<div class="content-intro"><p><strong>WPP is the trusted growth partner for the world’s leading brands. </strong></p>
<p><strong>We unite cutting-edge media intelligence and data solutions, world-class creativity, next-generation production, transformative enterprise solutions and expert strategic counsel in a single company – powered by exceptional talent and our agentic marketing platform, WPP Open, to help our clients navigate change, capture opportunity and deliver transformational growth. </strong><br><strong> </strong><br><strong>We work with the world's most valuable brands and have global reach across 100+ markets, with deep local expertise.</strong><br><strong> </strong><br><strong>Our people are the key to our success. We're committed to fostering a culture of creativity, belonging and continuous learning, attracting and developing the brightest talent, and providing exciting career opportunities that help our people grow. </strong><br><strong> </strong><br><strong>For more information, visit <a href="https://eur02.safelinks.protection.outlook.com/?url=http%3A%2F%2Fwpp.com%2F&data=05%7C02%7CErica.Durr%40wpp.com%7C9bf4566a65bc46a48ac008de749116ea%7C150b5e663d884dee83f6ed149b727a00%7C0%7C0%7C639076363668176216%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&sdata=Q9juosud56XGLThSFZ1NpPZd6FXpJPxV74OeRZWoh%2B4%3D&reserved=0" target="_blank">WPP.com.</a></strong><br><strong> </strong></p></div><p> </p>
<h1><span data-teams="true">Senior Technology Risk Analyst</span></h1>
<ul>
<li><strong>Department:</strong> Data & Technology Solutions (DTS)</li>
<li><strong>Reports To:</strong> SVP Security and Compliance</li>
<li><strong>Location:</strong> [London/Hybrid 2 days a week in office]</li>
<li><strong>Position Type:</strong> Full-Time</li>
</ul>
<hr>
<h3><strong>Role Purpose</strong></h3>
<p>The <strong>Senior Technology Risk Analyst</strong> is responsible for managing and continuously improving the Information Security Management System (ISMS) across Data & Technology Solutions. You will ensure that security policies, controls, risks, exceptions, and governance processes are properly maintained, evidenced, reviewed, and acted upon.</p>
<p>Reporting to the SVP Security and Compliance, you will provide the operational backbone for security governance across DTS. This is a <strong>hands-on</strong> Governance, Risk, and Compliance (GRC) role. You will collaborate across security, product, engineering, infrastructure, architecture, legal, risk, compliance, and delivery teams to transform security governance into a dynamic, working management system rather than a static documentation exercise.</p>
<hr>
<h3><strong>Key Responsibilities</strong></h3>
<h4><strong>1. ISMS Ownership & Operation</strong></h4>
<ul>
<li>Manage the day-to-day operation and continuous improvement of the DTS ISMS.</li>
<li>Maintain the ISMS framework, documentation, control library, policies, standards, and procedures.</li>
<li>Ensure the ISMS accurately reflects how DTS operates across products, platforms, infrastructure, data, and engineering.</li>
<li>Support alignment with frameworks such as <strong>ISO 27001, SOC 2, GDPR, HIPAA</strong> (where applicable), and wider WPP security requirements.</li>
<li>Ensure ISMS artefacts are version-controlled, approved, reviewed, and communicated appropriately.</li>
<li>Maintain clear evidence of security governance activity, control operation, risk treatment, and management reviews.</li>
</ul>
<h4><strong>2. Policy Management & Control Governance</strong></h4>
<ul>
<li>Own the lifecycle of DTS security and compliance policies, standards, procedures, and control documentation.</li>
<li>Coordinate policy reviews with Security, Architecture, Infrastructure, Engineering, Product, Legal, Risk, and Enterprise Technology stakeholders.</li>
<li>Ensure policies are practical, clear, enforceable, and aligned with DTS's operating reality.</li>
<li>Track policy exceptions, waivers, compensating controls, and review dates.</li>
<li>Ensure policy changes are communicated and seamlessly embedded into operational processes.</li>
</ul>
<h4><strong>3. Risk Review Board Operation</strong></h4>
<ul>
<li>Establish and continuously run the <strong>DTS Risk Review Board</strong>.</li>
<li>Define the Board’s cadence, agenda, inputs, outputs, attendees, and escalation routes.</li>
