Your job didn't install a certificate on their Exchange server that was signed by a CA that your browser accepts as trusted.
The CA's that Internet Explorer accepts as trusted ("root CA's") out of the box are all third-party companies (Verisign, Thawte, Comodo, and even Microsoft themselves) charge to have this done. So it's not uncommon for people not to do this for smaller installations.
However, your job can use Windows Server "CA Enrollment Services", issue such a certificate for their domain, and give you instructions on how to import it on your laptop.
There's really nothing you, on your end, can do about this, unfortunately.
Also, another thing: The exchange server within your company network (accessible when you are at work) might have a different domain name than when you are outside of the network. So, maybe they did get a certificate but only for their internal LAN domain name. Again, this is something the people who configured the Exchange server would have to handle and there's not a lot you can do from your end.