There's one CISO school of thought that believes the job is to run every automated scanner they can get their hands on, report results to engineering and job is done. That can certainly all be outsourced.
Another school of thought (where I inhabit) is that sure, you need to do that, but to really have a secure product or service it has to be built ground-up with security as a core requirement. You can't outsource that (ok you could but it means having expensive consultants sitting in with the engineering teams day to day, at which point it's far cheaper to have an in-house security team).
And to be painfully honest, it also encourages coverups and lying on reports. As a security engineer at another vendor who has worked with these MSPs and their clients I have seen a lot of things that went sideways and the MSP wants to cover it up and it makes responding to an incident really hard.
If outsourcing credit card processing to Stripe and Paypal is not abdicating your responsibilities, that also isnt.
What were they doing?
I worked on a major product that was known for our security benefits, and we didn't have a team of five on "security." We made sure that everyone understood best practices, and eventually had a "head of security" that oversaw our product and other products as well.
So, what was the security team really doing?
If you're good at your job so there's no issues: "What are you _really_ doing?"
If you're bad at your job so there's tons of issues: "What are you _really_ doing?"