Mozilla

Staff Security Engineer

Mozilla$163K — $218K *
US-AnywhereRemote in United States
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 5 years of experience in information security, GRC, or compliance-focused roles.
  • Deep knowledge of ISO 27001 and SOC 2 Trust Services Criteria from audit involvement.
  • Experience maintaining an Information Security Management System (ISMS).
  • Proven track record in creating and revising security policies with cross-functional collaboration.
  • Ability to track compliance gaps and connect remediation to broader risk programs.
  • Excellent communication skills for effectively working with diverse stakeholders.
  • Relevant industry certifications (e.g., CISA, CISSP) are advantageous.

Responsibilities

  • Maintain and enhance the Information Security Management System (ISMS).
  • Support ISO 27001 and SOC 2 Type 2 audit execution and readiness.
  • Contribute to SOC 2 System Description and audit documentation.
  • Track and manage gaps and remediation from audits.
  • Lead the security policy creation and revision process.
  • Facilitate compliance scaling for new products or business units.
  • Support internal audit functions to meet ISO 27001 requirements.
  • Collaborate with cross-functional teams to translate compliance into actionable practices.

Benefits

  • Generous performance-based bonus plans for all eligible employees.
  • Rich medical, dental, and vision coverage.
  • Immediate 100% vesting on retirement contributions, regardless of employee contribution.
  • Quarterly wellness days for all employees to take a collective pause.
  • Country-specific holidays plus a day off for your birthday.
  • One-time stipend for home office setup.
  • Annual budget for professional development activities.
  • Quarterly stipends for employee well-being initiatives.
  • Considerable paid parental leave benefits.
  • Employee referral bonus program.
Full Job Description
About this team and role:

This role is part of the Governance, Risk & Compliance (GRC) function within Mozilla's Security team. The Security team supports Product, Enterprise, and GRC functions across the organization, aligned with the mission to build a safe and secure internet. This role is responsible for maintaining and advancing Mozilla's Information Security Management System (ISMS) and supporting our ISO 27001 and SOC 2 Type 2 compliance programs - from policy and control design through audit readiness and certification.

The ideal candidate has hands-on experience across the full breadth of a compliance program, is comfortable building process where none yet exists, and works well with a wide range of cross-functional stakeholders.
What you'll do:
  • Maintain and mature the ISMS, including the Statement of Applicability (SoA), risk treatment plans, and the Management Review Meeting (MRM) process and cadence.
  • Support ISO 27001 and SOC 2 Type 2 audit execution-helping determine scope, preparing evidence and narrative artifacts, participating in auditor interviews and walkthroughs, and resolving auditor findings.
  • Contribute to the SOC 2 System Description and other audit-specific narrative documentation, ensuring they accurately reflect the organization's actual control environment.
  • Track gaps and remediation efforts arising from readiness assessments and audits.
  • Lead the policy program-driving policy creation, revision, and cross-functional review cycles to keep the security policy set current, enforceable, and audit-ready.
  • Support compliance scaling as additional products or business units pursue readiness assessments and certification.
  • Support the internal audit function, partnering with internal or third-party resources as needed to meet ISO 27001's internal audit requirements.
  • Partner closely with Engineering, IT, Legal, Privacy, People teams, and product leadership to gather evidence, drive control ownership, and translate compliance requirements into practical, adoptable practices.
  • Advise the GRC manager and broader Security leadership on audit risk, certification readiness, and compliance program strategy.
What you'll bring:
  • 5 years of experience in information security, GRC, or compliance-focused roles.
  • Deep familiarity with ISO 27001 and SOC 2 Trust Services Criteria, gained through meaningful involvement in audits from readiness through certification.
  • Comfort operating across the full breadth of an ISMS-SoA maintenance, Management Review Meetings, and System Description authorship.
  • Demonstrated experience writing and revising security policies, including running cross-functional review cycles to gain organization-wide buy-in and adoption.
  • Experience tracking gaps and remediation plans and connecting that work to an organization's broader compliance and risk program.
  • Excellent cross-functional collaboration skills-comfortable working with engineers, product managers, legal, and executive stakeholders, and able to translate compliance requirements into practical, actionable workflows.
  • Ability to ramp up quickly and operate with a high degree of independence.
  • Comfort building processes where none yet exist.
  • Strong written and verbal communication skills; ability to represent Mozilla credibly and confidently in front of external auditors.
  • Relevant industry certifications (e.g., CISA, CISSP, ISO 27001 Lead Auditor/Implementer) are a plus.
Commitment to our values:
  • Welcoming differences
  • Being relationship-minded
  • Practicing responsible participation
  • Having grit
What you'll get:
  • Generous performance-based bonus plans to all eligible employees-we share in our success as one team.
  • Rich medical, dental, and vision coverage.
  • Generous retirement contributions with 100% immediate vesting (regardless of whether you contribute).
  • Quarterly all-company wellness days where everyone takes a pause together.
  • Country-specific holidays plus a day off for your birthday.
  • One-time home office stipend.
  • Annual professional development budget.
  • Quarterly well-being stipend.
  • Considerable paid parental leave.
  • Employee referral bonus program.
  • Other benefits (life/AD&D, disability, EAP, etc.-varies by country).

Hiring Ranges:

US Tier 1 Locations

$163,000-$218,000 USD

US Tier 2 Locations

$150,000-$200,000 USD

US Tier 3 Locations

$139,000-$185,000 USD

About Mozilla

Mozilla is a global community of technologists, thinkers, and builders working together to keep the internet open and accessible to all. The company is best known for its flagship product, the Firefox web browser, which is used by millions of people around the world. In addition to its browser, Mozilla also develops a range of other products and services, including a mobile operating system, a password manager, and a virtual private network (VPN) service.
Learn more about Mozilla
Size
1,000 employees
Industry
Founded
1998

Similar Jobs

More Jobs at Mozilla

More Information Technology Jobs

Find similar Staff Security Engineer jobs: