Customer Trust Specialist
Handles complex customer-facing security engagements for regulated enterprises, including audits, questionnaires, contract terms, executive briefings, and trust documentation. Requires broad security expertise, strong writing, independent judgment, and 10+ years of security experience, including leadership experience preferred.
About the job
Responsibilities
- Negotiate security terms and schedules with regulated enterprise customers, escalating issues and developing new positions with Legal.
- Manage complex customer questionnaires, RFPs, and security assessments through completion.
- Run onsite and remote security audits, including agenda development, control walkthroughs, disputed findings, and closure documentation.
- Present the company’s security posture to customer CISOs and answer questions about architecture, data handling, retention, tenancy, and model training.
- Maintain Legal-approved positions, canonical answer banks, audit runbooks, trust artifacts, white papers, FAQs, Trust Center content, and architecture diagrams.
- Build AI-powered questionnaire and RFP automation, automate evidence gathering, and verify machine-drafted responses.
- Route control gaps and capability requests to Product and Security owners and follow through to closure.
- Identify trends in customer expectations and report engagement metrics to leadership.
Requirements
- Security expertise in at least one domain, with working fluency across engineering, governance, risk, and compliance.
- Customer-facing security experience with audits, security questionnaires, contract security terms, or executive briefings for regulated enterprises.
- Ability to balance business needs and security requirements, make independent decisions, and escalate appropriately.
- Experience creating positions, playbooks, or standard answers used by colleagues.
- Strong written communication and technical security documentation skills.
- Ability to coordinate Engineering, Legal, and GRC stakeholders without direct authority.
- Bachelor’s degree or equivalent combination of education, training, and experience.
Nice-to-haves
- 10+ years of security experience, including 3+ years in security leadership.
- Experience applying large language models to security assurance or GRC workflows.
- Familiarity with financial-services security expectations, third-party risk, regulatory exam readiness, DORA, and PCI DSS.
- Knowledge of AI-specific trust topics, including training data handling, retention architectures, regional inference, and customer-managed encryption.
- Experience in an enterprise-security-sensitive company.
- Experience reviewing and refining security clauses and commitments.
- Understanding of AI system risks and security considerations for ML/AI products.
- Strategic prioritization and risk-versus-business-impact assessment skills.
Compensation
- Annual compensation: $255,000–$270,000 USD.
Skills
Security Governance, Risk Management, Compliance, Security Audits, Security Questionnaires, Contract Negotiation, Rfps, GRC, LLMs, Dora, Pci Dss, Trust Centers, Architecture Diagrams, Customer-Managed Encryption, Ai Security
Similar jobs
Security Engineering jobsLeads the multi-year technical strategy and architecture for Coinbase’s identity and access management platform across hundreds of systems and engineering teams. Requires 12+ years of software engineering experience, deep IAM and workload identity expertise, production Go, and distributed-systems experience on AWS.
Own and scale IT general controls, access governance, segregation of duties, and audit readiness across enterprise applications. The role combines SOX expertise with AI-enabled continuous controls monitoring and requires 10+ years of controls, audit, or enterprise governance experience.
Staff Security Software Engineer leading identity and access strategy, architecture, and hands-on platform development across customer, employee, contractor, and agentic identities. Requires 10+ years of production software experience and deep expertise in identity and authorization systems.
Design and operate distributed, low-latency infrastructure that protects Reddit from DDoS attacks, bots, scraping, and other network threats. The role requires 7+ years of distributed-systems experience plus expertise in security, networking, and production operations.
Staff-level AppSec engineer building secure coding practices and vulnerability management for a commerce platform. Requires 6+ years in application security with deep AWS and Python experience.