Staff Security Engineer
Location: Remote
Compensation: To Be Discussed
Reviewed: Tue, Aug 11, 2026
This job expires in: 28 days
Job Summary
To support Mozilla's Governance, Risk & Compliance (GRC) function, the full-time Staff Security Engineer will maintain and advance the Information Security Management System (ISMS), support ISO 27001 and SOC 2 Type 2 compliance programs, and collaborate with cross-functional teams in a remote environment.
Key responsibilities
- Maintain and mature the ISMS, including risk treatment plans and Management Review Meeting processes
- Support audit execution for ISO 27001 and SOC 2 Type 2, including evidence preparation and auditor interactions
- Lead the policy program, ensuring security policies are current, enforceable, and audit-ready
Required qualifications
- 5 years of experience in information security, GRC, or compliance-focused roles
- Deep familiarity with ISO 27001 and SOC 2 Trust Services Criteria
- Experience writing and revising security policies with cross-functional collaboration
- Proven ability to track compliance gaps and remediation efforts
- Relevant industry certifications (e.g., CISA, CISSP, ISO 27001 Lead Auditor/Implementer) are a plus
Complete Job Description
The complete job description is available to members. Premium membership includes:
Full access to 48,944 remote jobs from human-vetted companies, updated daily
Resume Builder - AI-powered tool to craft, enhance, and tailor your resume to a specific job
Twice-monthly live group coaching and the full Remote Career Center
20% member discount on Career Services
Backed by a 30-day money-back guarantee