Technical Security Governance Lead - Cloud, Vulnerability Management (Open)

WPP Media

São Paulo

Híbrido

BRL 280 000 - 360 000

Tempo integral

14 dias+
Gerador de candidaturas

Transforma esta função numa entrevista — um currículo e uma carta de apresentação criados à volta do que este empregador procura.

Ultrapassa os filtros ATS

Vantagens oferecidas por esta oferta de emprego

Hybrid work model
Equal opportunity employer

Resumo da oferta

WPP in São Paulo is seeking a Technical Security Governance Lead – Cloud & Vulnerability Management to shape the security posture across cloud and vulnerability domains. You will define guardrails, baselines, and remediation expectations spanning global clouds, workloads, identities, and infrastructure.

As a strategic lead, you will challenge engineering and product teams, ensuring risks are identified, prioritized, and remediated at scale, focusing on governance rather than day-to-day patching,

Qualificações

  • 5+ years in cloud security, vulnerability management, or governance.
  • Hands-on or governance knowledge of major cloud platforms (AWS, GCP, and Microsoft Azure).
  • Deep understanding of CNAPP and CSPM.
  • Vulnerability lifecycle management and modern risk-based prioritization.
  • Strong communication skills to influence engineering and security teams in a matrixed organization.

Responsabilidades

  • Define and maintain cloud and vulnerability governance guardrails, baselines, and posture expectations across cloud and vulnerability domains.
  • Translate enterprise policy and risk appetite into actionable, practical technical standards for engineering and product teams.
  • Provide independent challenge and strategic oversight where remediation plans or accepted risks exceed WPP’s tolerance.
  • Collaborate with Platform Engineering, Infrastructure, Product Security, and Risk teams to maintain aligned risk visibility.

Conhecimentos

Cloud security
Governance
Stakeholder engagement
Strategic leadership
Security auditing

Formação académica

Bachelor's degree in Information Security
Bachelor's degree in Computer Science
CISSP
CISM
CCSP
CISA

Ferramentas

AWS
GCP
Azure
CNAPP
CSPM

Descrição da oferta de emprego

WPP is the trusted growth partner for the world’s leading brands.

We unite cutting-edge media intelligence and data solutions, world-class creativity, next-generation production, transformative enterprise solutions and expert strategic counsel in a single company – powered by exceptional talent and our agentic marketing platform, WPP Open, to help our clients navigate change, capture opportunity and deliver transformational growth.

We work with the world’s most valuable brands and have global reach across 100+ markets, with deep local expertise.

Our people are the key to our success. We’re committed to fostering a culture of creativity, belonging and continuous learning, attracting and developing the brightest talent, and providing exciting career opportunities that help our people grow.

For more information, visit WPP.com.

Why we’re hiring:

We are looking for aTechnical Security Governance Lead – Cloud & Vulnerability Managementto help shape and strengthen the security posture of one of the world’s largest technology and creative ecosystems.

This role is responsible for leading security governance across our cloud and vulnerability management domains. You will define enforceable technical guardrails, minimum baselines, and remediation expectations across global cloud platforms, workloads, identities, and infrastructure.

As a strategic lead, you will provide independent oversight and collaborative challenge to engineering, infrastructure, and product teams—ensuring technical risks are consistently identified, prioritized, and remediated at scale. This is an opportunity to bring clarity, challenge, and strategic oversight to complex technical environments, focusing on overall posture, risk reduction, and governance discipline rather than operational day-to-day patching.

