
Staff Security Engineer
Posted 2 days ago

Posted 2 days ago
This is a fully remote position, open to applicants in United States.
• Oversee and enhance the Information Security Management System (ISMS), which includes the Statement of Applicability (SoA), risk treatment plans, and the Management Review Meeting (MRM) process and schedule.
• Assist in the execution of ISO 27001 and SOC 2 Type 2 audits, encompassing scope determination, preparation of evidence and narratives, auditor interviews and walkthroughs, as well as addressing auditor findings.
• Contribute to the SOC 2 System Description and other documentation specific to audits.
• Monitor and address gaps and remediation efforts that emerge from readiness assessments and audits.
• Lead the security policy initiative, which involves policy development, revisions, and cross-functional review cycles.
• Aid in scaling compliance as additional products or business units pursue readiness assessments and certification.
• Support the internal audit function with internal or external resources.
• Collaborate with Engineering, IT, Legal, Privacy, People teams, and product leadership to collect evidence, drive control ownership, and convert compliance requirements into actionable practices.
• Provide guidance to the GRC manager and Security leadership regarding audit risks, certification readiness, and compliance program strategies.
• Minimum of 5 years of experience in information security, governance, risk management, or compliance-oriented roles.
• Strong familiarity with ISO 27001 and SOC 2 Trust Services Criteria, including significant involvement in audits from preparation to certification.
• Experience across the entire scope of an ISMS, including SoA maintenance, Management Review Meetings, and authorship of System Descriptions.
• Proven experience in drafting and revising security policies and managing cross-functional review cycles.
• Experience in tracking gaps and remediation strategies within a larger compliance and risk framework.
• Ability to collaborate effectively with engineers, product managers, legal teams, and executive stakeholders, translating compliance requirements into practical workflows.
• Capability to quickly acclimate and operate autonomously.
• Comfort in establishing processes where none currently exist.
• Excellent written and verbal communication skills, with the ability to represent Mozilla before external auditors.
• Relevant industry certifications such as CISA, CISSP, or ISO 27001 Lead Auditor/Implementer are advantageous.
• Generous performance-based bonus plans available to all eligible employees—we celebrate our success as a unified team.
• Comprehensive medical, dental, and vision insurance.
• Generous retirement contributions with 100% immediate vesting, regardless of personal contributions.
• Quarterly wellness days for the entire company, allowing everyone to pause together.
• Country-specific holidays in addition to a day off for your birthday.
• One-time stipend for home office setup.
• Annual budget dedicated to professional development.
• Quarterly stipend for well-being.
• Significant paid parental leave.
• Employee referral bonus program.
• Additional benefits (life/AD&D, disability, EAP, etc.—varies by country).
OCHIN, Inc.
Dynanet Corporation
Solutions for Information Design, Inc.
Fuze Health
Get handpicked remote jobs straight to your inbox weekly.