Technical Security Governance Lead - Identity
wpp
São Paulo, Sao Paulo, Brazil
Posted Jun 11, 2026
- Other
- Legal & Compliance
Job description
**WPP is the trusted growth partner for the world’s leading brands.**
**We unite cutting-edge media intelligence and data solutions, world-class creativity, next-generation production, transformative enterprise solutions and expert strategic counsel in a single company – powered by exceptional talent and our agentic marketing platform, WPP Open, to help our clients navigate change, capture opportunity and deliver transformational growth.**
**We work with the world's most valuable brands and have global reach across 100+ markets, with deep local expertise.**
**Our people are the key to our success. We're committed to fostering a culture of creativity, belonging and continuous learning, attracting and developing the brightest talent, and providing exciting career opportunities that help our people grow.**
**For more information, visit [.](https://eur02.safelinks.protection.outlook.com/?url=http%3A%2F%2Fwpp.com%2F&data=05%7C02%7CErica.Durr%40wpp.com%7C9bf4566a65bc46a48ac008de749116ea%7C150b5e663d884dee83f6ed149b727a00%7C0%7C0%7C639076363668176216%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&sdata=Q9juosud56XGLThSFZ1NpPZd6FXpJPxV74OeRZWoh%2B4%3D&reserved=0)**
**Why we're hiring:**
The Technical Security Governance Lead is responsible for leading one or more technical security governance domains within Digital Security & Risk Management (DSRM). The role defines enforceable security guardrails and minimum baselines, monitors security posture and exposure, and provides independent oversight and challenge to Enterprise Technology (ET), DT&S engineering teams, and business-managed technology owners.
This role focuses on risk, exposure, and control effectiveness—ensuring that technical security risks are consistently identified, assessed, escalated, and reported—without designing, building, configuring, or operating technology platforms.
**What you'll be doing:**
**Technical Security Governance**
- Define and maintain technical governance guardrails, minimum baselines, and posture expectations for assigned domains.
- Translate enterprise policies, standards, and risk appetite into clear and actionable technical expectations for execution teams.
- Define exception criteria, escalation thresholds, and evidence requirements to ensure governance is auditable and defensible.
- Provide independent challenge to remediation plans and risk acceptances where residual risk remains unacceptable.
**Compliance Monitoring**
- Support audit readiness by ensuring evidence requirements are defined, traceable, and consistently produced by execution owners.
- Contribute technical governance input to ISO/SOC and internal assurance activities, including control operation validation where required.
- Identify recurring compliance gaps and drive corrective actions through agreed remediation plans and escalation routes.
**Collaboration and Stakeholder Engagement**
- Partner with Enterprise Technology, DT&S engineering, and business-managed technology owners to embed governance expectations into delivery workflows.
- Work closely with Risk Management, Client Assurance & Vendor Risk, and BISOs to ensure consistent risk visibility and business context.
- Communicate expectations clearly and pragmatically, enabling delivery teams to move quickly within defined boundaries.
#### Continuous Improvement
- Identify opportunities to improve governance processes, automation, and reporting to reduce friction and improve risk outcomes.
- Stay informed on emerging threats and technical risk trends and incorporate relevant changes into governance expectations.
- Drive maturity improvements across domains through measurable targets and iterative uplift plans.
**Domain Related Responsibilities - Identity**
- Define identity guardrails including authentication strength, privileged access controls, and identity-based risk thresholds.
- Monitor identity posture signals (e.g., MFA coverage, privileged access hygiene, risky access paths) and escalate systemic weaknesses.
- Ensure identity governance is treated as a primary attack-vector control domain across cloud, endpoint, and product environments.
**What you'll need:**
**Essential**
- Fluent English – reading, writing and conversation skills.
- Demonstrable experience in technical security governance, security assurance, or risk-based security oversight in a global environment
- Strong understanding of cybersecurity policies, standards, and frameworks (e.g., ISO 27001, NIST CSF).
- Strong understanding of cloud security, vulnerability management, identity risk, and modern attack paths and exposure management.
- Experience working with global engineering and operations teams
- Excellent analytical, problem-solving, and critical thinking skills.
- Strong communication and interpersonal skills, with the ability to collaborate effectively across teams.
- Ability to communicate risk and technical posture clearly to senior stakeholders and non-technical audiences.
**Nice-to-Have**
- Certifications such as CISSP, Azure, AWS, GCP or other related to the domain.
- Familiarity with posture and detection tooling (e.g., CNAPP/CSPM, EDR, vulnerability scanning, identity telemetry) and evidence management approaches.
- Working knowledge of agile methodologies.
- Experience in multinational, multicultural and matrixed companies.
- Bachelor's degree in Information Security, Computer Science or a related field
**Key Behaviour's & Competencies**
- Experience operating in decentralised or federated organisations — holding companies, media groups, professional services firms, or global technology businesses — where governance relies on influence rather than control.
- Demonstrated ability to build governance programmes from the ground up, including posture measurement frameworks, KPI/KRI design, and executive risk reporting.
- Broad technical security knowledge across multiple domains — enough to lead a specialist team, provide credible challenge, and recognise when you are being given an incomplete picture.
- Strong executive communication skills — able to translate complex risk and posture data into clear, honest narratives for senior and non-technical audiences.
- Experience governing across multiple regions and regulatory environments, with familiarity with GDPR and other major data protection frameworks.
- Familiarity with client data obligations and the reputational and commercial stakes that come with them.
**Applicants are asked to submit their application in English.**
**Who you are:**
**You're open*:*** We are inclusive and collaborative; we encourage the free exchange of ideas; we respect and celebrate diverse views. We are open-minded: to new ideas, new partnerships, new ways of working.
**You're optimistic*:*** We believe in the power of creativity, technology and talent to create brighter futures or our people, our clients and our communities. We approach all that we do with conviction: to try the new and to seek the unexpected.
**You're extraordinary:** we are stronger together: through collaboration we achieve the amazing. We are creative leaders and pioneers of our industry; we provide extraordinary every day.
**What we'll give you:**
**Passionate, inspired people** – We aim to create a culture in which people can do extraordinary work.
**Scale and opportunity** – We offer the opportunity to create, influence and complete projects at a scale that is unparalleled in the industry.
**Challenging and stimulating work** – Unique work and the opportunity to join a group of creative problem solvers. Are you up for the challenge?
#LI-Hybrid
**We believe the best work happens when we're together, fostering creativity, collaboration, and connection. That's why we’ve adopted a hybrid approach, with teams in the office around four days a week. If you require accommodations or flexibility, please discuss this with the hiring team during the interview process.**
**WPP is an equal opportunity employer and considers applicants for all positions without discrimination or regard to particular characteristics. We are committed to fostering a culture of respect in which everyone feels they belong and has the same opportunities to progress in their careers.**
#### **Please read our Privacy Notice () for more information on how we process the information you provide.**