Staff Security Engineer

Mozilla
United Kingdom
Workplace: RemoteFull timeGBP 81,000 - 108,000 annuallyFunction: CybersecurityExperience: 5+ yearsSkills: ["Cross-functional collaboration","Written communication","Verbal communication","Independence","Process building"]

Own and mature Mozilla’s Information Security Management System (ISMS) and help drive ISO 27001 and SOC 2 Type 2 compliance. Maintain core ISMS artifacts like the Statement of Applicability, risk treatment plans, and Management Review Meetings; support audit execution with evidence, narratives, and auditor interactions. Lead the security policy program, track gaps and remediation, and partner across Engineering, IT, Legal, Privacy, People, and product leadership to make compliance requirements practical and adoptable.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
Mozilla
Mozilla
1 day ago

Staff Security Engineer

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 7 hours agoStatus: Live

Job Summary

Own and mature Mozilla’s Information Security Management System (ISMS) and help drive ISO 27001 and SOC 2 Type 2 compliance. Maintain core ISMS artifacts like the Statement of Applicability, risk treatment plans, and Management Review Meetings; support audit execution with evidence, narratives, and auditor interactions. Lead the security policy program, track gaps and remediation, and partner across Engineering, IT, Legal, Privacy, People, and product leadership to make compliance requirements practical and adoptable.
Location: United Kingdom
Workplace: Remote
Employment Type: Full time
Job Function: Cybersecurity
Seniority: Mid level

Key Responsibilities

  • •Maintain and mature the ISMS, including SoA, risk treatment plans, and Management Review Meeting cadence.
  • •Support ISO 27001 and SOC 2 Type 2 audit execution, including scope, evidence/narratives, auditor interviews/walkthroughs, and findings resolution.
  • •Contribute to the SOC 2 System Description and other audit-specific narrative documentation to accurately reflect the control environment.
  • •Track gaps and remediation efforts arising from readiness assessments and audits.
  • •Lead and drive the security policy program (creation, revision, and cross-functional review cycles) to keep policies current and audit-ready.

Pay and Benefits

Salary: GBP 81,000 - 108,000 annually
Perks:Health InsuranceDentalVisionHome OfficeLearning BudgetWell-being StipendPaid ParentalAnnual Bonus

Key Requirements

  • •5+ years of experience in information security, GRC, or compliance-focused roles.
  • •Deep familiarity with ISO 27001 and SOC 2 Trust Services Criteria through involvement from readiness through certification.
  • •Comfort operating across the full ISMS lifecycle (SoA maintenance, Management Review Meetings, and System Description authorship).
  • •Proven experience writing and revising security policies, including running cross-functional review cycles to drive organization-wide buy-in.
  • •Experience tracking readiness gaps, remediation plans, and connecting them to the broader compliance and risk program.
Experience:5+ yearsGRCInformation securityCompliance
Skills:Cross-functional collaborationWritten communicationVerbal communicationIndependenceProcess building
Certifications:CISACISSPISO 27001 Lead AuditorISO 27001 Implementer
Tech Stack:ISO 27001SOC 2 Type 2SOC 2 Trust Services CriteriaStatement of Applicability (SoA)Management Review Meetings (MRM)System Description

Company Brief

Mozilla
Mozilla is a mission-driven organization that builds open-source internet products (notably the Firefox browser) and advocates for an open, private, and secure web through software, research, and community programs.
Industry: Enterprise Software
Company Size: Large (251 to 1,000 employees)
Growth: Nonprofit & NGO
Headquarters: San Francisco, United States
Founded: 1998
Glassdoor
Glassdoor: 2.9
WebsiteLinkedInGlassdoor