Staff Security Engineer

Job not on LinkedIn

🔥 0 minutes ago

Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of Mozilla

Mozilla

501 - 1000 employees

Founded 1998

👥 B2C

🔒 Cybersecurity

B2C • Cybersecurity • Software

Mozilla is a non-profit organization dedicated to promoting an open and accessible internet. They are the makers of the popular Firefox browser, which emphasizes user privacy, speed, and control. Mozilla also offers a range of products that focus on internet security and privacy, including Mozilla VPN, Firefox Relay, and Mozilla Monitor. Additionally, the organization is involved in open-source projects, AI innovation, and advocating for digital rights. Mozilla aims to empower users with trustworthy technology and policies that protect privacy, support open-source AI development, and foster accountability for tech companies.

📋 Description

• Maintain and mature Mozilla's Information Security Management System, including the Statement of Applicability, risk treatment plans, and Management Review Meeting process • Support ISO 27001 and SOC 2 Type 2 audit execution, including scoping, evidence and narrative preparation, auditor interviews, walkthroughs, and finding resolution • Contribute to SOC 2 System Description and other audit-specific narrative documentation • Track gaps and remediation efforts from readiness assessments and audits • Lead security policy creation, revision, and cross-functional review cycles • Support compliance scaling as additional products or business units pursue assessments and certification • Support the internal audit function and ISO 27001 internal audit requirements • Partner with Engineering, IT, Legal, Privacy, People teams, and product leadership to gather evidence and drive control ownership • Translate compliance requirements into practical, adoptable practices • Advise the GRC manager and Security leadership on audit risk, certification readiness, and compliance strategy

🎯 Requirements

• 5 years of experience in information security, GRC, or compliance-focused roles • Deep familiarity with ISO 27001 and SOC 2 Trust Services Criteria through audits from readiness through certification • Experience across the full breadth of an ISMS, including SoA maintenance, Management Review Meetings, and System Description authorship • Demonstrated experience writing and revising security policies and running cross-functional review cycles • Experience tracking gaps and remediation plans within compliance and risk programs • Ability to work with engineers, product managers, legal, and executive stakeholders and translate compliance requirements into actionable workflows • Ability to ramp up quickly and operate independently • Comfort building processes where none exist • Strong written and verbal communication skills and ability to represent Mozilla before external auditors • Relevant certifications such as CISA, CISSP, or ISO 27001 Lead Auditor/Implementer are a plus

🏖️ Benefits

• Generous performance-based bonus plans for all eligible employees • Rich medical, dental, and vision coverage • Generous retirement contributions with 100% immediate vesting • Quarterly all-company wellness days • Country-specific holidays plus a day off for your birthday • One-time home office stipend • Annual professional development budget • Quarterly well-being stipend • Considerable paid parental leave • Employee referral bonus program • Other benefits including life/AD&D, disability, and EAP, varying by country

Apply Now

Similar Jobs

🕒 4 days ago

Chainguard

51 - 200

🔐 Security

☁️ SaaS

🔒 Cybersecurity

Staff Product Security Engineer securing Chainguard’s hardened open-source software builds. Designing secure CI/CD pipelines and cloud-native controls across Kubernetes, GCP, and AWS.

🕒 4 days ago

Atos

10,000+ employees

💼 Consulting

🏥 Healthcare

📦 Logistics

Cybersecurity advisory director leading secure digital transformation consulting for Atos clients in Canada and North America. Shaping strategy, managing executive engagements, developing consultants, and driving profitable practice growth.

🗣️🇫🇷 French Required

🕒 August 4

Kyndryl

10,000+ employees

💼 Consulting

📦 Logistics

🏥 Healthcare

Mainframe Security Architect designing IBM Z and z/OS security for Kyndryl’s managed-services clients. Leading architecture, integration, operational readiness, and resilient security delivery.

🕒 August 3

LiveKit

11 - 50

🔌 API

🤖 Artificial Intelligence

📡 Telecommunications

🕒 July 28

Forward Financing

201 - 500

💸 Finance

💳 Fintech

🤝 B2B

Staff Security Engineer owning the security technology stack for a fintech company. Leading technical direction and mentoring engineers across security functions.

🇨🇦 Canada – Remote

💵 $160k - $200k / year

💰 $250M Debt Financing on 2021-05

⏰ Full Time

🔴 Lead

👮‍♂️ Cybersecurity / Security Engineer