Head of Security Incident Management
Core
Leading and maturing WPP's global Security Incident Management capability, providing strategic, operational, and technical leadership across the entire incident response lifecycle.
Role type
Senior IC Head of Security Incident Management
Builds
Global security incident response operating model and automation-first capabilities
Domain
Cybersecurity / Enterprise Security Operations
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
Enterprise-scale Security Incident Management leadership, Crisis response direction, Modern incident response methodologies, Multidisciplinary team leadership, SIEM/SOAR/EDR/XDR expertise, Cloud security, Identity security, Digital forensics, Service management frameworks, Executive communication
Preferred skills
Automation-first operating models, Highly regulated global organization experience, Cyber crisis management, CISSP/CISM/GCIH certifications
Technologies
SIEM, SOAR, EDR/XDR, Cloud security platforms, Digital forensics tools
Responsibilities
Own end-to-end Security Incident Management capability, Lead and develop Security Incident Management Leads and Responders, Establish strategic direction for incident response, Maintain accountability for critical and major security incidents, Act as senior escalation authority for Sev1 and Sev2 incidents, Ensure appropriate incident governance and stakeholder engagement, Define and own Security Incident Management strategy and roadmap, Develop globally consistent incident response operating model, Establish incident response frameworks and standards, Drive adoption of intelligence-led response capabilities, Partner with Security Architecture and Automation functions, Lead transformation into automation-first capability, Sponsor operational innovation, Lead strategic coordination during major cyber incidents and breaches, Oversee engagement with forensic providers and law enforcement, Ensure effective recovery and lessons learned, Own Security Incident Management policies and playbooks, Chair incident review and service improvement forums, Oversee Root Cause Analysis and Post Incident Review programmes, Define Security Incident Management KPIs and SLAs, Provide regular reporting to executive stakeholders
Seniority
Senior, hands-on IC with strategic leadership