Staff Security Engineer

Mozilla
United States
Workplace: RemoteFull timeFunction: CybersecurityExperience: 5+ yearsSkills: ["Cross-functional collaboration","Independence","Written communication","Verbal communication","Stakeholder management"]

Own and mature Mozilla’s Information Security Management System (ISMS) and GRC processes, including Statement of Applicability maintenance, risk treatment plans, and Management Review Meeting cadence. Drive ISO 27001 and SOC 2 Type 2 audit readiness by supporting audit execution, preparing evidence and audit narratives, and resolving findings. Lead the security policy program and track remediation through readiness assessments, partnering across Engineering, IT, Legal, Privacy, and internal audit.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
Mozilla
Mozilla
1 day ago

Staff Security Engineer

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 7 hours agoStatus: Live
Reposted: similar role first listed 10 months ago

Job Summary

Own and mature Mozilla’s Information Security Management System (ISMS) and GRC processes, including Statement of Applicability maintenance, risk treatment plans, and Management Review Meeting cadence. Drive ISO 27001 and SOC 2 Type 2 audit readiness by supporting audit execution, preparing evidence and audit narratives, and resolving findings. Lead the security policy program and track remediation through readiness assessments, partnering across Engineering, IT, Legal, Privacy, and internal audit.
Location: United States
Workplace: Remote
Employment Type: Full time
Job Function: Cybersecurity
Seniority: Sr. Manager level

Key Responsibilities

  • •Maintain and mature the ISMS, including Statement of Applicability (SoA), risk treatment plans, and Management Review Meeting cadence.
  • •Support ISO 27001 and SOC 2 Type 2 audit execution by scoping, preparing evidence and narratives, participating in walkthroughs/interviews, and resolving findings.
  • •Contribute to SOC 2 System Description and other audit narrative documentation to reflect the actual control environment.
  • •Track readiness assessment and audit gaps, manage remediation efforts, and support compliance scaling for new products/business units.
  • •Lead the security policy program and partner with Engineering, IT, Legal, Privacy, and People to gather evidence and translate compliance requirements into practical practices.

Pay and Benefits

Perks:MedicalDentalVisionRetirementHome OfficeLearning BudgetPaid Parental

Key Requirements

  • •5+ years of experience in information security, GRC, or compliance-focused roles.
  • •Meaningful involvement in ISO 27001 and SOC 2 audits from readiness through certification.
  • •Hands-on familiarity across the ISMS, including SoA maintenance, Management Review Meetings, and System Description documentation.
  • •Experience writing and revising security policies, including running cross-functional review cycles for adoption.
  • •Experience tracking audit gaps and remediation plans, connecting them to broader compliance and risk programs.
Experience:5+ years
Skills:Cross-functional collaborationIndependenceWritten communicationVerbal communicationStakeholder management
Certifications:CISACISSPISO 27001 Lead AuditorISO 27001 Implementer
Languages:English
Tech Stack:ISMSISO 27001SOC 2

Company Brief

Mozilla
Mozilla is a mission-driven organization that builds open-source internet products (notably the Firefox browser) and advocates for an open, private, and secure web through software, research, and community programs.
Industry: Enterprise Software
Company Size: Large (251 to 1,000 employees)
Growth: Nonprofit & NGO
Headquarters: San Francisco, United States
Founded: 1998
Glassdoor
Glassdoor: 2.9
WebsiteLinkedInGlassdoor