Staff Security GRC Engineer @Mozilla

    14 days ago·Mozilla is hiring a remote Staff Security GRC Engineer·📍 Canada

    Overview

    This role is part of the Governance, Risk & Compliance (GRC) function within Mozilla's Security team. The Security team supports Product, Enterprise, and GRC functions across the organization, aligned with the mission to build a safe and secure internet.

    Key Responsibilities

    • Maintain and mature the Information Security Management System (ISMS), including the Statement of Applicability (SoA), risk treatment plans, and Management Review Meetings.
    • Support ISO 27001 and SOC 2 Type 2 audit execution, participating in auditor interviews and resolving findings.
    • Contribute to audit-specific documentation, ensuring it reflects the organization's actual control environment.
    • Track gaps and remediation efforts from assessments and audits.
    • Lead the policy program—driving creation, revision, and review cycles to keep security policies current and audit-ready.
    • Support compliance scaling for additional products or business units pursuing assessments and certification.
    • Partner with internal or third-party resources for meeting ISO 27001's internal audit requirements.
    • Collaborate with Engineering, IT, Legal, Privacy, People teams, and product leadership to gather evidence and drive control ownership.
    • Advise the GRC manager and Security leadership on audit risk, certification readiness, and compliance program strategy.

    Requirements

    • 5 years of experience in information security, GRC, or compliance-focused roles.
    • Familiarity with ISO 27001 and SOC 2 Trust Services Criteria, with experience in audits.
    • Experience with ISMS maintenance, Management Review Meetings, and System Description authorship.
    • Skilled in writing and revising security policies, and running cross-functional review cycles.
    • Experience tracking gaps and remediation plans and connecting them to compliance and risk programs.
    • Excellent collaboration skills across various stakeholders, translating compliance requirements into workflows.
    • Strong written and verbal communication skills.
    • Relevant industry certifications (e.g., CISA, CISSP) are a plus.

    Benefits

    • Performance-based bonus plans.
    • Rich medical, dental, and vision coverage.
    • Generous retirement contributions with immediate vesting.
    • Quarterly all-company wellness days.
    • Country-specific holidays plus a day off for your birthday.
    • Home office stipend.
    • Annual professional development budget.
    • Quarterly well-being stipend.
    • Paid parental leave.
    • Employee referral bonus program.
    • Other benefits vary by country.

    Location

    Remote in Canada

    How to Apply

    Apply through Mozilla's career page.

    Get jobs in your inbox

    Join over 10,000 subscribers receiving our weekly newsletter.