> Markdown version of [/jobs/ext/2425114-security-trust-engineer](https://www.wearedevelopers.com/jobs/ext/2425114-security-trust-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security & Trust Engineer - **Company:** AssetWatch, Inc. - **Location:** United States - **Experience:** Experienced - **Salary:** $126,000.0 - $140,000.0 - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Ad Management, Amazon Web Services, JIRA, Software as a Service, Cyber Security, Identity and Access Management, Phishing, Software Vulnerability Management, Microsoft InTune, CIS Benchmarks - **Published:** August 25, 2026 - **Apply:** https://www.dice.com/job-detail/493ee7e2-a869-40cd-94a5-59095dd47cd0 ## About the Role * 3+ years of experience in a security engineering, security analyst, GRC, or IT security role. * Direct experience responding to customer security questionnaires and supporting customer security calls. * Hands-on experience with SOC 2; experience with Vanta or a similar GRC/trust platform Drata, Secureframe, etc.). * Working knowledge of endpoint protection/EDR tools CrowdStrike or similar). * Familiarity with identity and access management concepts SSO, MFA, Conditional Access) in a Microsoft/Entra ID environment. * Comfortable working independently in a remote, fast-moving environment and managing multiple priorities. * Strong written and verbal communication skills; able to explain security topics to both technical and non-technical audiences. Preferred Qualifications * Experience with Microsoft 365, Intune, and MDM security baselines. * Experience with vulnerability management tooling and vendor risk management processes. * Relevant certification such as Security+, CySA , CISSP, or a Vanta/Drata compliance certification. * Experience with EU compliance programs GDPR, ISO 27001 * Experience supporting a SaaS or industrial IoT company through a customer facing security review process. * Familiarity with Jira, Slack, and Notion in a security operations context. ## Description The Security Engineer is a hands-on role responsible for the day-to-day operation of AssetWatch's security program. This person will be a primary technical point of contact establishing trust in customer-facing security conversations, own responses to customer security questionnaires and due diligence requests, and help drive our SOC 2 Type 2 program forward using tooling like Vanta. The role also supports broader security engineering work across endpoint protection, identity, vulnerability management, and vendor risk., Customer & Sales Support * Join customer and prospect calls as the security subject matter expert, establishing trust in AssetWatch's security posture, architecture, and compliance program. * Address AWS/Web/mobile platform etc * Own end-to-end responses to customer security questionnaires SIG, CAIQ, custom formats) and RFP security sections. * Maintain a library of pre-approved answers, evidence, and reference architecture diagrams to speed up questionnaire turnaround. * Owner to support security-related contract reviews and due diligence requests working with Legal, Sales, and Customer Success. * Triage and provide an initial response to customer security questionnaires, RFP security sections, and due diligence requests within two business days, coordinating escalations when additional technical or legal review is required. * Ensure compliance for Customer contractual obligations Compliance & Risk (SOC 2 / Vanta) * Serve as a day-to-day control owner within Trust Center Vanta, keeping evidence current and remediating failing checks. * Support the annual SOC 2 Type 2 audit cycle, including auditor requests, evidence collection, and readiness reviews. * Help extend the compliance program to additional trust service categories (e.g., Availability, Confidentiality) as AssetWatch's program matures. * Maintain and update security policies, procedures, and control documentation. * Run and document AssetWatch's vendor security review process SEC040) for new and existing vendors. * Participate in Risk Assessment and Vendor Reviews across the org Security Engineering & Operations * Administer and tune CrowdStrike Falcon EDR, including alert triage and response. * Support identity and access security across Entra ID, including Conditional Access, MFA, and Platform SSO. * Work with the IT team on Intune-managed security baselines and compliance policies across Windows and macOS. * Own vulnerability management: scanning, prioritization, tracking remediation to closure, and reporting on trends. * Support security incident response, including investigation, containment, and post-incident documentation. * Monitor for and respond to threats such as domain impersonation, phishing, and credential exposure. * Administer AssetWatch's security awareness training program (e.g., KnowBe4, including campaign setup and reporting. Collaboration & Documentation * Partner closely with the Director of IT on initiatives and tooling. * Document processes and runbooks in Notion so security operations are repeatable and auditable. * Track security work in Jira and contribute to sprint or project planning as needed. * Communicate clearly with non-technical stakeholders, translating security concepts into plain language. ## Related Videos - [Improving quality with Agentic AI with Rovo Dev and Xray](https://www.wearedevelopers.com/videos/2005-improving-quality-with-agentic-ai-with-rovo-dev-and-xray) - [Passkeys: Truly Phishing-Resistant? Implementation and Pitfalls](https://www.wearedevelopers.com/videos/100156-passkeys-truly-phishing-resistant-implementation-and-pitfalls) - [Introduction to Responsible AI: Balancing Value and Risk](https://www.wearedevelopers.com/videos/1972-introduction-to-responsible-ai-balancing-value-and-risk) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Collaboration Quantified: Lessons from Open Source Developer Networks](https://www.wearedevelopers.com/videos/1422-collaboration-quantified-lessons-from-open-source-developer-networks) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Trustworthy AI Starts at Deployment: 5 Checks Before You Ship](https://www.wearedevelopers.com/magazine/753-trustworthy-ai-starts-at-deployment-5-checks-before-you-ship) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents)