Sida 1 av 1
WPP is the trusted growth partner for the world’s leading brands. We unite cutting-edge media intelligence and data solutions, world-class creativity, next-generation production, transformative enterprise solutions and expert strategic counsel in a single company – powered by exceptional talent and our agentic marketing platform, WPP Open, to help our clients navigate change, capture opportunity and deliver transformational growth. We work with the world's most valuable brands and have global reach across 100+ markets, with deep local expertise. Our people are the key to our success. We're committed to fostering a culture of creativity, belonging and continuous learning, attracting and developing the brightest talent, and providing exciting career opportunities that help our people grow. For more information, visit WPP.com. * Department: Data & Technology Solutions (DTS) * Reports To: SVP Security and Compliance * Location: [London/Hybrid 2 days a week in office] * Position Type: Full-Time ROLE OVERVIEW The Product, Application and Offensive Security Lead is responsible for embedding security directly into the design, development, testing, and operation of DTS products and platforms. This is a hands-on security engineering role. The role requires someone who can work directly with product and engineering teams, review designs, assess APIs, run threat models, test systems, coordinate penetration testing, identify vulnerabilities, and help teams remediate issues. The role ensures DTS products, APIs, data collaboration capabilities, AI-enabled workflows, and client-facing services are designed, built, and tested securely. It also owns the practical offensive security and adversarial assurance activity needed to test DTS products from an attacker’s perspective. The Product, Application and Offensive Security Lead will work closely with Product, Engineering, Architecture, Infrastructure, Security Operations, Privacy, Cloud and Platform Security, and the ISMS and Risk Officer to ensure security issues are identified early, fixed effectively, and tracked through governance where required. ---------------------------------------------------------------------------------------------------------------------------------- KEY RESPONSIBILITIES 1. HANDS-ON PRODUCT AND APPLICATION SECURITY Provide hands-on security support across DTS products and engineering teams. This includes: * Reviewing product designs, technical designs, APIs, services, and integrations. * Identifying security weaknesses in applications, workflows, and data flows. * Advising engineering teams on secure implementation. * Supporting secure design decisions during product discovery and delivery. * Helping teams resolve security issues pragmatically without creating unnecessary delivery friction. 2. SECURE SOFTWARE DEVELOPMENT LIFECYCLE (SDLC) Embed security into the software development lifecycle across DTS. This includes: * Defining and applying secure engineering standards. * Supporting secure coding practices. * Reviewing CI/CD security controls. * Supporting SAST, DAST, SCA, secrets scanning, dependency scanning, and container scanning. * Helping teams triage, prioritise, and remediate security findings. * Working with engineering teams to make security checks practical and repeatable. 3. THREAT MODELLING AND SECURITY DESIGN REVIEWS Run threat modelling and security design reviews for new and changed capabilities. This includes: * Facilitating threat modelling sessions with engineering and product teams. * Reviewing authentication and authorization designs. * Assessing API exposure, data flows, trust boundaries, and abuse cases. * Identifying risks around tenant isolation, privilege escalation, data leakage, and misuse. * Documenting key findings, recommendations, and residual risks. 4. OFFENSIVE SECURITY AND ADVERSARIAL TESTING Carry out and coordinate offensive security testing across DTS products and platforms. This includes: * Performing hands-on security testing of products, APIs, and workflows. * Coordinating external penetration tests. * Supporting red team and purple team exercises where required. * Testing abuse cases and attacker paths. * Testing access control, authentication, authorization, and data leakage risks. * Validating remediation of security findings. * Feeding material risks into the ISMS and Risk Officer for tracking. 5. API, INTEGRATION AND DATA PRODUCT SECURITY Provide security assurance for APIs, integrations, and data products. This includes: * Reviewing externally exposed APIs and partner integrations. * Assessing rate limiting, authorization, tenant isolation, logging, abuse prevention, and data leakage controls. * Supporting secure integration between InfoSum, Open Intelligence, Resolve, WPP Open, and third-party platforms. * Reviewing data product workflows for misuse, excessive access, or unintended exposure. * Working with Privacy Engineering on privacy-sensitive APIs, algorithms, and outputs. 