Skip to main content
Mozilla Corporation

Staff Security GRC Engineer

RemoteUnited Kingdom only
Published
Role
Security
Experience
Staff
Company size
Enterprise
£81k–£108k/yr
Check eligibility

Open to GB only. Set where you work from to check your eligibility.

No BS summary

Staff-level Security GRC engineer with 5+ years' experience. Hands-on ownership of ISMS, ISO 27001 and SOC 2 Type 2 audit readiness, policy design, and remediation tracking. Must be UK-based (Remote UK) and able to partner with engineering, legal, privacy and product teams.

Core skills

ISO 27001SOC 2 Type 2ISMS

Required skills

audit readinesspolicy developmentrisk treatment and remediation trackinginternal audit support

Optional skills

CISACISSPISO 27001 Lead Auditor/Implementer

What you'll do

  • Maintain and mature the ISMS, including the Statement of Applicability (SoA), risk treatment plans, and Management Review Meeting (MRM) process and cadence.
  • Support ISO 27001 and SOC 2 Type 2 audit execution: determine scope, prepare evidence and narrative artifacts, participate in auditor interviews and walkthroughs, and resolve auditor findings.
  • Contribute to the SOC 2 System Description and other audit-specific narrative documentation to accurately reflect the control environment.
  • Track gaps and remediation efforts arising from readiness assessments and audits.
  • Lead the policy program: drive policy creation, revision, and cross-functional review cycles to keep security policies current, enforceable, and audit-ready.
  • Support compliance scaling as additional products or business units pursue readiness assessments and certification.
  • Support the internal audit function, partnering with internal or third-party resources to meet ISO 27001 internal audit requirements.
  • Partner closely with Engineering, IT, Legal, Privacy, People teams, and product leadership to gather evidence, drive control ownership, and translate compliance requirements into practical practices.
  • Advise the GRC manager and Security leadership on audit risk, certification readiness, and compliance program strategy.

What they require

  • 5 years of experience in information security, GRC, or compliance-focused roles.
  • Deep familiarity with ISO 27001 and SOC 2 Trust Services Criteria, with meaningful involvement in audits from readiness through certification.
  • Experience operating across an ISMS: SoA maintenance, Management Review Meetings, and System Description authorship.
  • Demonstrated experience writing and revising security policies and running cross-functional review cycles for adoption.
  • Experience tracking gaps and remediation plans and connecting that work to a broader compliance and risk program.
  • Excellent cross-functional collaboration skills with engineers, product managers, legal, and executive stakeholders, and ability to translate compliance requirements into actionable workflows.
  • Ability to ramp up quickly, operate independently, and build processes where none exist.
  • Strong written and verbal communication skills; ability to represent Mozilla in front of external auditors.
  • Relevant industry certifications (e.g., CISA, CISSP, ISO 27001 Lead Auditor/Implementer) are a plus.

Benefits

  • Generous performance-based bonus plans to all eligible employees
  • Rich medical, dental, and vision coverage
  • Generous retirement contributions with 100% immediate vesting (regardless of whether you contribute)
  • Quarterly all-company wellness days
  • Country-specific holidays plus a day off for your birthday
  • One-time home office stipend
  • Annual professional development budget
  • Quarterly well-being stipend
  • Considerable paid parental leave
  • Employee referral bonus program
  • Other benefits (life/AD&D, disability, EAP, etc.—varies by country)

Mozilla Corporation is a non-profit-backed technology company that makes products like Firefox and builds open-source software to make the internet better for people. Ecosystem Services builds and operates back-end platforms powering Mozilla products and services, including privacy, security, notifications, real-time updates, and configuration delivery.

TechnologyEnterprisemozilla.org

What people say about this company

4.1/ 5

  • Employees value the company's commitment to open-source principles and its mission to promote internet privacy.
  • The work-life balance is often highlighted as a significant benefit.
  • Some employees have noted challenges with management and communication within teams.
£81k–£108k/yr