drive corrective action.
- Adaptable & Collaborative: Culturally aware and capable of working effectively with diverse, global teams in a fast-paced environment.
Who you are:
What We Offer
~1 min readLocation & Eligibility
Listing Details
- Posted
- July 27, 2026
- First seen
- July 27, 2026
- Last seen
- July 27, 2026
Posting Health
- Days active
- 0
- Repost count
- 0
- Trust Level
- 67%
- Scored at
- July 27, 2026
Signal breakdown
Please let Wpp know you found this job on Jobera.
3 other jobs at Wpp
View all →Explore open roles at Wpp.
Similar Management jobs
View all →Browse Similar Jobs
Stay ahead of the market
Get the latest job openings, salary trends, and hiring insights delivered to your inbox every week.
No spam. Unsubscribe at any time.
