Skip to main content
Mozilla Corporation

Staff Security GRC Engineer

RemoteUnited States only
Published
Role
Security
Experience
Staff
Company size
Enterprise
Salary not disclosed
Check eligibility

Open to US only. Set where you work from to check your eligibility.

No BS summary

Seasoned GRC/security engineer with 5+ years in information security, compliance and governance, deep hands-on ISO 27001 and SOC 2 Type 2 audit experience. Must be comfortable owning ISMS, policy, and audit readiness, working independently across engineer, legal, and executive stakeholders.

Core skills

ISO 27001SOC 2

Optional skills

CISACISSPISO 27001 Lead AuditorISO 27001 Implementer

What you'll do

  • Maintain and mature the ISMS, including the Statement of Applicability (SoA), risk treatment plans, and the Management Review Meeting (MRM) process and cadence.
  • Support ISO 27001 and SOC 2 Type 2 audit execution—helping determine scope, preparing evidence and narrative artifacts, participating in auditor interviews and walkthroughs, and resolving auditor findings.
  • Contribute to the SOC 2 System Description and other audit-specific narrative documentation, ensuring they accurately reflect the organization's actual control environment.
  • Track gaps and remediation efforts arising from readiness assessments and audits.
  • Lead the policy program—driving policy creation, revision, and cross-functional review cycles to keep the security policy set current, enforceable, and audit-ready.
  • Support compliance scaling as additional products or business units pursue, or compliance scaling as additional products or business units pursue, or compliance scaling as additional products or business units pursue, or compliance scaling as additional products or business units pursue, or compliance scaling as additional products or business units pursue readiness assessments and certification.
  • Support the internal audit function, partnering with internal or third-party resources as needed to meet ISO 27001's internal audit requirements.
  • Partner closely with Engineering, IT, Legal, Privacy, People teams, and product leadership to gather evidence, drive control ownership, and own control ownership.
  • Advise the GRC manager and broader Security leadership on audit risk, certification readiness, and compliance program strategy.

What they require

  • 5 years of experience in information security, GRC, or compliance-focused roles.
  • Deep familiarity with ISO 27001 and SOC 2 Trust Services Criteria.
  • Comfort operating across the full breadth of an ISMS.
  • Demonstrated experience writing and revising security policies.
  • Experience tracking gaps and remediation plans.
  • Excellent cross-functional collaboration skills.
  • Ability to ramp up quickly and operate with a high degree of independence.
  • Comfort building processes where none exist.
  • Strong written and verbal communication skills.
  • Commitment to our values: Welcoming differences, Being relationship-minded, Practicing responsible participation, Having grit.
  • Preferred: Relevant industry certifications (e.g., CISA, CISSP, ISO 27001 Lead Auditor/Implementer).

Benefits

  • Generous performance-based bonus plans to all eligible employees.
  • Rich medical, dental, and vision coverage.
  • Generous retirement contributions with 100% immediate vesting.
  • Quarterly all-company wellness days.
  • Country-specific holidays plus a day off for your birthday.
  • One-time home office stipend.
  • Annual professional development budget.
  • Quarterly well-being stipend.
  • Considerable paid parental leave.
  • Employee referral bonus program.
  • Other benefits (life/AD&D, disability, EAP, etc.)—varies by country.

Mozilla Corporation is a non-profit-backed technology company that makes products like Firefox and builds open-source software to make the internet better for people. Ecosystem Services builds and operates back-end platforms powering Mozilla products and services, including privacy, security, notifications, real-time updates, and configuration delivery.

TechnologyEnterprisemozilla.org

What people say about this company

4.1/ 5

  • Employees value the company's commitment to open-source principles and its mission to promote internet privacy.
  • The work-life balance is often highlighted as a significant benefit.
  • Some employees have noted challenges with management and communication within teams.
Salary not disclosed