Technical Security Governance Lead - Identity

WPP

São Paulo

Presencial

BRL 167 400 - 279 000

Tempo integral

14 dias+

Recebe mais respostas dos empregadores

Envia um currículo específico para a oferta em poucos minutos.

Resumo da oferta

WPP is seeking a Technical Security Governance Lead in São Paulo to lead security governance efforts within Digital Security & Risk Management. This role will establish and enforce technical security guidelines and ensure that risks are effectively managed.

The ideal candidate will have strong governance experience, an understanding of cloud security, and the ability to communicate effectively with various stakeholders.

A hybrid work model is adopted, encouraging team collaboration while providing flexibility.

Qualificações

  • Fluent English – reading, writing and conversation skills.
  • Demonstrable experience in technical security governance, security assurance, or risk‑based security oversight in a global environment.
  • Strong understanding of cybersecurity policies, standards and frameworks (e.g., ISO 27001, NIST CSF).
  • Strong understanding of cloud security, vulnerability management, identity risk and modern attack paths and exposure management.
  • Experience working with global engineering and operations teams.
  • Excellent analytical, problem‑solving and critical thinking skills.
  • Strong communication and interpersonal skills, with the ability to collaborate effectively across teams.
  • Ability to communicate risk and technical posture clearly to senior stakeholders and non‑technical audiences.

Responsabilidades

  • Define and maintain technical governance guardrails, minimum baselines, and posture expectations for assigned domains.
  • Translate enterprise policies, standards, and risk appetite into clear and actionable technical expectations for execution teams.
  • Define exception criteria, escalation thresholds, and evidence requirements to ensure governance is auditable and defensible.
  • Provide independent challenge to remediation plans and risk acceptances where residual risk remains unacceptable.
  • Support audit readiness by ensuring evidence requirements are defined, traceable, and consistently produced by execution owners.
  • Identify recurring compliance gaps and drive corrective actions through agreed remediation plans and escalation routes.
  • Communicate expectations clearly and pragmatically, enabling delivery teams to move quickly within defined boundaries.

Descrição da oferta de emprego

Technical Security Governance Lead - Identity

The Technical Security Governance Lead is responsible for leading one or more technical security governance domains within Digital Security & Risk Management (DSRM). The role defines enforceable security guardrails and minimum baselines, monitors security posture and exposure, and provides independent oversight and challenge to Enterprise Technology, DT&S engineering teams, and business‑managed technology owners. This role focuses on risk, exposure, and control effectiveness—ensuring that technical security risks are consistently identified, assessed, escalated, and reported—without designing, building, configuring, or operating technology platforms.

