Overview
This role is part of the Governance, Risk & Compliance (GRC) function within Mozilla's Security team. The Security team supports Product, Enterprise, and GRC functions across the organization, aligned with the mission to build a safe and secure internet. This role is responsible for maintaining and advancing Mozilla's Information Security Management System (ISMS) and supporting ISO 27001 and SOC 2 Type 2 compliance programs.
Key Responsibilities
- Maintain and mature the ISMS, including the Statement of Applicability (SoA), risk treatment plans, and Management Review Meeting (MRM) process.
- Support ISO 27001 and SOC 2 Type 2 audit execution, including determining scope, preparing evidence, and participating in auditor interviews.
- Contribute to audit-specific documentation, ensuring they accurately reflect the organization's control environment.
- Track gaps and remediation efforts from assessments and audits.
- Lead the policy program, keeping the security policy set current and audit-ready.
- Support compliance efforts as additional products pursue readiness assessments and certification.
- Support the internal audit function to meet ISO 27001's requirements.
- Partner with various teams to gather evidence and translate compliance requirements into actionable practices.
- Advise on audit risk, certification readiness, and compliance program strategy.
Requirements
- 5 years of experience in information security, GRC, or compliance roles.
- Familiarity with ISO 27001 and SOC 2 Trust Services Criteria.
- Experience across the full breadth of an ISMS, including SoA maintenance and draft documentation.
- Experience writing and revising security policies.
- Experience tracking gaps and connecting compliance work to risk programs.
- Excellent collaboration skills with cross-functional teams.
- Strong written and verbal communication skills.
- Relevant industry certifications (e.g., CISA, CISSP, ISO 27001 Lead Auditor/Implementer) are a plus.
Benefits
- Performance-based bonus plans.
- Rich medical, dental, and vision coverage.
- Generous retirement contributions with 100% immediate vesting.
- Quarterly wellness days.
- Country-specific holidays and a day off for your birthday.
- Home office stipend.
- Annual professional development budget.
- Quarterly well-being stipend.
- Paid parental leave.
- Employee referral bonus program.
Location
Remote UK
How to Apply
Please submit your application through the provided application link.
Deadline
No deadline stated.