Assistant Manager - Cyber Threat Hunter

WTW

Madrid

Presencial

EUR 75.000 - 110.000

Jornada completa

hace 22 horas
Sé de los primeros/as/es en solicitar esta vacante
Generador de candidaturas

No envíes un currículum genérico: crea un currículum y una carta de presentación adaptados a este puesto concreto.

Supera los filtros ATS

Descripción de la vacante

Willis Towers Watson is seeking a Cyber Threat Hunting Assistant Manager to drive intelligence-led hunts across its global environment. The role focuses on proactive threat discovery, advanced analytics, and collaboration with cross‑functional teams to strengthen security posture.

The role requires hands-on expertise in threat hunting, cybersecurity, and incident response, with the ability to convert intelligence from multiple sources into active hunting campaigns and measurable improvements.

Formación

  • Extensive experience in cyber threat hunting & security incident response in global environments.
  • Proficiency with SIEM/EDR, threat hunting tooling and incident response processes.
  • Familiarity with MITRE ATT&CK, cyber kill chain and post‑exploitation tooling.

Responsabilidades

  • Develop hypothesis-driven, intelligence-led threat hunts to uncover adversary TTPs.
  • Analyze security trends and provide actionable insights to leadership.
  • Enhance detection and response capabilities through threat intelligence integration.
  • Create threat hunt reports, playbooks, and SOPs for ongoing operations.
  • Conduct host and network forensics, log analysis, and evidence collection.

Conocimientos

Threat hunting
Incident response
MITRE ATT&CK
Log analysis
Threat intelligence
Cloud security
Forensics
Python
PowerShell
KQL

Herramientas

SIEM
EDR

Descripción del empleo

Description

As a Cyber Threat Hunting Assistant Manager, within the Threat Discovery and Fusion Unit (TDFU), you will play a key role in proactively hunting for adversary activity across WTW's global environment by turning cyber threat intelligence into active pursuit of hidden threats. This hands‑on technical role requires prior experience in threat hunting, cybersecurity, and incident response. You will leverage your expertise to consume and fuse intelligence from multiple internal and external sources, research emerging threats and adversary tradecraft, and develop and execute intelligence‑led hunts that surface malicious activity evading existing detections, while contributing to WTW’s intelligence‑led cyber defense strategy.

As a Cyber Threat Hunting Assistant Manager, within the Threat Discovery and Fusion Unit (TDFU), you will play a key role in proactively hunting for adversary activity across WTW's global environment by turning cyber threat intelligence into active pursuit of hidden threats. This hands‑on technical role requires prior experience in threat hunting, cybersecurity, and incident response. You will leverage your expertise to consume and fuse intelligence from multiple internal and external sources, research emerging threats and adversary tradecraft, and develop and execute intelligence‑led hunts that surface malicious activity evading existing detections, while contributing to WTW’s intelligence‑led cyber defense strategy.

We are seeking a motivated and intellectually curious professional with a passion for threat hunting and a strong technical foundation. This role does not include line management responsibilities but offers opportunities to collaborate with a global, multi‑disciplinary team and contribute to enhancing WTW’s overall security posture.

The Role

The Cyber Threat Hunting Associate Manager will provide global threat hunting capability for WTW, responsibilities of this role will include:

  • Develop and execute hypothesis‑driven, intelligence‑led threat hunts to uncover adversary tactics, techniques, and procedures (TTPs.
  • Analyze security trends and assess their impact on the organization, providing actionable insights to leadership.
  • Analyze threat intelligence to enhance detection and response capabilities and ensure alignment with WTW’s security strategy.
  • Convert intelligence inputs across all categories into hypothesis‑driven, intelligence‑led hunts, and feed findings back into WTW's detection capabilities and intelligence picture.
  • Utilize advanced threat hunting tools and techniques, including behavioral analytics, anomaly detection, and threat intelligence integration.
  • Support incident response activities by conducting forensic analysis, identifying root causes, and recommending mitigation strategies.
  • Research vulnerabilities and exploits available to cybercriminals that have not yet reached WTW's sectors but are likely to target the organization, assessing exposure ahead of impact
  • Research and hunt for new malware types, infostealers, RATs, and similar tooling - observed as steps in attacks against enterprise environments
  • Collaborate with stakeholders across ICSD and other teams to improve threat detection and response processes.
  • Create and maintain documentation, such as threat hunt reports, playbooks, and standard operating procedures (SOPs).
  • Conduct host and network forensics, log analysis, and evidence collection for on‑premises and cloud systems, ensuring proper chain of custody and documentation.
Qualifications
The Requirements

