M

Staff Security Engineer

Mozilla

Remote · Full Time

Be the first to apply

Experience
5+ yrs
Salary
GBP 81,000 – GBP 108,000 / year
Openings
1
Posted
4 ਘੰਟੇ ਪਹਿਲਾਂ
Work mode
Work from home
Resume
Required to apply

Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.

Job description

About Mozilla

Mozilla Corporation is a nonprofit-backed technology organization that has influenced the internet positively for over 25 years by developing pioneering products like Firefox, a privacy-focused web browser. Serving over 225 million users each month, Mozilla is advancing technologies in AI, social media, security, and more, all while staying committed to its mission of creating an internet built for people, not corporations. Mozilla Corporation is fully owned by the nonprofit Mozilla Foundation, operating without shareholder pressures, and supported by thousands of global contributors who build open-source software to empower internet users.

Team and Role Overview

This position is within the Governance, Risk & Compliance (GRC) division of Mozilla's Security team, which supports Product, Enterprise, and GRC functions focused on ensuring a safe and secure internet experience. The Staff Security Engineer will be responsible for maintaining and enhancing Mozilla's Information Security Management System (ISMS) and supporting compliance programs like ISO 27001 and SOC 2 Type 2, covering policy development, control implementation, audit preparation, and certification.

Key Responsibilities

  • Enhance and sustain the ISMS, including management of the Statement of Applicability (SoA), risk treatment planning, and managing Management Review Meetings (MRM) processes and schedules.
  • Support execution of ISO 27001 and SOC 2 Type 2 audits by defining scope, preparing required materials and narratives, assisting in auditor interactions, and addressing audit findings.
  • Draft and maintain SOC 2 System Descriptions and other audit documentation to accurately represent Mozilla's control environment.
  • Monitor and follow up on audit and readiness assessment findings through gap analysis and remediation tracking.
  • Lead the security policy lifecycle to develop, revise, and facilitate cross-team reviews ensuring policies remain current, enforceable, and audit-ready.
  • Assist with scaling compliance efforts to new products or business units undergoing readiness assessments or certifications.
  • Support internal audit processes, collaborating with internal and external auditors to fulfill ISO 27001 internal audit obligations.
  • Collaborate closely with Engineering, IT, Legal, Privacy, People, and product leadership to gather necessary evidence, manage control ownership, and interpret compliance requirements into actionable procedures.
  • Provide guidance to GRC management and Security leadership on audit risk, certification readiness, and overall compliance strategy.

Qualifications and Experience

  • At least five years of experience in information security, governance, risk management, or compliance roles.
  • In-depth knowledge of ISO 27001 and SOC 2 Trust Services Criteria with extensive participation in audits from preparation to certification.
  • Proven ability to manage all facets of an ISMS including SoA upkeep, Management Review Meetings, and authoring System Descriptions.
  • Experience developing and updating security policies, conducting cross-functional reviews to secure organization-wide consensus and compliance.
  • Skilled in tracking audit findings and remediation efforts and integrating these into broader compliance and risk frameworks.
  • Strong partnership skills working with engineers, product managers, legal, and executives to translate compliance into practical workflows.
  • Comfortable building or improving compliance processes where lacking and capable of working independently with minimal supervision.
  • Excellent communication abilities for representing the organization confidently to external auditors and stakeholders.
  • Industry certifications such as CISA, CISSP, or ISO 27001 Lead Auditor/Implementer are advantageous.

Values and Culture

  • Commitment to inclusivity and respecting differences.
  • Emphasis on relationship-building and collaboration.
  • Engagement through responsible and meaningful participation.
  • Resilience and perseverance (grit) in work challenges.

Benefits

  • Performance-based bonus schemes accessible to eligible employees, sharing success collectively.
  • Comprehensive medical, dental, and vision insurance.
  • Generous retirement plan contributions fully vested immediately regardless of employee contributions.
  • Quarterly company-wide wellness days encouraging collective rest.
  • Official holidays including an additional day off for your birthday.
  • One-time stipend to support home office setup.
  • Annual budget allocated for professional development.
  • Quarterly stipend dedicated to well-being.
  • Substantial paid parental leave policy.
  • Employee referral incentive program.
  • Varied additional benefits including life, AD&D, disability insurance, and employee assistance programs depending on the country.

Diversity, Equity, and Inclusion

Mozilla recognizes the importance of diverse perspectives and creative practices to enrich its mission and actively welcomes applications from all individuals, including women, racialized and Indigenous people, persons with disabilities, and those across all sexual orientations and gender identities. Reasonable accommodations are provided for qualified applicants with disabilities throughout the recruitment process upon request. Mozilla is an equal opportunity employer committed to fair treatment regardless of race, religion, gender, sexual orientation, age, disability, or other legally protected factors.

Level

Mid

How they work

Communication Teamwork & Collaboration Adaptability Independence

Leave it if you'd like a reply — we won't use it for anything else.

Click to browse, drag & drop, or paste a screenshot

PNG, JPG, GIF, MP4, WebM, MOV · Max 20MB each · Up to 5 files

🤖
Online · instant AI help