Overview
In this role you will lead the Global Cyber Security Incident Response Team in managing complex incidents and advancing WTW’s incident management capabilities. You will coordinate cross-functional responses, refine playbooks, and ensure clear communication with senior leaders and stakeholders. You will drive AI-assisted containment and orchestration across security tools to reduce impact and shorten recovery times. You will mentor teams, embed lessons learned, and contribute to building a security-aware culture across a large, global footprint. This position offers diverse, high-impact work with opportunities to influence security strategy and operations.
Pay / Benefits
- 25 days of annual leave
- private healthcare
- group life insurance
- hybrid working
- pension with 10% company match
- volunteer day
Responsibilities
- Serve as the primary lead for significant security incidents, coordinating response across technical and business teams to minimize impact and enable timely resolution
- Establish, refine, and maintain incident response processes, playbooks, and workflows aligned with industry best practices and organizational needs
- Act as the central point of contact for incident response activities, ensuring effective communication with internal/external stakeholders including senior leadership, Legal, HR and Compliance
- Leverage AI and automation to accelerate containment, response, and remediation within SOAR playbooks and response workflows
- Lead in-depth technical investigations of security incidents escalated from the SOC, ensuring containment, eradication, and recovery while identifying root causes
- Adept at leading global response teams, integrating SIEM/SOAR platforms, and collaborating with MSSPs to mitigate cloud-native and supply chain attacks
- Coordinate with SOC, Threat Hunting, CTI, Insider Threat, and Vulnerability Management teams for seamless coordination during incidents
- Lead root cause analysis and post-incident reviews to identify gaps and implement lessons learned
- Develop and maintain KPIs and metrics to measure incident response effectiveness
- Act as a liaison between technical teams and business stakeholders, ensuring clear incident status updates
Key requirements
- Strong work experience in SOC or incident response
- Understanding of cybersecurity principles, frameworks, and tools
- Awareness of AI/ML applications in security operations (AI-augmented detection, triage, automation)
- Familiarity with AI-specific threats and incident types (prompt injection, model/data poisoning, GenAI data exposure) and OWASP LLM Top 10 / MITRE ATLAS
- Hands-on cloud incident response across Azure, AWS, and/or GCP; awareness of cloud-native log sources (Azure Activity/Entra ID sign-in logs, AWS CloudTrail)
- Proven ability to lead high-stakes security incidents and coordinate cross-functional teams
- Deep understanding of MITRE ATT&CK, cyber kill chain, and IR methodologies
- Exceptional verbal and written communication skills, including to executives
- Proactive and decisive mindset, ability to perform under pressure
- Strong analytical and problem-solving skills
- Collaborative and adaptable with mentoring and development mindset
- Communication
- Leadership
- Collaboration
- SOC / Incident Response
- AI/ML in security operations
- AI threat awareness (prompt injection, data poisoning) and GenAI security
…
