The Senior AI Security & Automation Engineer plays a pivotal role in enhancing the efficiency and maturity of the organisation’s security operations by designing and implementing robust automated solutions. Working in close collaboration with Global Information and Cyber Security Defence (ICSD) function, this role identifies opportunities to streamline processes, accelerate incident response, and reduce operational overhead through intelligent automation.
In addition to building scalable automation workflows this individual will contribute to the broader Security Engineering team, including supporting Detection Engineering through the design, development, and optimisation of high-fidelity threat detections, ensuring effective visibility of threats across the environment. The ideal candidate combines a deep understanding of cybersecurity operations with a strong background in scripting, automation, and detection engineering practices to build scalable, resilient, and secure systems.
The Role:
What you'll bring:
Bachelor’s degree in computer science, Information Security, or a related field, or equivalent work experience.
Demonstrated experience delivering cybersecurity solutions, with a strong emphasis on security engineering and automated controls.
Comfortable writing scripts using languages such as Python, PowerShell, or Bash, and experience with automation platforms such as Azure Logic Apps, SOAR tools (e.g., Microsoft Sentinel, Splunk SOAR, Cortex XSOAR).
Experience building and tuning detections using SIEM platforms (e.g., KQL, SPL) and working with security telemetry across endpoint, identity, network, and cloud.
Experience designing SOAR workflows for automated security response and incident triage.
Proven experience with Large Language Models (LLMs) such as Claude, GPT-4, OpenAI, Azure OpenAI, or similar frameworks.
Deep understanding of cybersecurity domains, including incident response, threat detection, and Identity and Access Management (IAM) principles.
Experience with RESTful APIs, JSON, and integrating various security platforms.
Familiarity with cloud platforms and cloud-native security services.
Knowledge of Microsoft Security products such as Microsoft Sentinel, Microsoft Defender XDR, Microsoft Defender for Cloud, Microsoft Intune, etc.
Solid understanding of ITSM and change control processes.
Understanding log management, SIEM tools, endpoint detection and other security platforms.
Other Knowledge, Skills and Abilities:
Certifications (Preferred):
What we offer
Enjoy a benefits package designed to help you thrive, both professionally and personally. You'll receive 25 days of annual leave plus an extra WTW day to relax and recharge. Our comprehensive health and wellbeing offering includes private healthcare, life insurance, group income protection, and regular health assessments, all giving you peace of mind. Secure your future with our defined contribution pension scheme, featuring matched contributions up to 10% from the company.
We support your growth and balance with hybrid working options, access to an employee assistance programme, and a fully paid volunteer day to make a difference in your community. On top of these, you can opt into a variety of additional perks including an electric vehicle car scheme, share scheme, cycle-to-work programme, dental and optical cover, critical illness protection, and much more. Start making the most of your career and wellbeing with a range of benefits tailored for you.
Equal Opportunity Employer
We’re committed to equal employment opportunity and provide application, interview and workplace adjustments and accommodations to all applicants. If you foresee any barriers, from the application process through to joining WTW, please email candidate.helpdesk@wtwco.com

At WTW (NASDAQ: WTW), we provide data-driven, insight-led solutions in the areas of people, risk and capital. Leveraging the global view and local expertise of our colleagues serving 140 countries and markets, we help you sharpen your strategy, enhance organizational resilience, motivate your workforce and maximize performance.