The problem is, companies get a tonne of emails like this - usually from crackpots who think that they've found a vulnerability when they haven't.
May I suggest an email which establishes your credentials and gives a bit more details - without necessarily telling a customer service agent the full details.
For example:
> My name is Bob, I'm a security researcher at FooCorp. I've discovered a serious security vulnerability with your XYZ system. It is possible to reset customers' accounts without any authorisation. I've been able to replicate this on test account abc@123. I think this is caused by a misconfigured widget. Please can you forward this message on to your head of security. You can see my previous security work at http://....
Something like that may be more likely to get some positive attention.