WPP

Senior Security Incident Responder

ChennaiFull timeSeniorPosted 20 days ago
Apply on WPP →

Sign into see who you know at WPP.

WPP is the trusted growth partner for the world’s leading brands.  We unite cutting-edge media intelligence and data solutions, world-class creativity, next-generation production, transformative enterprise solutions and expert strategic counsel in a single company – powered by exceptional talent and our agentic marketing platform, WPP Open, to help our clients navigate change, capture opportunity and deliver transformational growth.  We work with the world's most valuable brands and have global reach across 100+ markets, with deep local expertise. Our people are the key to our success. We're committed to fostering a culture of creativity, belonging and continuous learning, attracting and developing the brightest talent, and providing exciting career opportunities that help our people grow.  For more information, visit WPP.com. Why we're hiring: The Senior Security Incident Responder is a lead technical authority for incident response execution, responsible for handling the most complex, high-impact, and business-critical security incidents across WPP. The role does not have line management responsibility; people management remains with the Security Incident Management Lead. What you'll be doing: KEY RESPONSIBILITIES Advanced Incident Detection, Analysis & Response - Lead investigations for high-severity and complex security incidents. - Perform deep technical analysis using SIEM, SOAR, EDR/XDR, identity, email, and cloud telemetry. - Execute and oversee containment, eradication, and recovery actions. - Act as technical incident commander when delegated. Escalation Handling & Stakeholder Coordination - Serve as the primary escalation point for complex incidents. - Coordinate with Legal, Privacy, Risk, Technology Operations, and agency teams. - Provide clear technical updates to senior stakeholders. Forensics, Evidence Handling & Assurance - Lead forensic evidence collection, preservation, and analysis. - Ensure documentation and artefacts are audit-ready. - Support external forensic or law-enforcement engagement when required. Quality Assurance, Playbook Maturity & Continuous Improvement - Review incident handling quality and identify process or tooling gaps. - Improve incident response playbooks and SOPs. - Lead or support post-incident reviews and ensure actions are tracked. Technical Leadership & Capability Uplift - Mentor Security Incident Responders without line management responsibility. - Partner with Detection Engineering, Threat Intelligence, Automation, and VM teams. - Identify opportunities for automation and response optimisation. What you'll need: Essential: - Extensive hands-on experience responding to enterprise-scale security incidents. - Deep technical expertise across SIEM, SOAR, EDR/XDR, identity, email, and cloud platforms. - Strong forensic, investigation, and root cause analysis skills. - Ability to operate calmly under pressure and communicate clearly. Desirable: - Ex...