
Staff Security Engineer
Posted 2 days ago

Posted 2 days ago
This is a fully remote position, open to applicants in Canada.
• Oversee and enhance Mozilla's Information Security Management System, encompassing the Statement of Applicability, risk treatment strategies, and the Management Review Meeting process.
• Assist in the execution of ISO 27001 and SOC 2 Type 2 audits, which includes scoping, preparing evidence and narratives, conducting auditor interviews, walkthroughs, and resolving findings.
• Contribute to the SOC 2 System Description and other audit-related narrative documentation.
• Monitor gaps and remediation efforts stemming from readiness assessments and audits.
• Lead the development, revision, and cross-departmental review cycles of security policies.
• Facilitate compliance scaling as additional products or business units engage in assessments and certifications.
• Support the internal audit function and the internal audit requirements for ISO 27001.
• Collaborate with Engineering, IT, Legal, Privacy, People teams, and product leadership to collect evidence and promote control ownership.
• Convert compliance requirements into practical and adoptable practices.
• Provide guidance to the GRC manager and Security leadership regarding audit risks, certification readiness, and compliance strategies.
• Minimum of 5 years of experience in information security, GRC, or compliance-oriented roles.
• In-depth knowledge of ISO 27001 and SOC 2 Trust Services Criteria through audits from readiness to certification.
• Experience across the entire spectrum of an ISMS, including maintenance of the SoA, Management Review Meetings, and authorship of the System Description.
• Proven experience in writing and revising security policies and facilitating cross-functional review cycles.
• Experience in tracking gaps and remediation plans within compliance and risk management programs.
• Capability to collaborate with engineers, product managers, legal, and executive stakeholders, translating compliance requirements into actionable workflows.
• Ability to quickly adapt and work independently.
• Comfort in establishing processes where none currently exist.
• Excellent written and verbal communication skills, with the ability to represent Mozilla in discussions with external auditors.
• Relevant certifications such as CISA, CISSP, or ISO 27001 Lead Auditor/Implementer are advantageous.
• Generous performance-based bonus plans for all eligible employees.
• Comprehensive medical, dental, and vision coverage.
• Generous retirement contributions with 100% immediate vesting.
• Quarterly all-company wellness days.
• Country-specific holidays plus an additional day off for your birthday.
• One-time home office stipend.
• Annual professional development budget.
• Quarterly well-being stipend.
• Substantial paid parental leave.
• Employee referral bonus program.
• Additional benefits including life/AD&D, disability, and EAP, varying by country.
OCHIN, Inc.
Dynanet Corporation
Solutions for Information Design, Inc.
Fuze Health
Get handpicked remote jobs straight to your inbox weekly.