Jobs / United States / WPP 2005 Limited

Penetration Tester

WPP 2005 Limited · 🇺🇸 United Kingdon

Sponsorship verdict

No sponsorship evidence yet

No government record and no wording either way. Not a refusal — ask the recruiter.

  • No government sponsor record hereThis employer does not appear with approvals in the government data SponsorApply holds.
  • The posting doesn’t mention sponsorshipSilence isn’t a refusal — ask the recruiter before investing much time.
  • No salary bar for this routeH-1B has no fixed salary bar: the employer must pay at least the prevailing wage for the role and area. Cap-subject employers enter a lottery weighted by wage level. Source: https://www.federalregister.gov/documents/2025/12/29/2025-23853/weighted-selection-process-for-registrants-and-petitioners-seeking-to-file-cap-subject-h-1b, rules effective 2026-02-27.
  • Confirmed live todayWhen a source last listed this job as open.

US H-1B: cap-subject employers enter a lottery weighted by wage level — Level I gets 1 entry, Level IV gets 4 (DHS projected selection odds ≈15% at Level I to ≈61% at Level IV). Universities and non-profit research employers are cap-exempt. The $100,000 fee for new petitions from abroad is currently blocked by a court order (appeal pending).

A verdict summarises public evidence; it is not legal advice and never a guarantee — the employer and the immigration authority decide. Sign in to factor in where you can already work.

Start free →

Or apply yourself on the official page →

Why not apply?

Sponsorship unknown

No register record and no sponsorship wording in the posting. Worth asking the employer before investing significant time.

SponsorApply flags time-wasters so your applications go where they can land. These come from the posting's own wording — read the original listing to confirm. See better-fit alternatives →

Sponsor Radar — WPP 2005 Limited

No sponsorship history found

This employer does not appear with approvals in the government data SponsorApply holds.

Past sponsorship or register membership never guarantees sponsorship for this vacancy or for you. Full Sponsor Radar for WPP 2005 Limited →

About the role

WPP is the trusted growth partner for the world’s leading brands. We unite cutting-edge media intelligence and data solutions, world-class creativity, next-generation production, transformative enterprise solutions and expert strategic counsel in a single company – powered by exceptional talent and our agentic marketing platform, WPP Open, to help our clients navigate change, capture opportunity and deliver transformational growth. We work with the world's most valuable brands and have global reach across 100+ markets, with deep local expertise. Our people are the key to our success. We're committed to fostering a culture of creativity, belonging and continuous learning, attracting and developing the brightest talent, and providing exciting career opportunities that help our people grow. For more information, visit WPP.com. • Department: Data & Technology Solutions (DTS) • Reports To: SVP Security and Compliance • Location: [London/Hybrid 2 days a week in office] • Position Type: Full-Time Role Overview The Product, Application and Offensive Security Engineer is responsible for embedding security directly into the design, development, testing, and operation of DTS products and platforms. This is a hands-on security engineering role. The role requires someone who can work directly with product and engineering teams, review designs, assess APIs, run threat models, test systems, coordinate penetration testing, identify vulnerabilities, and help teams remediate issues. The role ensures DTS products, APIs, data collaboration capabilities, AI-enabled workflows, and client-facing services are designed, built, and tested securely. It also owns the practical offensive security and adversarial assurance activity needed to test DTS products from an attacker’s perspective. The Product, Application and Offensive Security Lead will work closely with Product, Engineering, Architecture, Infrastructure, Security Operations, Privacy, Cloud and Platform Security, and the ISMS and Risk Officer to ensure security issues are identified early, fixed effectively, and tracked through governance where required. Key Responsibilities 1. Hands-on Product and Application Security Provide hands-on security support across DTS products and engineering teams. This includes: • Reviewing product designs, technical designs, APIs, services, and integrations. • Identifying security weaknesses in applications, workflows, and data flows. • Advising engineering teams on secure implementation. • Supporting secure design decisions during product discovery and delivery. • Helping teams resolve security issues pragmatically without creating unnecessary delivery friction. 2. Secure Software Development Lifecycle (SDLC) Embed security into the software development lifecycle across DTS. This includes: • Defining and applying secure engineering standards. • Supporting secure coding practices. • Reviewing CI/CD security controls. • Supporting SAST, DAST, SCA, secrets scanning, dependency scanning, and container scanning. • Helping teams triage, prioritise, and remediate security findings. • Working with engineering teams to make security checks practical and repeatable. 3. Threat Modelling and Security Design Reviews Run threat modelling and security design reviews for new and changed capabilities. This includes: • Facilitating threat modelling sessions with engineering and product teams. • Reviewing authentication and authorization designs. • Assessing API exposure, data flows, trust boundaries, and abuse cases. • Identifying risks around tenant isolation, privilege escalation, data leakage, and misuse. • Documenting key findings, recommendations, and residual risks. 4. Offensive Security and Adversarial Testing Carry out and coordinate offen

View the official posting →

Source: Greenhouse (employer board) First seen: 2026-08-30 Last confirmed: 2026-10-03 How our data works → Report this job

Similar opportunities