Responsibilities
  • Define and maintain technical governance guardrails, minimum baselines, and posture expectations for assigned domains.
  • Translate enterprise policies, standards, and risk appetite into clear and actionable technical expectations for execution teams.
  • Define exception criteria, escalation thresholds, and evidence requirements to ensure governance is auditable and defensible.
  • Provide independent challenge to remediation plans and risk acceptances where residual risk remains unacceptable.
  • Support audit readiness by ensuring evidence requirements are defined, traceable, and consistently produced by execution owners.
  • Contribute technical governance input to ISO/SOC and internal assurance activities, including control operation validation where required.
  • Identify recurring compliance gaps and drive corrective actions through agreed remediation plans and escalation routes.
  • Partner with Enterprise Technology, DT&S engineering, and business‑managed technology owners to embed governance expectations into delivery workflows.
  • Work closely with Risk Management, Client Assurance & Vendor Risk, and BISOs to ensure consistent risk visibility and business context.
  • Communicate expectations clearly and pragmatically, enabling delivery teams to move quickly within defined boundaries.
  • Identify opportunities to improve governance processes, automation, and reporting to reduce friction and improve risk outcomes.
  • Stay informed on emerging threats and technical risk trends and incorporate relevant changes into governance expectations.
  • Drive maturity improvements across domains through measurable targets and iterative uplift plans.
Domain Related Responsibilities – Identity
  • Define identity guardrails including authentication strength, privileged access controls, and identity‑based risk thresholds.
  • Monitor identity posture signals (e.g., MFA coverage, privileged access hygiene, risky access paths) and elevate systemic weaknesses.
  • Ensure identity governance is treated as a primary attack‑vector control domain across cloud, endpoint, and product environments.
Qualifications
  • Fluent English – reading, writing and conversation skills.
  • Demonstrable experience in technical security governance, security assurance, or risk‑based security oversight in a global environment.
  • Strong understanding of cybersecurity policies, standards and frameworks (e.g., ISO 27001, NIST CSF).
  • Strong understanding of cloud security, vulnerability management, identity risk and modern attack paths and exposure management.
  • Experience working with global engineering and operations teams.
  • Excellent analytical, problem‑solving and critical thinking skills.
  • Strong communication and interpersonal skills, with the ability to collaborate effectively across teams.
  • Ability to communicate risk and technical posture clearly to senior stakeholders and non‑technical audiences.
Nice‑to‑Have
  • Certifications such as CISSP, Azure, AWS, GCP or other related to the domain.
  • Familiarity with posture and detection tooling (e.g., CNAPP/CSPM, EDR, vulnerability scanning, identity telemetry) and evidence management approaches.
  • Working knowledge of agile methodologies.
  • Experience in multinational, multicultural and matrixed companies.
  • Bachelor’s degree in Information Security, Computer Science or a related field.
Key Behaviours & Competencies
  • Experience operating in decentralised or federated organisations where governance relies on influence rather than control.
  • Demonstrated ability to build governance programmes from the ground up, including posture measurement frameworks, KPI/KRI design and executive risk reporting.
  • Broad technical security knowledge across multiple domains, enabling credible challenge and recognition of incomplete pictures.
  • Strong executive communication skills—able to translate complex risk and posture data into clear, honest narratives for senior and non‑technical audiences.
  • Experience governing across multiple regions and regulatory environments, with familiarity with GDPR and other major data protection frameworks.
  • Familiarity with client data obligations and the reputational and commercial stakes that come with them.
Work Environment

We believe the best work happens when we're together, fostering creativity, collaboration, and connection. We’ve adopted a hybrid approach, with teams in the office around four days a week. If you require accommodations or flexibility, please discuss this with the hiring team during the interview process.

WPP is an equal opportunity employer and considers applicants for all positions without discrimination or regard to particular characteristics. We are committed to fostering a culture of respect in which everyone feels they belong and has the same opportunities to progress in their careers.

Obtém a tua avaliação gratuita e confidencial do currículo.
ou arrasta e larga o ficheiro aqui.
Similar jobs

Ofertas semelhantes que vale a pena comparar

Risk Specialist
Risk Specialist

WPP • São Paulo

Presencial
BRL 80 000 - 120 000
Cultural diversity and respect
Challenging and stimulating work
Cybersecurity Manager
Cybersecurity Manager

Jobtailor • Belo Horizonte

Presencial
BRL 350 000 - 550 000
Senior Information Security Engineer
Senior Information Security Engineer

WEX • São Paulo

Presencial
BRL 180 000 - 260 000
Senior Information Security Engineer
Senior Information Security Engineer

WEX Inc • Brasil

Presencial
BRL 150 000 - 240 000
Technology Risk & Controls Transformation Specialist
Technology Risk & Controls Transformation Specialist

WPP • São Paulo

Híbrido
BRL 250 000 - 380 000
Information Security Specialist I
Information Security Specialist I

Jobtailor • Joinville

Presencial
BRL 180 000 - 280 000
Tech Compliance Pleno II
Tech Compliance Pleno II

AB InBev • Campinas

Presencial
BRL 80 000 - 120 000
Technology Risk & Controls Senior Specialist
Technology Risk & Controls Senior Specialist

WPP • São Paulo

Híbrido
BRL 180 000 - 300 000
Junior Identity & Access Management Analyst |Supero Outsourcing
Junior Identity & Access Management Analyst |Supero Outsourcing

Grupo Supero • Brasil

Presencial
BRL 60 000 - 80 000
SR ISO Assessment Consultant IRC295881
SR ISO Assessment Consultant IRC295881

GlobalLogic • Buenos Aires

Híbrido
BRL 110 000 - 160 000