About the Role
The Threat-Led Detection Engineer will design, build, and maintain high-quality threat detections within WTW’s Global Information and Cyber Security Defence (ICSD) function, helping WTW detect adversary activity quickly and accurately across its global estate. This is a hands-on engineering role for someone with a strong cyber security mindset and a genuine interest in how attackers operate.
Responsibilities
- Design, write, test, and maintain high-fidelity detection rules across SIEM, EDR/XDR, cloud, identity, and network data sources.
- Apply a threat-led approach, developing detections mapped to adversary tradecraft using the MITRE ATT&CK framework, the Cyber Kill Chain, and the Diamond Model.
- Rapidly create new detections in response to emerging threats, Cyber Threat Intelligence, and incident or hunt findings.
- Contribute to the detection library, ensuring detections are version-controlled, documented, tested, and mapped to MITRE ATT&CK coverage.
- Tune and optimise existing detections to reduce false positives and continuously improve fidelity.
- Practise Detection-as-Code, using Git-based workflows, peer review, and automated testing for detection content.
- Validate detections through adversary emulation and testing (e.g. Atomic Red Team) and collaborate on purple-team exercises.
- Support the integration of AI and automation into detection and triage workflows, and help build detections for AI/GenAI-specific threats.
- Collaborate with SOC, Threat Hunting, CTI, and Incident Response to close detection gaps surfaced during hunts and incidents.
- Write clear detection documentation and response guidance so each detection is actionable for analysts.
- Onboard and validate new log sources and telemetry to expand detection coverage.
- Contribute to detection coverage and quality metrics to help measure and improve detection effectiveness.
Requirements
- Strong cyber security mindset.
- Genuine interest in how attackers operate.
- Experience with SIEM, EDR/XDR, cloud, identity, and network data sources.
- Familiarity with MITRE ATT&CK framework, Cyber Kill Chain, and Diamond Model.
- Experience with Detection-as-Code principles and Git-based workflows.
- Experience with adversary emulation and testing (e.g. Atomic Red Team).
- Experience with AI and automation in detection and triage workflows.
- Experience building detections for AI/GenAI-specific threats.
- Experience collaborating with SOC, Threat Hunting, CTI, and Incident Response teams.
- Experience writing detection documentation and response guidance.
- Experience onboarding and validating new log sources and telemetry.
- Experience contributing to detection coverage and quality metrics.
Skills
- Threat detection rule writing and tuning
- Cyber Threat Intelligence analysis
- Incident Response
- Threat Hunting
- Detection-as-Code
- MITRE ATT&CK framework
- Cyber Kill Chain
- Diamond Model
- SIEM
- EDR/XDR
- Cloud security
- Identity and Access Management security
- Network security
- Adversary emulation
- Atomic Red Team
- AI and automation
- GenAI security
- Log source onboarding
- Telemetry validation
- Version control (Git)
- Peer review
- Automated testing
Location
- London
Work Type
- Hybrid
Experience Level
- Hands-on engineering role
About the Company
- WTW has a large global footprint.
- The company fosters a security-aware culture.
- WTW aims to be a great place to work.
