Staff Security Engineer

Job not on LinkedIn

🔥 0 minutes ago

Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of Mozilla

Mozilla

501 - 1000 employees

Founded 1998

👥 B2C

🔒 Cybersecurity

B2C • Cybersecurity • Software

Mozilla is a non-profit organization dedicated to promoting an open and accessible internet. They are the makers of the popular Firefox browser, which emphasizes user privacy, speed, and control. Mozilla also offers a range of products that focus on internet security and privacy, including Mozilla VPN, Firefox Relay, and Mozilla Monitor. Additionally, the organization is involved in open-source projects, AI innovation, and advocating for digital rights. Mozilla aims to empower users with trustworthy technology and policies that protect privacy, support open-source AI development, and foster accountability for tech companies.

📋 Description

• Maintain and mature the ISMS, including the Statement of Applicability (SoA), risk treatment plans, and the Management Review Meeting (MRM) process and cadence. • Support ISO 27001 and SOC 2 Type 2 audit execution by determining scope, preparing evidence and narrative artifacts, participating in auditor interviews and walkthroughs, and resolving auditor findings. • Contribute to the SOC 2 System Description and other audit-specific narrative documentation. • Track gaps and remediation efforts arising from readiness assessments and audits. • Lead the policy program, driving policy creation, revision, and cross-functional review cycles. • Support compliance scaling as additional products or business units pursue readiness assessments and certification. • Support the internal audit function, partnering with internal or third-party resources as needed. • Partner with Engineering, IT, Legal, Privacy, People teams, and product leadership to gather evidence, drive control ownership, and translate compliance requirements into practical practices. • Advise the GRC manager and broader Security leadership on audit risk, certification readiness, and compliance program strategy.

🎯 Requirements

• 5 years of experience in information security, GRC, or compliance-focused roles. • Deep familiarity with ISO 27001 and SOC 2 Trust Services Criteria, gained through meaningful involvement in audits from readiness through certification. • Comfort operating across the full breadth of an ISMS, including SoA maintenance, Management Review Meetings, and System Description authorship. • Demonstrated experience writing and revising security policies and running cross-functional review cycles. • Experience tracking gaps and remediation plans and connecting that work to the broader compliance and risk program. • Ability to work with engineers, product managers, legal, and executive stakeholders and translate compliance requirements into practical workflows. • Ability to ramp up quickly and operate independently. • Comfort building processes where none yet exist. • Strong written and verbal communication skills. • Ability to represent Mozilla credibly and confidently in front of external auditors. • Relevant industry certifications such as CISA, CISSP, or ISO 27001 Lead Auditor/Implementer are a plus.

🏖️ Benefits

• Generous performance-based bonus plans to all eligible employees—we share in our success as one team. • Rich medical, dental, and vision coverage. • Generous retirement contributions with 100% immediate vesting (regardless of whether you contribute). • Quarterly all-company wellness days where everyone takes a pause together. • Country-specific holidays plus a day off for your birthday. • One-time home office stipend. • Annual professional development budget. • Quarterly well-being stipend. • Considerable paid parental leave. • Employee referral bonus program. • Other benefits (life/AD&D, disability, EAP, etc.—varies by country).

Apply Now

Similar Jobs

🕒 4 days ago

Chainguard

51 - 200

🔐 Security

☁️ SaaS

🔒 Cybersecurity

Staff Product Security Engineer securing Chainguard’s hardened open-source software and cloud-native product stack. Building CI/CD controls, Kubernetes hardening, supply-chain security, and cloud risk visibility.

🕒 August 4

Wiz

201 - 500

🔒 Cybersecurity

Security Engineer securing Wiz’s cloud and AI security platform, products, CI/CD, and production infrastructure. Leading threat modeling, cloud security automation, vulnerability management, and detection and response operations.

🕒 July 27

LastPass

501 - 1000

🔒 Cybersecurity

☁️ SaaS

🤝 B2B

Principal Cloud Security Engineer at LastPass ensuring security best practices across cloud infrastructure. Partnering with engineering teams to drive secure practices and solutions.

🕒 June 29

Zscaler

5001 - 10000

🔒 Cybersecurity

☁️ SaaS

🏢 Enterprise

Principal AI Security Specialist driving AI technical strategy and ensuring enterprise security. Collaborate with executives and deliver compelling demonstrations of Zscaler's AI security capabilities.

🕒 May 20

Chainalysis Inc.

501 - 1000

🔌 API

💳 Fintech

🔒 Cybersecurity

Staff Security Engineer overseeing product security for Chainalysis' SaaS solutions and leading risk management frameworks. Engaging directly with AI tools and security automation.