
Staff Security Engineer
Posted 2 days ago

Posted 2 days ago
This is a fully remote position, open to applicants in United Kingdom.
• Oversee and enhance the Information Security Management System (ISMS), which includes the Statement of Applicability (SoA), risk treatment plans, and the Management Review Meeting (MRM) process and schedule.
• Assist in the execution of ISO 27001 and SOC 2 Type 2 audits by defining the scope, preparing necessary evidence and narrative documentation, participating in auditor interviews and walkthroughs, and addressing auditor findings.
• Contribute to the SOC 2 System Description and other audit-related narrative documents.
• Monitor gaps and remediation activities that arise from readiness assessments and audits.
• Lead the policy program by facilitating policy development, revisions, and cross-functional review cycles.
• Aid in compliance scaling as new products or business units seek readiness assessments and certification.
• Support the internal audit function by collaborating with internal or external resources as required.
• Collaborate with Engineering, IT, Legal, Privacy, People teams, and product leadership to collect evidence, promote control ownership, and convert compliance requirements into actionable practices.
• Provide guidance to the GRC manager and broader Security leadership regarding audit risk, certification readiness, and compliance program strategy.
• A minimum of 5 years of experience in information security, GRC, or compliance-related roles.
• Extensive knowledge of ISO 27001 and SOC 2 Trust Services Criteria, acquired through substantial participation in audits from readiness to certification.
• Proficient in managing all aspects of an ISMS, including SoA maintenance, Management Review Meetings, and System Description authorship.
• Proven experience in drafting and revising security policies and facilitating cross-functional review cycles.
• Experience in tracking gaps and remediation strategies while linking these efforts to a larger compliance and risk program.
• Capability to collaborate with engineers, product managers, legal teams, and executive stakeholders, translating compliance requirements into practical workflows.
• Ability to quickly adapt and work independently.
• Comfort in establishing processes in areas where none currently exist.
• Excellent written and verbal communication skills.
• Capacity to represent Mozilla confidently and credibly in front of external auditors.
• Relevant industry certifications such as CISA, CISSP, or ISO 27001 Lead Auditor/Implementer are advantageous.
• Generous performance-based bonus plans for all eligible employees—our success is shared collectively as one team.
• Comprehensive medical, dental, and vision coverage.
• Generous retirement contributions with 100% immediate vesting (regardless of your contributions).
• Quarterly all-company wellness days where everyone pauses together.
• Country-specific holidays plus an additional day off for your birthday.
• One-time home office stipend.
• Annual professional development budget.
• Quarterly well-being stipend.
• Substantial paid parental leave.
• Employee referral bonus program.
• Additional benefits (life/AD&D, disability, EAP, etc.—varies by country).
OCHIN, Inc.
Dynanet Corporation
Solutions for Information Design, Inc.
Fuze Health
Get handpicked remote jobs straight to your inbox weekly.