6. AI AND AGENTIC SECURITY TESTING Provide hands-on security review and adversarial testing for AI-enabled and agentic capabilities. This includes: * Testing prompt injection, tool misuse, data leakage, and excessive agency. * Reviewing how agents access APIs, data, tools, and workflows. * Testing whether agent permissions can be bypassed or escalated. * Assessing action boundaries and human approval points. * Working with Identity, AI, and Data Access Governance to validate agent access models. * Documenting AI and agentic security risks and remediation actions. 7. VULNERABILITY TRIAGE AND REMEDIATION SUPPORT Help teams understand, prioritise, and fix security vulnerabilities. This includes: * Reviewing vulnerability findings from scans, penetration tests, code reviews, cloud tools, and external reports. * Prioritising findings based on exploitability, exposure, data sensitivity, and business impact. * Working directly with engineers to define remediation options. * Validating that fixes are effective. * Supporting exception and risk acceptance decisions where remediation is delayed. * Ensuring significant issues are visible through the DTS risk process. 8. ENGINEERING ENABLEMENT AND SECURITY COACHING Act as a practical security partner to engineering teams. This includes: * Providing secure implementation guidance. * Creating lightweight security patterns and examples. * Coaching engineers on common application, API, and AI security risks. * Helping teams understand the “why” behind security requirements. * Supporting a culture where security is part of product quality, not a separate approval gate. ---------------------------------------------------------------------------------------------------------------------------------- KEY ACCOUNTABILITIES The Product, Application and Offensive Security Lead will be accountable for: * Hands-on application and product security support across DTS. * Secure SDLC guidance and practical adoption. * Threat modelling and security design reviews. * API, integration, and data product security reviews. * Offensive security and adversarial testing activity. * AI and agentic security testing. * Vulnerability triage, remediation guidance, and fix validation. * Coordination with ISMS/Risk to ensure material risks and exceptions are tracked. * Helping engineering teams build secure systems without unnecessary delivery drag. ---------------------------------------------------------------------------------------------------------------------------------- SKILLS AND EXPERIENCE The successful candidate will have: * Strong hands-on experience in application security, product security, offensive security, security engineering, or penetration testing. * Good understanding of modern software engineering, APIs, SaaS platforms, distributed systems, and cloud-native applications. * Experience with threat modelling and secure design reviews. * Practical knowledge of common application and API security risks, including authentication, authorization, tenant isolation, injection, data leakage, privilege escalation, and supply chain risk. * Experience using security testing tools and techniques across web applications, APIs, cloud services, and CI/CD pipelines. * Familiarity with SAST, DAST, SCA, secrets scanning, dependency scanning, and vulnerability management workflows. * Experience working directly with engineers to remediate findings. * Understanding of AI and agentic security risks would be highly valuable. * Ability to communicate clearly with engineering, product, architecture, security, and leadership stakeholders. * A pragmatic, delivery-aware approach to security. ---------------------------------------------------------------------------------------------------------------------------------- LEADERSHIP EXPECTATIONS The Product, Application and Offensive Security Lead is expected to: * Be hands-on and technically credible with engineering teams. * Act as a trusted security partner, not just a reviewer or approver. * Challenge insecure designs constructively. * Help teams find practical ways to reduce risk. * Prioritise issues based on real-world exploitability and business impact. * Work across multiple DTS product areas without becoming a delivery bottleneck. * Escalate material risks clearly through the appropriate governance routes. * Promote secure engineering habits through practical guidance and example. ---------------------------------------------------------------------------------------------------------------------------------- SUCCESS MEASURES Success in the role will be measured by: * Security being embedded earlier in product and engineering delivery. * Reduction in high-risk application, API, and product vulnerabilities. * Regular threat modelling and security reviews for critical DTS capabilities. * Effective offensive and adversarial testing of products, APIs, and workflows. * Faster remediation of penetration test and security testing findings. * Improved security assurance for AI and agentic workflows. * Engineering teams receiving practical, actionable