Act as the customer's technical owner for security services, quantify security maturity via the TAM Score, build a 12-month technical roadmap, deliver QBRs, provide reactive ticket-based support, drive proactive improvements (tuning, automation), create technical deliverables (playbooks, analytics, workbooks), and advise on defensive security gaps and mitigation services.
The TAM is the customer's technical owner for the service and the expert voice in the relationship. They quantify the customer's security maturity through the TAM Score framework, build and steer a defensible 12-month technical roadmap, and provide the depth of Microsoft Azure Sentinel/Defender XDR expertise needed to advise credibly on priorities. TAMs translate data into narrative - interpreting scores, surfacing the highest-leverage gaps, and guiding customers toward measurable improvement quarter by quarter. They act as a technical buffer between customers and internal operational teams by resolving technical queries, advising on improvements, and ensuring issues are properly packaged when escalation is required.
Key Responsibilities
- Own the technical relationship: understand the customer environment end-to-end, maintain technical context, and operate as the trusted advisor in the partnership.
- Own the TAM Score narrative: interpret Environment, SOC, and Health scores into a credible story about where the customer stands and where to focus next - accountable for the quality of the diagnosis and recommendations, not the absolute score.
- Build and maintain the 12-month technical roadmap: anchored to the TAM Score, with defined quarterly focus areas tied to the highest-leverage gaps.
- Deliver the TAM/technical portion of Quarterly Business Reviews: present the score, narrate progress, and align with customer stakeholders up to CISO/senior IT leadership.
- Deliver reactive technical support via tickets (troubleshooting, investigation support, remediation guidance).
- Deliver proactive technical expertise and drive continuous improvement (Tier A included): posture and coverage advisory, tuning/noise reduction, cost/retention optimisation, automation uplift.
- Own technical deliverables: automation/playbooks where in scope, custom analytics and workbooks.
- Drive the operational health-check catalogue as scheduled workstreams within the roadmap.
- Advise on Defensive Breadth gaps (pentest cadence, IR retainer, EASM, DLP, tabletops, etc) - surfacing risk credibly and identifying where NCC services can close the gap.
- Maintain and refresh the threat overview as the customer's environment and threat landscape evolve.
Key Requirements
- Proven experience in cybersecurity, IT operations, or managed security services (3–7+ years)
- Background in a customer-facing technical role (e.g. TAM, Security Consultant)
- Experience engaging senior stakeholders (CISO, Head of IT/Security)
- Strong understanding of SOC operations, threat detection, and incident response
- Ability to understand end-to-end customer environments (cloud, infrastructure, security stack)
- Experience with security tools (e.g. SIEM, EDR, SOAR, DLP, vulnerability management)
- Able to interpret and translate security metrics into clear risk-based narratives
- Proven ability to build and maintain 12-month technical roadmaps with quarterly focus
- Strong skills in data analysis, prioritisation, and identifying high-impact improvements
- Experience delivering Quarterly Business Reviews (QBRs) to senior audiences
- Ability to act as a trusted advisor, owning the technical customer relationship
- Experience balancing reactive support (tickets, troubleshooting) and proactive improvement
- Capability to deliver continuous improvement initiatives (tuning, optimisation, automation)
- Experience creating technical deliverables (playbooks, dashboards, analytics, reports)
- Knowledge of defensive security domains (pentest, IR, EASM, DLP, tabletop exercises)
- Ability to identify security gaps and align solutions/services to mitigate risk
- Strong communication and storytelling skills, adapting for technical and non-technical audiences
- Familiarity with service management practices (e.g. ITIL, ticketing systems)
- Relevant certifications (e.g. CISSP, CISM, Security+, cloud security) – desirable
- Proactive, accountable, and customer-focused mindset with strong ownership
Job Benefits
- Flexible Working: Balance your work and personal life with our flexible working options.
- Generous Holiday Allowance: Enjoy 25 days of holiday, plus bank holidays, with the option to buy up to 5 additional days of annual leave.
- Medicash & Critical Illness Scheme
- Financial & Investment Benefits: Enjoy peace of mind with our Pension, Life Assurance, and Share Save Scheme.
- Community & Volunteering Programmes: Make a difference in your community with our volunteering opportunities.
- Green Car Scheme: Drive green and save money with our eco-friendly car scheme.
- Cycle Scheme: Stay fit and healthy with our cycle-to-work scheme.
- Special Time Off: Take time off for those big moments in life, like getting married/entering into a civil partnership, becoming a grandparent, and welcoming home a new pet.
- Family Planning: Benefit from our generous maternity and paternity leave, as well as time off and support for those undergoing fertility treatments.
About
We assess, develop and manage cyber threats across our increasingly connected society. We advise global technology, manufacturers, financial institutions, critical national infrastructure providers, retailers and governments on the best way to keep businesses, software and personal data safe.With our knowledge, experience and global footprint, we are best placed to help businesses identify, assess, mitigate & respond to the risks they face.We are passionate about making the Internet safer and revolutionising the way in which organisations think about cyber security.Headquartered in Manchester, UK, with over 35 offices across the world, NCC Group employs more than 2,000 people and is a trusted advisor to 15,000 clients worldwide.
Similar Jobs
Artificial Intelligence • Cloud • Software
Own post-sales technical relationships for a small portfolio of enterprise customers. Drive incident triage and remediation, provide proactive architecture and cost-optimization guidance, scope and coordinate Professional Services and FDE engagements, represent customer needs internally, and carry renewal accountability and TAM-specific CSAT/SLAs.
Top Skills:
App RouterFluid ComputeIsr (Incremental Static Regeneration)Mcp ServersNext.JsVercelVercel Ai Sdk
Software • Generative AI
Serve as the technical lead for enterprise customers on Fireworks' inference platform: manage onboarding, deployment, SSO/security, performance benchmarking, troubleshooting, and escalations; advise on model selection, fine-tuning, prompt engineering, and cost/latency optimization; run QBRs, drive adoption, identify expansion, and feed customer insights into product roadmaps.
Top Skills:
Agent ArchitecturesAPIsAWSAzureDeepseekFine-TuningGCPInference OptimizationLlamaLlmsMixtralModel ServingOpen-Source ModelsPrompt EngineeringRag
Information Technology • Professional Services • Software • Cybersecurity
Act as the customer's technical owner for security services: assess security maturity (TAM Score), build and execute a 12-month technical roadmap, provide Azure Sentinel/Defender XDR expertise, translate metrics into risk-based narratives, deliver QBRs, resolve technical issues, drive proactive improvements (tuning, automation), produce technical deliverables (playbooks, analytics, dashboards), and advise on defensive security gaps.
Top Skills:
AnalyticsDashboardsDefender XdrDlpEasmEdrItilMicrosoft Azure SentinelPlaybooks/AutomationSIEMSoarTicketing SystemsVulnerability Management
What you need to know about the London Tech Scene
London isn't just a hub for established businesses; it's also a nursery for innovation. Boasting one of the most recognized fintech ecosystems in Europe, attracting billions in investments each year, London's success has made it a go-to destination for startups looking to make their mark. Top U.K. companies like Hoptin, Moneybox and Marshmallow have already made the city their base — yet fintech is just the beginning. From healthtech to renewable energy to cybersecurity and beyond, the city's startups are breaking new ground across a range of industries.


