Senior Technology Risk Analyst
WPP · United Kingdom · Hybrid
Posted Jul 6, 2026
Sign up free: we match you to jobs like this, tailor your application and fill the form. 2 free applications every day.
WPP is the trusted growth partner for the world’s leading brands.
We unite cutting-edge media intelligence and data solutions, world-class creativity, next-generation production, transformative enterprise solutions and expert strategic counsel in a single company – powered by exceptional talent and our agentic marketing platform, WPP Open, to help our clients navigate change, capture opportunity and deliver transformational growth. We work with the world's most valuable brands and have global reach across 100+ markets, with deep local expertise. Our people are the key to our success. We're committed to fostering a culture of creativity, belonging and continuous learning, attracting and developing the brightest talent, and providing exciting career opportunities that help our people grow. For more information, visit WPP.com.
Senior Technology Risk Analyst
Department: Data & Technology Solutions (DTS)
Reports To: SVP Security and Compliance
Location: [London/Hybrid 2 days a week in office]
Position Type: Full-Time
Role Purpose
The Senior Technology Risk Analyst is responsible for managing and continuously improving the Information Security Management System (ISMS) across Data & Technology Solutions. You will ensure that security policies, controls, risks, exceptions, and governance processes are properly maintained, evidenced, reviewed, and acted upon.
Reporting to the SVP Security and Compliance, you will provide the operational backbone for security governance across DTS. This is a hands-on Governance, Risk, and Compliance (GRC) role. You will collaborate across security, product, engineering, infrastructure, architecture, legal, risk, compliance, and delivery teams to transform security governance into a dynamic, working management system rather than a static documentation exercise.
Key Responsibilities
1. ISMS Ownership & Operation
Manage the day-to-day operation and continuous improvement of the DTS ISMS.
Maintain the ISMS framework, documentation, control library, policies, standards, and procedures.
Ensure the ISMS accurately reflects how DTS operates across products, platforms, infrastructure, data, and engineering.
Support alignment with frameworks such as ISO 27001, SOC 2, GDPR, HIPAA (where applicable), and wider WPP security requirements.
Ensure ISMS artefacts are version-controlled, approved, reviewed, and communicated appropriately.
Maintain clear evidence of security governance activity, control operation, risk treatment, and management reviews.
2. Policy Management & Control Governance
Own the lifecycle of DTS security and compliance policies, standards, procedures, and control documentation.
Coordinate policy reviews with Security, Architecture, Infrastructure, Engineering, Product, Legal, Risk, and Enterprise Technology stakeholders.
Ensure policies are practical, clear, enforceable, and aligned with DTS's operating reality.
Track policy exceptions, waivers, compensating…