Technical Account Manager, Managed Services Security
Job description
The Technical Account Manager (TAM) is a member of the AHEAD Managed Services Client Experience team, responsible for guiding clients through the strategic, operational, and technical aspects of their security transformation and driving measurable outcomes from AHEAD Managed Security Services. Working within AHEAD’s outcome-led delivery model, the TAM builds close client relationships to understand business goals, security challenges, and compliance requirements, and translates them into a prioritized roadmap that reduces risk and accelerates value realization.
The role calls for strong security depth across managed detection and response, security operations, endpoint protection, and incident response, combined with client-facing advisory skills and commercial acumen. A platform-first, multi-vendor mindset is essential: hands-on experience with Palo Alto Networks Cortex XSIAM and Cortex XDR is expected, but not exclusively—demonstrated fluency across other leading SIEM, XDR, and SOAR platforms and security automation is equally key. Experience with AI-enabled and agentic SOC operations—how AI, analytics, and automation accelerate detection, triage, and response and reduce mean time to detect and respond—is a core requirement of the role.
What success looks like
- Client health and satisfaction: sustained high client health and CSAT across the named account base, with issues addressed before they affect the relationship.
- Retention and growth: strong renewal and gross retention, plus qualified expansion opportunities surfaced to MSS leadership and account teams.
- Security outcomes: measurable risk reduction and improved detection and response maturity, including reduced mean time to detect and respond and broader detection coverage.
- Delivery quality: audit-ready case quality and defensibility, delivered consistently through the Unified Delivery Framework.
- Commercial health: engagements scoped and delivered to sustain both client value and healthy service margins.
Summary of essential job functions
- Serves as the client’s single point of contact and advocate for technical and security matters across AHEAD Managed Security Services, building trusted relationships with a named client base and a deep understanding of each client’s environment, program maturity, and risk profile.
- Acts as a strategic security advisor, aligning managed services capabilities to business objectives, security priorities, and regulatory requirements, and framing every engagement around defined client outcomes rather than task completion.
- Owns the client health relationship, proactively monitoring service adoption, outcome attainment, and satisfaction signals, and driving corrective action before issues impact renewal or retention.
- Leads the Quarterly Business Review (QBR) operating model, communicating service value, security trends, risk observations, quantified business impact, and a forward-looking strategic roadmap to executive stakeholders.
- Champions a platform-first approach, guiding clients toward consolidated SIEM, XDR, and SOAR platforms—including Palo Alto Networks Cortex XSIAM and Cortex XDR as well as other leading technologies—to reduce tool sprawl, improve telemetry coverage, and lower total cost of operations.
- Advances AI-enabled and agentic SOC maturity, advising on automation, analytics, and AI-driven detection and response workflows that improve speed, consistency, and analyst efficiency.
- Performs risk and maturity assessments and technology evaluations to identify gaps and prioritize remediation and optimization aligned to strategic goals, compliance frameworks, and security best practices.
- Supports the adoption, tuning, and optimization of security technologies—SIEM, XDR, SOAR, endpoint telemetry, and threat detection platforms—and partners with clients to improve incident response maturity, detection coverage, and workflow automation.
- Understands AHEAD’s value-based packaging and service tiers well enough to speak to clients about coverage options, tradeoffs, and outcomes, and channels client needs and expansion opportunities back to MSS leadership and account teams for packaging review and roadmap planning, applying commercial and client-profitability awareness so engagements are scoped and delivered efficiently.
- Acts as a technical liaison and escalation point between the client and AHEAD support, engineering, security operations, and leadership teams, leveraging the Unified Delivery Framework to ensure consistent, high-quality delivery.
- Reinforces case quality and defensibility—ensuring incident documentation, investigation notes, and response actions are complete, accurate, and audit-ready—and reviews incidents, trends, and root causes with clients and internal teams to drive continuous improvement.
- Partners with Client Directors and Service Account Managers on planning, budgeting, roadmap development, and reporting, and identifies up-sell and cross-sell opportunities tied to demonstrated client value and outcome gaps.
