Serve as the primary security point of contact for external customers, owning the end-to-end customer security relationship.
Lead customer security programs for managed services, ensuring alignment with contractual obligations, regulatory requirements, and enterprise security standards.
Translate customer security requirements into actionable security objectives, coordinating delivery across internal Information Security, Engineering, Cloud Platform, and Application Security teams.
Provide oversight and governance of MSSP-delivered Security Operations, including monitoring, incident detection, response coordination, and SLA adherence.
Own and coordinate customer-specific governance, risk, and compliance (GRC) activities, including risk assessments, control mapping, and remediation tracking.
Lead customer security governance forums, periodic security reviews, and executive-level briefings.
Coordinate customer security questionnaires, audits, certifications, and assurance activities in partnership with internal GRC and compliance teams.
Ensure timely and effective communication of security posture, risks, incidents, and remediation plans to customers and executive stakeholders.
Track and manage customer security risks, exceptions, and remediation activities through formal governance processes.
Support the continuous improvement and scalability of the enterprise customer security program model.
Perform additional duties as assigned by the Director of Information Security.
Requirements
Strong knowledge of information security governance, risk management, and compliance in customer-facing or regulated environments.
Broad understanding of enterprise and cloud security domains, including infrastructure security, application security, identity and access management, logging and monitoring, and incident response.
Experience overseeing or coordinating security services delivered through Managed Security Service Providers or shared service models.
Demonstrated ability to lead cross-functional initiatives and influence stakeholders without direct authority.
Excellent written and verbal communication skills, with the ability to convey complex security topics to non-technical and executive audiences.
Familiarity with common security frameworks and standards (e.g., ISO 27001, SOC 2, NIST).
Bachelor’s degree in Information Security, Computer Science, Systems Engineering, or a related field required.