At a Glance
- Tasks: Lead a global team to enhance cybersecurity and implement cutting-edge detection strategies.
- Company: Join WPP, a creative powerhouse transforming the marketing industry.
- Benefits: Enjoy a vibrant culture, hybrid work model, and opportunities for personal growth.
- Why this job: Shape the future of cybersecurity in a dynamic, innovative environment.
- Qualifications: Expertise in SIEM, automation, and strong leadership skills required.
- Other info: Collaborative atmosphere with a focus on creativity and continuous learning.
The predicted salary is between 43200 - 72000 ÂŁ per year.
WPP is the creative transformation company. We use the power of creativity to build better futures for our people, planet, clients, and communities. Working at WPP means being part of a global network of more than 100,000 talented people dedicated to doing extraordinary work for our clients. We operate in over 100 countries, with corporate headquarters in New York, London and Singapore. WPP is a world leader in marketing services, with deep AI, data and technology capabilities, global presence and unrivalled creative talent. Our clients include many of the biggest companies and advertisers in the world, including approximately 300 of the Fortune Global 500. Our people are the key to our success. We’re committed to fostering a culture of creativity, belonging and continuous learning, attracting and developing the brightest talent, and providing exciting career opportunities that help our people grow.
Why we’re hiring: WPP is at the forefront of the marketing and advertising industry’s largest transformation. Our Global CIO is leading a significant evolution of our Enterprise Technology capabilities, bringing together over 2,500 technology professionals into an integrated global team. This team will play a crucial role in enabling the ongoing transformation of our agencies and functions. Imagine shaping the cybersecurity landscape of a global powerhouse. As WPP’s next Head of Detection Engineering & Response, you’ll command a critical role, leading a global team to fortify our defenses with state‑of‑the‑art detection, rapid incident management, and relentless threat hunting. This pivotal position is your chance to revolutionize our SOC, transitioning it into an Autonomic Security Operations (ASO) model. We’re seeking a leader who can deliver an automation‑first, intelligence‑driven shield, fully aligned with the ambitious GCAT SOC10x principles, and fundamentally change how we protect WPP.
What you’ll be doing:
- Design and implement high‑fidelity detection logic across SIEM, EDR, NDR, and cloud‑native platforms.
- Operationalize detection‑as‑code practices, including version control, automated testing, and continuous improvement.
- Collaborate with Threat Intelligence and manage Threat Hunting teams to integrate adversary TTPs into detection pipelines.
- Drive automation of alert triage and enrichment through SOAR playbooks.
- Ensure telemetry coverage across endpoints, networks, and cloud environments for comprehensive visibility.
- Own the end‑to‑end security incident response lifecycle: detection, containment, eradication, recovery, and lessons learned.
- Establish and enforce SOC processes, workflows, and playbooks for efficient incident handling.
- Coordinate with Legal, Privacy, and Risk teams during major incidents to ensure compliance and minimize business impact.
- Lead post‑incident reviews and root cause analysis to strengthen detection and response capabilities.
- Develop and execute hypothesis‑driven hunts leveraging MITRE ATT&CK and threat intelligence.
- Identify gaps in existing detection coverage and feed findings back into engineering pipelines.
- Use advanced analytics and machine learning models to uncover stealthy or emerging threats.
- Foster a proactive security culture by embedding hunting practices into daily operations.
Strategic Alignment to GCAT SOC10x:
- 10X People: Build a high‑performing team with continuous learning and knowledge‑sharing culture.
- 10X Process: Implement agile, automated workflows for detection and response.
- 10X Technology: Leverage AI/ML‑driven detection models and cloud‑scale telemetry ingestion.
- 10X Visibility: Achieve full‑stack observability across hybrid environments.
- 10X Speed: Reduce Mean Time to Detect (MTTD) and Mean Time to Respond (MTTR) through automation and orchestration.
What you’ll need:
- Deep knowledge of SIEM, SOAR, EDR, NDR, and cloud security platforms.
- Proficiency in scripting and automation (Python, PowerShell) and detection‑as‑code principles.
- Strong understanding of adversary tactics, techniques, and procedures (TTPs) and MITRE ATT&CK framework.
- Experience with threat intelligence integration and behavioral analytics.
- Proven track record of leading global SOC or Detection & Response teams in complex enterprise environments.
- Ability to define vision, strategy, and roadmaps for detection engineering and incident response.
- Skilled in stakeholder management and cross‑functional collaboration (Legal, Risk, IT, DevOps).
