Sida 1 av 1
WPP is the trusted growth partner for the world’s leading brands. We unite cutting-edge media intelligence and data solutions, world-class creativity, next-generation production, transformative enterprise solutions and expert strategic counsel in a single company – powered by exceptional talent and our agentic marketing platform, WPP Open, to help our clients navigate change, capture opportunity and deliver transformational growth. We work with the world's most valuable brands and have global reach across 100+ markets, with deep local expertise. Our people are the key to our success. We're committed to fostering a culture of creativity, belonging and continuous learning, attracting and developing the brightest talent, and providing exciting career opportunities that help our people grow. For more information, visit WPP.com. * Department: Data & Technology Solutions (DTS) * Reports To: SVP Security and Compliance * Location: [London/Hybrid 2 days a week in office] * Position Type: Full-Time ROLE OVERVIEW The Product, Application and Offensive Security Lead is responsible for embedding security directly into the design, development, testing, and operation of DTS products and platforms. This is a hands-on security engineering role. The role requires someone who can work directly with product and engineering teams, review designs, assess APIs, run threat models, test systems, coordinate penetration testing, identify vulnerabilities, and help teams remediate issues. The role ensures DTS products, APIs, data collaboration capabilities, AI-enabled workflows, and client-facing services are designed, built, and tested securely. It also owns the practical offensive security and adversarial assurance activity needed to test DTS products from an attacker’s perspective. The Product, Application and Offensive Security Lead will work closely with Product, Engineering, Architecture, Infrastructure, Security Operations, Privacy, Cloud and Platform Security, and the ISMS and Risk Officer to ensure security issues are identified early, fixed effectively, and tracked through governance where required. ---------------------------------------------------------------------------------------------------------------------------------- KEY RESPONSIBILITIES 1. HANDS-ON PRODUCT AND APPLICATION SECURITY Provide hands-on security support across DTS products and engineering teams. This includes: * Reviewing product designs, technical designs, APIs, services, and integrations. * Identifying security weaknesses in applications, workflows, and data flows. * Advising engineering teams on secure implementation. * Supporting secure design decisions during product discovery and delivery. * Helping teams resolve security issues pragmatically without creating unnecessary delivery friction. 2. SECURE SOFTWARE DEVELOPMENT LIFECYCLE (SDLC) Embed security into the software development lifecycle across DTS. This includes: * Defining and applying secure engineering standards. * Supporting secure coding practices. * Reviewing CI/CD security controls. * Supporting SAST, DAST, SCA, secrets scanning, dependency scanning, and container scanning. * Helping teams triage, prioritise, and remediate security findings. * Working with engineering teams to make security checks practical and repeatable. 3. THREAT MODELLING AND SECURITY DESIGN REVIEWS Run threat modelling and security design reviews for new and changed capabilities. This includes: * Facilitating threat modelling sessions with engineering and product teams. * Reviewing authentication and authorization designs. * Assessing API exposure, data flows, trust boundaries, and abuse cases. * Identifying risks around tenant isolation, privilege escalation, data leakage, and misuse. * Documenting key findings, recommendations, and residual risks. 4. OFFENSIVE SECURITY AND ADVERSARIAL TESTING Carry out and coordinate offensive security testing across DTS products and platforms. This includes: * Performing hands-on security testing of products, APIs, and workflows. * Coordinating external penetration tests. * Supporting red team and purple team exercises where required. * Testing abuse cases and attacker paths. * Testing access control, authentication, authorization, and data leakage risks. * Validating remediation of security findings. * Feeding material risks into the ISMS and Risk Officer for tracking. 5. API, INTEGRATION AND DATA PRODUCT SECURITY Provide security assurance for APIs, integrations, and data products. This includes: * Reviewing externally exposed APIs and partner integrations. * Assessing rate limiting, authorization, tenant isolation, logging, abuse prevention, and data leakage controls. * Supporting secure integration between InfoSum, Open Intelligence, Resolve, WPP Open, and third-party platforms. * Reviewing data product workflows for misuse, excessive access, or unintended exposure. * Working with Privacy Engineering on privacy-sensitive APIs, algorithms, and outputs. 6. AI AND AGENTIC SECURITY TESTING Provide hands-on security review and adversarial testing for AI-enabled and agentic capabilities. This includes: * Testing prompt injection, tool misuse, data leakage, and excessive agency. * Reviewing how agents access APIs, data, tools, and workflows. * Testing whether agent permissions can be bypassed or escalated. * Assessing action boundaries and human approval points. * Working with Identity, AI, and Data Access Governance to validate agent access models. * Documenting AI and agentic security risks and remediation actions. 7. VULNERABILITY TRIAGE AND REMEDIATION SUPPORT Help teams understand, prioritise, and fix security vulnerabilities. This includes: * Reviewing vulnerability findings from scans, penetration tests, code reviews, cloud tools, and external reports. * Prioritising findings based on exploitability, exposure, data sensitivity, and business impact. * Working directly with engineers to define remediation options. * Validating that fixes are effective. * Supporting exception and risk acceptance decisions where remediation is delayed. * Ensuring significant issues are visible through the DTS risk process. 