Senior Technology Risk Analyst

WPP — GB — inconnu

What our tracking knows about this posting

Published on 3 August 2026 · first appeared in our records on 1 September 2026.

Stable posting: first seen on 1 September 2026, with no abnormal reposting.

This posting shows no salary — 8% of open juridique postings in GB do.

View the posting at the employer Have my resume reviewed for this job
<div class="content-intro"><p><strong>WPP is the trusted growth partner for the world’s leading brands.&nbsp;</strong></p> <p><strong>We unite cutting-edge media intelligence and data solutions, world-class creativity, next-generation production, transformative enterprise solutions and expert strategic counsel in a single company – powered by exceptional talent and our agentic marketing platform, WPP Open, to help our clients navigate change, capture opportunity and deliver transformational growth.&nbsp;</strong><br><strong>&nbsp;</strong><br><strong>We work with the world's most valuable brands and have global reach across 100+ markets, with deep local expertise.</strong><br><strong>&nbsp;</strong><br><strong>Our people are the key to our success. We're committed to fostering a culture of creativity, belonging and continuous learning, attracting and developing the brightest talent, and providing exciting career opportunities that help our people grow.&nbsp;</strong><br><strong>&nbsp;</strong><br><strong>For more information, visit <a href="https://eur02.safelinks.protection.outlook.com/?url=http%3A%2F%2Fwpp.com%2F&amp;data=05%7C02%7CErica.Durr%40wpp.com%7C9bf4566a65bc46a48ac008de749116ea%7C150b5e663d884dee83f6ed149b727a00%7C0%7C0%7C639076363668176216%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&amp;sdata=Q9juosud56XGLThSFZ1NpPZd6FXpJPxV74OeRZWoh%2B4%3D&amp;reserved=0" target="_blank">WPP.com.</a></strong><br><strong>&nbsp;</strong></p></div><p>&nbsp;</p> <h1><span data-teams="true">Senior Technology Risk Analyst</span></h1> <ul> <li><strong>Department:</strong>&nbsp;Data &amp; Technology Solutions (DTS)</li> <li><strong>Reports To:</strong>&nbsp;SVP Security and Compliance</li> <li><strong>Location:</strong> [London/Hybrid 2 days a week in office]</li> <li><strong>Position Type:</strong>&nbsp;Full-Time</li> </ul> <hr> <h3><strong>Role Purpose</strong></h3> <p>The&nbsp;<strong>Senior Technology Risk Analyst</strong>&nbsp;is responsible for managing and continuously improving the Information Security Management System (ISMS) across Data &amp; Technology Solutions. You will ensure that security policies, controls, risks, exceptions, and governance processes are properly maintained, evidenced, reviewed, and acted upon.</p> <p>Reporting to the SVP Security and Compliance, you will provide the operational backbone for security governance across DTS. This is a&nbsp;<strong>hands-on</strong>&nbsp;Governance, Risk, and Compliance (GRC) role. You will collaborate across security, product, engineering, infrastructure, architecture, legal, risk, compliance, and delivery teams to transform security governance into a dynamic, working management system rather than a static documentation exercise.</p> <hr> <h3><strong>Key Responsibilities</strong></h3> <h4><strong>1. ISMS Ownership &amp; Operation</strong></h4> <ul> <li>Manage the day-to-day operation and continuous improvement of the DTS ISMS.</li> <li>Maintain the ISMS framework, documentation, control library, policies, standards, and procedures.</li> <li>Ensure the ISMS accurately reflects how DTS operates across products, platforms, infrastructure, data, and engineering.</li> <li>Support alignment with frameworks such as&nbsp;<strong>ISO 27001, SOC 2, GDPR, HIPAA</strong>&nbsp;(where applicable), and wider WPP security requirements.</li> <li>Ensure ISMS artefacts are version-controlled, approved, reviewed, and communicated appropriately.</li> <li>Maintain clear evidence of security governance activity, control operation, risk treatment, and management reviews.</li> </ul> <h4><strong>2. Policy Management &amp; Control Governance</strong></h4> <ul> <li>Own the lifecycle of DTS security and compliance policies, standards, procedures, and control documentation.</li> <li>Coordinate policy reviews with Security, Architecture, Infrastructure, Engineering, Product, Legal, Risk, and Enterprise Technology stakeholders.</li> <li>Ensure policies are practical, clear, enforceable, and aligned with DTS's operating reality.</li> <li>Track policy exceptions, waivers, compensating controls, and review dates.</li> <li>Ensure policy changes are communicated and seamlessly embedded into operational processes.