Staff Security GRC Engineer
RemoteIn English
About the job
Mozilla is looking for a Staff Security GRC Engineer to maintain and mature its Information Security Management System (ISMS) and support key compliance audits. This remote role involves driving the policy program and helping scale the internal audit function.
What you will do
- Maintain and mature the ISMS, including SoA, risk treatment plans, and MRM process
- Support ISO 27001 and SOC 2 Type 2 audit execution
- Contribute to SOC 2 System Description and audit narratives
- Track gaps and remediation efforts from audits
- Lead the policy program, driving creation and revision
- Support compliance scaling and internal audit function
What you bring
- 5 years in information security, GRC, or compliance
- Deep familiarity with ISO 27001 and SOC 2 Trust Services Criteria
- Experience with ISMS breadth, including SoA and MRM
- Experience writing and revising security policies
- Experience tracking gaps and remediation plans
- Strong collaboration and communication skills
Nice to have
- Relevant certifications (CISA, CISSP, ISO 27001 Lead Auditor/Implementer)
What you get
- Performance-based bonus plans
- Medical, dental, and vision coverage
- Retirement contributions with immediate vesting
- Quarterly wellness days
- Home office stipend
- Professional development budget
About Mozilla
Mozilla is the organization behind Firefox and a champion of internet privacy and open standards.
Summary by Personeel.com. The full job description and the application form are on Mozilla's website (job-boards.greenhouse.io); Apply takes you straight there.
More jobs at Mozilla
- Staff Technical Support Manager, EnterpriseThuiswerken
- Staff RecruiterThuiswerken
- Staff Product Engineer, Enterprise AIThuiswerken
- Staff Operations EngineerThuiswerken
- Staff Designer, Rapid PrototypingThuiswerken