8. ENGINEERING ENABLEMENT AND SECURITY COACHING Act as a practical security partner to engineering teams. This includes: * Providing secure implementation guidance. * Creating lightweight security patterns and examples. * Coaching engineers on common application, API, and AI security risks. * Helping teams understand the “why” behind security requirements. * Supporting a culture where security is part of product quality, not a separate approval gate. ---------------------------------------------------------------------------------------------------------------------------------- KEY ACCOUNTABILITIES The Product, Application and Offensive Security Lead will be accountable for: * Hands-on application and product security support across DTS. * Secure SDLC guidance and practical adoption. * Threat modelling and security design reviews. * API, integration, and data product security reviews. * Offensive security and adversarial testing activity. * AI and agentic security testing. * Vulnerability triage, remediation guidance, and fix validation. * Coordination with ISMS/Risk to ensure material risks and exceptions are tracked. * Helping engineering teams build secure systems without unnecessary delivery drag. ---------------------------------------------------------------------------------------------------------------------------------- SKILLS AND EXPERIENCE The successful candidate will have: * Strong hands-on experience in application security, product security, offensive security, security engineering, or penetration testing. * Good understanding of modern software engineering, APIs, SaaS platforms, distributed systems, and cloud-native applications. * Experience with threat modelling and secure design reviews. * Practical knowledge of common application and API security risks, including authentication, authorization, tenant isolation, injection, data leakage, privilege escalation, and supply chain risk. * Experience using security testing tools and techniques across web applications, APIs, cloud services, and CI/CD pipelines. * Familiarity with SAST, DAST, SCA, secrets scanning, dependency scanning, and vulnerability management workflows. * Experience working directly with engineers to remediate findings. * Understanding of AI and agentic security risks would be highly valuable. * Ability to communicate clearly with engineering, product, architecture, security, and leadership stakeholders. * A pragmatic, delivery-aware approach to security. ---------------------------------------------------------------------------------------------------------------------------------- LEADERSHIP EXPECTATIONS The Product, Application and Offensive Security Lead is expected to: * Be hands-on and technically credible with engineering teams. * Act as a trusted security partner, not just a reviewer or approver. * Challenge insecure designs constructively. * Help teams find practical ways to reduce risk. * Prioritise issues based on real-world exploitability and business impact. * Work across multiple DTS product areas without becoming a delivery bottleneck. * Escalate material risks clearly through the appropriate governance routes. * Promote secure engineering habits through practical guidance and example. ---------------------------------------------------------------------------------------------------------------------------------- SUCCESS MEASURES Success in the role will be measured by: * Security being embedded earlier in product and engineering delivery. * Reduction in high-risk application, API, and product vulnerabilities. * Regular threat modelling and security reviews for critical DTS capabilities. * Effective offensive and adversarial testing of products, APIs, and workflows. * Faster remediation of penetration test and security testing findings. * Improved security assurance for AI and agentic workflows. * Engineering teams receiving practical, actionable security guidance. * Material security risks being surfaced and tracked through the DTS risk process. * Security being viewed by engineering teams as an enabler of trusted delivery rather than a blocker. You're open: We are inclusive and collaborative; we encourage the free exchange of ideas; we respect and celebrate diverse views. We are open-minded: to new ideas, new partnerships, new ways of working. You're optimistic: We believe in the power of creativity, technology and talent to create brighter futures or our people, our clients and our communities. We approach all that we do with conviction: to try the new and to seek the unexpected. You're extraordinary: we are stronger together: through collaboration we achieve the amazing. We are creative leaders and pioneers of our industry; we provide extraordinary every day. What we'll give you: Passionate, inspired people – We aim to create a culture in which people can do extraordinary work. Scale and opportunity – We offer the opportunity to create, influence and complete projects at a scale that is unparalleled in the industry. Challenging and stimulating work – Unique work and the opportunity to join a group of creative problem solvers. Are you up for the challenge? #LI-Hybrid We believe the best work happens when we're together, fostering creativity, collaboration, and connection. That's why we’ve adopted a hybrid approach, with teams in the office around four days a week. If you require accommodations or flexibility, please discuss this with the hiring team during the interview process. WPP is an equal opportunity employer and considers applicants for all positions without discrimination or regard to particular characteristics. We are committed to fostering a culture of respect in which everyone feels they belong and has the same opportunities to progress in their careers. PLEASE READ OUR PRIVACY NOTICE (HTTPS://WWW.WPP.COM/EN/CAREERS/WPP-PRIVACY-POLICY-FOR-RECRUITMENT) FOR MORE INFORMATION ON HOW WE PROCESS THE INFORMATION YOU PROVIDE.
