Remotery

Staff Security Engineer

Posted 2 days ago

This is a fully remote position, open to applicants in United States.

📋 Description

• Oversee and enhance the Information Security Management System (ISMS), which includes the Statement of Applicability (SoA), risk treatment strategies, and the Management Review Meeting (MRM) process and schedule.

• Assist in the execution of ISO 27001 and SOC 2 Type 2 audits, including defining the scope, preparing evidence and narratives, conducting auditor interviews and walkthroughs, and addressing auditor findings.

• Contribute to the SOC 2 System Description and other documentation specific to audits.

• Monitor gaps and remediation actions that arise from readiness evaluations and audits.

• Direct the security policy program, which encompasses policy development, updates, and cross-functional review cycles.

• Aid in scaling compliance efforts as new products or business units seek readiness evaluations and certifications.

• Support the internal audit process and collaborate with internal or external resources to fulfill ISO 27001 internal audit requirements.

• Collaborate with Engineering, IT, Legal, Privacy, People teams, and product leadership to collect evidence, promote control ownership, and convert compliance requirements into practical actions.

• Provide guidance to the GRC manager and Security leadership on audit risks, certification readiness, and the strategy for the compliance program.


⛳️ Requirements

• A minimum of 5 years of experience in information security, Governance, Risk, and Compliance (GRC), or roles focused on compliance.

• Extensive knowledge of ISO 27001 and SOC 2 Trust Services Criteria gained through audits from readiness to certification.

• Experience covering the entire spectrum of an ISMS, including maintenance of the SoA, Management Review Meetings, and authorship of System Descriptions.

• Proven ability to draft and update security policies and facilitate cross-functional review cycles.

• Experience in identifying gaps and tracking remediation plans within compliance and risk initiatives.

• Capacity to collaborate with engineers, product managers, legal teams, and executive stakeholders to translate compliance requirements into practical workflows.

• Quick learning ability and capability to work independently.

• Comfort in establishing processes where they are currently lacking.

• Excellent written and verbal communication skills, with the ability to represent Mozilla to external auditors.

• Relevant industry certifications such as CISA, CISSP, or ISO 27001 Lead Auditor/Implementer are advantageous.


🏝️ Benefits

• Competitive performance-based bonus plans available to all eligible employees.

• Comprehensive medical, dental, and vision insurance coverage.

• Generous retirement contributions with immediate 100% vesting (regardless of personal contributions).

• Quarterly wellness days for the entire company to take a collective pause.

• Country-specific holidays along with an additional day off for your birthday.

• One-time stipend for home office setup.

• Annual budget for professional development.

• Quarterly well-being stipend.

• Significant paid parental leave.

• Employee referral bonus program.

• Additional benefits (life/AD&D, disability, EAP, etc.—varies by location).

People also viewed

OCHIN, Inc.8 hours ago

Security Application Analyst

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer$85.7k – $137.1k/year
ApplyView job
Dynanet Corporation8 hours ago

AI Security Engineer

US flagMaryland OnlyFull-timeCybersecurity / Security Engineer
ApplyView job
Solutions for Information Design, Inc.8 hours ago

Infrastructure & Security Engineer

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer$110k – $130k/year
ApplyView job
Fuze Health9 hours ago

Senior Security Engineer

US flagArizona, +4 more statesFull-timeCybersecurity / Security Engineer$156.8k – $196k/year
ApplyView job
LG Energy Solution Vertech, Inc.9 hours ago

Cybersecurity Specialist III

US flagMassachusetts OnlyFull-timeCybersecurity / Security Engineer$98k – $110k/year
ApplyView job
Coupa Software16 hours ago

Senior Security Engineer – Red Team

IN flagIndia OnlyFull-timeCybersecurity / Security Engineer
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers