Перейти к основному содержимому
Mozilla Corporation

Staff Security GRC Engineer

УдалённоUnited States только
Опубликовано
Роль
Безопасность
Опыт
Стафф
Размер компании
Крупная
Зарплата не указана
Проверьте доступность

Доступно для: US only. Укажите, откуда вы работаете, чтобы проверить доступность.

Коротко по делу

Seasoned GRC/security engineer with 5+ years in information security, compliance and governance, deep hands-on ISO 27001 and SOC 2 Type 2 audit experience. Must be comfortable owning ISMS, policy, and audit readiness, working independently across engineer, legal, and executive stakeholders.

Ключевые навыки

ISO 27001SOC 2

Желательные навыки

CISACISSPISO 27001 Lead AuditorISO 27001 Implementer

Чем предстоит заниматься

  • Maintain and mature the ISMS, including the Statement of Applicability (SoA), risk treatment plans, and the Management Review Meeting (MRM) process and cadence.
  • Support ISO 27001 and SOC 2 Type 2 audit execution—helping determine scope, preparing evidence and narrative artifacts, participating in auditor interviews and walkthroughs, and resolving auditor findings.
  • Contribute to the SOC 2 System Description and other audit-specific narrative documentation, ensuring they accurately reflect the organization's actual control environment.
  • Track gaps and remediation efforts arising from readiness assessments and audits.
  • Lead the policy program—driving policy creation, revision, and cross-functional review cycles to keep the security policy set current, enforceable, and audit-ready.
  • Support compliance scaling as additional products or business units pursue, or compliance scaling as additional products or business units pursue, or compliance scaling as additional products or business units pursue, or compliance scaling as additional products or business units pursue, or compliance scaling as additional products or business units pursue readiness assessments and certification.
  • Support the internal audit function, partnering with internal or third-party resources as needed to meet ISO 27001's internal audit requirements.
  • Partner closely with Engineering, IT, Legal, Privacy, People teams, and product leadership to gather evidence, drive control ownership, and own control ownership.
  • Advise the GRC manager and broader Security leadership on audit risk, certification readiness, and compliance program strategy.

Что требуется

  • 5 years of experience in information security, GRC, or compliance-focused roles.
  • Deep familiarity with ISO 27001 and SOC 2 Trust Services Criteria.
  • Comfort operating across the full breadth of an ISMS.
  • Demonstrated experience writing and revising security policies.
  • Experience tracking gaps and remediation plans.
  • Excellent cross-functional collaboration skills.
  • Ability to ramp up quickly and operate with a high degree of independence.
  • Comfort building processes where none exist.
  • Strong written and verbal communication skills.
  • Commitment to our values: Welcoming differences, Being relationship-minded, Practicing responsible participation, Having grit.
  • Preferred: Relevant industry certifications (e.g., CISA, CISSP, ISO 27001 Lead Auditor/Implementer).

Преимущества

  • Generous performance-based bonus plans to all eligible employees.
  • Rich medical, dental, and vision coverage.
  • Generous retirement contributions with 100% immediate vesting.
  • Quarterly all-company wellness days.
  • Country-specific holidays plus a day off for your birthday.
  • One-time home office stipend.
  • Annual professional development budget.
  • Quarterly well-being stipend.
  • Considerable paid parental leave.
  • Employee referral bonus program.
  • Other benefits (life/AD&D, disability, EAP, etc.)—varies by country.

Mozilla Corporation is a non-profit-backed technology company that makes products like Firefox and builds open-source software to make the internet better for people. Ecosystem Services builds and operates back-end platforms powering Mozilla products and services, including privacy, security, notifications, real-time updates, and configuration delivery.

TechnologyКрупнаяmozilla.org

Что говорят о компании

4.1/ 5

  • Employees value the company's commitment to open-source principles and its mission to promote internet privacy.
  • The work-life balance is often highlighted as a significant benefit.
  • Some employees have noted challenges with management and communication within teams.
Зарплата не указана