Product, Application and Offensive Security Lead in London

Product, Application and Offensive Security Lead in London

London Full-Time 63000 - 77000 £ / year (est.) Home office (partial)
InfoSum

At a Glance

  • Tasks: Lead security in product design, development, and testing for innovative data collaboration technology.
  • Company: Join WPP, a global leader in media intelligence and data solutions.
  • Benefits: Enjoy competitive salary, hybrid work, and opportunities for continuous learning.
  • Other info: Dynamic role with excellent career growth in a creative and inclusive culture.
  • Why this job: Make a real impact on security in cutting-edge tech that powers trusted data collaboration.
  • Qualifications: Experience in security engineering and a passion for innovative technology.

The predicted salary is between 63000 - 77000 £ per year.

Info Sum is WPP's privacy-first data collaboration technology, trusted by global businesses to unlock the full potential of their first-party data without risk.

Its patented, cross-cloud, decentralized collaboration technology levers advanced Privacy-Enhancing Technologies (PETs) to radically transform how companies generate audience intelligence and drive better customer experiences.

As the foundational infrastructure underpinning WPP Open, Info Sum powers trusted data collaboration across every cloud, client, and capability.

WPP is the trusted growth partner for the world's leading brands.

We unite cutting-edge media intelligence and data solutions, world-class creativity, next-generation production, transformative enterprise solutions and expert strategic counsel in a single company – powered by exceptional talent and our agentic marketing platform, WPP Open, to help our clients navigate change, capture opportunity and deliver transformational growth.

We work with the world's most valuable brands and have global reach across 100+ markets, with deep local expertise.

Our people are the key to our success.

We're committed to fostering a culture of creativity, belonging and continuous learning, attracting and developing the brightest talent, and providing exciting career opportunities that help our people grow.

For more information, visit WPP. com.

  • Department: Data & Technology Solutions (DTS)
  • Reports To: SVP Security and Compliance
  • Location: (London/Hybrid 2 days a week in office)
  • Position Type: Full-Time

Role Overview
The Product, Application and Offensive Security Engineer is responsible for embedding security directly into the design, development, testing, and operation of DTS products and platforms.

This is a hands-on security engineering role.

The role requires someone who can work directly with product and engineering teams, review designs, assess APIs, run threat models, test systems, coordinate penetration testing, identify vulnerabilities, and help teams remediate issues.

The role ensures DTS products, APIs, data collaboration capabilities, AI-enabled workflows, and client-facing services are designed, built, and tested securely.

It also owns the practical offensive security and adversarial assurance activity needed to test DTS products from an attacker’s perspective.

The Product, Application and Offensive Security Lead will work closely with Product, Engineering, Architecture, Infrastructure, Security Operations, Privacy, Cloud and Platform Security, and the ISMS and Risk Officer to ensure security issues are identified early, fixed effectively, and tracked through governance where required.

Key Responsibilities

  • Hands-on Product and Application Security

Provide hands-on security support across DTS products and engineering teams. This includes:

  • Reviewing product designs, technical designs, APIs, services, and integrations.
  • Identifying security weaknesses in applications, workflows, and data flows.
  • Advising engineering teams on secure implementation.
  • Supporting secure design decisions during product discovery and delivery.
  • Helping teams resolve security issues pragmatically without creating unnecessary delivery friction.
  • Secure Software Development Lifecycle (SDLC)
  • Embed security into the software development lifecycle across DTS. This includes:
  • Defining and applying secure engineering standards.
  • Supporting secure coding practices.
  • Reviewing CI/CD security controls.
  • Supporting SAST, DAST, SCA, secrets scanning, dependency scanning, and container scanning.
  • Helping teams triage, prioritise, and remediate security findings.
  • Working with engineering teams to make security checks practical and repeatable.
  • Threat Modelling and Security Design Reviews

Run threat modelling and security design reviews for new and changed capabilities. This includes:

  • Facilitating threat modelling sessions with engineering and product teams.
  • Reviewing authentication and authorization designs.
  • Assessing API exposure, data flows, trust boundaries, and abuse cases.
  • Identifying risks around tenant isolation, privilege escalation, data leakage, and misuse.
  • Documenting key findings, recommendations, and residual risks.
  • Offensive Security and Adversarial Testing

Carry out and coordinate offensive security testing across DTS products and platforms. This includes:

  • Performing hands-on security testing of products, APIs, and workflows.
  • Coordinating external penetration tests.
  • Supporting red team and purple team exercises where required.
  • Testing abuse cases and attacker paths.
  • Testing access control, authentication, authorization, and
  • #J-18808-Ljbffr

Product, Application and Offensive Security Lead in London employer: InfoSum

InfoSum is an exceptional employer that fosters a culture of creativity and collaboration, empowering employees to do extraordinary work. With a strong focus on professional growth, the company offers unique opportunities to influence large-scale projects while maintaining a hybrid work environment that promotes flexibility and connection. Employees benefit from a supportive atmosphere that values diversity and inclusion, ensuring everyone has the chance to thrive in their careers.

InfoSum

Contact Details:

InfoSum Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land Product, Application and Offensive Security Lead in London

Get Involved in the Cybersecurity Community

Diving into the cybersecurity community is key for landing that full-time gig. Join forums like Reddit's r/cybersecurity or attend local meetups to connect with industry veterans and other job seekers. Networking is everything in this field—don’t just be a passive lurker!

Show Off Your Skills with Capture the Flag Competitions

Participate in Capture the Flag (CTF) competitions; these are not just a fun way to boost your skills but also a chance to showcase your talent to potential employers. Many companies, including InfoSum, love seeing candidates who actively engage in these challenges.

Tailor Your Online Presence

Make sure your LinkedIn and any professional profiles reflect your cybersecurity expertise. Share your projects, whether they’re personal or from a previous role, to catch the eye of hiring managers. This is how they’ll find your passion and commitment to the field!

Apply Directly Through InfoSum

Don’t forget to head straight to our website and check out any openings for cybersecurity roles at InfoSum. Applying directly can sometimes give you an edge, especially if you can mention that you've been following our work or engaging in the community.

We think you need these skills to ace Product, Application and Offensive Security Lead in London

Security Engineering
API Security Assessment
Threat Modelling
Penetration Testing
Vulnerability Identification
Secure Software Development Lifecycle (SDLC)
Secure Coding Practices

Some tips for your application 🫡

Show off your technical skills:In cybersecurity, it's crucial to highlight your technical prowess. Make sure your CV showcases specific skills like network security, penetration testing, or threat analysis. If you have relevant certifications (like CEH or CISSP), pop those on the front page to grab attention!

Tailor your portfolio for the role:Even for a full-time role, a portfolio can set you apart. If you've worked on any cybersecurity projects—be it CTF challenges, security assessments, or research papers—include these in your application. This demonstrates not just your skills, but also your hands-on experience!

Use real-world examples:When writing your cover letter, don’t just stick to your qualifications. Share real-world examples of how you’ve tackled security issues or vulnerabilities. This gives the hiring team at InfoSum insight into your practical problem-solving abilities and makes your application memorable.

Demonstrate your passion for cybersecurity:Cybersecurity is an ever-evolving field, so show us that you’re always learning! Mention any recent courses, webinars, or industry events you’ve attended. This not only exhibits your enthusiasm but also signals to InfoSum that you’re committed to staying ahead in the game.

How to prepare for a job interview at InfoSum

Sharpen Your Technical Skills

For a role in cybersecurity, it’s essential to be up-to-date with the latest tools and techniques. Brush up on your knowledge of firewalls, intrusion detection systems, and vulnerability assessment tools. Be ready to discuss specific scenarios where you’ve applied these skills, as hands-on experience can really set us apart in interviews.

Prepare for Scenario-Based Questions

Expect the interviewers at InfoSum to throw in some hypothetical situations to see how you’d handle them. Think about common security breaches or incidents and be prepared to explain how you would respond. This not only shows your problem-solving skills but also your understanding of real-world cybersecurity challenges.

Highlight Your Certifications

Certifications like CompTIA Security+, CISSP, or CEH can give you a significant edge in a full-time role in cybersecurity. Make sure to mention these during your interview and be prepared to discuss what you learned through those certifications and how they relate to the position at InfoSum.

Show Your Passion for Cybersecurity

Since you’re going for a full-time gig, showing genuine enthusiasm for the field can make all the difference. Share any personal projects, blogs, or communities you’re part of that relate to cybersecurity. This not only showcases your passion but also your commitment to staying engaged in this ever-evolving field.