Sida 1 av 1
WPP is the trusted growth partner for the world’s leading brands. We unite cutting-edge media intelligence and data solutions, world-class creativity, next-generation production, transformative enterprise solutions and expert strategic counsel in a single company – powered by exceptional talent and our agentic marketing platform, WPP Open, to help our clients navigate change, capture opportunity and deliver transformational growth. We work with the world's most valuable brands and have global reach across 100+ markets, with deep local expertise. Our people are the key to our success. We're committed to fostering a culture of creativity, belonging and continuous learning, attracting and developing the brightest talent, and providing exciting career opportunities that help our people grow. For more information, visit WPP.com. * Department: Data & Technology Solutions (DTS) * Reports To: SVP Security and Compliance * Location: [London/Hybrid 2 days a week in office] * Position Type: Full-Time ROLE OVERVIEW The Product, Application and Offensive Security Lead is responsible for embedding security directly into the design, development, testing, and operation of DTS products and platforms. This is a hands-on security engineering role. The role requires someone who can work directly with product and engineering teams, review designs, assess APIs, run threat models, test systems, coordinate penetration testing, identify vulnerabilities, and help teams remediate issues. The role ensures DTS products, APIs, data collaboration capabilities, AI-enabled workflows, and client-facing services are designed, built, and tested securely. It also owns the practical offensive security and adversarial assurance activity needed to test DTS products from an attacker’s perspective. The Product, Application and Offensive Security Lead will work closely with Product, Engineering, Architecture, Infrastructure, Security Operations, Privacy, Cloud and Platform Security, and the ISMS and Risk Officer to ensure security issues are identified early, fixed effectively, and tracked through governance where required. ---------------------------------------------------------------------------------------------------------------------------------- KEY RESPONSIBILITIES 1. HANDS-ON PRODUCT AND APPLICATION SECURITY Provide hands-on security support across DTS products and engineering teams. This includes: * Reviewing product designs, technical designs, APIs, services, and integrations. * Identifying security weaknesses in applications, workflows, and data flows. * Advising engineering teams on secure implementation. * Supporting secure design decisions during product discovery and delivery. * Helping teams resolve security issues pragmatically without creating unnecessary delivery friction. 2. SECURE SOFTWARE DEVELOPMENT LIFECYCLE (SDLC) Embed security into the software development lifecycle across DTS. This includes: * Defining and applying secure engineering standards. * Supporting secure coding practices. * Reviewing CI/CD security controls. * Supporting SAST, DAST, SCA, secrets scanning, dependency scanning, and container scanning. * Helping teams triage, prioritise, and remediate security findings. * Working with engineering teams to make security checks practical and repeatable. 3. THREAT MODELLING AND SECURITY DESIGN REVIEWS Run threat modelling and security design reviews for new and changed capabilities. This includes: * Facilitating threat modelling sessions with engineering and product teams. * Reviewing authentication and authorization designs. * Assessing API exposure, data flows, trust boundaries, and abuse cases. * Identifying risks around tenant isolation, privilege escalation, data leakage, and misuse. * Documenting key findings, recommendations, and residual risks. 4. OFFENSIVE SECURITY AND ADVERSARIAL TESTING Carry out and coordinate offensive security testing across DTS products and platforms. This includes: * Performing hands-on security testing of products, APIs, and workflows. * Coordinating external penetration tests. * Supporting red team and purple team exercises where required. * Testing abuse cases and attacker paths. * Testing access control, authentication, authorization, and data leakage risks. * Validating remediation of security findings. * Feeding material risks into the ISMS and Risk Officer for tracking. 5. API, INTEGRATION AND DATA PRODUCT SECURITY Provide security assurance for APIs, integrations, and data products. This includes: * Reviewing externally exposed APIs and partner integrations. * Assessing rate limiting, authorization, tenant isolation, logging, abuse prevention, and data leakage controls. * Supporting secure integration between InfoSum, Open Intelligence, Resolve, WPP Open, and third-party platforms. * Reviewing data product workflows for misuse, excessive access, or unintended exposure. * Working with Privacy Engineering on privacy-sensitive APIs, algorithms, and outputs. 6. AI AND AGENTIC SECURITY TESTING Provide hands-on security review and adversarial testing for AI-enabled and agentic capabilities. This includes: * Testing prompt injection, tool misuse, data leakage, and excessive agency. * Reviewing how agents access APIs, data, tools, and workflows. * Testing whether agent permissions can be bypassed or escalated. * Assessing action boundaries and human approval points. * Working with Identity, AI, and Data Access Governance to validate agent access models. * Documenting AI and agentic security risks and remediation actions. 