security guidance. * Material security risks being surfaced and tracked through the DTS risk process. * Security being viewed by engineering teams as an enabler of trusted delivery rather than a blocker. You're open: We are inclusive and collaborative; we encourage the free exchange of ideas; we respect and celebrate diverse views. We are open-minded: to new ideas, new partnerships, new ways of working. You're optimistic: We believe in the power of creativity, technology and talent to create brighter futures or our people, our clients and our communities. We approach all that we do with conviction: to try the new and to seek the unexpected. You're extraordinary: we are stronger together: through collaboration we achieve the amazing. We are creative leaders and pioneers of our industry; we provide extraordinary every day. What we'll give you: Passionate, inspired people – We aim to create a culture in which people can do extraordinary work. Scale and opportunity – We offer the opportunity to create, influence and complete projects at a scale that is unparalleled in the industry. Challenging and stimulating work – Unique work and the opportunity to join a group of creative problem solvers. Are you up for the challenge? #LI-Hybrid We believe the best work happens when we're together, fostering creativity, collaboration, and connection. That's why we’ve adopted a hybrid approach, with teams in the office around four days a week. If you require accommodations or flexibility, please discuss this with the hiring team during the interview process. WPP is an equal opportunity employer and considers applicants for all positions without discrimination or regard to particular characteristics. We are committed to fostering a culture of respect in which everyone feels they belong and has the same opportunities to progress in their careers. PLEASE READ OUR PRIVACY NOTICE (HTTPS://WWW.WPP.COM/EN/CAREERS/WPP-PRIVACY-POLICY-FOR-RECRUITMENT) FOR MORE INFORMATION ON HOW WE PROCESS THE INFORMATION YOU PROVIDE.
Aker Systems was founded in 2017 by a team of experienced technology professionals who recognised an opportunity to provide highly secure enterprise data platforms to large organisations. We build and operate ground-breaking, ultra-secure, high performance, cloud-based data infrastructure for the enterprise. Our proprietary technology solutions drive performance and reduce costs while helping our clients to improve the management and sharing of data across their organisations. In 2024, Aker Systems won the Breakthrough Culture Awards highlighting growth companies putting culture first. In 2020 Aker Systems was recognised as a ‘One to Watch’ on the Sunday Times Tech Track. The Company was also recognised at the Thames Valley Tech Awards 2020; winning the Thames Valley Tech Company of the year, the Emerging Tech Company and High Growth Tech Business categories. We encourage people of all different backgrounds and identities to apply. We are committed to maintaining an inclusive, and supportive place for you to do your very best work. About the Role We are seeking a Lead Performance Automation Engineer to define and drive performance engineering strategy, tooling, and practices across large-scale, distributed, cloud-native platforms. This is a technical leadership role responsible for ensuring systems are: * Scalable * Reliable * Resilient under load * Optimised for performance and cost efficiency You will lead performance testing and engineering initiatives across multiple teams, embedding non-functional quality into every stage of the software lifecycle. Key Responsibilities 1. Performance Engineering Strategy & Leadership * Define and own the organisation-wide performance testing and engineering strategy. * Establish standards for: * Performance testing approaches * Workload modelling * Capacity planning * Introduce and scale performance engineering practices across multiple delivery teams. * Provide technical leadership and mentoring to QA and engineering teams on performance best practices. * Align performance goals with business SLAs, SLOs, and user experience expectations. 2. Performance Test Architecture & Automation * Design and implement scalable performance test frameworks and automation pipelines. * Lead adoption of tools such as: * Gatling, JMeter, k6, Locust or similar * Build reusable solutions for: * Load testing * Stress testing * Spike testing * Soak testing * Integrate performance testing into CI/CD pipelines for continuous validation. * Ensure performance tests are repeatable, reliable, and production-representative. 3. Workload Modelling & Test Design * Define realistic user workload models based on production data and usage patterns. * Design performance test scenarios reflecting: * Peak load * Concurrent users * Throughput and latency requirements * Apply risk-based prioritisation for performance testing. * Ensure coverage across: * APIs * Microservices * Data pipelines * Event-driven systems 4. Backend, API & Distributed System Performance * Lead performance validation for: * Microservices architectures * Event-driven systems (Kafka) * High-throughput APIs * Analyse latency, throughput, error rates, and bottlenecks across distributed systems. * Validate system behaviour under failure conditions and degraded environments. * Ensure horizontal scalability and resilience strategies are tested. 