Principal Java Engineer - Backend Platform Salary: £76,340 - £100,340 Per Annum Contract: Full-Time, Permanent Location: Hybrid - minimum 2 days per week in office, Basingstoke/London/Bristol ABOUT THE ROLE The Principal Software Engineer (Full-Stack, Backend-leaning) is a senior engineer responsible for the backend architecture, data pipelines, and API layer of a new sports technology product, while remaining capable of contributing to frontend development as needed. This role sits within a small, fast-moving product engineering team and requires someone comfortable owning end-to-end technical delivery across the stack, with backend and data work as the primary focus. WHAT YOU’LL BUILD You will be a core contributor to a new backend platform being built from scratch. The work spans the full data journey - from ingestion at the edge through to storage, transformation, and delivery to end users. Key areas of focus include: * Low-latency data pipelines that ingest and process live sports tracking data, with strict latency requirements for time-critical outputs delivered to coaches and analysts in near real-time. * Event-driven processing using Kafka for streaming data and control messages between on-site devices and cloud services, handling both fast-path live outputs and asynchronous post-processing workflows via SQS and AWS Batch. * Cloud infrastructure on AWS, including Greengrass for edge-to-cloud orchestration, S3 for video and data storage, and Lambda for lightweight processing tasks. * Data transformation and aggregation layers that normalise tracking outputs, store them in a data lake, and make them available to downstream consumers via clean API contracts. * REST and WebSocket APIs that serve both a live data product for immediate consumption and an insights portal for historical analysis and performance comparison. * Observability and reliability - instrumentation, logging, and tracing are built in from the start, not bolted on. The platform needs to run 24/7 without on-site support. KEY RESPONSIBILITIES * Design and build backend services and APIs (REST/WebSocket) supporting data ingestion, transformation, and delivery to frontend and downstream consumers, with particular attention to latency and throughput given real-time processing requirements. * Own data storage and pipeline architecture, including integration with streaming/event infrastructure. * Implement authentication and authorisation in line with the team's chosen cloud identity and access management approach. * Provide technical direction and review for frontend development (React/TypeScript), working closely with frontend engineers to align on approach, component contracts, and data shapes - this is a collaboration and oversight function rather than day-to-day frontend delivery. * Collaborate closely with computer vision/data science engineers to define and consume data contracts. * Participate in technical decision-making for a product in active development, including architecture choices with long-term implications for scale, latency, and maintainability. * Contribute to technical leadership of the wider engineering team, given the seniority of this role. SKILLS AND EXPERIENCE * Strong backend engineering background with production experience in Java (required). * Demonstrated experience building low-latency, high-throughput systems - this is a core requirement, not a nice-to-have. * Working knowledge of a modern frontend framework such as React/TypeScript, sufficient to review and direct frontend work rather than deliver it independently. * Experience with cloud infrastructure and event-driven architectures (e.g. Kafka or equivalent streaming technology). * Experience designing and evolving API contracts (OpenAPI or similar) in a fast-moving, still-evolving product environment. * Familiarity with modern cloud identity and access management approaches (e.g. AWS Cognito or equivalent) is a plus. * Strong communication skills - able to work directly with product and cross-functional stakeholders, and to mentor or direct engineers outside their own core discipline. * Comfortable with ambiguity: this is a build-phase product with evolving scope and infrastructure decisions still being finalised. BENEFITS AND PERKS * 25 days annual leave (excluding bank holidays) * Enhanced pension scheme with 5% matching * Hybrid working model * Complimentary Unmind wellbeing app * Onsite gym (Basingstoke) * Access to sporting events and tickets * Sony Group Company discounts EQUAL OPPORTUNITY EMPLOYER Hawk-Eye is committed to fostering an inclusive and diverse workplace. We ensure all employees are treated fairly, regardless of gender, marital status, race, nationality, religion, age, disability, or union membership. We value diversity and strive to create an environment where everyone can reach their full potential. APPLY TODAY If you are passionate about building high-performance backend systems and want to work on real-time data products at scale, we would love to hear from you.
