Senior Technology Risk Analyst
InfoSum
| Company | InfoSum |
| Category | Uncategorised |
| Location | London |
| Remote | On-site (inferred) |
| Employment | Not stated |
| Level | Senior |
| Salary | Not stated by the employer |
| Posted | 14 Jul 2026 |
| Last verified | 11 Aug 2026 |
| Source | Employer ATS (greenhouse) |
Description
InfoSum is WPP’s privacy-first data collaboration technology, trusted by global businesses to unlock the full potential of their first-party data without risk. Its patented, cross-cloud, decentralized collaboration technology leverages advanced Privacy-Enhancing Technologies (PETs) to radically transform how companies generate audience intelligence and drive better customer experiences. As the foundational infrastructure underpinning WPP Open, InfoSum powers trusted data collaboration across every cloud, client, and capability.
Role Purpose
The Senior Technology Risk Analyst is responsible for managing and continuously improving the Information Security Management System (ISMS) across Data & Technology Solutions. You will ensure that security policies, controls, risks, exceptions, and governance processes are properly maintained, evidenced, reviewed, and acted upon.
Reporting to the SVP Security and Compliance, you will provide the operational backbone for security governance across DTS. This is a hands-on Governance, Risk, and Compliance (GRC) role. You will collaborate across security, product, engineering, infrastructure, architecture, legal, risk, compliance, and delivery teams to transform security governance into a dynamic, working management system rather than a static documentation exercise.
Key Responsibilities
1. ISMS Ownership & Operation
Manage the day-to-day operation and continuous improvement of the DTS ISMS.
Maintain the ISMS framework, documentation, control library, policies, standards, and procedures.
Ensure the ISMS accurately reflects how DTS operates across products, platforms, infrastructure, data, and engineering.
Support alignment with frameworks such as ISO 27001, SOC 2, GDPR, HIPAA (where applicable), and wider WPP security requirements.
Ensure ISMS artefacts are version-controlled, approved, reviewed, and communicated appropriately.
Maintain clear evidence of security governance activity, control operation, risk treatment, and management reviews.
2. Policy Management & Control Governance
Own the lifecycle of DTS security and compliance policies, standards, procedures, and control documentation.
Coordinate policy reviews with Security, Architecture, Infrastructure, Engineering, Product, Legal, Risk, and Enterprise Technology stakeholders.
Ensure policies are practical, clear, enforceable, and aligned with DTS's operating reality.
Track policy exceptions, waivers, compensating controls, and review dates.
Ensure policy changes are communicated and seamlessly embedded into operational processes.
3. Risk Review Board Operation
Establish and continuously run the DTS Risk Review Board .
Define the Board’s cadence, agenda, inputs, outputs, attendees, and escalation routes.
Prepare comprehensive risk packs, dashboards, decision logs, and action trackers.
Ensure risks are presented clearly, consistently, and with appropriate supporting evidence.
Track decisions, owners, due dates, mitigations, exceptions, and residual risks.
Escalate risks exceeding agreed thresholds to the SVP Security and Compliance, DTS leadership, the CISO office, or other appropriate forums.
4. Risk Register Management
Own and maintain the central DTS security and compliance risk register.
Capture, assess, categorise, and maintain security, compliance, privacy, operational resilience, third-party, and technology risks.
Ensure all risks have clear descriptions, owners, likelihood/impact ratings, inherent risk scores, mitigations, residual risk scores, treatment plans, and target dates.
Partner with risk owners to ensure mitigations are realistic, funded, and actively progressed.
Track overdue risk actions and escalate insufficient progress.
Produce regular risk reporting for DTS leadership and wider WPP governance forums.
5. Control Assurance & Evidence Management
Suppo