Skip to main content
Mozilla Corporation

Staff Security GRC Engineer

RemoteFrance only
Published
Role
Security
Experience
Staff
€65k–€87k/yr
Check eligibility

Open to FR only. Set where you work from to check your eligibility.

No BS summary

Staff-level security GRC engineer with ~5+ years in information security/GRC focused on ISO 27001 and SOC 2 compliance. Hands-on ISMS ownership (SoA, risk treatment, MRM), audit readiness and evidence collection. Remote role limited to France.

Core skills

ISO 27001SOC 2ISMS

Required skills

Information Security Management System (ISMS)Statement of Applicability (SoA)SOC 2 System Descriptionrisk treatment / remediation trackingaudit readiness and evidence preparationsecurity policy writing and governanceinternal audit

Optional skills

CISACISSPISO 27001 Lead Auditor/Implementer

What you'll do

  • Maintain and mature the ISMS, including the Statement of Applicability (SoA), risk treatment plans, and the Management Review Meeting (MRM) process and cadence.
  • Support ISO 27001 and SOC 2 Type 2 audit execution—helping determine scope, preparing evidence and narrative artifacts, participating in auditor interviews and walkthroughs, and resolving auditor findings.
  • Contribute to the SOC 2 System Description and other audit-specific narrative documentation, ensuring they accurately reflect the organization's actual control environment.
  • Track gaps and remediation efforts arising from readiness assessments and audits.
  • Lead the policy program—driving policy creation, revision, and cross-functional review cycles to keep the security policy set current, enforceable, and audit-ready.
  • Support compliance scaling as additional products or business units pursue readiness assessments and certification.
  • Support the internal audit function, partnering with internal or third-party resources as needed to meet ISO 27001's internal audit requirements.
  • Partner closely with Engineering, IT, Legal, Privacy, People teams, and product leadership to gather evidence, drive control ownership, and translate compliance requirements into practical, adoptable practices.
  • Advise the GRC manager and broader Security leadership on audit risk, certification readiness, and compliance program strategy.

What they require

  • 5 years of experience in information security, GRC, or compliance-focused roles.
  • Deep familiarity with ISO 27001 and SOC 2 Trust Services Criteria, gained through meaningful involvement in audits from readiness through certification.
  • Comfort operating across the full breadth of an ISMS—SoA maintenance, Management Review Meetings, and System Description authorship.
  • Demonstrated experience writing and revising security policies, including running cross-functional review cycles to gain organization-wide buy-in and adoption.
  • Experience tracking gaps and remediation plans and connecting that work to an organization's broader compliance and risk program.
  • Excellent cross-functional collaboration skills—comfortable working with engineers, product managers, legal, and executive stakeholders, and able to translate compliance requirements into practical, actionable workflows.
  • Ability to ramp up quickly and operate with a high degree of independence.
  • Comfort building processes where none yet exist.
  • Strong written and verbal communication skills; ability to represent Mozilla credibly and confidently in front of external auditors.
  • Preferred: Relevant industry certifications (e.g., CISA, CISSP, ISO 27001 Lead Auditor/Implementer) are a plus.

Benefits

  • Generous performance-based bonus plans to all eligible employees
  • Rich medical, dental, and vision coverage
  • Generous retirement contributions with 100% immediate vesting (regardless of whether you contribute)
  • Quarterly all-company wellness days
  • Country-specific holidays plus a day off for your birthday
  • One-time home office stipend
  • Annual professional development budget
  • Quarterly well-being stipend
  • Considerable paid parental leave
  • Employee referral bonus program
  • Other benefits (life/AD&D, disability, EAP, etc.—varies by country)

Mozilla Corporation is a non-profit-backed technology company that makes products like Firefox and builds open-source software to make the internet better for people. Ecosystem Services builds and operates back-end platforms powering Mozilla products and services, including privacy, security, notifications, real-time updates, and configuration delivery.

TechnologyEnterprisemozilla.org

What people say about this company

4.1/ 5

  • Employees value the company's commitment to open-source principles and its mission to promote internet privacy.
  • The work-life balance is often highlighted as a significant benefit.
  • Some employees have noted challenges with management and communication within teams.
€65k–€87k/yr