role isn't about writing code day-to-day. Instead, you'll influence governance of how secure software is built, deployed and maintained across cloud-native platforms, APIs, AI-enabled applications and global engineering teams. This is an opportunity to influence software security governance at global scale, helping … insecurecodingtrendsanddependencyrisks.Strengthengovernanceofsoftwaresupplychains,open-sourcedependenciesandSoftwareBillofMaterials(SBOM)practices.SupportthedevelopmentofsecureCI/CDpipelinesthroughcontrolssuchascodescanning,secretsdetectionandreleasegovernance.HelpshapeWPP'sapproachtosecuringAI-enabledapplications,includingareassuchaspromptinjectionresilience,agentcontrolsanddataprotection.Provideinsight,reportingandchallengetoensuresoftwaresecurityrisksareunderstood,prioritisedandeffectivelymanaged.Drivecontinuousimprovementsinsoftwaresecuritymaturityacrosstheorganisation.What you'll need:Experienceinapplicationsecurity,softwaresecurity,DevSecOps,softwareassuranceortechnicalsecuritygovernance.StrongunderstandingofSecureSDLC,applicationsecurityandmodernsoftwaredevelopmentpractices.KnowledgeofCI/CDsecurity,cloud-nativeenvironmentsandsoftwaresupplychainrisk.Experienceworkingcloselywithengineeringteamstoimprovesecurityoutcomes.Strongstakeholdermanagementandcommunicationskills,withtheabilitytoinfluencetechnicalandnon-technicalaudiences.Apragmaticapproachtobalancingsecurity,riskanddelivery.Nice to Have:Experience with cloud platforms such as AWS, Azure or Google Cloud.Knowledge of SAST, DAST, SCA or software ...