Staff Security Engineer

Mozilla
United States
Workplace: RemoteFull timeFunction: CybersecuritySkills: ["Cross-functional collaboration","Independent execution","Process building","Written communication","Verbal communication"]

Own and mature Mozilla’s Information Security Management System (ISMS) and drive its audit readiness. Lead policy and control program work across Statement of Applicability (SoA), risk treatment plans, and Management Review Meetings. Support ISO 27001 and SOC 2 Type 2 audits by preparing evidence and narratives, resolving findings, and maintaining SOC 2 system description documentation. Coordinate gap tracking and remediation with cross-functional partners across Security, Engineering, IT, Legal, Privacy, and People.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
Mozilla
Mozilla
1 day ago

Staff Security Engineer

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 7 hours agoStatus: Live
Reposted: similar role first listed 10 months ago

Job Summary

Own and mature Mozilla’s Information Security Management System (ISMS) and drive its audit readiness. Lead policy and control program work across Statement of Applicability (SoA), risk treatment plans, and Management Review Meetings. Support ISO 27001 and SOC 2 Type 2 audits by preparing evidence and narratives, resolving findings, and maintaining SOC 2 system description documentation. Coordinate gap tracking and remediation with cross-functional partners across Security, Engineering, IT, Legal, Privacy, and People.
Location: United States
Workplace: Remote
Employment Type: Full time
Job Function: Cybersecurity
Seniority: Mid level

Key Responsibilities

  • •Maintain and mature the ISMS, including Statement of Applicability (SoA), risk treatment plans, and Management Review Meeting cadence.
  • •Support ISO 27001 and SOC 2 Type 2 audit execution by preparing evidence and narrative artifacts, participating in auditor interviews/walkthroughs, and resolving findings.
  • •Contribute to the SOC 2 System Description and other audit-specific narrative documentation to reflect the real control environment.
  • •Track gaps and remediation efforts from readiness assessments and audits, and support compliance scaling as new products/business units pursue certification.
  • •Lead the policy program by driving security policy creation, revision, and cross-functional review cycles to keep policies current, enforceable, and audit-ready.

Pay and Benefits

Perks:Health InsuranceDentalVisionHome OfficeLearning BudgetPaid ParentalAnnual Bonus

Key Requirements

  • •5+ years of experience in information security, GRC, or compliance-focused roles.
  • •Deep familiarity with ISO 27001 and SOC 2 Trust Services Criteria from meaningful audit involvement through certification.
  • •Strong capability across the ISMS lifecycle (SoA maintenance, Management Review Meetings, and System Description authorship).
  • •Experience writing and revising security policies, including running cross-functional review cycles for organization-wide adoption.
  • •Ability to track readiness gaps and remediation plans and connect them to broader compliance and risk programs.
Experience:Information securityGRCComplianceAudit readinessISO 27001SOC 2
Skills:Cross-functional collaborationIndependent executionProcess buildingWritten communicationVerbal communication
Certifications:CISACISSPISO 27001 Lead AuditorISO 27001 Implementer

Company Brief

Mozilla
Mozilla is a mission-driven organization that builds open-source internet products (notably the Firefox browser) and advocates for an open, private, and secure web through software, research, and community programs.
Industry: Enterprise Software
Company Size: Large (251 to 1,000 employees)
Growth: Nonprofit & NGO
Headquarters: San Francisco, United States
Founded: 1998
Glassdoor
Glassdoor: 2.9
WebsiteLinkedInGlassdoor