SUMMARY OF THE ROLE: At Maze, we're building AI-powered vulnerability management at a moment when generative AI is fundamentally changing what's possible in cybersecurity. Our engineering team is small, fast, and technically elite — and we're hiring an Engineering Director who is the same. This is not a coordination role. It is a senior technical leadership role for someone who earns respect by being on the tools, thinks deeply about architecture, and happens to be exceptional at growing engineers and running a high-performance org. You'll work in close partnership with our CTO, Santiago, taking ownership of a growing set of teams and tech leads as we scale from 20 to 35+ engineers. Your success will be measured the same way everyone's is at Maze: by the customer value and revenue impact of what your teams ship — not by process compliance, headcount growth, or delivery cadence. You'll have genuine accountability over a portion of the engineering org, with tech leads reporting to you, and you'll be expected to know your teams' codebases well enough to make good decisions, spot problems early, and earn the trust of every engineer who works with you. The person we're looking for has probably been the most senior technical person in a fast-moving 10–20 person engineering team — a CTO, VP, or Head of Engineering at a startup — and is ready to bring that energy and credibility to a company with more firepower behind it. If you want to stay close to the code, grow exceptional engineers, and help shape an org that will define how AI-native security companies are built, this is that role. YOUR CONTRIBUTIONS TO OUR JOURNEY: * Own engineering leadership for a growing portion of our org: Take clear accountability for a set of small, high-output product teams (typically 3–5 engineers each), with tech leads reporting directly to you. Ensure every team has unambiguous priorities, strong support, and everything they need to move fast. * Stay close to the technical work: Engage directly with architecture decisions, code reviews, and technical discussions across your teams. We expect you to spend meaningful time understanding what each team is building — not as a gatekeeper, but as a trusted technical voice who can contribute, challenge, and improve. * Grow the engineering leaders of Maze's future: Take ownership of career development, performance management, and coaching for tech leads and senior engineers in your teams. Build the kind of trust with engineers that comes from genuinely knowing their work, their growth areas, and their ambitions — not from generic 1:1s. * Drive cross-team coordination without creating bureaucracy: Own the planning and coordination layer that keeps multiple small teams aligned and unblocked. Keep it lightweight, decision-focused, and in service of engineering velocity — not process for its own sake. * Lead technical hiring: Take ownership of engineering hiring within your area, from defining the bar and shaping interview processes to closing exceptional candidates. The quality of who we hire is one of the highest-leverage things either of us can do. * Build the org we need to scale: Work closely with Santiago to design team structures, identify emerging leaders from within, and evolve how we operate as the team doubles. We grow leaders from the inside where we can — you'll be central to identifying, developing, and empowering the next generation. * Maintain technical excellence as we grow: Partner with tech leads to uphold code quality, shared engineering practices, and high standards across the org — without letting process replace judgment. WHAT YOU NEED TO BE SUCCESSFUL: * Technical credibility that engineers will respect: A strong engineering background with the ability to meaningfully engage in architecture discussions, code reviews, and technical decisions. You don't need to be the best coder in the room, but you need to be in the room for the right reasons. * Experience as the most senior technical leader of a small, high-output team: You've been a CTO, VP Engineering, or Head of Engineering at a startup — or a tech lead in a similarly fast-moving environment — where you were accountable for both technical outcomes and the people delivering them. You know what it looks like to lead 10–20 engineers, not just manage them. * Genuine people leadership, not just org design: A proven track record of performance management, career development, and growing engineers into leaders. You've had hard conversations, made difficult calls, and built cultures where high performance and high support coexist. * The hands-on instinct: You're drawn to being close to the work. You'd rather understand a problem by reading the code than by reading a status update. You see "staying technical" as a feature of your leadership style, not a tension with it. * Comfort with small-team operating models: Experience working in environments where teams are lean, fast, and expected to figure things out — not environments where scale compensates for speed. You know how to get a lot done with a little. * Strong hiring instincts: You've been deeply involved in engineering hiring — defining the bar, building processes, closing candidates — and you have strong opinions about what great looks like. * A business owner's mindset: You measure yourself by customer outcomes and revenue impact. You push your teams to understand why they're building what they're building, not just how. * Nice to Haves: * Experience in cybersecurity, AI, or security tooling — or a genuine interest in the domain and willingness to go deep quickly. * Founder or early-stage startup experience, particularly having built an engineering org from a small base. * Familiarity with agentic AI systems, LLMs, or ML-adjacent engineering — not as a researcher, but as someone who's built or led teams building on top of these technologies. * Experience managing distributed teams. WHY JOIN US: * Ambitious challenge: We're using generative AI — LLMs and agents — to solve some of the most pressing problems in cybersecurity today. The engineering challenges are genuinely hard, the domain matters, and we're early enough that the architectural decisions you make will define the platform for years. * Expert team: We are a team of hands-on leaders with experience at Big Tech and high-growth scale-ups, including teams behind multiple acquisitions and an IPO. We hire for quality over speed and it shows. * Impactful work: Cybersecurity is a force for good. The products your teams build directly help security teams protect their organisations against real attacks. The mission isn't decorative. * Build an AI-native engineering org from the ground up: We're designing the team structure, culture, and ways of working with a blank sheet of paper, in an era where agentic coding tools are changing what small teams can accomplish. You'll shape that from the start. * Real ownership and a clear growth path: You'll have genuine accountability over a meaningful portion of the organisation from day one, with a direct partnership with Santiago and significant equity upside as we scale.