Can you clarify who "our security team" is?
I work for a large Fortune 150, one that you've heard of, and we have a security team that is constantly scanning our network for weaknesses and potential exploit vectors. They will kill (firewall off) any sites that might compromise the network and tell the application owner to fix the issue before they allow it back on the public net.
> I work at a large Fortune 150 [...] we have [an] internal CA
(This was a lot clearer when there weren't so many other comments in between.)