<li>Prepare comprehensive risk packs, dashboards, decision logs, and action trackers.</li>
<li>Ensure risks are presented clearly, consistently, and with appropriate supporting evidence.</li>
<li>Track decisions, owners, due dates, mitigations, exceptions, and residual risks.</li>
<li>Escalate risks exceeding agreed thresholds to the SVP Security and Compliance, DTS leadership, the CISO office, or other appropriate forums.</li>
</ul>
<h4><strong>4. Risk Register Management</strong></h4>
<ul>
<li>Own and maintain the central DTS security and compliance risk register.</li>
<li>Capture, assess, categorise, and maintain security, compliance, privacy, operational resilience, third-party, and technology risks.</li>
<li>Ensure all risks have clear descriptions, owners, likelihood/impact ratings, inherent risk scores, mitigations, residual risk scores, treatment plans, and target dates.</li>
<li>Partner with risk owners to ensure mitigations are realistic, funded, and actively progressed.</li>
<li>Track overdue risk actions and escalate insufficient progress.</li>
<li>Produce regular risk reporting for DTS leadership and wider WPP governance forums.</li>
</ul>
<h4><strong>5. Control Assurance & Evidence Management</strong></h4>
<ul>
<li>Support ongoing assurance activity by ensuring controls are consistently evidenced, tested, and reviewed.</li>
<li>Maintain control evidence for ISO 27001, SOC 2, client assurance, internal audits, and other compliance needs.</li>
<li>Coordinate evidence collection from Engineering, Infrastructure, Security, Product, HR, Legal, and Enterprise Technology.</li>
<li>Identify gaps between documented controls and actual operating practices, tracking remediation plans.</li>
</ul>
<h4><strong>6. Compliance Support & Audit Readiness</strong></h4>
<ul>
<li>Support DTS compliance obligations (ISO 27001, SOC 2, HIPAA, GDPR-related controls, and client-specific requirements).</li>
<li>Help prepare for internal/external audits, client reviews, security questionnaires, and due diligence exercises.</li>
<li>Maintain an organized, always-ready evidence library and audit trail.</li>
<li>Support management reviews required by ISO 27001 and other governance frameworks.</li>
</ul>
<h4><strong>7. Exception, Waiver & Remediation Tracking</strong></h4>
<ul>
<li>Manage the formal process for security exceptions, policy waivers, risk acceptances, and remediation plans.</li>
<li>Ensure exceptions are documented, reviewed, approved, time-bound, and assigned to accountable owners.</li>
<li>Track compensating controls, monitor residual risk, and manage the renewal/escalation of expired exceptions.</li>
</ul>
<h4><strong>8. Third-Party & Supplier Risk Support</strong></h4>
<ul>
<li>Help assess security and compliance risks associated with vendors, partners, tools, platforms, and managed services.</li>
<li>Maintain supplier risk records and coordinate with Procurement, Legal, CISO, Enterprise Technology, and Product teams.</li>
<li>Ensure third-party risk is appropriately integrated into the DTS risk register and Risk Review Board.</li>
</ul>
<h4><strong>9. Security Governance Reporting</strong></h4>
<ul>
<li>Produce clear, reliable, and actionable governance dashboards and reports for the SVP Security and Compliance and DTS leadership.</li>
<li>Translate complex governance and technical data into clear business language, highlighting trends, overdue actions, and material risks.</li>
</ul>
<h4><strong>10. Stakeholder Engagement & Culture</strong></h4>
<ul>
<li>Foster a collaborative and practical security governance culture across DTS.</li>
<li>Coach risk owners on how to describe, assess, treat, and monitor risks.</li>
<li>Ensure risk processes support business delivery rather than becoming bureaucratic overhead.</li>
</ul>
<hr>
<h3><strong>Key Accountabilities</strong></h3>
<p>The ISMS and Risk Officer will be directly accountable for:</p>
<ul>
<li>Effective operation, accuracy, and maintenance of the DTS Senior Technology Risk Analyst.</li>
<li>Continuous, disciplined operation of the DTS Risk Review Board.</li>
<li>Up-to-date, approved, and realistic security policies, standards, and control documentation.</li>
<li>Structured tracking of risks, exceptions, waivers, and remediation plans.</li>
<li>Audit-ready evidence management and reliable governance reporting to leadership.</li>
</ul>
<hr>
<h3><strong>Skills & Experience</strong></h3>
<p><stro