Overview
This role is part of the Governance, Risk & Compliance (GRC) function within Mozilla's Security team. The Security team supports Product, Enterprise, and GRC functions across the organization, aligned with the mission to build a safe and secure internet.
Key Responsibilities
- Maintain and mature the Information Security Management System (ISMS), including the Statement of Applicability (SoA), risk treatment plans, and Management Review Meetings.
- Support ISO 27001 and SOC 2 Type 2 audit execution, participating in auditor interviews and resolving findings.
- Contribute to audit-specific documentation, ensuring it reflects the organization's actual control environment.
- Track gaps and remediation efforts from assessments and audits.
- Lead the policy program—driving creation, revision, and review cycles to keep security policies current and audit-ready.
- Support compliance scaling for additional products or business units pursuing assessments and certification.
- Partner with internal or third-party resources for meeting ISO 27001's internal audit requirements.
- Collaborate with Engineering, IT, Legal, Privacy, People teams, and product leadership to gather evidence and drive control ownership.
- Advise the GRC manager and Security leadership on audit risk, certification readiness, and compliance program strategy.
Requirements
- 5 years of experience in information security, GRC, or compliance-focused roles.
- Familiarity with ISO 27001 and SOC 2 Trust Services Criteria, with experience in audits.
- Experience with ISMS maintenance, Management Review Meetings, and System Description authorship.
- Skilled in writing and revising security policies, and running cross-functional review cycles.
- Experience tracking gaps and remediation plans and connecting them to compliance and risk programs.
- Excellent collaboration skills across various stakeholders, translating compliance requirements into workflows.
- Strong written and verbal communication skills.
- Relevant industry certifications (e.g., CISA, CISSP) are a plus.
Benefits
- Performance-based bonus plans.
- Rich medical, dental, and vision coverage.
- Generous retirement contributions with immediate vesting.
- Quarterly all-company wellness days.
- Country-specific holidays plus a day off for your birthday.
- Home office stipend.
- Annual professional development budget.
- Quarterly well-being stipend.
- Paid parental leave.
- Employee referral bonus program.
- Other benefits vary by country.
Location
Remote in Canada
How to Apply
Apply through Mozilla's career page.