5. Cloud, Infrastructure & Scalability Testing * Validate performance across: * AWS cloud environments * Containerised platforms (Docker, Kubernetes) * Conduct capacity planning and infrastructure benchmarking. * Ensure systems scale efficiently using: * Auto-scaling * Load balancing * Distributed architectures * Evaluate performance of Infrastructure as Code (Terraform) deployments. 6. Observability, Analysis & Bottleneck Resolution * Use observability tools to analyse system performance, including: * Metrics (Prometheus, Datadog) * Logs (ELK) * Traces (distributed tracing tools) * Identify and diagnose: * CPU, memory, I/O bottlenecks * Network latency issues * Database performance constraints * Collaborate with engineering teams to optimise system performance and architecture. 7. Non-Functional Quality Governance * Define and enforce performance SLAs, SLOs, and acceptance criteria. * Establish quality gates for performance within CI/CD pipelines. * Ensure performance requirements are validated before production release. * Drive adoption of performance testing standards across teams. * Support audit, compliance, and regulatory expectations in performance-critical systems. 8. Production Performance & Continuous Improvement * Analyse real production performance data to refine testing strategies. * Lead performance-related incident investigations and RCA activities. * Establish feedback loops between production observability and test environments. * Drive improvements in: * System responsiveness * Stability under load * Operational resilience 9. Metrics, Reporting & Optimisation * Define and track performance KPIs, including: * Response times * Throughput * Error rates * Resource utilisation * Build performance dashboards and reporting frameworks. * Drive continuous optimisation initiatives based on performance data. * Align performance metrics with business outcomes and user experience. Technology Environment Performance Testing Tools * Gatling, k6, JMeter, Locust (or similar) Languages * Java, Kotlin, Python, or JavaScript Architecture * Microservices, Event-driven systems, Kafka Cloud & Infrastructure * AWS, Kubernetes, Docker, Terraform CI/CD * GitHub Actions, GitLab CI, Jenkins Observability * Prometheus, Grafana, Datadog, ELK, Distributed Tracing What We’re Looking For Essential * Proven experience as a Performance Test Lead / Performance Engineer / SDET * Strong experience defining performance testing strategies and frameworks * Hands-on expertise with modern performance testing tools * Deep understanding of: * Scalability and distributed system performance * Cloud-native architectures * Experience integrating performance testing into CI/CD pipelines * Strong skills in: * Performance analysis and bottleneck identification * Root cause analysis and system optimisation * Experience defining and tracking performance SLAs/SLOs and KPIs * Ability to lead and influence cross-team quality improvements Desirable * Experience in high-scale or regulated environments * Exposure to: * Chaos engineering * Resilience and fault injection testing * Experience with capacity planning and cost optimisation * Knowledge of security-performance interactions (e.g., encryption overhead) Personal Attributes * Strong systems thinking and analytical mindset * Ability to translate performance data into practical engineering improvements * Influential leader across engineering and product teams * Proactive and outcome-driven * Strong communication and stakeholder management skills Aker Systems Attributes At Aker we work as a team; we are collaborative, hardworking, open, and delivery obsessed. There is no blame culture here: try things, and take responsibility for the outcomes. You are always part of the wider Aker. We help our colleagues and take pride in successfully achieving difficult tasks. We run towards problems and help to solve them. Communicate always, do so accurately and in a timely fashion. In return, we offer a competitive salary, 25 days holiday plus bank holidays, company paid medical insurance and life assurance, pension scheme, annual training allowance, wellbeing allowance, virtual GP, Employee Assistance plan and more. Equal Opportunities Aker Systems fosters a diverse environment that encourages openness in its communications and is committed to providing equal employment opportunity for all people regardless of race, religion, gender or sexual orientation, age, marital status, national origin, citizenship status, disability, veteran status or other personal characteristics. We embrace differences of opinion and diversity because they help challenge us and find new groundbreaking technical solutions.