Staff Security Engineer

Job not on LinkedIn

🔥 1 minute ago

Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of Mozilla

Mozilla

501 - 1000 employees

Founded 1998

👥 B2C

🔒 Cybersecurity

B2C • Cybersecurity • Software

Mozilla is a non-profit organization dedicated to promoting an open and accessible internet. They are the makers of the popular Firefox browser, which emphasizes user privacy, speed, and control. Mozilla also offers a range of products that focus on internet security and privacy, including Mozilla VPN, Firefox Relay, and Mozilla Monitor. Additionally, the organization is involved in open-source projects, AI innovation, and advocating for digital rights. Mozilla aims to empower users with trustworthy technology and policies that protect privacy, support open-source AI development, and foster accountability for tech companies.

📋 Description

• Maintain and mature the ISMS, including the Statement of Applicability (SoA), risk treatment plans, and the Management Review Meeting (MRM) process and cadence. • Support ISO 27001 and SOC 2 Type 2 audit execution, including scope determination, evidence and narrative preparation, auditor interviews and walkthroughs, and resolution of auditor findings. • Contribute to the SOC 2 System Description and other audit-specific narrative documentation. • Track gaps and remediation efforts from readiness assessments and audits. • Lead the security policy program, including policy creation, revision, and cross-functional review cycles. • Support compliance scaling as additional products or business units pursue readiness assessments and certification. • Support the internal audit function with internal or third-party resources. • Partner with Engineering, IT, Legal, Privacy, People teams, and product leadership to gather evidence, drive control ownership, and translate compliance requirements into practical practices. • Advise the GRC manager and Security leadership on audit risk, certification readiness, and compliance program strategy.

🎯 Requirements

• 5 years of experience in information security, GRC, or compliance-focused roles. • Deep familiarity with ISO 27001 and SOC 2 Trust Services Criteria through audits from readiness through certification. • Experience across the full breadth of an ISMS, including SoA maintenance, Management Review Meetings, and System Description authorship. • Demonstrated experience writing and revising security policies and running cross-functional review cycles. • Experience tracking gaps and remediation plans within a broader compliance and risk program. • Ability to work with engineers, product managers, legal, and executive stakeholders and translate compliance requirements into practical workflows. • Ability to ramp up quickly and operate independently. • Comfort building processes where none yet exist. • Strong written and verbal communication skills and ability to represent Mozilla before external auditors. • Relevant industry certifications such as CISA, CISSP, or ISO 27001 Lead Auditor/Implementer are a plus.

🏖️ Benefits

• Generous performance-based bonus plans to all eligible employees—we share in our success as one team. • Rich medical, dental, and vision coverage. • Generous retirement contributions with 100% immediate vesting (regardless of whether you contribute). • Quarterly all-company wellness days where everyone takes a pause together. • Country-specific holidays plus a day off for your birthday. • One-time home office stipend. • Annual professional development budget. • Quarterly well-being stipend. • Considerable paid parental leave. • Employee referral bonus program. • Other benefits (life/AD&D, disability, EAP, etc.—varies by country).

Apply Now

Similar Jobs

🕒 4 days ago

Orcrist Technologies GmbH

11 - 50

💼 Consulting

🎖️ Defense

📦 Logistics

Director building physical and organizational security for Orcrist’s petabyte-scale B2B data intelligence platform. Managing classified-work protection, sites, personnel security, crisis response, vendors, and regulatory compliance.

🗣️🇩🇪 German Required

🕒 August 4

Wiz

201 - 500

🔒 Cybersecurity

Security Engineer securing Wiz’s cloud and AI security platform, products, CI/CD, and production infrastructure. Leading threat modeling, vulnerability management, cloud hardening, and detection response.

AWS

Azure

Cloud

Google Cloud Platform

Kubernetes

Python

Terraform

Go

🕒 July 28

Staffbase

501 - 1000

👥 HR Tech

☁️ SaaS

🏢 Enterprise

Senior deputy for InfoSec within Staffbase's Finance & Operations department. Driving compliance, audit readiness, and customer trust in a SaaS environment.

🗣️🇩🇪 German Required

🕒 July 15

Mesalvo GmbH

201 - 500

Head of Security developing information security and data protection strategies for healthcare technology company Mesalvo. Leading projects and advising management on secure solutions with a focus on health and care.

🗣️🇩🇪 German Required

Cloud

Cyber Security

🕒 June 12

Cloud Software Group

10,000+ employees

Technical Sales Specialist at Citrix driving product adoption for security solutions in enterprise environments. Collaborating with customers to integrate and optimize security within their existing frameworks.

Citrix

Cloud

DNS

TCP/IP