7. VULNERABILITY TRIAGE AND REMEDIATION SUPPORT Help teams understand, prioritise, and fix security vulnerabilities. This includes: * Reviewing vulnerability findings from scans, penetration tests, code reviews, cloud tools, and external reports. * Prioritising findings based on exploitability, exposure, data sensitivity, and business impact. * Working directly with engineers to define remediation options. * Validating that fixes are effective. * Supporting exception and risk acceptance decisions where remediation is delayed. * Ensuring significant issues are visible through the DTS risk process. 8. ENGINEERING ENABLEMENT AND SECURITY COACHING Act as a practical security partner to engineering teams. This includes: * Providing secure implementation guidance. * Creating lightweight security patterns and examples. * Coaching engineers on common application, API, and AI security risks. * Helping teams understand the “why” behind security requirements. * Supporting a culture where security is part of product quality, not a separate approval gate. ---------------------------------------------------------------------------------------------------------------------------------- KEY ACCOUNTABILITIES The Product, Application and Offensive Security Lead will be accountable for: * Hands-on application and product security support across DTS. * Secure SDLC guidance and practical adoption. * Threat modelling and security design reviews. * API, integration, and data product security reviews. * Offensive security and adversarial testing activity. * AI and agentic security testing. * Vulnerability triage, remediation guidance, and fix validation. * Coordination with ISMS/Risk to ensure material risks and exceptions are tracked. * Helping engineering teams build secure systems without unnecessary delivery drag. ---------------------------------------------------------------------------------------------------------------------------------- SKILLS AND EXPERIENCE The successful candidate will have: * Strong hands-on experience in application security, product security, offensive security, security engineering, or penetration testing. * Good understanding of modern software engineering, APIs, SaaS platforms, distributed systems, and cloud-native applications. * Experience with threat modelling and secure design reviews. * Practical knowledge of common application and API security risks, including authentication, authorization, tenant isolation, injection, data leakage, privilege escalation, and supply chain risk. * Experience using security testing tools and techniques across web applications, APIs, cloud services, and CI/CD pipelines. * Familiarity with SAST, DAST, SCA, secrets scanning, dependency scanning, and vulnerability management workflows. * Experience working directly with engineers to remediate findings. * Understanding of AI and agentic security risks would be highly valuable. * Ability to communicate clearly with engineering, product, architecture, security, and leadership stakeholders. * A pragmatic, delivery-aware approach to security. ---------------------------------------------------------------------------------------------------------------------------------- LEADERSHIP EXPECTATIONS The Product, Application and Offensive Security Lead is expected to: * Be hands-on and technically credible with engineering teams. * Act as a trusted security partner, not just a reviewer or approver. * Challenge insecure designs constructively. * Help teams find practical ways to reduce risk. * Prioritise issues based on real-world exploitability and business impact. * Work across multiple DTS product areas without becoming a delivery bottleneck. * Escalate material risks clearly through the appropriate governance routes. * Promote secure engineering habits through practical guidance and example. ---------------------------------------------------------------------------------------------------------------------------------- SUCCESS MEASURES Success in the role will be measured by: * Security being embedded earlier in product and engineering delivery. * Reduction in high-risk application, API, and product vulnerabilities. * Regular threat modelling and security reviews for critical DTS capabilities. * Effective offensive and adversarial testing of products, APIs, and workflows. * Faster remediation of penetration test and security testing findings. * Improved security assurance for AI and agentic workflows. * Engineering teams receiving practical, actionable security guidance. * Material security risks being surfaced and tracked through the DTS risk process. * Security being viewed by engineering teams as an enabler of trusted delivery rather than a blocker. You're open: We are inclusive and collaborative; we encourage the free exchange of ideas; we respect and celebrate diverse views. We are open-minded: to new ideas, new partnerships, new ways of working. You're optimistic: We believe in the power of creativity, technology and talent to create brighter futures or our people, our clients and our communities. We