wagey.ggwagey.gg
31,365  jobs31,365  jobs
Browse Tech JobsCompaniesFeaturesPricingFAQs
Log InGet Started Free
Jobs(31,365)/Risk Manager Role(77)/WPP (30) - ISMS and Risk Officer
WPP

WPP - ISMS and Risk Officer

United Kingdom - Hybrid3w ago
In OfficeEMEACybersecuritySoftwareRisk ManagerCISOGovernanceRisk ManagementTechnical WritingDocumentationCoaching

Requirements

• Proven experience in information security governance, risk management, compliance, audit, or ISMS operation. • information security governance, risk management, compliance, audit, or ISMS operation • Strong working knowledge of ISO 27001 and practical ISMS management. • ISO 27001 • Familiarity with SOC 2, GDPR, HIPAA, cloud security, SaaS platforms, and enterprise security controls. • SOC 2, GDPR, HIPAA • Experience maintaining risk registers, policy frameworks, control libraries, and audit evidence repositories. • Experience running or supporting risk committees, governance forums, or control review boards. • Excellent technical writing skills (policies, standards, risk statements, and governance reports). • Ability to collaborate with technical teams and translate technical issues into business risk/compliance language. • Strong organizational skills, high attention to detail, and a constructive yet persistent approach to driving action. • Preferred: • Experience operating within a complex, matrixed, enterprise environment is highly valued. • Leadership Expectations • Disciplined & Reliable: Bring structure, order, and high standards of documentation to risk and compliance processes. • Disciplined & Reliable: • Pragmatic & Delivery-Aware: Build trust with technical teams by making governance useful, proportionate, and aligned with delivery. • Pragmatic & Delivery-Aware: • Proactive: Follow through persistently on actions, dates, and evidence, and escalate bottlenecks clearly. • Proactive: • Collaborative: Support the SVP Security and Compliance in building a mature, transparent, and well-governed security function. • Collaborative: • Success Measures • Success Measures • A current, well-maintained DTS ISMS with zero "reactive" compliance rushes. • Security policies and standards reviewed, updated, and communicated on schedule. • The Risk Review Board operating systematically with clear actions and high leadership engagement. • DTS risk register actively used by leadership to drive risk-based decisions. • Audit and certification evidence organized so there are "fewer surprises" during external audits and client reviews. • Security governance fully embedded as a natural part of daily DTS operations. • You're open: We are inclusive and collaborative; we encourage the free exchange of ideas; we respect and celebrate diverse views. We are open-minded: to new ideas, new partnerships, new ways of working. • You're open: • You're optimistic: We believe in the power of creativity, technology and talent to create brighter futures or our people, our clients and our communities. We approach all that we do with conviction: to try the new and to seek the unexpected. • You're optimistic: • You're extraordinary: we are stronger together: through collaboration we achieve the amazing. We are creative leaders and pioneers of our industry; we provide extraordinary every day. • You're extraordinary: • What we'll give you: • Passionate, inspired people – We aim to create a culture in which people can do extraordinary work. • Passionate, inspired people • Scale and opportunity – We offer the opportunity to create, influence and complete projects at a scale that is unparalleled in the industry. • Scale and opportunity • Challenging and stimulating work – Unique work and the opportunity to join a group of creative problem solvers. Are you up for the challenge? • Challenging and stimulating work • We believe the best work happens when we're together, fostering creativity, collaboration, and connection. That's why we’ve adopted a hybrid approach, with teams in the office around four days a week. If you require accommodations or flexibility, please discuss this with the hiring team during the interview process.

