远程工作雷达

安全与信任工程师

Security & Trust Engineer

开发工程限定地区(需当地身份)与中国几乎无重叠,需长期倒时差
公司AssetWatch
薪资$126,000 - $140,000/年
工作地点United States、Canada
地域资格限定地区(需当地身份)
时区要求与中国几乎无重叠,需长期倒时差
用工类型permanent
发布时间23 天前
数据来源4dayweek.io
前往 4dayweek.io 查看并投递 →
注意地域限制:该职位明确限定在 United States、Canada 招聘。如果你是位于中国大陆的求职者,通常需要当地工作身份才能投递,或需与雇主确认是否接受独立合同(Contractor)形式合作。
作息提示:与中国几乎无重叠,需长期倒时差。

AssetWatch通过提供无与伦比的设备状态监测体验,帮助全球制造商保障生产运行。我们致力于保护客户每天关心的资产。我们是一个专注且有能力的团队,包括世界知名的工程师和杰出的商业领袖,共同致力于打造预测性维护的未来。在进入快速增长的新阶段时,我们正在寻找能够带领这一进程的人才。

**关于AssetWatch**

AssetWatch是一家以远程办公为主的工业设备状态监测公司,帮助制造商和工业运营商在设备故障发生前进行预测。我们的IT与安全团队支持现代化的以微软为主的云环境,负责保护公司和客户数据,维护我们的SOC 2合规项目,并让客户对我们的信息安全措施充满信心。

**职位概述**

安全工程师是一个实践性强的职位,负责AssetWatch安全项目的日常运作。该职位将作为客户安全对话的主要技术联系人,负责处理客户安全问卷和尽职调查请求,并使用Vanta等工具推动我们的SOC 2 Type 2项目。该职位还支持更广泛的安全工程工作,包括端点防护、身份管理、漏洞管理和供应商风险。

**主要职责**

**客户与销售支持**

- 作为安全专家参与客户和潜在客户的电话会议,建立客户对AssetWatch安全态势、架构和合规项目的信任。
- 处理AWS/Web/移动平台等相关问题。
- 负责客户安全问卷(SIG、CAIQ、自定义格式)和RFP安全部分的全流程响应。
- 维护一个预批准的答案库、证据和参考架构图,加快问卷处理速度。
- 负责支持与法律、销售和客户成功团队合作的安全相关合同审查和尽职调查请求。
- 在两个工作日内处理客户安全问卷、RFP安全部分和尽职调查请求,并在需要额外技术或法律审查时协调升级处理。
- 确保客户合同义务的合规性

**合规与风险(SOC 2 / Vanta)**

- 作为Trust Center V中的日常控制负责人

查看英文原文

AssetWatch serves global manufacturers by powering manufacturing uptime through the delivery of an unparalleled condition monitoring experience, with a passion to care about the assets our customers care for every day. We are a devoted and capable team that includes world-renowned engineers and distinguished business leaders united by a common goal – To build the future of predictive maintenance. As we enter the next phase of rapid growth, we are seeking people to help lead the journey.

**About AssetWatch**

AssetWatch is a remote-first industrial condition monitoring company that helps manufacturers and industrial operators predict equipment failure before it happens. Our IT & Security team supports a modern, cloud-first Microsoft environment and is responsible for protecting company and customer data, maintaining our SOC 2 compliance program, and giving customers confidence in how we secure their information.

**Position Summary**

The Security Engineer is a hands-on role responsible for the day-to-day operation of AssetWatch's security program. This person will be a primary technical point of contact establishing trust in customer-facing security conversations, own responses to customer security questionnaires and due diligence requests, and help drive our SOC 2 Type 2 program forward using tooling like Vanta. The role also supports broader security engineering work across endpoint protection, identity, vulnerability management, and vendor risk.

**Key Responsibilities**

**Customer & Sales Support**

- Join customer and prospect calls as the security subject matter expert, establishing trust in AssetWatch's security posture, architecture, and compliance program.
- Address AWS/Web/mobile platform etc
- Own end-to-end responses to customer security questionnaires SIG, CAIQ, custom formats) and RFP security sections.
- Maintain a library of pre-approved answers, evidence, and reference architecture diagrams to speed up questionnaire turnaround.
- Owner to support security-related contract reviews and due diligence requests working with Legal, Sales, and Customer Success.
- Triage and provide an initial response to customer security questionnaires, RFP security sections, and due diligence requests within two business days, coordinating escalations when additional technical or legal review is required.
- Ensure compliance for Customer contractual obligations