approach all that we do with conviction: to try the new and to seek the unexpected. You're extraordinary: we are stronger together: through collaboration we achieve the amazing. We are creative leaders and pioneers of our industry; we provide extraordinary every day. What we'll give you: Passionate, inspired people – We aim to create a culture in which people can do extraordinary work. Scale and opportunity – We offer the opportunity to create, influence and complete projects at a scale that is unparalleled in the industry. Challenging and stimulating work – Unique work and the opportunity to join a group of creative problem solvers. Are you up for the challenge? #LI-Hybrid We believe the best work happens when we're together, fostering creativity, collaboration, and connection. That's why we’ve adopted a hybrid approach, with teams in the office around four days a week. If you require accommodations or flexibility, please discuss this with the hiring team during the interview process. WPP is an equal opportunity employer and considers applicants for all positions without discrimination or regard to particular characteristics. We are committed to fostering a culture of respect in which everyone feels they belong and has the same opportunities to progress in their careers. PLEASE READ OUR PRIVACY NOTICE (HTTPS://WWW.WPP.COM/EN/CAREERS/WPP-PRIVACY-POLICY-FOR-RECRUITMENT) FOR MORE INFORMATION ON HOW WE PROCESS THE INFORMATION YOU PROVIDE.
We Are Skyral: We believe every decision maker can be empowered by technology. Skyral combines AI, leading edge simulation technology and world class expertise to transform the decision making experience. Our products and services enable faster and more confident decisions in a complex, unforgiving world. We deploy practical, intuitive and efficient solutions to governments and enterprises, delivering outstanding outcomes at the speed of relevance. ---------------------------------------------------------------------------------------------------------------------------------- What We Do: (Omnia Training) At Omnia Training, we’ve brought together some of the UK’s most innovative defence training organisations under one powerful mission: to transform the British Army’s training system and create the best-trained Army in the world. Omnia Training is redefining the British Army’s collective training. To do that, we are looking for the best and brightest minds from across the UK. Omnia Training is at the heart of the UK’s bold Land Industrial Strategy. This is more than a job — it’s a mission. You will be part of a high-impact, collaborative environment, where every person in our team plays a critical role in delivering Omnia Training’s vision; designing, delivering, and transforming collective training. Please note that this role will require onsite working in Warminster. Due to the nature of this role, Skyral can only consider applications from candidates who live in the UK and are eligible for SC clearance. ---------------------------------------------------------------------------------------------------------------------------------- What We Are Looking For: * Proven ability to lead a software development team * Experience leading multidisciplinary engineering teams. * Ability to engage with MOD customer and commercial content providers * Ability to translate architecture into working systems. * Ability to unblock teams across modelling, integration, and platform issues. * A solid understanding of modelling and simulation principles. * A strong grounding in distributed systems design. ---------------------------------------------------------------------------------------------------------------------------------- Key Technical Proficiencies: * C++ and Go (Golang). * Cloud Native Computing & SDLC (Kubernetes, Git, CI/CD, ORAS, ArgoCD etc.) * Strong debugging and problem-solving skills across system boundaries. * Ability to reason about performance, latency, and system behaviour. * Familiarity with containerisation, Kubernetes-style environments, and distributed deployments. ---------------------------------------------------------------------------------------------------------------------------------- What You’ll Be Responsible For: * Leading a team of developers and the Skyral primary point of contact at Warminster. * You will hold technical accountability across multiple concurrent projects, whilst ensuring the team delivers a fully working training system, not just components. * Support the development solution architectures and turn these into implementation. * Make technical decisions across modelling, integration, and platform usage. * Step into problems across modelling challenges, integration issues, deployment blockers and guide engineering work across all disciplines. * Ensure solutions are designed to be composable, reusable, and comply with platform-first principles. * Act as the final escalation point for technical issues on site. * Maintain momentum across multiple parallel workstreams. ---------------------------------------------------------------------------------------------------------------------------------- Note: Please feel empowered to apply for this position, even if you think you may only align with some of the qualities listed above. Your unique skills and perspectives