1. Hands-on Product and Application Security
Provide hands-on security support across DTS products and engineering teams. This includes:
•
Reviewing product designs, technical designs, APIs, services, and integrations.
•
Identifying security weaknesses in applications, workflows, and data flows.
•
Advising engineering teams on secure implementation.
•
Supporting secure design decisions during product discovery and delivery.
•
Helping teams resolve security issues pragmatically without creating unnecessary delivery friction.
2. Secure Software Development Lifecycle (SDLC)
Embed security into the software development lifecycle across DTS. This includes:
•
Defining and applying secure engineering standards.
•
Supporting secure coding practices.
•
Reviewing CI/CD security controls.
•
Supporting SAST, DAST, SCA, secrets scanning, dependency scanning, and container scanning.
•
Helping teams triage, prioritise, and remediate security findings.
•
Working with engineering teams to make security checks practical and repeatable.
3. Threat Modelling and Security Design Reviews
Run threat modelling and security design reviews for new and changed capabilities. This includes:
•
Facilitating threat modelling sessions with engineering and product teams.
•
Reviewing authentication and authorization designs.
•
Assessing API exposure, data flows, trust boundaries, and abuse cases.
•
Identifying risks around tenant isolation, privilege escalation, data leakage, and misuse.
•
Documenting key findings, recommendations, and residual risks.
4. Offensive Security and Adversarial Testing
Carry out and coordinate offensive security testing across DTS products and platforms. This includes:
•
Performing hands-on security testing of products, APIs, and workflows.
•
Coordinating external penetration tests.
•
Supporting red team and purple team exercises where required.
•
Testing abuse cases and attacker paths.
•
Testing access control, authentication, authorization, and data leakage risks.
•
Validating remediation of security findings.
•
Feeding material risks into the ISMS and Risk Officer for tracking.
5. API, Integration and Data Product Security
Provide security assurance for APIs, integrations, and data products. This includes:
•
Reviewing externally exposed APIs and partner integrations.
•
Assessing rate limiting, authorization, tenant isolation, logging, abuse prevention, and data leakage controls.
•
Supporting secure integration between InfoSum, Open Intelligence, Resolve, WPP Open, and third-party platforms.
•
Reviewing data product workflows for misuse, excessive access, or unintended exposure.
•
Working with Privacy Engineering on privacy-sensitive APIs, algorithms, and outputs.
6. AI and Agentic Security Testing
Provide hands-on security review and adversarial testing for AI-enabled and agentic capabilities. This includes:
•
Testing prompt injection, tool misuse, data leakage, and excessive agency.
•
Reviewing how agents access APIs, data, tools, and workflows.
•
Testing whether agent permissions can be bypassed or escalated.
•
Assessing action boundaries and human approval points.
•
Working with Identity, AI, and Data Access Governance to validate agent access models.
•
Documenting AI and agentic security risks and remediation actions.
7. Vulnerability Triage and Remediation Support
Help teams understand, prioritise, and fix security vulnerabilities. This includes:
•
Reviewing vulnerability findings from scans, penetration tests, code reviews, cloud tools, and external reports.
•
Prioritising findings based on exploitability, exposure, data sensitivity, and business impact.
•
Working directly with engineers to define remediation options.
•
Validating that fixes are effective.
•
Supporting exception and risk acceptance decisions where remediation is delayed.
•
Ensuring significant issues are visible through the DTS risk process.
8. Engineering Enablement and Security Coaching
Act as a practical security partner to engineering teams. This includes:
•
Providing secure implementation guidance.
•
Creating lightweight security patterns and examples.
•
Coaching engineers on common application, API, and AI security risks.
•
Helping teams understand the “why” behind security requirements.
•
Supporting a culture where security is part of product quality, not a separate approval gate.