Staff Security Engineer

Job not on LinkedIn

🔥 0 minutes ago

Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of Mozilla

Mozilla

501 - 1000 employees

Founded 1998

👥 B2C

🔒 Cybersecurity

B2C • Cybersecurity • Software

Mozilla is a non-profit organization dedicated to promoting an open and accessible internet. They are the makers of the popular Firefox browser, which emphasizes user privacy, speed, and control. Mozilla also offers a range of products that focus on internet security and privacy, including Mozilla VPN, Firefox Relay, and Mozilla Monitor. Additionally, the organization is involved in open-source projects, AI innovation, and advocating for digital rights. Mozilla aims to empower users with trustworthy technology and policies that protect privacy, support open-source AI development, and foster accountability for tech companies.

📋 Description

• Maintain and mature the ISMS, including the Statement of Applicability (SoA), risk treatment plans, and the Management Review Meeting (MRM) process and cadence. • Support ISO 27001 and SOC 2 Type 2 audit execution by helping determine scope, preparing evidence and narrative artifacts, participating in auditor interviews and walkthroughs, and resolving auditor findings. • Contribute to the SOC 2 System Description and other audit-specific narrative documentation. • Track gaps and remediation efforts arising from readiness assessments and audits. • Lead the policy program, including policy creation, revision, and cross-functional review cycles. • Support compliance scaling as additional products or business units pursue readiness assessments and certification. • Support the internal audit function, partnering with internal or third-party resources to meet ISO 27001 internal audit requirements. • Partner with Engineering, IT, Legal, Privacy, People teams, and product leadership to gather evidence, drive control ownership, and translate compliance requirements into practical practices. • Advise the GRC manager and broader Security leadership on audit risk, certification readiness, and compliance program strategy.

🎯 Requirements

• 5 years of experience in information security, GRC, or compliance-focused roles. • Deep familiarity with ISO 27001 and SOC 2 Trust Services Criteria through meaningful involvement in audits from readiness through certification. • Experience across the full breadth of an ISMS, including SoA maintenance, Management Review Meetings, and System Description authorship. • Demonstrated experience writing and revising security policies and running cross-functional review cycles. • Experience tracking gaps and remediation plans and connecting that work to broader compliance and risk programs. • Ability to work with engineers, product managers, legal, and executive stakeholders and translate compliance requirements into actionable workflows. • Ability to ramp up quickly and operate independently. • Comfort building processes where none yet exist. • Strong written and verbal communication skills and ability to represent Mozilla before external auditors. • Relevant industry certifications such as CISA, CISSP, or ISO 27001 Lead Auditor/Implementer are a plus.

🏖️ Benefits

• Generous performance-based bonus plans to all eligible employees—we share in our success as one team. • Rich medical, dental, and vision coverage. • Generous retirement contributions with 100% immediate vesting (regardless of whether you contribute). • Quarterly all-company wellness days where everyone takes a pause together. • Country-specific holidays plus a day off for your birthday. • One-time home office stipend. • Annual professional development budget. • Quarterly well-being stipend. • Considerable paid parental leave. • Employee referral bonus program. • Other benefits (life/AD&D, disability, EAP, etc.—varies by country).

Apply Now

Similar Jobs

🕒 4 days ago

Palo Alto Networks

10,000+ employees

🔒 Cybersecurity

🏢 Enterprise

GTM Director driving IoT/OT cybersecurity revenue across European enterprise markets for Palo Alto Networks. Launching sales plays, building partner motions, and translating technical capabilities into executive business outcomes.

BigQuery

Cyber Security

IoT

SFDC

🕒 August 4

Wiz

201 - 500

🔒 Cybersecurity

Security Engineer securing Wiz’s cloud and AI security products, CI/CD, and production infrastructure. Leading threat modeling, vulnerability management, detection, and response across cloud-native environments.

AWS

Azure

Cloud

Google Cloud Platform

Kubernetes

Python

Terraform

Go

🕒 June 29

Dome Group

11 - 50

💼 Consulting

🛡️ Insurance

🏦 Banking

GRC Security Engineer responsible for managing compliance and risk. Leading ISO 27001 program and third-party security reviews at DataDome.

🗣️🇫🇷 French Required

Cyber Security

🕒 June 24

Morpho

51 - 200

₿ Crypto

🌐 Web 3

Head of Security at Morpho driving security strategy across organization. Leading team and ensuring security for DeFi lending protocol infrastructure and partners.

Cloud

Web3