Overview
The role involves working as a Staff Security GRC Engineer within Mozilla's Security team, focusing on Governance, Risk & Compliance (GRC). The team supports various functions across the organization in creating a safe and secure internet.
Key Responsibilities
- Maintain and advance Mozilla's Information Security Management System (ISMS).
- Support ISO 27001 and SOC 2 Type 2 audit execution, including scope determination and participant organization.
- Contribute to audit-specific documentation, ensuring they accurately reflect the organization’s control environment.
- Track gaps and remediation from readiness assessments and audits.
- Lead the policy program and manage policy creation and review cycles.
- Support compliance scaling for additional products or business units.
- Support the internal audit function for ISO 27001 compliance.
- Collaborate across teams to gather evidence and implement compliance practices.
- Advise management on audit risk and compliance program strategy.
Requirements
- 5 years of experience in information security, GRC, or compliance roles.
- Familiarity with ISO 27001 and SOC 2 Trust Services Criteria.
- Experience maintaining an ISMS and writing security policies.
- Ability to track compliance gaps and remediation plans.
- Strong collaboration skills and ability to work across teams.
- Excellent written and verbal communication skills.
- Relevant industry certifications (e.g., CISA, CISSP) are a plus.
Benefits
- Performance-based bonus plans.
- Medical, dental, and vision coverage.
- Retirement contributions with immediate vesting.
- Quarterly wellness days.
- Country-specific holidays and a birthday day off.
- Home office stipend.
- Annual professional development budget.
- Generous parental leave.
- Employee referral bonus program.
- Additional benefits may vary by country.
Location
Remote US
How to Apply
To apply, please visit the Mozilla careers page.
Deadline
Not specified.