Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
JobTailor Logo

See all jobs on JobTailor

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
Mozilla

Staff Security Engineer

Mozilla

Mozilla Staff Security Engineer maintaining ISMS and supporting ISO 27001 and SOC 2 Type 2 compliance programs. Driving audits, policies, remediation, and cross-functional security controls.

Posted 8/11/2026full-timeRemote • 🇬🇧 United KingdomLead💰 £81,000 - £108,000 per yearWebsite

Core Competencies

Role fit
Core Competencies

Use this summary to align your resume positioning with the role.

Demonstrates expertise in maintaining and maturing Information Security Management Systems (ISMS) and executing ISO 27001 and SOC 2 audits. Proficient in policy creation, compliance strategy, and cross-functional collaboration to ensure effective risk management and certification readiness.

Highest-signal resume keywords
ISO 27001SOC 2 Audit ExecutionInformation Security Management System (ISMS)Policy Creation and RevisionGRC Compliance

ATS Keywords

Tailor your resume
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills
Risk Treatment PlansStatement of Applicability (SoA)Management Review Meetings (MRM)Audit Evidence PreparationSecurity Policy WritingGap Tracking and RemediationCompliance Requirements Translation
Soft Skills
Strong Written CommunicationStrong Verbal CommunicationCross-Functional CollaborationIndependent Operation
Certifications & Qualifications
CISACISSPISO 27001 Lead AuditorISO 27001 Implementer
Industry Keywords
GRCComplianceAudit RiskTrust Services CriteriaInternal Audit Function

About the role

Key responsibilities & impact
  • Maintain and mature the ISMS, including the Statement of Applicability (SoA), risk treatment plans, and the Management Review Meeting (MRM) process and cadence.
  • Support ISO 27001 and SOC 2 Type 2 audit execution by determining scope, preparing evidence and narrative artifacts, participating in auditor interviews and walkthroughs, and resolving auditor findings.
  • Contribute to the SOC 2 System Description and other audit-specific narrative documentation.
  • Track gaps and remediation efforts arising from readiness assessments and audits.
  • Lead the policy program, driving policy creation, revision, and cross-functional review cycles.
  • Support compliance scaling as additional products or business units pursue readiness assessments and certification.
  • Support the internal audit function, partnering with internal or third-party resources as needed.
  • Partner with Engineering, IT, Legal, Privacy, People teams, and product leadership to gather evidence, drive control ownership, and translate compliance requirements into practical practices.
  • Advise the GRC manager and broader Security leadership on audit risk, certification readiness, and compliance program strategy.

Requirements

What you’ll need
  • 5 years of experience in information security, GRC, or compliance-focused roles.
  • Deep familiarity with ISO 27001 and SOC 2 Trust Services Criteria, gained through meaningful involvement in audits from readiness through certification.
  • Comfort operating across the full breadth of an ISMS, including SoA maintenance, Management Review Meetings, and System Description authorship.
  • Demonstrated experience writing and revising security policies and running cross-functional review cycles.
  • Experience tracking gaps and remediation plans and connecting that work to the broader compliance and risk program.
  • Ability to work with engineers, product managers, legal, and executive stakeholders and translate compliance requirements into practical workflows.
  • Ability to ramp up quickly and operate independently.
  • Comfort building processes where none yet exist.
  • Strong written and verbal communication skills.
  • Ability to represent Mozilla credibly and confidently in front of external auditors.
  • Relevant industry certifications such as CISA, CISSP, or ISO 27001 Lead Auditor/Implementer are a plus.

Benefits

Comp & perks
  • Generous performance-based bonus plans to all eligible employees—we share in our success as one team.
  • Rich medical, dental, and vision coverage.
  • Generous retirement contributions with 100% immediate vesting (regardless of whether you contribute).
  • Quarterly all-company wellness days where everyone takes a pause together.
  • Country-specific holidays plus a day off for your birthday.
  • One-time home office stipend.
  • Annual professional development budget.
  • Quarterly well-being stipend.
  • Considerable paid parental leave.
  • Employee referral bonus program.
  • Other benefits (life/AD&D, disability, EAP, etc.—varies by country).