Security & Trust Engineer
Columbus, NE - USA
Job Summary
AssetWatch serves global manufacturers by powering manufacturing uptime through the delivery of an unparalleled condition monitoring experience with a passion to care about the assets our customers care for every day. We are a devoted and capable team that includes world-renowned engineers and distinguished business leaders united by a common goal To build the future of predictive maintenance. As we enter the next phase of rapid growth we are seeking people to help lead the journey.
About AssetWatch
AssetWatch is a remote-first industrial condition monitoring company that helps manufacturers and industrial operators predict equipment failure before it happens. Our IT & Security team supports a modern cloud-first Microsoft environment and is responsible for protecting company and customer data maintaining our SOC 2 compliance program and giving customers confidence in how we secure their information.
Position Summary
The Security Engineer is a hands-on role responsible for the day-to-day operation of AssetWatchs security program. This person will be a primary technical point of contact establishing trust in customer-facing security conversations own responses to customer security questionnaires and due diligence requests and help drive our SOC 2 Type 2 program forward using tooling like Vanta. The role also supports broader security engineering work across endpoint protection identity vulnerability management and vendor risk.
Key Responsibilities
Customer & Sales Support
- Join customer and prospect calls as the security subject matter expert establishing trust in AssetWatchs security posture architecture and compliance program.
- Address AWS/Web/mobile platform etc
- Own end-to-end responses to customer security questionnaires SIG CAIQ custom formats) and RFP security sections.
- Maintain a library of pre-approved answers evidence and reference architecture diagrams to speed up questionnaire turnaround.
- Owner to support security-related contract reviews and due diligence requests working with Legal Sales and Customer Success.
- Triage and provide an initial response to customer security questionnaires RFP security sections and due diligence requests within two business days coordinating escalations when additional technical or legal review is required.
- Ensure compliance for Customer contractual obligations
Compliance & Risk (SOC 2 / Vanta)
- Serve as a day-to-day control owner within Trust Center Vanta keeping evidence current and remediating failing checks.
- Support the annual SOC 2 Type 2 audit cycle including auditor requests evidence collection and readiness reviews.
- Help extend the compliance program to additional trust service categories (e.g. Availability Confidentiality) as AssetWatchs program matures.
- Maintain and update security policies procedures and control documentation.
- Run and document AssetWatchs vendor security review process SEC040) for new and existing vendors.
- Participate in Risk Assessment and Vendor Reviews across the org
Security Engineering & Operations
- Administer and tune CrowdStrike Falcon EDR including alert triage and response.
- Support identity and access security across Entra ID including Conditional Access MFA and Platform SSO.
- Work with the IT team on Intune-managed security baselines and compliance policies across Windows and macOS.
- Own vulnerability management: scanning prioritization tracking remediation to closure and reporting on trends.
- Support security incident response including investigation containment and post-incident documentation.
- Monitor for and respond to threats such as domain impersonation phishing and credential exposure.
- Administer AssetWatchs security awareness training program (e.g. KnowBe4 including campaign setup and reporting.
Collaboration & Documentation
- Partner closely with the Director of IT on initiatives and tooling.
- Document processes and runbooks in Notion so security operations are repeatable and auditable.
- Track security work in Jira and contribute to sprint or project planning as needed.
- Communicate clearly with non-technical stakeholders translating security concepts into plain language.
Required Qualifications
- 3 years of experience in a security engineering security analyst GRC or IT security role.
- Direct experience responding to customer security questionnaires and supporting customer security calls.
- Hands-on experience with SOC 2; experience with Vanta or a similar GRC/trust platform Drata Secureframe etc.).
- Working knowledge of endpoint protection/EDR tools CrowdStrike or similar).
- Familiarity with identity and access management concepts SSO MFA Conditional Access) in a Microsoft/Entra ID environment.
- Comfortable working independently in a remote fast-moving environment and managing multiple priorities.
- Strong written and verbal communication skills; able to explain security topics to both technical and non-technical audiences.
Preferred Qualifications
- Experience with Microsoft 365 Intune and MDM security baselines.
- Experience with vulnerability management tooling and vendor risk management processes.
- Relevant certification such as Security CySA CISSP or a Vanta/Drata compliance certification.
- Experience with EU compliance programs GDPR ISO 27001
- Experience supporting a SaaS or industrial IoT company through a customer facing security review process.
- Familiarity with Jira Slack and Notion in a security operations context.
What Success Looks Like
- Customer security questionnaires are turned around quickly and accurately with minimal escalation to leadership.
- Vanta stays green: controls are owned evidence is current and audit prep is proactive rather than reactive.
- Vendor reviews are completed on a predictable cadence with clear well documented findings.
- The security program is well documented so knowledge doesnt live in one persons head.
The base salary range for this full-time position is posted below plus equity and benefits. Variable pay bonuses and other cash compensation will be discussed throughout the interview process.
The salary range was determined by role level and location. Individual pay is determined by work location and additional factors including job-related skills experience and relevant education or training. Your recruiter can share more about the specific salary range applicable to your location during the hiring process.
AssetWatch Salary Range (US)
$126000 - $140000 USD
AssetWatch is a remote-first company that puts people at the center of everything we do. We want our team members to thrive - thats why we offer a range of benefits and perks designed to support your well-being growth and work-life balance.
- Competitive compensation package including stock options
- Flexible work schedule
- Comprehensive benefits including retirement plan match
- Opportunity to make a real impact every day
- Work with a dynamic and growing team
- Unlimited PTO
Required Experience:
IC
About Company
From sensors to AI insights to prescriptive action — AssetWatch gives manufacturers a smarter way to protect assets, prevent downtime, and build a reliability program that scales.