Level

WPP

Senior Security Incident Responder

AI in this role

WPP is the trusted growth partner for the world’s leading brands. 

We unite cutting-edge media intelligence and data solutions, world-class creativity, next-generation production, transformative enterprise solutions and expert strategic counsel in a single company – powered by exceptional talent and our agentic marketing platform, WPP Open, to help our clients navigate change, capture opportunity and deliver transformational growth. 
 
We work with the world's most valuable brands and have global reach across 100+ markets, with deep local expertise.
 
Our people are the key to our success. We're committed to fostering a culture of creativity, belonging and continuous learning, attracting and developing the brightest talent, and providing exciting career opportunities that help our people grow. 
 
For more information, visit WPP.com.
 

Why we're hiring:

The Senior Security Incident Responder is a lead technical authority for incident response execution, responsible for handling the most complex, high-impact, and business-critical security incidents across WPP. The role does not have line management responsibility; people management remains with the Security Incident Management Lead.

What you'll be doing:

KEY RESPONSIBILITIES

  1. Advanced Incident Detection, Analysis & Response

- Lead investigations for high-severity and complex security incidents.

- Perform deep technical analysis using SIEM, SOAR, EDR/XDR, identity, email, and cloud telemetry.

- Execute and oversee containment, eradication, and recovery actions.

- Act as technical incident commander when delegated.

  1. Escalation Handling & Stakeholder Coordination

- Serve as the primary escalation point for complex incidents.

- Coordinate with Legal, Privacy, Risk, Technology Operations, and agency teams.

- Provide clear technical updates to senior stakeholders.

  1. Forensics, Evidence Handling & Assurance

- Lead forensic evidence collection, preservation, and analysis.

- Ensure documentation and artefacts are audit-ready.

- Support external forensic or law-enforcement engagement when required.

  1. Quality Assurance, Playbook Maturity & Continuous Improvement

- Review incident handling quality and identify process or tooling gaps.

- Improve incident response playbooks and SOPs.

- Lead or support post-incident reviews and ensure actions are tracked.

  1. Technical Leadership & Capability Uplift

- Mentor Security Incident Responders without line management responsibility.

- Partner with Detection Engineering, Threat Intelligence, Automation, and VM teams.

- Identify opportunities for automation and response optimisation.

What you'll need:

Essential:

- Extensive hands-on experience responding to enterprise-scale security incidents.

- Deep technical expertise across SIEM, SOAR, EDR/XDR, identity, email, and cloud platforms.

- Strong forensic, investigation, and root cause analysis skills.

- Ability to operate calmly under pressure and communicate clearly.

Desirable:

- Experience acting as incident commander or senior escalation point.

- Familiarity with MITRE ATT&CK and threat-led response.

- Relevant certifications (GCIH, GCFA, GCED, CISSP).

Who you are:

You're open: we are inclusive and collaborative; we encourage the free exchange of ideas; we respect and celebrate diverse views. We are open-minded: to new ideas, new partnerships, new ways of working.

You're optimistic: we approach all that we do with confidence: to try the new and to seek the unexpected.

You're extraordinary: We are stronger together: through collaboration we achieve the amazing. We are creative leaders and pioneers of our industry; we provide extraordinary every day.

 

What we'll give you:

Passionate, inspired people – we champion a culture of people that do extraordinary work

Scale and opportunity – we offer the opportunity to create, influence and deliver projects at a scale that is unparalleled in the industry.

Challenging and stimulating work – unique work and the opportunity to join a group of creative problem solvers. 

 

#LI-Hybrid 

We believe the best work happens when we're together, fostering creativity, collaboration, and connection. That's why we’ve adopted a hybrid approach, with teams in the office around four days a week. If you require accommodations or flexibility, please discuss this with the hiring team during the interview process.

WPP is an equal opportunity employer and considers applicants for all positions without discrimination or regard to particular characteristics. We are committed to fostering a culture of respect in which everyone feels they belong and has the same opportunities to progress in their careers.

Please read our Privacy Notice (https://www.wpp.com/en/careers/wpp-privacy-policy-for-recruitment) for more information on how we process the information you provide.

How we rate this

Senior Security Incident Responder at WPP rates 37 out of 100 for how much of the daily work is AI. That makes it Little AI (AI Level 1 of 4). The level is about AI in the job, not seniority.

Classification

Little AI. AI is not part of the work.

  1. ●●●● Builds AI80 to 100
  2. ●●●○ Works on AI60 to 79
  3. ●●○○ Uses AI40 to 59
  4. ●○○○ Little AI0 to 39

Levels come from how often the tools, models and workflows of the role are named in the posting itself. Open the description and count.

Get new AI jobs by email

One email a week with the new AI jobs, each rated for how much AI is in the work. No recruiter spam, unsubscribe in one click.

Free. One email a week. Unsubscribe in one click.

Similar roles

Security roles that involve little AI, at other companies.

What kind of AI work fits you?

Answer 12 practical questions in about three minutes. Get a simple profile, the work it points to, and live roles to explore next.

Find my next step

More jobs at WPP

Related searches

Same AI level