Mozilla is a mission-driven technology company dedicated to keeping the internet open and accessible to everyone. As a Staff Security Engineer, you will join our Governance, Risk & Compliance (GRC) team to maintain and advance our Information Security Management System (ISMS) while supporting critical compliance programs.
Key responsibilities
- Maintain and mature the ISMS, including risk treatment plans and the Management Review Meeting process.
- Support ISO 27001 and SOC 2 Type 2 audit execution by preparing evidence, managing artifacts, and resolving findings.
- Lead the policy program by driving creation, revision, and cross-functional review cycles.
- Partner with Engineering, IT, Legal, and Privacy teams to translate compliance requirements into practical, adoptable practices.
- Advise leadership on audit risk, certification readiness, and overall compliance strategy.
Requirements
- 5 years of experience in information security, GRC, or compliance-focused roles.
- Deep familiarity with ISO 27001 and SOC 2 Trust Services Criteria.
- Proven experience in writing security policies and managing cross-functional review cycles.
- Strong ability to build processes where none exist and operate with a high degree of independence.
- Excellent communication skills with the ability to represent Mozilla confidently before external auditors.
What we offer
- Generous performance-based bonus plans and retirement contributions.
- Comprehensive medical, dental, and vision coverage.
- Annual professional development budget and quarterly well-being stipends.
- Flexible time off, including country-specific holidays and a birthday day off.
- One-time home office stipend to support your remote work environment.