Staff Security GRC Engineer @Mozilla

    14 days ago·Mozilla is hiring a remote Staff Security GRC Engineer·📍 United Kingdom

    Overview

    This role is part of the Governance, Risk & Compliance (GRC) function within Mozilla's Security team. The Security team supports Product, Enterprise, and GRC functions across the organization, aligned with the mission to build a safe and secure internet. This role is responsible for maintaining and advancing Mozilla's Information Security Management System (ISMS) and supporting ISO 27001 and SOC 2 Type 2 compliance programs.

    Key Responsibilities

    • Maintain and mature the ISMS, including the Statement of Applicability (SoA), risk treatment plans, and Management Review Meeting (MRM) process.
    • Support ISO 27001 and SOC 2 Type 2 audit execution, including determining scope, preparing evidence, and participating in auditor interviews.
    • Contribute to audit-specific documentation, ensuring they accurately reflect the organization's control environment.
    • Track gaps and remediation efforts from assessments and audits.
    • Lead the policy program, keeping the security policy set current and audit-ready.
    • Support compliance efforts as additional products pursue readiness assessments and certification.
    • Support the internal audit function to meet ISO 27001's requirements.
    • Partner with various teams to gather evidence and translate compliance requirements into actionable practices.
    • Advise on audit risk, certification readiness, and compliance program strategy.

    Requirements

    • 5 years of experience in information security, GRC, or compliance roles.
    • Familiarity with ISO 27001 and SOC 2 Trust Services Criteria.
    • Experience across the full breadth of an ISMS, including SoA maintenance and draft documentation.
    • Experience writing and revising security policies.
    • Experience tracking gaps and connecting compliance work to risk programs.
    • Excellent collaboration skills with cross-functional teams.
    • Strong written and verbal communication skills.
    • Relevant industry certifications (e.g., CISA, CISSP, ISO 27001 Lead Auditor/Implementer) are a plus.

    Benefits

    • Performance-based bonus plans.
    • Rich medical, dental, and vision coverage.
    • Generous retirement contributions with 100% immediate vesting.
    • Quarterly wellness days.
    • Country-specific holidays and a day off for your birthday.
    • Home office stipend.
    • Annual professional development budget.
    • Quarterly well-being stipend.
    • Paid parental leave.
    • Employee referral bonus program.

    Location

    Remote UK

    How to Apply

    Please submit your application through the provided application link.

    Deadline

    No deadline stated.

    Get jobs in your inbox

    Join over 10,000 subscribers receiving our weekly newsletter.