Loading jobs…
Loading jobs…
WPP
WPP is the trusted growth partner for the world’s leading brands. We unite cutting-edge media intelligence and data solutions, world-class creativity, next-generation production, transformative enterprise solutions and expert strategic counsel in a single company – powered by exceptional talent and our agentic marketing platform, WPP Open, to help our clients navigate change, capture opportunity and deliver transformational growth. We work with the world's most valuable brands and have global reach across 100+ markets, with deep local expertise.
Our people are the key to our success. We're committed to fostering a culture of creativity, belonging and continuous learning, attracting and developing the brightest talent, and providing exciting career opportunities that help our people grow. com.
Why we're hiring: The Identity, AI and Data Access Governance Lead is responsible for governing who, and what, can access DTS systems, data, APIs, tools, workflows and AI-enabled capabilities. This is a hands-on governance and control role, reporting into the SVP Security and Compliance. The role ensures that access across DTS is appropriate, auditable, reviewed, least-privileged and aligned with security, privacy, compliance and client commitments.
The scope covers traditional human access, external users, privileged access, service accounts, machine identities, API keys, tokens, dataset access, and the emerging governance of AI agents and agentic workflows. The role will work closely with Architecture, Security, Product, Engineering, Infrastructure, Privacy, Legal/DPO, TechOps, Enterprise Technology and the ISMS and Risk Officer to ensure DTS has a clear and controlled model for access across platforms such as WPP Open, Choreograph, InfoSum, Open Intelligence, Resolve and related DTS capabilities. What you'll be doing: 1.
Identity and access governance framework Define and maintain the access governance framework for DTS. This includes: Defining access governance standards, processes and control expectations. Establishing how access should be requested, approved, provisioned, reviewed, revoked and evidenced.
Ensuring access governance covers internal users, external users, clients, partners, vendors, service accounts, machine identities and AI agents.
Requirements
Ensuring access governance is practical for product and engineering teams to implement. 2. Access reviews and recertification Own the process for regular access reviews and recertification across DTS.
for access reviews. Coordinating access reviews for critical DTS systems, production environments, privileged roles, sensitive datasets, client-facing platforms and administrative tools. Ensuring access review outcomes are tracked, remediated and evidenced.
Identifying stale, excessive, orphaned or poorly owned access. Escalating overdue, high-risk or unresolved access issues through the appropriate governance channels. 3.
Privileged access governance Ensure privileged access across DTS is properly controlled, justified and auditable. This includes: Reviewing access to production systems, cloud environments, security tools, databases, CI/CD tooling, administrative consoles and sensitive platforms. Supporting least-privilege, just-in-time and time-bound access models where appropriate.
Working with Cloud and Platform Security and Infrastructure to improve privileged access controls. Ensuring privileged access risks are visible in the DTS risk register where required. 4.
External user, client and partner access governance Govern access for external users, clients, agencies, partners and vendors. This includes: Defining standards for external user onboarding, approval, permissions, expiry and offboarding.