We are looking for a candidate for the Cyber Threat Hunting Lead Associate who has the following:

  • A detail‑oriented professional with a proactive mindset to stay ahead of emerging threats.
  • A team player who thrives in a collaborative environment and can navigate complex challenges effectively.
  • Someone passionate about making a tangible impact on WTW’s cybersecurity resilience
  • Extensive experience in cyber threat hunting & security incident response in global environments.
  • Strong problem‑solving and analytical skills, with the ability to influence stakeholders and drive effective decision‑making.
  • Expertise in adversarial tactics, techniques, and procedures (TTPs), the MITRE ATT&CK framework, cyber kill chain, and hacking/post‑exploitation tools.
  • Proficiency in interpreting and querying diverse log types (e.g., Windows Event, Web server, Firewall logs) and conducting threat hunts within SIEM and EDR tools. [SR1.1]
  • Knowledge of forensic methodologies, open‑source tooling, and cloud security, including incident response in cloud environments.
  • Familiarity with scripting languages such as Python, PowerShell, and KQL, with a functional understanding of programming concepts.
  • Industry‑recognized certifications in Cyber Incident Response, Forensics, or Malware Analysis are a plus.
  • Strong communication, collaboration, and interpersonal skills to effectively convey security and risk concepts across diverse audiences.

We’re committed to equal employment opportunity and provide application, interview and workplace adjustments and accommodations to all applicants. If you foresee any barriers, from the application process through to joining WTW, please email candidate.helpdesk@willistowerswatson.com.

Consigue la evaluación confidencial y gratuita de tu currículum.
o arrastra y suelta tu archivo aquí
Similar jobs

Puestos de trabajo similares que vale la pena comparar

Assistant Manager - Cyber Threat Hunter
Assistant Manager - Cyber Threat Hunter

Willis Towers Watson • Madrid

Presencial
EUR 65.000 - 95.000
Threat Hunter Associate Manager, Global Cyber Defense
Threat Hunter Associate Manager, Global Cyber Defense

Willis Towers Watson • Madrid

Presencial
EUR 65.000 - 95.000
Cyber Threat Hunting Lead — Global Defense
Cyber Threat Hunting Lead — Global Defense

WTW • Madrid

Presencial
EUR 75.000 - 110.000
Cyber Threat Hunting Manager
Cyber Threat Hunting Manager

Apollo Solutions • Madrid

Presencial
EUR 75.000 - 110.000
Cyber Threat Hunter
Cyber Threat Hunter

Allianz Technology • Madrid

Híbrido
EUR 70.000 - 110.000
Hybrid work model
Bonus scheme
Pension
+3
Threat Hunting Manager — Lead, Detect & Defend (Madrid)
Threat Hunting Manager — Lead, Detect & Defend (Madrid)

Apollo Solutions • Madrid

Presencial
EUR 75.000 - 110.000
Threat Intelligence Engineer
Threat Intelligence Engineer

Allianz Technology • Barcelona

Híbrido
EUR 60.000 - 80.000
Hybrid work model
Performance-based compensation
Lifelong learning opportunities
+2
Threat Intelligence Engineer
Threat Intelligence Engineer

Allianz Technology • Madrid

Híbrido
EUR 55.000 - 75.000
Hybrid work model
Performance-based compensation
Employee shares program
Principal Security Engineer, Detection
Principal Security Engineer, Detection

Jobtailor • Madrid

Presencial
EUR 90.000 - 120.000
Cyber Threat Hunter
Cyber Threat Hunter

Dormont Manufacturing Co • Madrid

Presencial
EUR 50.000 - 75.000
Health insurance for you and your family
Transport allowance
Flexible work model