
Staff Security Engineer
Posted 2 days ago

Posted 2 days ago
This is a fully remote position, open to applicants in Germany.
• Oversee and enhance the Information Security Management System (ISMS), which includes the Statement of Applicability (SoA), risk treatment strategies, and the Management Review Meeting (MRM) process and schedule.
• Assist in executing ISO 27001 and SOC 2 Type 2 audits, which encompasses defining the scope, preparing evidence and narratives, conducting auditor interviews and walkthroughs, and addressing auditor findings.
• Contribute to the SOC 2 System Description alongside other audit-related narrative documentation.
• Monitor gaps and remediation initiatives stemming from readiness evaluations and audits.
• Lead the security policy initiative, which includes developing, revising, and managing cross-functional review cycles for policies.
• Facilitate compliance scaling as new products or business units work towards readiness evaluations and certifications.
• Assist the internal audit function with resources from internal or third-party entities.
• Collaborate with Engineering, IT, Legal, Privacy, People teams, and product leadership to collect evidence, promote control ownership, and convert compliance requirements into actionable practices.
• Provide guidance to the GRC manager and Security leadership on audit risks, certification preparedness, and compliance program strategies.
• Minimum of 5 years of experience in information security, governance, risk management, or compliance-oriented roles.
• Comprehensive understanding of ISO 27001 and the SOC 2 Trust Services Criteria acquired through audits from readiness to certification.
• Experience encompassing the entire scope of an ISMS, which includes maintaining the SoA, conducting Management Review Meetings, and authoring System Descriptions.
• Proven track record of drafting and revising security policies and managing cross-functional review processes.
• Experience in tracking compliance gaps and remediation strategies within a wider compliance and risk framework.
• Capability to collaborate with engineers, product managers, legal teams, and executive stakeholders to translate compliance mandates into practical workflows.
• Ability to quickly acclimate and function independently.
• Comfort in establishing processes where none currently exist.
• Excellent written and verbal communication skills, with the ability to represent Mozilla before external auditors.
• Relevant industry certifications such as CISA, CISSP, or ISO 27001 Lead Auditor/Implementer are advantageous.
• Generous performance-based bonus plans for all eligible employees, promoting shared success as a unified team.
• Comprehensive medical, dental, and vision insurance coverage.
• Substantial retirement contributions with 100% immediate vesting, regardless of employee contributions.
• Quarterly wellness days for the entire company to collectively take a break.
• Country-specific holidays along with an additional day off for your birthday.
• One-time stipend for setting up a home office.
• Annual budget for professional development.
• Quarterly well-being stipend.
• Ample paid parental leave.
• Employee referral bonus program.
• Additional benefits (life/AD&D, disability, EAP, etc., which may vary by country).
OCHIN, Inc.
Dynanet Corporation
Solutions for Information Design, Inc.
Fuze Health
Get handpicked remote jobs straight to your inbox weekly.