Associate Manager - Cyber Security Incident Response

WTW

Greater London

On-site

GBP 90,000 - 130,000

Full time

14 days+
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

25 days annual leave
Private healthcare
Group pension with company match
Hybrid working
Volunteer day
Share scheme

Job summary

WTW is seeking an Associate Manager in Cyber Security Incident Response based in London with a hybrid work model. The role leads incident response and drives improvements across the organisation, including coordination with executives and cross-functional teams. Global travel may be required.

The role emphasizes AI-assisted triage, playbooks, and integration with SIEM/SOAR platforms to accelerate containment and remediation. A history of mentoring security professionals is valued.

Qualifications

  • Strong work experience in SOC or incident response.
  • Understanding of AI/ML applications in security operations.
  • Cloud incident response across Azure, AWS and/or GCP.
  • Ability to lead high-stakes security incidents and coordinate cross-functional teams.
  • Knowledge of MITRE ATT&CK and incident response methodologies.

Responsibilities

  • Serve as the primary lead for significant security incidents and coordinate response.
  • Develop and maintain incident response playbooks and workflows.
  • Communicate with internal and external stakeholders including executives.
  • Lead in-depth technical investigations and containment efforts.
  • Coordinate with SOC, Threat Hunting, CTI, Insider Threat and Vulnerability teams.

Skills

SOC experience
Incident response leadership
Communication skills
Problem solving
Mentoring

Tools

MITRE ATT&CK
Azure
AWS
GCP
SOAR
SIEM
AI/ML in security

Job description

Description

The Associate Manager - Cyber Security Incident Response will play a pivotal role within WTW’s Global Information and Cyber Security Defence (ICSD) function, leading the response to complex security incidents and driving initiatives to enhance WTW’s Cyber incident management capabilities. This mid senior-level role requires a highly experienced professional with strong expertise in incident response and cybersecurity. The individual will work as part of a global, multi-disciplined security community with strong support across the business, contributing to fostering a security-aware culture while ensuring WTW remains a great place to work. With WTW’s large global footprint, this role offers a fascinating range of work, and occasional global travel may be required.

The individual will work as part of a global, multi-disciplined security community with strong support across the business, contributing to fostering a security-aware culture while ensuring WTW remains a great place to work. With WTW’s large global footprint, this role offers a fascinating range of work, and occasional global travel may be required.

This role is based in London and follows a hybrid working model, with a minimum requirement of three days per month in the office. Applications are also welcome from candidates based elsewhere in the UK; however, travel to the London office will be required as and when needed to meet business demands.

The Role:

TheAssociate Manager - Cyber Security Incident Responsewill play a key role in managing and responding to security incidents within WTW’s Global Cyber Security Incident Response Team. Responsibilities of this role will include:

  • Serve as the primary lead for significant security incidents, coordinating response efforts across technical and business teams to minimize impact and ensure timely resolution.
  • Establish, refine, and maintain incident response processes, playbooks, and workflows to align with industry best practices and WTW’s organizational needs.
  • Act as the central point of contact for incident response activities, ensuring effective communication with internal and external stakeholders, including senior leadership, Legal, HR, and Compliance teams.
  • Leverage AI and automation to accelerate incident containment, response, and remediation — embedding AI-assisted triage, alert enrichment, and decision support into SOAR playbooks and response workflows
  • Lead the in-depth technical investigation of security incidents escalated from the SOC, ensuring timely containment, eradication, and recovery while identifying root causes and potential impact.
  • Adept at leading global response teams, integrating SIEM/SOAR platforms, and collaborating with MSSPs to mitigate cloud-native and supply chain attack.
  • Work closely with SOC, Threat Hunting, CTI, Insider Threat, and Vulnerability Management teams to ensure seamless coordination and information sharing during incidents.
  • Lead root cause analysis and post-incident reviews to identify gaps, implement lessons learned, and enhance the overall incident response program.
  • Evaluate and prioritize incidents based on potential impact and severity, escalating issues to higher levels of management or other teams as required.
  • Contribute to the development and maintenance of key performance indicators (KPIs) and metrics to measure the effectiveness of incident response processes.
  • Act as a liaison between technical teams and business stakeholders, ensuring clear communication during incidents and status updates.
Qualifications
What you'll bring:

We are looking for a candidate forCyber Security Incident Responsewho has the following:

  • Strong work experience in SOC or incident response, with a strong understanding of cybersecurity principles, frameworks, and tools.
  • Understanding of AI/ML applications in security operations, including AI-augmented detection, triage, and response automation.
  • Awareness of AI-specific threats and incident types (prompt injection, model/data poisoning, sensitive-data exposure via GenAI), and familiarity with OWASP LLM Top 10 / MITRE ATLAS.
  • Hands-on cloud incident response across Azure, AWS, and/or GCP, including cloud-native log sources (Azure Activity/Entra ID sign-in logs, AWS CloudTrail) and the reality that cloud IR differs from on-prem.
  • Proven ability to lead high-stakes security incidents and coordinate cross-functional teams effectively.
  • Deep understanding of MITRE ATT&CK, cyber kill chain, and incident response methodologies.
  • Exceptional verbal and written communication skills, with the ability to convey complex technical concepts to non-technical audiences, including executives.
  • A proactive and decisive mindset with the ability to operate under pressure.
  • Strong analytical and problem-solving skills to make informed decisions in complex situations.
  • Collaborative and adaptable, with a passion for mentoring and developing team members.
What we offer:
  • You will receive 25 days of annual leave plus an extra WTW day to relax and recharge
  • Our comprehensive health and wellbeing offering includes private healthcare, life insurance, group income protection, and regular health assessments, all giving you peace of mind
  • Secure your future with our defined contribution pension scheme, featuring matched contributions up to 10% from the company
  • We support your growth and balance with hybrid working options, access to an employee assistance programme, and a fully paid volunteer day to make a difference in your community
  • On top of these, you can opt into a variety of additional perks including an electric vehicle car scheme, share scheme, cycle-to-work programme, dental and optical cover, critical illness protection, and much more
Equal Opportunity Employer

We’re committed to equal employment opportunity and provide application, interview and workplace adjustments and accommodations to all applicants. If you foresee any barriers, from the application process through to joining WTW, please email candidatehelpdesk@wtwco.com

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Associate – Information Security
Senior Associate – Information Security

Willis Towers Watson • Ipswich

Hybrid
GBP 55,000 - 75,000
25 days annual leave
Private healthcare
Life insurance
+3
WAF Engineer
WAF Engineer

WTW • Greater London

Hybrid
GBP 70,000 - 110,000
Hybrid working options
Private healthcare
Life insurance
+2
Crisis Management & Scenario Testing Specialist
Crisis Management & Scenario Testing Specialist

WTW • Greater London

Hybrid
GBP 90,000 - 130,000
Hybrid working options
Private healthcare
Life insurance
+3
Crisis Management & Scenario Testing Specialist
Crisis Management & Scenario Testing Specialist

Willis Towers Watson • Greater London

Hybrid
GBP 90,000 - 130,000
25 days annual leave
Private healthcare
Life insurance
+2
Senior Director- Technology Governance and Regulatory Strategy
Senior Director- Technology Governance and Regulatory Strategy

Willis Towers Watson • Greater London

On-site
GBP 140,000 - 190,000
25 days annual leave
Private healthcare
Life insurance
+9
Senior Director- Technology Governance and Regulatory Strategy
Senior Director- Technology Governance and Regulatory Strategy

Willis Towers Watson • City Of London

Hybrid
GBP 130,000 - 180,000
Hybrid working options
Private healthcare
Life insurance
+4
Global Cyber Incident Response Lead
Global Cyber Incident Response Lead

WTW • Greater London

Hybrid
GBP 90,000 - 130,000
25 days annual leave
Private healthcare
Group pension with company match
+3
Senior Software Engineer
Senior Software Engineer

Willis Towers Watson • Reigate

Hybrid
GBP 90,000 - 130,000
25 days annual leave
Private healthcare
Life insurance
+9
Senior Director of Service Delivery
Senior Director of Service Delivery

WTW • Reigate

Hybrid
GBP 120,000 - 180,000
25 days annual leave
Private healthcare
Group income protection
+7
Forward Deployed AI Engineer
Forward Deployed AI Engineer

Willis Towers Watson • Greater London

Hybrid
GBP 120,000 - 150,000
Hybrid working
Private healthcare
Pension scheme matched up to 10%
+3