could be just what we’re looking for. ---------------------------------------------------------------------------------------------------------------------------------- What We Can Offer You: (Same For All Roles) * Honest Conversations About Compensation - We are actively recruiting for various positions and considering candidates with diverse levels of experience. Skyral maintains a well defined salary range which a member of our Talent team will discuss with you during the first initial call. * Unlimited Paid Holiday - At Skyral, we recognise the dedication and individual circumstances of our team members. We value and support the need to maintain a work-life balance, whether it’s taking time off during school holidays to be with your children, or simply having the flexibility to enjoy extended weekends without the stress of monitoring your remaining days off. * Private Medical & Dental Insurance - Your health and wellbeing is our priority. Skyral is partnered with Bupa and from day one you are covered with a Level 3 policy. Additionally, if you wish to include family members or dependents on this policy, we offer a substantial discount. * Enhanced Parental Leave - 26 weeks Maternity and 4 weeks Paternity leave. * Everything Else - Company Pension, Company Swag, Employee Assistance Programme. ---------------------------------------------------------------------------------------------------------------------------------- At Skyral, we are committed to fostering a culture of diversity, equality and inclusion. We also ensure that individuals with disabilities have access to reasonable adjustments. If you require such accommodations during the job application process we ask that you inform a member of our talent team.
Janes equips defence, government, and industry leaders with objective, accurate, and shareable data and analysis. Our experts combine advanced technology with proven tradecraft to deliver validated and contextual intelligence to assess threats, accelerate decisions, and anticipate change with confidence. We deliver our intelligence with the flexibility to fuse it with multiple sources in any system, enrich AI solutions, or access it through our portal. Job purpose: The Solutions Engineer is a critical member of the Product team, responsible for enabling the integration and optimization of Janes interconnected intelligence capabilities across the customer base. Working within the Product Solutions team, you will support the deployment, configuration, and enhancement of Janes data across a variety of systems, platforms, and mission-critical capabilities. This role focuses on enabling Janes data within individual systems, facilitating interoperability with third-party and customer datasets, and aligning with Customer’s AI, intelligence and data requirements. You will help define and document data standards, technical specifications, and integration pathways to improve customer outcomes and drive innovation. You will contribute to high-impact customer and partner projects across Europe and NATO, helping shape the future of Janes technical estate - including our graph knowledgebase, intelligence products, and supporting infrastructure. Your work will have a direct impact on national security and defence capability. How you will contribute at Janes: * System Integration: Support the integration of Janes data and models into customer systems of record, ensuring seamless functionality and operational relevance. * Product Delivery: Assist in the development and delivery of Janes Interconnected Intelligence products, capturing and aligning where possible with standards and technical expectations. * Customer Advisory: Provide remote and on-site technical advisory services to customers, offering guidance on data attributes, integration strategies, and system optimization. * Ontology & Model Development: Advise on the evolution of Janes data models and ontologies to ensure compatibility and seamless integration with customer ecosystems. * Gap Analysis: Identify and prioritize unmet data requirements critical to customer adoption and mission success. * Strategic Expansion: Explore adjacent content and data domains for potential expansion - either organically or via acquisition - to deepen Janes relevance and support for customer missions. * Market Intelligence: Monitor and report on partner and competitor activity within customer to identify opportunities for collaboration, expansion, or risk mitigation. * Presales & Bids: Support technical presales engagements, bid responses, and proposal submissions with subject matter expertise and solution design input. The ideal skills and experience for this role are: * Technical Proficiency: * * Proficient in Python, including SDKs, APIs, and data engineering best practices. * Solid understanding of the Software Development Lifecycle (SDLC). * Familiarity with at least one of the following technologies: ArcGIS, Palantir, RDBMS, Graph Databases. * Understanding of data models and/or ontologies * Experience in data integration, system interoperability or technical advisory roles—preferably within defence and intelligence sectors. * Communication: * Excellent presentation and communication skills, with the ability to engage technical and non-technical stakeholders. * Mindset & Approach: * * Passion for solving complex technical challenges. * Innovative, dynamic, and creative approach to problem-solving. * Willingness to learn, grow, and adapt in a fast-paced environment. * Clearance: * Eligibility to hold security clearance, including willingness to undergo the clearance process with company sponsorship if not already cleared. Desirable Skills & Experience: * Front-End & Web Technologies: * * Experience with JavaScript libraries (e.g., React) or frameworks (e.g., Vue). * Familiarity with geospatial JavaScript libraries such as ArcGIS Maps SDK, OpenLayers, Leaflet, Cesium etc. * Back-End & Infrastructure: * * Experience with Docker, Elasticsearch Palantir graph databases (e.g., Neo4j, ArangoDB, GraphDB). * Hands-on experience with cloud platforms and services, particularly AWS (EC2, Lambda, S3, etc.). * Background in backend or frontend architecture and development. * Geospatial & Intelligence Tools: * * Relevant experience using Esri technology and the full ArcGIS Enterprise suite, including ArcGIS Knowledge. * Security & Clearance: * * Experience working with national security and defence organizations. * Knowledge of the Intelligence cycle and ability to understand operational requirements and priorities. * Active security clearance is a strong advantage. Benefits: * 27 days of annual leave * Healthy half (0.5 day leave every 6 months for wellbeing) * Leave- study/ volunteer/ reserve forces * Pension plan (6% employer contribution) * Private medical insurance – BUPA * Maternity (100% of basic salary for the first 26 weeks followed by Statutory Maternity Pay) * Paternity (100% of basic salary for 6 weeks) * Life cover * Access to LinkedIn Learning * Access to an on-site gym ---------------------------------------------------------------------------------------------------------------------------------- LIFE AT JANES We believe Janes is truly a great place to work. Our values and leadership code drive everything we do, and we understand that the right behaviours and culture will always result in the best outcomes for our customers, our colleagues, our shareholders, and our business. We provide a supportive, stretching, and dynamic environment with the ability for you to grow rapidly, both personally and professionally. Janes is an inclusive and equal opportunities employer and encourages applications regardless of age, race, disability, religion / belief, sexual orientation, gender reassignment, marriage or civil partnership, pregnancy/maternity, or gender. Although this role is advertised as full time, Janes believed that flexibility at work can provide many significant benefits both to our colleagues and the business. We already work in a hybrid style across all offices and regions and can support different ways of working and offer different flexible working arrangements. So, if you are interested and have any requirements or needs in the way you would like to work, please apply, and speak to us about this. We will always consider part time or flexible applications Job Applicants - Privacy Policy Know your rights document
Kyowa Kirin is a fast-growing global specialty pharmaceutical company that applies state-of-the-art biotechnologies to discover and deliver novel medicines in four disease areas: bone and mineral; intractable hematologic; hematology oncology; and rare disease. A Japan-based company, our goal is to translate science into smiles by delivering therapies where no adequate treatments currently exist, working from drug discovery to product development and commercialization. In North America, we are headquartered in Princeton, NJ, with offices in California, North Carolina, and Mississauga, Ontario. Summary: The Manager, ICT Delivery plays a critical role in delivery of complex technology projects and IT services. They combine strategic planning with tactical execution to align team output with broader organizational goals, managing everything from initial scoping to final deployment and post-launch support. They ensure that digital initiatives are executed efficiently, securely and in alignment with GxP standards. They exhibit strong delivery leadership with a deep appreciation for the complexities of the pharmaceutical environment. Essential Functions: • Participate in project planning, execution, risk management, and quality assurance across multiple concurrent initiatives. • Ensure solutions meet regulatory and data privacy requirements, including GxP, 21 CFR Part 11, HIPPA, GDPR and data integrity standards. • Apply and follow appropriate delivery methodologies (Agile, Waterfall, hybrid) based on project needs and compliance considerations. • Collaborate with business, technical teams and vendors to ensure accurate translation of business requirements into technical solutions. • Assume accountability throughout all phases of system development lifecycle from ideation and planning through production support and troubleshooting. Additional activities may include, but are not limited to: • IT Project Oversight - Review project timelines, milestones, risks and budget to ensure delivery stays on track. • Stakeholder Communication & Alignment - Manage expectations, clarify priorities and drive compromise between business needs and technical constraints. • SDLC Compliance – Ensure all system