Identity, AI and Data Access Governance Lead
WPP · United Kingdom
Identity, AI and Data Access Governance Lead at WPP, based in United Kingdom. This is a permanent role.
- Salary
- Competitive
- Location
- United Kingdom
- Contract
- Permanent
- Posted
- 2 weeks ago
- Closes
- 31 Aug 2026
- Sector
- Data Entry
Reference 8583528002
About the role
WPP is the trusted growth partner for the world’s leading brands.
We unite cutting-edge media intelligence and data solutions, world-class creativity, next-generation production, transformative enterprise solutions and expert strategic counsel in a single company – powered by exceptional talent and our agentic marketing platform, WPP Open, to help our clients navigate change, capture opportunity and deliver transformational growth.
We work with the world's most valuable brands and have global reach across 100+ markets, with deep local expertise.
Our people are the key to our success. We're committed to fostering a culture of creativity, belonging and continuous learning, attracting and developing the brightest talent, and providing exciting career opportunities that help our people grow.
For more information, visit WPP.com.
Why we're hiring:
The Identity, AI and Data Access Governance Lead is responsible for governing who, and what, can access DTS systems, data, APIs, tools, workflows and AI-enabled capabilities.
This is a hands-on governance and control role, reporting into the SVP Security and Compliance. The role ensures that access across DTS is appropriate, auditable, reviewed, least-privileged and aligned with security, privacy, compliance and client commitments.
The scope covers traditional human access, external users, privileged access, service accounts, machine identities, API keys, tokens, dataset access, and the emerging governance of AI agents and agentic workflows.
The role will work closely with Architecture, Security, Product, Engineering, Infrastructure, Privacy, Legal/DPO, TechOps, Enterprise Technology and the ISMS and Risk Officer to ensure DTS has a clear and controlled model for access across platforms such as WPP Open, Choreograph, InfoSum, Open Intelligence, Resolve and related DTS capabilities.
What you'll be doing:
1. Identity and access governance framework
Define and maintain the access governance framework for DTS.
This includes:
- Defining access governance standards, processes and control expectations.
- Establishing how access should be requested, approved, provisioned, reviewed, revoked and evidenced.
- Ensuring access governance covers internal users, external users, clients, partners, vendors, service accounts, machine identities and AI agents.
- Aligning identity and access governance with DTS architecture, security, privacy, compliance and data governance requirements.
- Ensuring access governance is practical for product and engineering teams to implement.
2. Access reviews and recertification
Own the process for regular access reviews and recertification across DTS.
This includes:
- Defining the scope, frequency and evidence requirements for access reviews.
- Coordinating access reviews for critical DTS systems, production environments, privileged roles, sensitive datasets, client-facing platforms and administrative tools.
- Ensuring access review outcomes are tracked, remediated and evidenced.
- Identifying stale, excessive, orphaned or poorly owned access.
- Escalating overdue, high-risk or unresolved access issues through the appropriate governance channels.
3. Privileged access governance
Ensure privileged access across DTS is properly controlled, justified and auditable.
This includes:
- Reviewing access to production systems, cloud environments, security tools, databases, CI/CD tooling, administrative consoles and sensitive platforms.
- Supporting least-privilege, just-in-time and time-bound access models where appropriate.
- Working with Cloud and Platform Security and Infrastructure to improve privileged access controls.
- Ensuring privileged access risks are visible in the DTS risk register where required.
4. External user, client and partner access governance
Govern access for external users, clients, agencies, partners and vendors.
This includes:
- Defining standards for external user onboarding, approval, permissions, expiry and offboarding.
- Ensuring external access has a clear business owner and justification.
- Supporting access governance across client workspaces, agency environments, partner integrations and shared collaboration areas.
- Working with Product and Engineering to ensure tenant, workspace and client-level isolation is appropriately governed.
- Tracking risks related to stale accounts, vendor access, partner permissions and external user overprivilege.
5. Service account, machine identity and API access governance
Govern non-human access across DTS systems and platforms.
This includes:
- Defining standards for service accounts, machine identities, automation users, API keys, tokens, secrets and integration credentials.
- Ensuring non-human access has clear ownership, purpose, scope, rotation, expiry and auditability.
- Working with Product, Engineering, Cloud Security and Infrastructure to reduce unmanaged credential risk.
- Ensuring service accounts and machine identities are included in access reviews.
- Supporting stronger governance of API access, token issuance, credential lifecycle and integration permissions.
6. AI and agentic access governance
Define and oversee the governance model for AI agents and agentic workflows across DTS.
This includes:
- Defining how AI agents are identified, permissioned, monitored, reviewed and revoked.
- Ensuring agents have clear ownership, scoped permissions and auditable actions.
- Defining which agent actions require human approval or additional control.
- Governing agent access to APIs, tools, datasets, workflows, client environments and production capabilities.
- Ensuring agents act within delegated authority and cannot exceed the permissions of the user, system or business process they represent.
- Working with Product, Architecture and Security to ensure agentic workflows are designed with clear action boundaries.
- Working with the Product, Application and Offensive Security Lead to test whether agent permissions and action boundaries can be bypassed.
- Working with Privacy Engineering to ensure AI access models support permitted use, minimisation and data protection requirements.
7. Data access governance
Govern access to sensitive, client, partner and WPP-owned data across DTS.
This includes:
- Defining standards for dataset access approval, review, revocation and evidence.
- Supporting data classification from an access-control and security-governance perspective.
- Ensuring access to sensitive data is role-based, purpose-based, least-privileged and auditable.
- Supporting controls for cross-client, cross-market, cross-agency and partner data access.
Reference: 8583528002 · Posted 2 weeks ago · Closes 31 Aug 2026 · Listed via WPP
Apply for this job
This role is listed via WPP. Applications are handled on the employer's site.
Apply on employer siteOpens the employer's website in a new tab.
Safe applying: a genuine employer will never ask you to pay for a DBS check, training or equipment, or move you onto WhatsApp before you are hired. If this listing does, report it and do not pay anything.