Staff Security Engineer
Job description
About the role
You will own the end-to-end governance, risk, and compliance lifecycle for Mozilla's Security team, maintaining and maturing the Information Security Management System (ISMS) with a focus on policy, control design, and audit readiness. You will partner with cross-functional stakeholders including Engineering, IT, Legal, Privacy, People teams, and product leadership to translate compliance requirements into practical, adoptable practices across the organization. You will support the execution and evidence preparation for ISO 27001 and SOC 2 Type 2 audits, including scoping, auditor interviews, walkthroughs, and resolving auditor findings. You will contribute directly to the SOC 2 System Description and other audit-specific narrative documentation, ensuring they accurately reflect the organization's actual control environment and risk posture. You will track gaps and remediation efforts arising from readiness assessments and audits, driving closure where required. You will lead the security policy program, owning policy creation, revision, and cross-functional review cycles to keep the policy set current, enforceable, and audit-ready. You will advise the GRC manager and broader Security leadership on audit risk, certification readiness, and compliance program strategy. This role is responsible for maintaining and advancing Mozilla's ISMS and supporting our ISO 27001 and SOC 2 Type 2 compliance programs from policy and control design through audit readiness and certification.
Key facts
What you'll do
- Maintain and mature the ISMS, including the Statement of Applicability (SoA), risk treatment plans, and the Management Review Meeting (MRM) process and cadence.
- Support ISO 27001 and SOC 2 Type 2 audit execution - helping determine scope, preparing evidence and narrative artifacts, participating in auditor interviews and walkthroughs, and resolving auditor findings.
- Contribute to the SOC 2 System Description and other audit-specific narrative documentation, ensuring they accurately reflect the organization's actual control environment.
- Track gaps and remediation efforts arising from readiness assessments and audits.
- Lead the policy program - driving policy creation, revision, and cross-functional review cycles to keep the security policy set current, enforceable, and audit-ready.
- Support compliance scaling as additional products or business units pursue readiness assessments and certification.
- Support the internal audit function, partnering with internal or third-party resources as needed to meet ISO 27001's internal audit requirements.
- Partner closely with Engineering, IT, Legal, Privacy, People teams, and product leadership to gather evidence, drive control ownership, and translate compliance requirements into practical, adoptable practices.
- Advise the GRC manager and broader Security leadership on audit risk, certification readiness, and compliance program strategy.
- Coordinate with stakeholders to establish control objectives and ensure alignment between business initiatives and security requirements.
- Drive continuous improvement across the compliance lifecycle, identifying process gaps and implementing enhancements.
- Represent Mozilla Security in cross-organizational working groups related to risk, audit, and regulatory alignment.
- Maintain awareness of emerging standards, regulatory trends, and industry best practices relevant to information security management.
- Collaborate with product and operations teams to embed security and compliance requirements into delivery workflows.
Requirements
- 5 years of experience in information security, GRC, or compliance-focused roles.
- Deep familiarity with ISO 27001 and SOC 2 Trust Services Criteria, gained through professional work implementing and auditing these frameworks.
- Experience maintaining and maturing an Information Security Management System (ISMS) and supporting related certifications.
- Hands-on experience preparing audit evidence, narratives, and artifacts for external and internal audits.
- Demonstrated ability to work effectively with a wide range of cross-functional stakeholders in a matrixed organization.
- Strong written and verbal communication skills, with the ability to translate technical security concepts into clear, actionable guidance for non-specialists.
- Experience driving policy development, review cycles, and policy adoption across a large, distributed organization.
- Comfort working in a fast-paced, mission-driven environment aligned with open source and public-interest technology.
- Ability to manage multiple priorities and deliverables in a dynamic, deadline-driven environment.
- Willingness to follow Mozilla's policies and processes while helping to evolve them in response to audit, risk, and business needs.
Nice to have
- Experience with additional frameworks such as NIST CSF or privacy-related standards.
- Background in open source or technology product environments.
Practical notes
- This is a remote US role with full-time engagement.
- No additional hours, travel, visa, or application deadline requirements are specified in the source.