
Staff Security Engineer
Posted 2 days ago

Posted 2 days ago
This is a fully remote position, open to applicants in France.
• Oversee and enhance the Information Security Management System (ISMS), including the Statement of Applicability (SoA), risk treatment strategies, and the Management Review Meeting (MRM) process and schedule.
• Assist in the execution of ISO 27001 and SOC 2 Type 2 audits by defining scope, preparing evidence and narrative documentation, participating in auditor interviews and walkthroughs, and addressing auditor findings.
• Contribute to the SOC 2 System Description and other audit-related narrative documents.
• Monitor gaps and remediation actions arising from readiness evaluations and audits.
• Direct the policy program, which encompasses policy formulation, updates, and cross-functional review cycles.
• Facilitate compliance scaling as new products or business units pursue readiness evaluations and certifications.
• Support the internal audit function by collaborating with internal or third-party resources to fulfill ISO 27001 internal audit requirements.
• Collaborate with Engineering, IT, Legal, Privacy, Human Resources, and product leadership to collect evidence, drive control ownership, and convert compliance requirements into practical implementations.
• Provide guidance to the Governance, Risk, and Compliance (GRC) manager and the wider Security leadership on audit risks, certification preparedness, and compliance program strategies.
• A minimum of 5 years of experience in information security, governance risk compliance (GRC), or similar compliance-oriented roles.
• Extensive knowledge of ISO 27001 and SOC 2 Trust Services Criteria through active participation in audits from preparation to certification.
• Experience encompassing all aspects of an ISMS, including SoA maintenance, Management Review Meetings, and authorship of System Descriptions.
• Proven track record in drafting and amending security policies and conducting cross-functional review cycles.
• Experience in identifying gaps and remediation plans, linking this work to broader compliance and risk initiatives.
• Capability to collaborate with engineers, product managers, legal teams, and executive stakeholders, translating compliance requirements into actionable workflows.
• Ability to quickly adapt and work autonomously.
• Comfort in establishing processes where none currently exist.
• Excellent written and verbal communication skills, with the ability to represent Mozilla before external auditors.
• Relevant industry certifications such as CISA, CISSP, or ISO 27001 Lead Auditor/Implementer are advantageous.
• Generous performance-based bonus plans available to all eligible employees—we celebrate our success as one united team.
• Comprehensive medical, dental, and vision insurance coverage.
• Significant retirement contributions with 100% immediate vesting (regardless of your contributions).
• Quarterly wellness days for all employees to take a collective break.
• Country-specific holidays plus an additional day off for your birthday.
• One-time stipend for home office setup.
• Annual budget for professional development.
• Quarterly well-being stipend.
• Generous paid parental leave.
• Employee referral bonus program.
• Additional benefits (life/AD&D, disability, EAP, etc.—varies by country).
OCHIN, Inc.
Dynanet Corporation
Solutions for Information Design, Inc.
Fuze Health
Get handpicked remote jobs straight to your inbox weekly.