Threat-Led Detection Engineer at WTW | City of London, England | Rezi

Threat-Led Detection Engineer at WTW

Threat-Led Detection Engineer

WTW · City of London, England

1 months ago

Threat-Led Detection Engineer

WTW · City of London, England

a month ago
Resume preview

Impress employers and recruiters.
Choose from hundreds of resume examples.

Target Resume Now

About the Role

The Threat-Led Detection Engineer will design, build, and maintain high-quality threat detections within WTW’s Global Information and Cyber Security Defence (ICSD) function, helping WTW detect adversary activity quickly and accurately across its global estate. This is a hands-on engineering role for someone with a strong cyber security mindset and a genuine interest in how attackers operate.

Responsibilities

  • Design, write, test, and maintain high-fidelity detection rules across SIEM, EDR/XDR, cloud, identity, and network data sources.
  • Apply a threat-led approach, developing detections mapped to adversary tradecraft using the MITRE ATT&CK framework, the Cyber Kill Chain, and the Diamond Model.
  • Rapidly create new detections in response to emerging threats, Cyber Threat Intelligence, and incident or hunt findings.
  • Contribute to the detection library, ensuring detections are version-controlled, documented, tested, and mapped to MITRE ATT&CK coverage.
  • Tune and optimise existing detections to reduce false positives and continuously improve fidelity.
  • Practise Detection-as-Code, using Git-based workflows, peer review, and automated testing for detection content.
  • Validate detections through adversary emulation and testing (e.g. Atomic Red Team) and collaborate on purple-team exercises.
  • Support the integration of AI and automation into detection and triage workflows, and help build detections for AI/GenAI-specific threats.
  • Collaborate with SOC, Threat Hunting, CTI, and Incident Response to close detection gaps surfaced during hunts and incidents.
  • Write clear detection documentation and response guidance so each detection is actionable for analysts.
  • Onboard and validate new log sources and telemetry to expand detection coverage.
  • Contribute to detection coverage and quality metrics to help measure and improve detection effectiveness.

Requirements

  • Strong cyber security mindset.
  • Genuine interest in how attackers operate.
  • Experience with SIEM, EDR/XDR, cloud, identity, and network data sources.
  • Familiarity with MITRE ATT&CK framework, Cyber Kill Chain, and Diamond Model.
  • Experience with Detection-as-Code principles and Git-based workflows.
  • Experience with adversary emulation and testing (e.g. Atomic Red Team).
  • Experience with AI and automation in detection and triage workflows.
  • Experience building detections for AI/GenAI-specific threats.
  • Experience collaborating with SOC, Threat Hunting, CTI, and Incident Response teams.
  • Experience writing detection documentation and response guidance.
  • Experience onboarding and validating new log sources and telemetry.
  • Experience contributing to detection coverage and quality metrics.

Skills

  • Threat detection rule writing and tuning
  • Cyber Threat Intelligence analysis
  • Incident Response
  • Threat Hunting
  • Detection-as-Code
  • MITRE ATT&CK framework
  • Cyber Kill Chain
  • Diamond Model
  • SIEM
  • EDR/XDR
  • Cloud security
  • Identity and Access Management security
  • Network security
  • Adversary emulation
  • Atomic Red Team
  • AI and automation
  • GenAI security
  • Log source onboarding
  • Telemetry validation
  • Version control (Git)
  • Peer review
  • Automated testing

Location

  • London

Work Type

  • Hybrid

Experience Level

  • Hands-on engineering role

About the Company

  • WTW has a large global footprint.
  • The company fosters a security-aware culture.
  • WTW aims to be a great place to work.