changes follow appropriate lifecycle processes; review documentation for accuracy, completeness, and audit readiness. • Issue Resolution & Operational Support – Assist in the triage of issues / incidents that impact production systems or project timelines. Requirements: Education Bachelor’s degree or equivalent experience in computer science, information systems, engineering or related fields required Experience At least 5 years’ experience delivering IT projects within a regulated industry, ideally pharmaceuticals or life sciences; Familiarity with multiple functional domains (e.g. Quality, Regulatory, Medical, Commercial and/or Clinical); Knowledge of GxP compliance, validation practices and regulated system requirements; Experience with large-scale, global implementations; Experience with enterprise technologies such as Veeva Vault, Salesforce.com, Microsoft Dynamics Technical Skills Proficient in MS Office Suite. Working Conditions: Requires up to 10% domestic and international travel The anticipated salary for this position will be $121,000 to $156,800. The actual salary offered for this role at commencement of employment may vary based on several factors including but not limited to relevant experience, skill set, qualifications, education (including applicable licenses and certifications, job-based knowledge, location, and other business and organizational needs. The listed salary is just one component of the overall compensation package. At Kyowa Kirin North America we provide a comprehensive range of benefits including: * 401K with company match * Annual Bonus Program (Sales Bonus for Sales Jobs) * Generous PTO and Holiday Schedule which includes Summer and Winter Shut-Downs, Sick Days and, Volunteer Days * Healthcare Benefits (Medical, Dental, Prescription Drugs and Vision) * HSA & FSA Programs * Well-Being and Work/Life Programs * Life & Disability Insurance * Concierge Services * Long Term Incentive Program (subject to job level and performance) * Pet Insurance * Tuition Assistance * Employee Referral Awards The compensation and benefits information set forth in this posting applies to candidates hired in the United States. Candidates hired outside the United States will be eligible for compensation and benefits in accordance with their local market. KKNA and all of its employees have an obligation to act in accordance with the law and with integrity in all our operations and interactions It is the policy of Kyowa Kirin North America, Inc. to provide equal employment opportunity to all qualified persons without regard to race, religion, creed, color, pregnancy, sex, age, national origin, disability, genetic trait or predisposition, veteran status, marital status, sexual orientation or affection preference or citizenship status or any other category protected by law. When you apply to a job on this site, the personal data contained in your application will be collected and stored by Kyowa Kirin, Inc. (“Controller”), which is located at 510 Carnegie Center Dr. Princeton, NJ 08540 USA and can be contacted by emailing kkus.talentacquisition.8h@kyowakirin.com. Controller’s data protection officer can be contacted at usprivacyoffice@kyowakirin.com. Your personal data will be processed for the purposes of managing Controller’s recruitment related activities, which include setting up and conducting interviews and tests for applicants, evaluating and assessing the results thereto, and as is otherwise needed in the recruitment and hiring processes. Such processing is legally permissible under Art. 6(1)(f) of General Data Protection Regulation (EU) 2016/679 (“GDPR”) as necessary for the purposes of the legitimate interests pursued by the Controller, which are the solicitation, evaluation, and selection of applicants for employment. Your personal data will be shared with Greenhouse Software, Inc., a cloud services provider located in the United States of America and engaged by Controller to help manage its recruitment and hiring process on Controller’s behalf. Accordingly, if you are located outside of the United States, your personal data will be transferred to the United States once you submit it through this site. The transfer will be made using appropriate additional safeguards under the standard contractual clauses approved by regulators for transfers of personal data outside the European Union. Your personal data will be retained by Controller as long as Controller determines it is necessary to evaluate your application for employment. Under the GDPR, if you are located in the European Union, you have the right to request access to your personal data, to request that your personal data be rectified or erased, and to request that processing of your personal data be restricted. You also have the right to data portability, and to lodge a complaint with an EU supervisory authority. If you have any questions about our use of your data, you may contact us by email at usprivacyoffice@kyowakirin.com. RECRUITMENT & STAFFING AGENCIES Kyowa Kirin does not accept agency resumes unless contacted directly by internal Kyowa Kirin Talent Acquisition. Please do not forward resumes to Kyowa Kirin employees or any other company location; Kyowa Kirin is not responsible for any fees related to unsolicited resumes. #LI-TT1 #Hybrid #Princeton