Technical Security Governance Lead - Cloud, Vulnerability Management
WPP
| Company | WPP |
| Category | Security |
| Location | São Paulo |
| Remote | On-site (inferred) |
| Employment | Not stated |
| Level | Lead |
| Salary | Not stated by the employer |
| Posted | 27 Jul 2026 |
| Last verified | 5 Aug 2026 |
| Source | Employer ATS (greenhouse) |
Description
WPP is the trusted growth partner for the world’s leading brands.
We unite cutting-edge media intelligence and data solutions, world-class creativity, next-generation production, transformative enterprise solutions and expert strategic counsel in a single company – powered by exceptional talent and our agentic marketing platform, WPP Open, to help our clients navigate change, capture opportunity and deliver transformational growth. We work with the world's most valuable brands and have global reach across 100+ markets, with deep local expertise. Our people are the key to our success. We're committed to fostering a culture of creativity, belonging and continuous learning, attracting and developing the brightest talent, and providing exciting career opportunities that help our people grow. For more information, visit WPP.com. Why we're hiring:
We are looking for a Technical Security Governance Lead – Cloud & Vulnerability Management to help shape and strengthen the security posture of one of the world’s largest technology and creative ecosystems.
This role is responsible for leading security governance across our cloud and vulnerability management domains. You will define enforceable technical guardrails, minimum baselines, and remediation expectations across global cloud platforms, workloads, identities, and infrastructure.
As a strategic lead, you will provide independent oversight and collaborative challenge to engineering, infrastructure, and product teams—ensuring technical risks are consistently identified, prioritized, and remediated at scale. This is an opportunity to bring clarity, challenge, and strategic oversight to complex technical environments, focusing on overall posture, risk reduction, and governance discipline rather than operational day-to-day patching.
What you'll be doing:
Technical Security Governance & Assurance
Define and maintain technical governance guardrails, baselines, and posture expectations across cloud and vulnerability domains.
Translate enterprise policy and risk appetite into actionable, practical technical standards for engineering and product teams.
Provide independent challenge and strategic oversight where remediation plans or accepted risks exceed WPP's tolerance.
Support compliance monitoring by partnering with product security to align technical evidence with audits, ISO, SOC, and internal assurance programs.
Cloud Security Governance
Define mandatory cloud guardrails across multi-cloud environments, focusing on key areas such as identity, logging, encryption, secrets management, and network segmentation.
Govern multi-cloud posture and monitor systemic control gaps across global tenants, workloads, and environments.
Define acceptable cloud exposure principles and blast-radius containment strategies to minimize real-world impact.
Collaborate with platform and infrastructure teams to review architecture, identify exposure, and improve cloud security maturity.
Vulnerability Management Governance
Own and govern the vulnerability lifecycle across infrastructure, endpoints, cloud workloads, containers, applications, and APIs.
Define modern, risk-based prioritization models using asset criticality, exposure context, and intelligence sources (e.g., CVSS, EPSS).
Establish remediation SLAs and expectation models, actively challenging backlog growth and SLA breaches while governing the exception process.
Validate remediation effectiveness and drive consistency in how global teams address and reduce critical exposures.
Collaboration & Stakeholder Engagement
Partner closely with Platform Engineering, Infrastructure, Product Security, and Risk teams to maintain aligned risk visibility.
Enable engineering teams to build securely and move quickly within defined gua