Staff Security Engineer

Mozilla

Completely RemoteFull TimeInformation Technology
Posted Today

Job description

Responsibilities

  • Maintain and mature the ISMS, including the Statement of Applicability (SoA) and risk treatment plans
  • Support ISO 27001 and SOC 2 Type 2 audit execution, including evidence preparation and auditor interviews
  • Lead the policy program by driving creation, revision, and cross-functional review cycles

Requirements

  • 5 years of experience in information security, GRC, or compliance-focused roles
  • Deep familiarity with ISO 27001 and SOC 2 Trust Services Criteria
  • Demonstrated experience writing and revising security policies

About the Company

Mozilla is a non-profit-backed technology company dedicated to shaping a better, more private, and open internet through pioneering brands like Firefox.

Skills & tools

ComplianceAuditCybersecurityRisk ManagementISO 27001SOC 2

What the team is looking for

Use this list as a quick fit check before you apply.

  1. 015+ years GRC experience
  2. 02ISO 27001/SOC 2 expertise
  3. 03Security policy authorship
NeverApplyAd

Wake up to a shortlist, not a search results page.

NeverApply scores every new listing against your CV, salary floor and visa. A handful of real matches by morning.

Get your daily matches