The Cyber Security Incident Response Assistant Manager will play a pivotal role within WTW’s Global Information and Cyber Security Defence (ICSD) function, leading the response to complex security incidents and driving initiatives to enhance WTW’s Cyber incident management capabilities. This mid senior-level role requires a highly experienced professional with more than 5 years of expertise in incident response and cybersecurity. You will also work beyond the technical domain, liaising with HR, Legal, Compliance, and other business units to ensure effective incident management and mitigation.
The individual will work as part of a global, multi-disciplined security community with strong support across the business, contributing to fostering a security-aware culture while ensuring WTW remains a great place to work. With WTW’s large global footprint, this role offers a fascinating range of work, and occasional global travel may be required.
The Role The Cyber Security Incident
Response Assistant Manager will play a key role in managing and responding to security incidents within WTW’s General Cyber Security Incident Response Team. Act as the central point of contact for incident response activities, ensuring effective communication with internal and external stakeholders, including senior leadership, Legal, HR, and Compliance teams. Adept at leading global response teams, integrating SIEM/SOAR platforms,
and collaborating with MSSPs to mitigate cloud-native and supply chain attack.
Work closely with SOC, Threat Hunting, CTI, Insider Threat, and Vulnerability Management teams to ensure seamless coordination and information sharing during incidents. Lead root cause analysis and post-incident reviews to identify gaps, implement lessons learned, and enhance the overall incident response program. Evaluate and prioritize incidents based on potential impact and severity, escalating issues to higher levels of management or other teams as required.
Contribute to the development and maintenance of key performance indicators (KPIs) and metrics to measure the effectiveness of incident response processes.
The Requirements
We are looking for a candidate for Cyber Security Incident Response who has the following: Minimum 5 years of experience in SOC or incident response, with a strong understanding of cybersecurity principles, frameworks, and tools. Awareness of AI-specific threats and incident types (prompt injection, model/data poisoning, sensitive-data exposure via GenAI), and familiarity with OWASP LLM Top 10 / MITRE ATLAS. Hands‑on cloud incident response across Azure, AWS, and/or GCP, including cloud‑native log sources (Azure Activity/Entra ID sign‑in logs, AWS CloudTrail) and the reality that cloud IR differs from on‑prem.
📌 Cyber Security Incident Response - Assistant Manager (Madrid)
🏢 WTW
📍 Madrid