Responsibilities

• 1. ISMS Ownership & Operation • Manage the day-to-day operation and continuous improvement of the DTS ISMS. • Maintain the ISMS framework, documentation, control library, policies, standards, and procedures. • Ensure the ISMS accurately reflects how DTS operates across products, platforms, infrastructure, data, and engineering. • Support alignment with frameworks such as ISO 27001, SOC 2, GDPR, HIPAA (where applicable), and wider WPP security requirements. • ISO 27001, SOC 2, GDPR, HIPAA • Ensure ISMS artefacts are version-controlled, approved, reviewed, and communicated appropriately. • Maintain clear evidence of security governance activity, control operation, risk treatment, and management reviews. • 2. Policy Management & Control Governance • Own the lifecycle of DTS security and compliance policies, standards, procedures, and control documentation. • Coordinate policy reviews with Security, Architecture, Infrastructure, Engineering, Product, Legal, Risk, and Enterprise Technology stakeholders. • Ensure policies are practical, clear, enforceable, and aligned with DTS's operating reality. • Track policy exceptions, waivers, compensating controls, and review dates. • Ensure policy changes are communicated and seamlessly embedded into operational processes. • 3. Risk Review Board Operation • Establish and continuously run the DTS Risk Review Board. • DTS Risk Review Board • Define the Board’s cadence, agenda, inputs, outputs, attendees, and escalation routes. • Prepare comprehensive risk packs, dashboards, decision logs, and action trackers. • Ensure risks are presented clearly, consistently, and with appropriate supporting evidence. • Track decisions, owners, due dates, mitigations, exceptions, and residual risks. • Escalate risks exceeding agreed thresholds to the SVP Security and Compliance, DTS leadership, the CISO office, or other appropriate forums. • 4. Risk Register Management • Own and maintain the central DTS security and compliance risk register. • Capture, assess, categorise, and maintain security, compliance, privacy, operational resilience, third-party, and technology risks. • Ensure all risks have clear descriptions, owners, likelihood/impact ratings, inherent risk scores, mitigations, residual risk scores, treatment plans, and target dates. • Partner with risk owners to ensure mitigations are realistic, funded, and actively progressed. • Track overdue risk actions and escalate insufficient progress. • Produce regular risk reporting for DTS leadership and wider WPP governance forums. • 5. Control Assurance & Evidence Management • Support ongoing assurance activity by ensuring controls are consistently evidenced, tested, and reviewed. • Maintain control evidence for ISO 27001, SOC 2, client assurance, internal audits, and other compliance needs. • Coordinate evidence collection from Engineering, Infrastructure, Security, Product, HR, Legal, and Enterprise Technology. • Identify gaps between documented controls and actual operating practices, tracking remediation plans. • 6. Compliance Support & Audit Readiness • Support DTS compliance obligations (ISO 27001, SOC 2, HIPAA, GDPR-related controls, and client-specific requirements). • Help prepare for internal/external audits, client reviews, security questionnaires, and due diligence exercises. • Maintain an organized, always-ready evidence library and audit trail. • Support management reviews required by ISO 27001 and other governance frameworks. • 7. Exception, Waiver & Remediation Tracking • Manage the formal process for security exceptions, policy waivers, risk acceptances, and remediation plans. • Ensure exceptions are documented, reviewed, approved, time-bound, and assigned to accountable owners. • Track compensating controls, monitor residual risk, and manage the renewal/escalation of expired exceptions. • 8. Third-Party & Supplier Risk Support • Help assess security and compliance risks associated with vendors, partners, tools, platforms, and managed services. • Maintain supplier risk records and coordinate with Procurement, Legal, CISO, Enterprise Technology, and Product teams. • Ensure third-party risk is appropriately integrated into the DTS risk register and Risk Review Board. • 9. Security Governance Reporting • Produce clear, reliable, and actionable governance dashboards and reports for the SVP Security and Compliance and DTS leadership. • Translate complex governance and technical data into clear business language, highlighting trends, overdue actions, and material risks. • 10. Stakeholder Engagement & Culture • Foster a collaborative and practical security governance culture across DTS. • Coach risk owners on how to describe, assess, treat, and monitor risks. • Ensure risk processes support business delivery rather than becoming bureaucratic overhead. • Key Accountabilities • The ISMS and Risk Officer will be directly accountable for: • Effective operation, accuracy, and maintenance of the DTS ISMS and Risk Register. • Continuous, disciplined operation of the DTS Risk Review Board. • Up-to-date, approved, and realistic security policies, standards, and control documentation. • Structured tracking of risks, exceptions, waivers, and remediation plans. • Audit-ready evidence management and reliable governance reporting to leadership.

Apply in one click

Upload My Resume

Drop here or click to browse · Tap to choose · PDF, DOCX, DOC, RTF, TXT

Apply in One Click
Apply in One Click

Similar roles

BybitBybit - Chief Risk Officer (ADGM, Broker Dealer)1mo ago
·Abu Dhabi, UAE
In OfficeEMEAC-levelFintechCybersecurityRisk ManagerStakeholder ManagementRisk ManagementLearning & DevelopmentReportingGovernance
MonzoMonzo - Senior Credit Risk Manager, Credit Platform2d ago
·Remote - UK·£125k - £170k/year/year
RemoteEMEASeniorBankingRisk ManagerRisk Management
Growe TalentsGrowe Talents - Junior Risk Manager5d ago
·Remote - EMEA
RemoteEMEAJuniorFintechPaymentsRisk ManagerRisk Management
Cooper Moss RutlandCooper Moss Rutland - Risk Manager - Construction Consultancy3w ago
·London, United Kingdom, Hybrid
In OfficeEMEARisk ManagerRisk Management
Capital on TapCapital on Tap - Risk Manager1mo ago
·London - Hybrid
In OfficeEMEABankingFintechRisk ManagerReportingARPURisk ManagementFRMGovernance
Decima InternationalDecima International - Risk Manager1w ago
·Dubai, United Arab Emirates
In OfficeEMEAPrincipalRisk ManagerMicrosoft OfficeExcelRisk ManagementReportingContract ReviewProcurementPower BIOracleChange ManagementDocumentationGovernancePMP
zopazopa - Risk Delivery Manager (Operational Resilience & Third Party Risk)4w ago
·London - Hybrid
In OfficeEMEACybersecurityDelivery ManagerRisk ManagerTeam ManagementRisk ManagementProcurementGovernance
BybitBybit - Chief Risk Officer (ADGM, RIE &RCH)1mo ago
·Abu Dhabi, UAE
In OfficeEMEAC-levelCybersecurityTransportationRisk ManagerDigital MarketingLearning & DevelopmentStakeholder ManagementReportingGovernance
teyateya - Outsourcing and Third Party Risk Management Lead1mo ago
·London, United Kingdom
In OfficeEMEAStaffBankingPaymentsRisk ManagerRisk ManagementDue Diligence

Browse more by category

Show 77 moreRisk ManagerShow 53 moreCISOShow 1,664 moreGovernanceShow 815 moreRisk ManagementShow 319 moreTechnical WritingShow 5,059 moreDocumentationShow 2,570 moreCoaching
Privacy·Terms··Contact·FAQ·Wagey on X