Staff Security Engineer
MozillaNorth AmericaFull TimeEngineering
Remotely
Listed on 3 job boards, which is a stronger signal than one board alone.
auditgrcpolicyismsiso 27001soc 2soamanagement review
Also available on
Job Description
📋 Description
- Role within Mozilla's Security team, part of Governance, Risk & Compliance (GRC).
- Maintain and advance Mozilla’s ISMS; support ISO 27001 and SOC 2 Type 2 programs from policy design
- Collaborate with cross-functional teams to translate compliance requirements into practical
🎯 Requirements
- 5+ years in information security, GRC, or compliance roles.
- Deep familiarity with ISO 27001 and SOC 2 criteria; audit experience from readiness to
- Experience maintaining SoA, Management Review Meetings, and System Description authorship.
- Strong policy writing and cross-functional review skills; able to drive adoption across teams.
- Excellent collaboration, written and verbal communication; comfortable with auditors.
🎁 Benefits
- Competitive bonus plans and comprehensive health coverage.
- Generous retirement contributions; wellness and work-life benefits.
- Parental leave, home office stipend, and professional development budget.
- Employee referral program and country-specific benefits.
Back to all jobs