FREE ACCESS
5,000–10,000 jobs/day
See all jobs on JobTailor
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.

Staff Security Engineer
MozillaStaff Security Engineer advancing Mozilla’s Information Security Management System and ISO 27001/SOC 2 compliance. Supporting audits, policies, remediation, and certification readiness for an open-source technology company.
Core Competencies
Role fitCore Competencies
Use this summary to align your resume positioning with the role.
Expertise in maintaining and maturing Information Security Management Systems (ISMS) with a focus on ISO 27001 and SOC 2 compliance, including policy creation, risk treatment, and audit execution. Proven ability to collaborate with cross-functional teams to translate compliance requirements into actionable practices.
Highest-signal resume keywords
ISO 27001 ComplianceSOC 2 Audit ExecutionInformation Security Management System (ISMS)Security Policy DevelopmentRisk Management
ATS Keywords
Tailor your resumeApplicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills
Information SecurityGRC (Governance, Risk, Compliance)Audit PreparationRisk Treatment PlansManagement Review MeetingsSystem Description AuthorshipGap TrackingRemediation PlanningCompliance StrategyControl Ownership
Soft Skills
Strong Written CommunicationStrong Verbal CommunicationCollaborationIndependenceProcess Building
Certifications & Qualifications
CISACISSPISO 27001 Lead AuditorISO 27001 Implementer
Industry Keywords
SOC 2 Trust Services CriteriaCompliance ScalingInternal AuditAudit RiskCertification Readiness
About the role
Key responsibilities & impact- Maintain and mature Mozilla's Information Security Management System, including the Statement of Applicability, risk treatment plans, and Management Review Meeting process
- Support ISO 27001 and SOC 2 Type 2 audit execution, including scoping, evidence and narrative preparation, auditor interviews, walkthroughs, and finding resolution
- Contribute to SOC 2 System Description and other audit-specific narrative documentation
- Track gaps and remediation efforts from readiness assessments and audits
- Lead security policy creation, revision, and cross-functional review cycles
- Support compliance scaling as additional products or business units pursue assessments and certification
- Support the internal audit function and ISO 27001 internal audit requirements
- Partner with Engineering, IT, Legal, Privacy, People teams, and product leadership to gather evidence and drive control ownership
- Translate compliance requirements into practical, adoptable practices
- Advise the GRC manager and Security leadership on audit risk, certification readiness, and compliance strategy
Requirements
What you’ll need- 5 years of experience in information security, GRC, or compliance-focused roles
- Deep familiarity with ISO 27001 and SOC 2 Trust Services Criteria through audits from readiness through certification
- Experience across the full breadth of an ISMS, including SoA maintenance, Management Review Meetings, and System Description authorship
- Demonstrated experience writing and revising security policies and running cross-functional review cycles
- Experience tracking gaps and remediation plans within compliance and risk programs
- Ability to work with engineers, product managers, legal, and executive stakeholders and translate compliance requirements into actionable workflows
- Ability to ramp up quickly and operate independently
- Comfort building processes where none exist
- Strong written and verbal communication skills and ability to represent Mozilla before external auditors
- Relevant certifications such as CISA, CISSP, or ISO 27001 Lead Auditor/Implementer are a plus
Benefits
Comp & perks- Generous performance-based bonus plans for all eligible employees
- Rich medical, dental, and vision coverage
- Generous retirement contributions with 100% immediate vesting
- Quarterly all-company wellness days
- Country-specific holidays plus a day off for your birthday
- One-time home office stipend
- Annual professional development budget
- Quarterly well-being stipend
- Considerable paid parental leave
- Employee referral bonus program
- Other benefits including life/AD&D, disability, and EAP, varying by country