Security & Trust Engineer
Assetwatch · Remote
About this role
**Security & Trust Engineer — AssetWatch** AssetWatch is a remote-first industrial condition monitoring company helping manufacturers and industrial operators predict equipment failure before it happens. Our IT & Security team supports a modern, cloud-first Microsoft environment, protects company and customer data, maintains our SOC 2 compliance program, and helps customers feel confident in how we secure their information. --- ## Position Summary This is a hands-on role responsible for the day-to-day operation of AssetWatch’s security program. You’ll be a primary technical point of contact for customer-facing security conversations, own responses to customer security questionnaires and due diligence requests, and help drive our SOC 2 Type 2 program forward using tooling like Vanta. You’ll also support broader security engineering work across endpoint protection, identity, vulnerability management, and vendor risk. --- ## Key Responsibilities ### Customer & Sales Support - Join customer and prospect calls as the security subject matter expert to establish trust in AssetWatch’s security posture, architecture, and compliance program. - Address security topics across AWS/web/mobile platforms (as applicable). - Own end-to-end responses to customer security questionnaires (SIG, CAIQ, and custom formats) and RFP security sections. - Maintain a library of pre-approved answers, evidence, and reference architecture diagrams to speed up questionnaire turnaround. - Support security-related contract reviews and due diligence requests with Legal, Sales, and Customer Success. - Triage and provide an initial response to questionnaires/RFP security sections/due diligence requests within **two business days**, escalating when additional technical or legal review is required. - Ensure compliance for customer contractual obligations. ### Compliance & Risk (SOC 2 / Vanta) - Serve as a day-to-day control owner within Trust Center Vanta: keep evidence current and remediate failing checks. - Support the annual SOC 2 Type 2 audit cycle (auditor requests, evidence collection, readiness reviews). - Help extend the compliance program to additional trust service categories (e.g., Availability, Confidentiality) as it matures. - Maintain and update security policies, procedures, and control documentation. - Run and document AssetWatch’s vendor security review process (SEC040) for new and existing vendors. - Participate in risk assessments and vendor reviews across the organization. ### Security Engineering & Operations - Administer and tune **CrowdStrike Falcon EDR**, including alert triage and response. - Support identity and access security across **Entra ID** (Conditional Access, MFA, Platform SSO). - Work with IT on **Intune-managed** security baselines and compliance policies across Windows and macOS. - Own vulnerability management: scanning, prioritization, tracking remediation to closure, and reporting trends. - Support security incident response: investigation, containment, and post-incident documentation. - Monitor for and respond to threats such as domain impersonation, phishing, and credential exposure. - Administer the security awareness training program (e.g., KnowBe4), including campaign setup and reporting. ### Collaboration & Documentation - Partner closely with the Director of IT on initiatives and tooling. - Document processes and runbooks in Notion so security operations are repeatable and auditable. - Track security work in Jira and contr
Listing freshness
CronJobs last confirmed this listing 1d ago. If its source stops confirming the opening for seven days, this page is removed from active inventory.