What you’ll be doing:
Technical Security Governance & Assurance
  • Define and maintaintechnical governance guardrails, baselines, and posture expectations across cloud and vulnerability domains.
  • Translate enterprise policyand risk appetite into actionable, practical technical standards for engineering and product teams.
  • Provide independent challengeand strategic oversight where remediation plans or accepted risks exceed WPP’s tolerance.
  • Support compliance monitoringby partnering with product security to align technical evidence with audits, ISO, SOC, and internal assurance programs.
Cloud Security Governance
  • Define mandatory cloud guardrailsacross multi-cloud environments, focusing on key areas such as identity, logging, encryption, secrets management, and network segmentation.
  • Govern multi-cloud postureand monitor systemic control gaps across global tenants, workloads, and environments.
  • Define acceptable cloud exposure principlesand blast-radius containment strategies to minimize real-world impact.
  • Collaborate with platform and infrastructure teamsto review architecture, identify exposure, and improve cloud security maturity.
Vulnerability Management Governance
  • Own and govern the vulnerability lifecycleacross infrastructure, endpoints, cloud workloads, containers, applications, and APIs.
  • Define modern, risk-based prioritization modelsusing asset criticality, exposure context, and intelligence sources (e.g., CVSS, EPSS).
  • Establish remediation SLAsand expectation models, actively challenging backlog growth and SLA breaches while governing the exception process.
  • Validate remediation effectivenessand drive consistency in how global teams address and reduce critical exposures.
Collaboration & Stakeholder Engagement
    • Partner closelywith Platform Engineering, Infrastructure, Product Security, and Risk teams to maintain aligned risk visibility.
    • Enable engineering teamsto build securely and move quickly within defined guardrails.
    • Help improvehow technical risk and security trends are measured, prioritized, and communicated to leadership.
What you’ll need:
Experience & Qualifications:
  • 5+ years of experiencein cloud security, vulnerability management, or technical security governance.
  • Strong hands-on or governance knowledgeof major cloud platforms (AWS, GCP, and Microsoft Azure).
  • Deep understanding of:
  • Cloud Native Application Protection Platforms (CNAPP) and Cloud Security Posture Management (CSPM).
  • Vulnerability lifecycle management and modern risk-based prioritization.
  • Cloud identity, access models, and modern attack paths.
  • Strong communication and stakeholder engagement skills, with the ability to influence and challenge engineering and security teams in a matrixed organization.
  • Education & Certifications:Bachelor’s degree in Information Security, Computer Science, or a related field (or equivalent experience). CISSP, CISM, CCSP, or CISA certifications are highly desirable.
Personal Attributes:
    • Strategic & Impact-Focused:Ability to align technical security initiatives with global business goals.
    • Proactive Leader:A strong sense of ownership and accountability, with the confidence to drive corrective action.
    • Adaptable & Collaborative:Culturally aware and capable of working effectively with diverse, global teams in a fast-paced environment.
Who you are:

You’re open_:_ We are inclusive and collaborative; we encourage the free exchange of ideas; we respect and celebrate diverse views. We are open-minded: to new ideas, new partnerships, new ways of working.

You’re optimistic_:_ We believe in the power of creativity, technology and talent to create brighter futures or our people, our clients and our communities. We approach all that we do with conviction: to try the new and to seek the unexpected.

You’re extraordinary: we are stronger together: through collaboration we achieve the amazing. We are creative leaders and pioneers of our industry; we provide extraordinary every day.

What we’ll give you:

Passionate, inspired people –We aim to create a culture in which people can do extraordinary work.

Scale and opportunity – We offer the opportunity to create, influence and complete projects at a scale that is unparalleled in the industry.

Challenging and stimulating work – Unique work and the opportunity to join a group of creative problem solvers. Are you up for the challenge?

#LI-Hybrid

We believe the best work happens when we’re together, fostering creativity, collaboration, and connection. That’s why we’ve adopted a hybrid approach, with teams in the office around four days a week. If you require accommodations or flexibility, please discuss this with the hiring team during the interview process.

WPP is an equal opportunity employer and considers applicants for all positions without discrimination or regard to particular characteristics. We are committed to fostering a culture of respect in which everyone feels they belong and has the same opportunities to progress in their careers.

Please read our Privacy Notice (https://www.wpp.com/en/careers/wpp-privacy-policy-for-recruitment)
Obtém a tua avaliação gratuita e confidencial do currículo.
ou arrasta e larga o ficheiro aqui.
Similar jobs

Ofertas semelhantes que vale a pena comparar

Technical Security Governance Lead - Exposure Management
Technical Security Governance Lead - Exposure Management

WPP Media • São Paulo

Híbrido
BRL 260 000 - 420 000
Health insurance
Security Awareness Specialist
Security Awareness Specialist

WPP Media • São Paulo

Híbrido
BRL 120 000 - 180 000
Technology Risk & Controls Senior Specialist
Technology Risk & Controls Senior Specialist

WPP Media • São Paulo

Híbrido
BRL 180 000 - 300 000
Freelance Senior DevOps Engineer
Freelance Senior DevOps Engineer

WPP Production • Buenos Aires

Presencial
BRL 618 000 - 826 000
Security Threat Intelligence Analyst
Security Threat Intelligence Analyst

WPP • São Paulo

Presencial
BRL 120 000 - 150 000
Passionate, inspired people
Challenging and stimulating work
Hybrid work model
Senior DevSecOps [US Client]
Senior DevSecOps [US Client]

PwC • Buenos Aires

Presencial
BRL 120 000 - 150 000
Senior Technical Account Manager, São Paulo
Senior Technical Account Manager, São Paulo

Wiz • São Paulo

Híbrido
BRL 400 000 - 560 000
Staff Technical Program Manager – Global Cloud & Infrastructure
Staff Technical Program Manager – Global Cloud & Infrastructure

WEX Inc. • São Paulo

Híbrido
BRL 350 000 - 620 000
Cyber Security Engineer - Vulnerability Management
Cyber Security Engineer - Vulnerability Management

StoneX Group Inc. • São Paulo

Híbrido
BRL 180 000 - 300 000
Medical and life insurance
Public transportation support
Meal and food allowances
Senior Information Security Engineer
Senior Information Security Engineer

WEX • São Paulo

Presencial
BRL 180 000 - 260 000