Staff Security Engineer
Location: Remote
Compensation: To Be Discussed
Reviewed: Tue, Aug 11, 2026
This job expires in: 28 days
Job Summary
To support the Governance, Risk & Compliance (GRC) function, the full-time Staff Security Engineer will maintain and advance Mozilla's Information Security Management System (ISMS), support ISO 27001 and SOC 2 Type 2 compliance programs, and collaborate with cross-functional teams in a remote work environment.
Key responsibilities
- Maintain and mature the ISMS, including the Statement of Applicability and risk treatment plans
- Support ISO 27001 and SOC 2 Type 2 audit execution by preparing evidence and participating in auditor interviews
- Lead the policy program to ensure security policies are current, enforceable, and audit-ready
Required qualifications
- 5 years of experience in information security, GRC, or compliance-focused roles
- Deep familiarity with ISO 27001 and SOC 2 Trust Services Criteria
- Experience writing and revising security policies with cross-functional review cycles
- Ability to track gaps and remediation plans within a compliance and risk program
- Relevant industry certifications (e.g., CISA, CISSP, ISO 27001 Lead Auditor/Implementer) are a plus
Complete Job Description
The complete job description is available to members. Premium membership includes:
Full access to 48,944 remote jobs from human-vetted companies, updated daily
Resume Builder - AI-powered tool to craft, enhance, and tailor your resume to a specific job
Twice-monthly live group coaching and the full Remote Career Center
20% member discount on Career Services
Backed by a 30-day money-back guarantee