← Back to jobs

Software Security Manager

Publicis Groupe Holdings B.V

City of London, England, United KingdomNot specifiedPosted 2026-06-22
Apply now →
Company Description Within Publicis Groupe’s Intelligent Creativity business, we specialize in bringing creative ideas to life, and to consumers. By combining 100 years of craft excellence with 6,000 experts across 52 locations of the world’s biggest studio network, we leverage the industry’s richest data, through the power of agentic AI, to radically redefine content production with Intelligent Content. We intuitively deliver this through Marcel Make, the world’s first Intelligent Content agent. The result? Predictively performing content that unlocks business growth in unprecedented ways. No more guesswork. No more waste. Just content that works, working a lot harder. Overview We are seeking a Software Security Manager to strengthen the security posture of our global production management platform, used by studios and creative teams around the world. You will lead the development and maintenance of software security documentation, governance, and compliance programmes, working across engineering, infrastructure, and legal functions to ensure our platform meets the highest standards of data protection and regulatory compliance. You will act as both advisor and implementer, ensuring secure development practices, managing audits, and embedding compliance across the full software lifecycle. Responsibilities Security Governance & Documentation Develop, maintain, and enforce security policies, standards and procedures aligned with ISO 27001, SOC 2, GDPR and other relevant frameworks. Own and continuously improve security documentation, including risk assessments, audit evidence, and technical compliance artefacts. Maintain records for SAST/DAST results, penetration testing reports, incident response playbooks, and vulnerability management processes. Manage the documentation lifecycle, ensuring accuracy, version control and accessibility across teams. Lead client security audits and work with growth teams on RFP / RFI responses Compliance & Risk Management Lead or support annual compliance audits (SOC 2, ISO 27001, GDPR, CCPA). Track and coordinate remediation activities for internal and external audit findings. Ensure ongoing alignment with data protection laws across the UK, EU, APAC and US, particularly concerning creative and production data. Partner with Legal, IT and Engineering to validate data residency and hosting compliance for enterprise clients. Software Security Enablement Work closely with DevOps and Engineering to embed security-by-design principles within CI/CD pipelines. Evaluate and implement security tooling (SAST, DAST, container scanning, secrets management) across development environments. Oversee secure access controls, API key management, and SSO/SAML configuration standards for enterprise deployments. Provide technical guidance and documentation for secure integrations with creative and production applications. Incident & Vulnerability Management Support incident response processes and maintain comprehensive incident and post-incident documentation. Manage vulnerability tracking, risk assessment, and communication of issues to relevant teams. Ensure timely patching, configuration management, and change control compliance. Cross-Functional Collaboration Collaborate with Product, Engineering, IT and Legal teams to ensure compliance is embedded within workflows rather than added retrospectively. Partner with client-facing teams to deliver security assurance documentation for enterprise RFPs, tenders, and renewals. Contribute to security-related client education and the development of public-facing materials outlining platform security and governance. Qualifications 5–7 years experience in software or SaaS security, ideally within the Media, Entertainment, or Cloud Production sector. Strong background in security documentation, audits and compliance evidence (SOC 2, ISO 27001, GDPR). Hands-on experience with application and infrastructure security tools (SAST, DAST, SIEM, identity management, MFA, SSO). Understanding of cloud security within AWS, Azure, or GCP. Excellent written and verbal communication skills, with the ability to translate technical content into business-friendly language. Confident working cross-functionally with engineers, legal teams and external partners. Desirable Qualifications Certifications such as CISSP, CISM, CCSK, ISO 27001 Lead Implementer, or equivalent. Experience with production, creative, or collaboration software systems (e.g. digital asset management, rendering, or workflow platforms). Knowledge of AI model governance and data usage compliance within creative technology environments. Additional Information Diversity and inclusion is a core part of who we are at Publicis Production. We’re committed to building an inclusive culture that encourages, celebrates and supports our wonderfully diverse employee group – whatever their age, gender identity, race, sexual orientation, physical or mental ability or ethnicity. Diversity and inclusion doesn’t just fuel our creativity and innovation, it brings us closer to our people and audiences. We will continue to strive to create a culture and environment where everyone feels empowered and more importantly comfortable enough to bring their full, authentic selves to work. We are committed to providing reasonable adjustments for employees with disabilities and for candidates in our application process. If you need assistance or adjustment due to a disability, please contact us.
View full description on employer site →