- Serves as a strategic contributor to customer satisfaction, client retention, renewal, and long-term trusted-advisor relationships.
Experience and Certifications
- 10+ years of related experience in security engineering, security operations, infrastructure engineering, technical sales, managed services, or IT consulting.
- 5+ years of client-facing experience in a technical advisory, TAM, solutions architect, or managed services role preferred.
- Strong background in cybersecurity operations, endpoint detection and response, security monitoring, incident response, and security platform administration.
- Hands-on experience designing, deploying, tuning, and supporting modern SIEM/XDR/SOAR platforms is required. Experience with Palo Alto Networks Cortex XSIAM and Cortex XDR is expected, but not limited to Cortex—equivalent depth across other leading SIEM, XDR, and SOAR platforms and security automation tooling is equally valued.
- Hands-on experience with AI-enabled and agentic SOC capabilities is key, including AI-assisted and automated detection, triage, investigation, and response, and applying automation to reduce manual effort and mean time to respond.
- Experience with detection content, alert tuning, telemetry normalization, automated response workflows, playbooks, and cross-platform integrations is strongly preferred.
- Demonstrated ability to translate security outcomes into business value and communicate them to executive stakeholders through structured reviews such as QBRs.
- Commercial or client-profitability awareness (scoping, service tiers, margin, or engagement economics) is a plus.
- Experience with security frameworks and regulatory requirements such as NIST CSF, CIS, HIPAA, FFIEC, SOX, or PCI-DSS preferred.
- Relevant certifications desired, such as Palo Alto Networks (especially SOC operations or Cortex platform administration), Microsoft, Cisco, Security+, CySA+, CISSP, CISM, GIAC, ITIL, or Project Management.
Technical background requirements
- Strong understanding of managed security services, SOC operations, detection and response workflows, and incident management.
- Working knowledge of platform-first security architecture and how consolidated SIEM/XDR/SOAR platforms and AI-enabled automation improve detection, response, and operational efficiency.
- Hands-on/practical experience with the following technologies:
- Modern SIEM, XDR, SOAR, EDR, and log management platforms
- Palo Alto Networks Cortex XSIAM
- Palo Alto Networks Cortex XDR
- Windows Server
- Active Directory
- Microsoft 365 and Office 365
- Public cloud platforms
- VMware
- Citrix
- Cisco
- Dell/EMC
- Familiarity with security integrations across endpoint, identity, network, cloud, and ticketing systems.
- Experience with security use case development, detection tuning, operational dashboards, reporting, and workflow automation preferred.
Required Skills
- Ability to communicate complex technical and security concepts and translate technical activity into quantified business outcomes and service value—verbally and in writing—for both executive and operational audiences.
- Business and commercial acumen, with the ability to balance client value, delivery efficiency, and service profitability.
- Vendor-agnostic platform adaptability, with the proven ability to work fluently across Palo Alto Networks Cortex XSIAM and Cortex XDR as well as other leading SIEM, XDR, SOAR, and security automation platforms, and to quickly learn and apply new detection, automation, and AI/agentic capabilities across a multi-vendor security ecosystem.
- Strong analytical and problem-solving skills, with the ability to translate operational and security data into actionable client recommendations.
- Ability to build trusted relationships and influence senior leadership teams.
- Ability to collaborate cross-functionally with Sales, Engineering, Support, and Security Operations teams within a unified delivery model.
- Proven knowledge of ITIL frameworks (especially Incident, Problem, and Change Management) and of cybersecurity operations, threat detection, vulnerability management, and security governance concepts.
- Commitment to case quality and defensibility, with attention to accurate, complete, and audit-ready documentation.
- Strong customer service orientation, with sound judgment and the ability to prioritize and execute in a fast-paced environment.
- Occasional on-call and after-hours work as the business requires; willingness to travel to customer sites as needed.
Education
- Undergraduate degree in Information Technology, Cybersecurity, Computer Science, or a related field preferred.
- Equivalent professional experience in infrastructure, security engineering, managed services, or client advisory roles will also be considered.
One profile. Every role.
Create your candidate profile once. R1 handles the matching, the tailoring, and the applications.
Create your profile