Staff Security GRC Engineer @Mozilla Corporation

    14 days ago·Mozilla Corporation is hiring a remote Staff Security GRC Engineer·📍 Germany

    Overview

    This role is part of the Governance, Risk & Compliance (GRC) function within Mozilla's Security team. The Security team supports Product, Enterprise, and GRC functions across the organization, aligned with the mission to build a safe and secure internet.

    Key Responsibilities

    • Maintain and mature the Information Security Management System (ISMS), including the Statement of Applicability (SoA), risk treatment plans, and Management Review Meeting (MRM) processes.
    • Support ISO 27001 and SOC 2 Type 2 audit execution—determining scope, preparing evidence, participating in auditor interviews, and resolving auditor findings.
    • Contribute to audit-specific narrative documentation, ensuring accuracy regarding the organization’s control environment.
    • Track gaps and remediation efforts from readiness assessments and audits.
    • Lead the policy program to drive policy creation, revision, and cross-functional review cycles.
    • Support compliance scaling as additional products pursue readiness assessments and certification.
    • Support internal audit functions to meet internal audit requirements.
    • Partner closely with various teams to gather evidence and translate compliance requirements into adoptable practices.
    • Advise Security leadership on audit risk and compliance program strategy.

    Requirements

    • 5 years of experience in information security, GRC, or compliance roles.
    • Familiarity with ISO 27001 and SOC 2 Trust Services Criteria with audit involvement.
    • Comfort operating across various ISMS functions.
    • Experience writing and revising security policies with cross-functional collaboration.
    • Ability to track compliance gaps and remediation plans.
    • Excellent cross-functional collaboration skills.
    • Strong written and verbal communication skills.
    • Relevant industry certifications (e.g., CISA, CISSP, ISO 27001 Lead Auditor) are advantageous.

    Benefits

    • Generous performance-based bonus plans.
    • Rich medical, dental, and vision coverage.
    • Generous retirement contributions with immediate vesting.
    • Quarterly wellness days for all employees.
    • Country-specific holidays plus a day off for your birthday.
    • Home office stipend and annual professional development budget.
    • Paid parental leave and employee referral bonus program.

    Location

    Remote within Germany.

    How to Apply

    Interested candidates should apply via Mozilla's career portal.

    Deadline

    No specific deadline mentioned.

    Get jobs in your inbox

    Join over 10,000 subscribers receiving our weekly newsletter.