Customer Trust Lead
Job description
About the role
You will own the end-to-end lifecycle of security and compliance due diligence for Emburse, acting as the single point of accountability for inbound security questionnaires and vendor risk assessments. You will serve as the trusted, credible interface between Emburse and enterprise buyers, procurement teams, and third-party risk functions who need rigorous proof of our security posture. In this specialized individual contributor role, you will manage the full response process for approximately 500 engagements annually across Emburse's portfolio of 14 products, ensuring consistency, accuracy, and timeliness. You will translate complex regulatory and technical control requirements into clear, defensible, and audience-appropriate language that reinforces trust in our platform. You will partner directly with the CISO and Data Protection Officer to interpret frameworks, resolve ambiguous requirements, and close policy or evidence gaps. You will also co-own and evolve the company's Trust Center, ensuring that self-serve content reduces repetitive inbound load while maintaining strict alignment with our underlying responses. Ultimately, you will be the operational backbone that enables secure, scalable sales, renewals, and Extended Services engagements by maintaining an always-current, audit-ready view of our compliance status.
Key facts
What you'll do
Drive end-to-end response for security questionnaires, DDQs, and vendor risk assessments across new business, renewals, Extended Services engagements, and Installations while supporting the full customer-facing organization via RFPIO.
Maintain and continuously refine a high-quality content library in RFPIO and SafeBase that reflects current, accurate, and approved Emburse positions across all 14 products and service lines.
Triage all inbound security requests to confirm scope, route non-security inquiries appropriately with documented rationale, and actively manage response SLAs through proactive communication with internal stakeholders.
Serve as the internal subject matter expert on Emburse's security and compliance posture for frameworks including SOC 2, ISO 27001, NIST 800-171, CSA CAIQ, GDPR, CCPA, and other frameworks required by our global customer base.
Translate intricate technical and regulatory controls into clear, precise, and customer-facing language that is tailored to the audience while remaining legally and technically defensible.
Partner with Security, Legal, and Product teams to validate responses, identify gaps, and ensure nothing is overstated, understated, or misrepresented in any customer deliverable.
Co-manage and maintain Emburse's SafeBase Trust Center as the primary self-service destination for customer security inquiries, ensuring all published content is current, consistent, and aligned with the RFPIO content library.
Drive SafeBase adoption among customers and Customer Success Managers to reduce inbound DDQ volume for requests that can be self-served, and analyze recurring questionnaire themes to identify and remediate content gaps.
Enforce intake governance by maintaining and applying routing guides, SLA tiers, and scope definitions; documenting reason codes for out-of-scope requests, declined engagements, and escalations to support continuous process improvement.
Maintain accurate, queryable records of all security engagements for pipeline visibility, capacity planning, and executive reporting while contributing to policies governing non-standard intake methods, including customer requests for portal-based vendor risk platform access.
Leverage data from completed questionnaires and assessments to identify trends, streamline control evidence, and recommend improvements to both product controls and customer communications.
Support audit preparation and evidence collection activities by coordinating with internal stakeholders, ensuring that documentation is complete, consistent, and readily available for reviewers.
Act as the escalation path for complex or sensitive security inquiries, balancing customer needs with Emburse's risk posture and regulatory obligations.
Champion continuous improvement by monitoring evolving standards, customer best practices, and regulatory updates to keep Emburse's security documentation current and comprehensive.
Requirements
5+ years in information security compliance, vendor risk, customer trust, or a closely related function with a demonstrated track record of managing security engagements in a SaaS context.
Demonstrated working knowledge of SOC 2 Type I and Type II, ISO 27001, NIST 800-53, System and Organization Controls (SCCs), Service Organization Control (SIG) reporting, CSA CAIQ, GDPR, and CCPA frameworks and their practical application.
Experience managing high-volume security questionnaire and DDQ workflows, including intake triage, response authoring, and SLA enforcement in a SaaS environment.
Exceptional written communication skills with the ability to produce precise, defensible, and audience-aware responses that balance transparency with risk management.
Proficiency with RFPIO or a comparable questionnaire automation platform for content assembly, version control, and stakeholder collaboration.
Strong organization skills and the ability to manage a large concurrent workload independently while maintaining strict attention to detail and accuracy.
Experience administering or contributing to a Trust Center platform such as SafeBase, Vanta, Drata, OneTrust, or Whistic, including content governance and stakeholder alignment.
Familiarity with public sector or regulated industry requirements such as FedRAMP, StateRAMP, and CMMC is preferred, though not required, as is prior background in Travel and Expense, fintech, or multi-product SaaS environments.
Nice to have
Preferred experience with public sector or regulated industry frameworks such as FedRAMP, StateRAMP, and CMMC.
A background in Travel and Expense, fintech, or multi-product SaaS environments that have undergone rigorous third-party security assessments.
Practical notes
This role is based in Dallas, TX, and requires in-office presence for day-to-day execution.
Full-time engagement with standard business hours applies.
Visa sponsorship considerations may apply based on individual eligibility and role requirements.
Candidates must meet the stated experience and framework knowledge requirements as hard eligibility criteria.