</li> </ul> <h4><strong>3. Risk Review Board Operation</strong></h4> <ul> <li>Establish and continuously run the&nbsp;<strong>DTS Risk Review Board</strong>.</li> <li>Define the Board’s cadence, agenda, inputs, outputs, attendees, and escalation routes.</li> <li>Prepare comprehensive risk packs, dashboards, decision logs, and action trackers.</li> <li>Ensure risks are presented clearly, consistently, and with appropriate supporting evidence.</li> <li>Track decisions, owners, due dates, mitigations, exceptions, and residual risks.</li> <li>Escalate risks exceeding agreed thresholds to the SVP Security and Compliance, DTS leadership, the CISO office, or other appropriate forums.</li> </ul> <h4><strong>4. Risk Register Management</strong></h4> <ul> <li>Own and maintain the central DTS security and compliance risk register.</li> <li>Capture, assess, categorise, and maintain security, compliance, privacy, operational resilience, third-party, and technology risks.</li> <li>Ensure all risks have clear descriptions, owners, likelihood/impact ratings, inherent risk scores, mitigations, residual risk scores, treatment plans, and target dates.</li> <li>Partner with risk owners to ensure mitigations are realistic, funded, and actively progressed.</li> <li>Track overdue risk actions and escalate insufficient progress.</li> <li>Produce regular risk reporting for DTS leadership and wider WPP governance forums.</li> </ul> <h4><strong>5. Control Assurance &amp; Evidence Management</strong></h4> <ul> <li>Support ongoing assurance activity by ensuring controls are consistently evidenced, tested, and reviewed.</li> <li>Maintain control evidence for ISO 27001, SOC 2, client assurance, internal audits, and other compliance needs.</li> <li>Coordinate evidence collection from Engineering, Infrastructure, Security, Product, HR, Legal, and Enterprise Technology.</li> <li>Identify gaps between documented controls and actual operating practices, tracking remediation plans.</li> </ul> <h4><strong>6. Compliance Support &amp; Audit Readiness</strong></h4> <ul> <li>Support DTS compliance obligations (ISO 27001, SOC 2, HIPAA, GDPR-related controls, and client-specific requirements).</li> <li>Help prepare for internal/external audits, client reviews, security questionnaires, and due diligence exercises.</li> <li>Maintain an organized, always-ready evidence library and audit trail.</li> <li>Support management reviews required by ISO 27001 and other governance frameworks.</li> </ul> <h4><strong>7. Exception, Waiver &amp; Remediation Tracking</strong></h4> <ul> <li>Manage the formal process for security exceptions, policy waivers, risk acceptances, and remediation plans.</li> <li>Ensure exceptions are documented, reviewed, approved, time-bound, and assigned to accountable owners.</li> <li>Track compensating controls, monitor residual risk, and manage the renewal/escalation of expired exceptions.</li> </ul> <h4><strong>8. Third-Party &amp; Supplier Risk Support</strong></h4> <ul> <li>Help assess security and compliance risks associated with vendors, partners, tools, platforms, and managed services.</li> <li>Maintain supplier risk records and coordinate with Procurement, Legal, CISO, Enterprise Technology, and Product teams.</li> <li>Ensure third-party risk is appropriately integrated into the DTS risk register and Risk Review Board.</li> </ul> <h4><strong>9. Security Governance Reporting</strong></h4> <ul> <li>Produce clear, reliable, and actionable governance dashboards and reports for the SVP Security and Compliance and DTS leadership.</li> <li>Translate complex governance and technical data into clear business language, highlighting trends, overdue actions, and material risks.</li> </ul> <h4><strong>10. Stakeholder Engagement &amp; Culture</strong></h4> <ul> <li>Foster a collaborative and practical security governance culture across DTS.</li> <li>Coach risk owners on how to describe, assess, treat, and monitor risks.</li> <li>Ensure risk processes support business delivery rather than becoming bureaucratic overhead.</li> </ul> <hr> <h3><strong>Key Accountabilities</strong></h3> <p>The ISMS and Risk Officer will be directly accountable for:</p> <ul> <li>Effective operation, accuracy, and maintenance of the DTS Senior Technology Risk Analyst.</li> <li>Continuous, disciplined operation of the DTS Risk Review Board.</li> <li>Up-to-date, approved, and realistic security policies, standards, and control documentation.</li> <li>Structured tracking of risks, exceptions, waivers, and remediation plans.</li> <li>Audit-ready evidence management and reliable governance reporting to leadership.</li> </ul> <hr> <h3><strong>Skills &amp; Experience</strong></h3> <p><stro