Senior AI Security & Automation Engineer
WTWAbout the role
The Role
The Senior AI Security & Automation Engineer plays a pivotal role in enhancing the efficiency and maturity of the organisation’s security operations by designing and implementing robust automated solutions. Working in close collaboration with Global Information and Cyber Security Defence (ICSD) function, this role identifies opportunities to streamline processes, accelerate incident response, and reduce operational overhead through intelligent automation.
In addition to building scalable automation workflows this individual will contribute to the broader Security Engineering team, supporting the development and maintenance of the organization’s security infrastructure. The ideal candidate combines a deep understanding of cybersecurity operations with a strong background in scripting and automation platforms to build scalable, resilient, and secure systems.
The Responsibilities
Design and deploy AI-driven security agents leveraging Large Language Models (LLMs) to automate traditionally manual security operations and workflows.
Leverage LLM-powered platforms such as Microsoft Security Copilot to support cybersecurity tasks including threat hunting, triage, investigations and response, and creating security incident response playbooks.
Build and maintain SOAR playbooks integrated with various security platforms (e.g., SIEMs, EDRs, identity platforms) to streamline incident response and automation.
Lead automation initiatives to eliminate manual processes, improve the reliability and visibility of security controls, and define metrics to measure the impact of process improvements.
Ensure automation workflows and monitoring solutions are resilient, integrated, and optimized for 24/7 detection and response capabilities.
Support the administration and management of security tools within the Security Engineering team.
Participate in proof-of-concepts for innovative security and automation solutions.
Lead security operations process improvements, including development and refinement of SOPs, playbooks, and standards.
Support security audits, assist in incident investigations, and promote adherence to security best practices across DevOps environments.
Create technical documentation and deliver enablement sessions to enhance security awareness and practices within engineering teams.
Foster a culture of security excellence by promoting secure coding and design practices across the organization.
The Qualifications:
Bachelor’s degree in computer science, Information Security, or a related field, or equivalent work experience.
5+ years of experience in cybersecurity, with a focus on security engineering and automation.
Comfortable writing scripts using languages such as Python, PowerShell, or Bash, and experience with automation platforms such as Azure Logic Apps, SOAR tools (e.g., Microsoft Sentinel, Splunk SOAR, Cortex XSOAR).
Experience designing SOAR workflows for automated security response and incident triage.
Proven experience with Large Language Models (LLMs) such as Claude, GPT-4, OpenAI, Azure OpenAI, or similar frameworks.
Deep understanding of cybersecurity domains, including incident response, threat detection, and Identity and Access Management (IAM) principles.
Experience with RESTful APIs, JSON, and integrating various security platforms.
Familiarity with cloud platforms and cloud-native security services.
Knowledge of Microsoft Security products such as Microsoft Sentinel, Microsoft Defender XDR, Micr
osoft Defender for Cloud, Microsoft Intune, etc.
Solid understanding of ITSM and change control processes.
Understanding log management, SIEM tools, endpoint detection and other security platforms.
Other Knowledge, Skills and Abilities
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s