- CISSP, GIAC GCFA/GCTI, or equivalent advanced security certifications.
- Automation‑first mindset with a focus on scalability and resilience.
- Strong analytical and problem‑solving skills.
- Excellent communication and leadership capabilities.
Who you are:
- You’re open: We are inclusive and collaborative; we encourage the free exchange of ideas; we respect and celebrate diverse views. We are open‑minded: to new ideas, new partnerships, new ways of working.
- You’re optimistic: We believe in the power of creativity, technology and talent to create brighter futures for our people, our clients and our communities. We approach all that we do with conviction: to try the new and to seek the unexpected.
- You’re extraordinary: we are stronger together: through collaboration we achieve the amazing. We are creative leaders and pioneers of our industry; we provide extraordinary every day.
What we’ll give you:
- Passionate, inspired people – We aim to create a culture in which people can do extraordinary work.
- Scale and opportunity – We offer the opportunity to create, influence and complete projects at a scale that is unparalleled in the industry.
- Challenging and stimulating work – Unique work and the opportunity to join a group of creative problem solvers.
Are you up for the challenge? We believe the best work happens when we’re together, fostering creativity, collaboration, and connection. That’s why we’ve adopted a hybrid approach, with teams in the office around four days a week. If you require accommodations or flexibility, please discuss this with the hiring team during the interview process.
Equal Opportunity and Privacy Notice: WPP is an equal opportunity employer and considers applicants for all positions without discrimination or regard to particular characteristics. We are committed to fostering a culture of respect in which everyone feels they belong and has the same opportunities to progress in their careers. Please read our Privacy Notice for more information on how we process the information you provide.
Head of Detection Engineering, London employer: WPP Media
Contact Detail:
WPP Media Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Head of Detection Engineering, London
✨Tip Number 1
Network like a pro! Reach out to current or former employees at WPP on LinkedIn. A friendly chat can give you insider info and maybe even a referral, which can really boost your chances.
✨Tip Number 2
Prepare for the interview by diving deep into WPP's recent projects and initiatives. Show us that you’re not just another candidate; you’re genuinely interested in how you can contribute to our creative transformation.
✨Tip Number 3
Practice your storytelling skills! Be ready to share specific examples of your past experiences that align with the role. We love hearing about how you've tackled challenges and led teams to success.
✨Tip Number 4
Don’t forget to apply through our website! It’s the best way to ensure your application gets seen by the right people. Plus, it shows you’re serious about joining our team.
We think you need these skills to ace Head of Detection Engineering, London
Some tips for your application 🫡
Show Your Passion: When writing your application, let your enthusiasm for the role shine through! We want to see how excited you are about the opportunity to lead detection engineering at WPP and how your skills align with our mission.
Tailor Your CV: Make sure to customise your CV to highlight relevant experience that matches the job description. We’re looking for specific skills in SIEM, SOAR, and automation, so don’t hold back on showcasing your expertise!
Craft a Compelling Cover Letter: Your cover letter is your chance to tell us why you’re the perfect fit for this role. Share your vision for the future of detection engineering and how you plan to drive innovation at WPP. Keep it engaging and personal!
Apply Through Our Website: We encourage you to apply directly through our website. It’s the best way to ensure your application gets into the right hands. Plus, you’ll find all the details you need about the role and our company culture there!
How to prepare for a job interview at WPP Media
✨Know Your Tech Inside Out
Make sure you’re well-versed in SIEM, SOAR, EDR, and NDR platforms. Brush up on your scripting skills, especially in Python and PowerShell, as these will be crucial for the role. Being able to discuss specific technologies and how you've used them in past roles will show you're the right fit.
✨Showcase Your Leadership Skills
As a Head of Detection Engineering, you'll need to demonstrate your ability to lead global teams. Prepare examples of how you've built high-performing teams and fostered a culture of continuous learning. Highlight any experience you have with cross-functional collaboration, especially with Legal and Risk teams.
✨Understand the Bigger Picture
Familiarise yourself with WPP's mission and values, particularly their focus on creativity and transformation. Be ready to discuss how your vision aligns with their goals, especially regarding automation and threat detection. This shows that you’re not just looking for a job, but are genuinely interested in contributing to their success.
✨Prepare for Scenario-Based Questions
Expect to face questions that assess your problem-solving abilities in real-world scenarios. Think about past incidents you've managed and how you applied detection and response strategies. Use the STAR method (Situation, Task, Action, Result) to structure your answers effectively.