Associate Manager – Cyber Security Incident Response

Company: Willis Towers Watson
Apply for the Associate Manager – Cyber Security Incident Response
Location: London
Job Description:

Overview

In this role you will lead the Global Cyber Security Incident Response Team in managing complex incidents and advancing WTW’s incident management capabilities. You will coordinate cross-functional responses, refine playbooks, and ensure clear communication with senior leaders and stakeholders. You will drive AI-assisted containment and orchestration across security tools to reduce impact and shorten recovery times. You will mentor teams, embed lessons learned, and contribute to building a security-aware culture across a large, global footprint. This position offers diverse, high-impact work with opportunities to influence security strategy and operations.

Pay / Benefits

  • 25 days of annual leave
  • private healthcare
  • group life insurance
  • hybrid working
  • pension with 10% company match
  • volunteer day

Responsibilities

  • Serve as the primary lead for significant security incidents, coordinating response across technical and business teams to minimize impact and enable timely resolution
  • Establish, refine, and maintain incident response processes, playbooks, and workflows aligned with industry best practices and organizational needs
  • Act as the central point of contact for incident response activities, ensuring effective communication with internal/external stakeholders including senior leadership, Legal, HR and Compliance
  • Leverage AI and automation to accelerate containment, response, and remediation within SOAR playbooks and response workflows
  • Lead in-depth technical investigations of security incidents escalated from the SOC, ensuring containment, eradication, and recovery while identifying root causes
  • Adept at leading global response teams, integrating SIEM/SOAR platforms, and collaborating with MSSPs to mitigate cloud-native and supply chain attacks
  • Coordinate with SOC, Threat Hunting, CTI, Insider Threat, and Vulnerability Management teams for seamless coordination during incidents
  • Lead root cause analysis and post-incident reviews to identify gaps and implement lessons learned
  • Develop and maintain KPIs and metrics to measure incident response effectiveness
  • Act as a liaison between technical teams and business stakeholders, ensuring clear incident status updates

Key requirements

  • Strong work experience in SOC or incident response
  • Understanding of cybersecurity principles, frameworks, and tools
  • Awareness of AI/ML applications in security operations (AI-augmented detection, triage, automation)
  • Familiarity with AI-specific threats and incident types (prompt injection, model/data poisoning, GenAI data exposure) and OWASP LLM Top 10 / MITRE ATLAS
  • Hands-on cloud incident response across Azure, AWS, and/or GCP; awareness of cloud-native log sources (Azure Activity/Entra ID sign-in logs, AWS CloudTrail)
  • Proven ability to lead high-stakes security incidents and coordinate cross-functional teams
  • Deep understanding of MITRE ATT&CK, cyber kill chain, and IR methodologies
  • Exceptional verbal and written communication skills, including to executives
  • Proactive and decisive mindset, ability to perform under pressure
  • Strong analytical and problem-solving skills
  • Collaborative and adaptable with mentoring and development mindset
  • Communication
  • Leadership
  • Collaboration
  • SOC / Incident Response
  • AI/ML in security operations
  • AI threat awareness (prompt injection, data poisoning) and GenAI security

…

Posted: October 1st, 2026