As a Cyber Threat Hunting Assistant Manager, within the Threat Discovery and Fusion Unit (TDFU), you will play a key role in proactively hunting for adversary activity across WTW's general environment by turning cyber threat intelligence into active pursuit of hidden threats. This hands-on technical role requires prior experience in threat hunting, cybersecurity, and incident response. You will leverage your expertise to consume and fuse intelligence from multiple internal and external sources, research emerging threats and adversary tradecraft, and develop and execute intelligence-led hunts that surface malicious activity evading existing detections, while contributing to WTW’s intelligence-led cyber defense strategy.
We are seeking a motivated and intellectually curious professional with a passion for threat hunting and a strong technical foundation. This role does not include line management responsibilities but offers opportunities to collaborate with a global, multi-disciplinary team and contribute to enhancing WTW’s overall security posture.
The Role The Cyber Threat Hunting Associate Manager will provide global threat hunting capability for WTW, responsibilities of this role will include:
- Develop and execute hypothesis-driven, intelligence-led threat hunts to uncover adversary tactics, techniques, and procedures (TTPs.
- Analyze security trends and assess their impact on the organization,
providing actionable insights to leadership.
- Analyze threat intelligence to enhance detection and response capabilities and ensure alignment with WTW’s security strategy.
- Convert intelligence inputs across all categories into hypothesis-driven, intelligence-led hunts, and feed findings back into WTW's detection capabilities and intelligence picture.
- Utilize advanced threat hunting tools and techniques, including behavioral analytics, anomaly detection, and threat intelligence integration.
- Support incident response activities by conducting forensic analysis, identifying root causes, and recommending mitigation strategies.
- Research vulnerabilities and exploits available to cybercriminals that have not yet reached WTW's sectors but are likely to target the organization, assessing exposure ahead of impact
- Research and hunt for new malware types, infostealers, RATs, and similar tooling—observed as steps in attacks against enterprise environments
- Collaborate with stakeholders across ICSD and other teams to improve threat detection and response processes.
- Create and maintain documentation, such as threat hunt reports, playbooks, and standard operating procedures (SOPs).
- Conduct host and network forensics, log analysis, and evidence collection for on-premises and cloud systems, ensuring proper chain of custody and documentation.
📌 Assistant Manager - Cyber Threat Hunter (Madrid)
🏢 WTW
📍 Madrid