**Compliance & Risk (SOC 2 / Vanta)**

- Serve as a day-to-day control owner within Trust Center Vanta, keeping evidence current and remediating failing checks.
- Support the annual SOC 2 Type 2 audit cycle, including auditor requests, evidence collection, and readiness reviews.
- Help extend the compliance program to additional trust service categories (e.g., Availability, Confidentiality) as AssetWatch's program matures.
- Maintain and update security policies, procedures, and control documentation.
- Run and document AssetWatch's vendor security review process SEC040) for new and existing vendors.
- Participate in Risk Assessment and Vendor Reviews across the org

**Security Engineering & Operations**

- Administer and tune CrowdStrike Falcon EDR, including alert triage and response.
- Support identity and access security across Entra ID, including Conditional Access, MFA, and Platform SSO.
- Work with the IT team on Intune-managed security baselines and compliance policies across Windows and macOS.
- Own vulnerability management: scanning, prioritization, tracking remediation to closure, and reporting on trends.
- Support security incident response, including investigation, containment, and post-incident documentation.
- Monitor for and respond to threats such as domain impersonation, phishing, and credential exposure.
- Administer AssetWatch's security awareness training program (e.g., KnowBe4, including campaign setup and reporting.

**Collaboration & Documentation**

- Partner closely with the Director of IT on initiatives and tooling.
- Document processes and runbooks in Notion so security operations are repeatable and auditable.
- Track security work in Jira and contribute to sprint or project planning as needed.
- Communicate clearly with non-technical stakeholders, translating security concepts into plain language.

**Required Qualifications**

- 3+ years of experience in a security engineering, security analyst, GRC, or IT security role.
- Direct experience responding to customer security questionnaires and supporting customer security calls.
- Hands-on experience with SOC 2; experience with Vanta or a similar GRC/trust platform Drata, Secureframe, etc.).
- Working knowledge of endpoint protection/EDR tools CrowdStrike or similar).
- Familiarity with identity and access management concepts SSO, MFA, Conditional Access) in a Microsoft/Entra ID environment.
- Comfortable working independently in a remote, fast-moving environment and managing multiple priorities.
- Strong written and verbal communication skills; able to explain security topics to both technical and non-technical audiences.

**Preferred Qualifications**

- Experience with Microsoft 365, Intune, and MDM security baselines.
- Experience with vulnerability management tooling and vendor risk management processes.
- Relevant certification such as Security+, CySA , CISSP, or a Vanta/Drata compliance certification.
- Experience with EU compliance programs GDPR, ISO 27001
- Experience supporting a SaaS or industrial IoT company through a customer facing security review process.
- Familiarity with Jira, Slack, and Notion in a security operations context.

**What Success Looks Like**

- Customer security questionnaires are turned around quickly and accurately, with minimal escalation to leadership.
- Vanta stays green: controls are owned, evidence is current, and audit prep is proactive rather than reactive.
- Vendor reviews are completed on a predictable cadence with clear, well documented findings.
- The security program is well documented, so knowledge doesn't live in one person's head.

#LI-REMOTE

The base salary range for this full-time position is posted below, plus equity and benefits. Variable pay, bonuses, and other cash compensation will be discussed throughout the interview process.

The salary range was determined by role, level, and location. Individual pay is determined by work location and additional factors, including job-related skills, experience, and relevant education or training. Your recruiter can share more about the specific salary range applicable to your location during the hiring process.

AssetWatch Salary Range (US)

$126,000—$140,000 USD

**What We Offer:**

AssetWatch is a remote-first company that puts people at the center of everything we do. We want our team members to thrive - that’s why we offer a range of benefits and perks designed to support your well-being, growth, and work-life balance.

- Competitive compensation package including stock options
- Flexible work schedule
- Comprehensive benefits including retirement plan match
- Opportunity to make a real impact every day
- Work with a dynamic and growing team
- Unlimited PTO

We have a distributed team that works remotely across locations in the United States and Ontario, Canada. Collaboration within core working hours is required.

本页面信息整理自 4dayweek.io,版权归原发布方所有。职位可能随时关闭,投递请以原始页面为准。 本站只做信息聚合展示,不参与招聘流程,也不向求职者收取任何费用。

该公司其他在招职位

现场与合作伙伴营销经理

AssetWatchUnited Statespermanent今天
市场运营职能支持限定地区(需当地身份)与中国几乎无重叠,需长期倒时差

客户成功总监

AssetWatchUnited States、Canadapermanent今天
AI市场运营限定地区(需当地身份)与中国几乎无重叠,需长期倒时差

高级经理,售后收入运营

AssetWatchUnited States、Canadapermanent昨天
市场运营职能支持限定地区(需当地身份)与中国几乎无重叠,需长期倒时差

全栈工程师

AssetWatchUnited States、Canadapermanent7 天前
开发工程限定地区(需当地身份)与中国几乎无重叠,需长期倒时差

← 返回全部职位