Mozilla

Staff Security Engineer

Mozilla$128K — $171K *
US-AnywhereRemote in Canada
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 5 years of experience in information security, GRC, or compliance roles.
  • Familiarity with ISO 27001 and SOC 2 Trust Services Criteria gained from audit involvement.
  • Experience with ISMS maintenance including SoA, risk treatment plans, and MRM.
  • Proven ability to write and revise security policies with cross-functional coordination.
  • Experience managing gaps and remediation plans within compliance programs.
  • Strong collaboration skills with technical and non-technical stakeholders.
  • Excellent written and verbal communication skills for external representation.

Responsibilities

  • Maintain and enhance the ISMS and associated documentation.
  • Support ISO 27001 and SOC 2 Type 2 audits by preparing evidence and participating in auditor interactions.
  • Contribute to audit-specific documentation ensuring its accuracy and relevance.
  • Monitor gaps and remediation activities post-audit.
  • Lead the development and review of security policies.
  • Facilitate compliance scaling for new products or business units.
  • Assist in internal audit functions to meet ISO 27001 requirements.
  • Collaborate across teams to align compliance needs with practical implementation.

Benefits

  • Generous performance-based bonuses for eligible employees.
  • Comprehensive medical, dental, and vision coverage.
  • 100% immediate vesting on retirement contributions.
  • Quarterly wellness days for collective downtime.
  • Inclusive holidays plus an additional day off for your birthday.
  • Home office stipend provided one-time only.
  • Dedicated budget for professional development annually.
  • Quarterly stipends for well-being support.
  • Substantial paid parental leave options.
  • Employee referral bonuses available.
  • Additional benefits include life, AD&D, and disability coverage varying by country.
Full Job Description
About this team and role:

This role is part of the Governance, Risk & Compliance (GRC) function within Mozilla's Security team. The Security team supports Product, Enterprise, and GRC functions across the organization, aligned with the mission to build a safe and secure internet. This role is responsible for maintaining and advancing Mozilla's Information Security Management System (ISMS) and supporting our ISO 27001 and SOC 2 Type 2 compliance programs - from policy and control design through audit readiness and certification.

The ideal candidate has hands-on experience across the full breadth of a compliance program, is comfortable building process where none yet exists, and works well with a wide range of cross-functional stakeholders.
What you'll do:
  • Maintain and mature the ISMS, including the Statement of Applicability (SoA), risk treatment plans, and the Management Review Meeting (MRM) process and cadence.
  • Support ISO 27001 and SOC 2 Type 2 audit execution-helping determine scope, preparing evidence and narrative artifacts, participating in auditor interviews and walkthroughs, and resolving auditor findings.
  • Contribute to the SOC 2 System Description and other audit-specific narrative documentation, ensuring they accurately reflect the organization's actual control environment.
  • Track gaps and remediation efforts arising from readiness assessments and audits.
  • Lead the policy program-driving policy creation, revision, and cross-functional review cycles to keep the security policy set current, enforceable, and audit-ready.
  • Support compliance scaling as additional products or business units pursue readiness assessments and certification.
  • Support the internal audit function, partnering with internal or third-party resources as needed to meet ISO 27001's internal audit requirements.
  • Partner closely with Engineering, IT, Legal, Privacy, People teams, and product leadership to gather evidence, drive control ownership, and translate compliance requirements into practical, adoptable practices.
  • Advise the GRC manager and broader Security leadership on audit risk, certification readiness, and compliance program strategy.
What you'll bring:
  • 5 years of experience in information security, GRC, or compliance-focused roles.
  • Deep familiarity with ISO 27001 and SOC 2 Trust Services Criteria, gained through meaningful involvement in audits from readiness through certification.
  • Comfort operating across the full breadth of an ISMS-SoA maintenance, Management Review Meetings, and System Description authorship.
  • Demonstrated experience writing and revising security policies, including running cross-functional review cycles to gain organization-wide buy-in and adoption.
  • Experience tracking gaps and remediation plans and connecting that work to an organization's broader compliance and risk program.
  • Excellent cross-functional collaboration skills-comfortable working with engineers, product managers, legal, and executive stakeholders, and able to translate compliance requirements into practical, actionable workflows.
  • Ability to ramp up quickly and operate with a high degree of independence.
  • Comfort building processes where none yet exist.
  • Strong written and verbal communication skills; ability to represent Mozilla credibly and confidently in front of external auditors.
  • Relevant industry certifications (e.g., CISA, CISSP, ISO 27001 Lead Auditor/Implementer) are a plus.
Commitment to our values:
  • Welcoming differences
  • Being relationship-minded
  • Practicing responsible participation
  • Having grit
What you'll get:
  • Generous performance-based bonus plans to all eligible employees-we share in our success as one team.
  • Rich medical, dental, and vision coverage.
  • Generous retirement contributions with 100% immediate vesting (regardless of whether you contribute).
  • Quarterly all-company wellness days where everyone takes a pause together.
  • Country-specific holidays plus a day off for your birthday.
  • One-time home office stipend.
  • Annual professional development budget.
  • Quarterly well-being stipend.
  • Considerable paid parental leave.
  • Employee referral bonus program.
  • Other benefits (life/AD&D, disability, EAP, etc.-varies by country).

Hiring Ranges:

Canada Tier 1 Locations

$128,000-$171,000 CAD

Canada Tier 2 Locations

$116,000-$155,000 CAD

About Mozilla

Mozilla is a global community of technologists, thinkers, and builders working together to keep the internet open and accessible to all. The company is best known for its flagship product, the Firefox web browser, which is used by millions of people around the world. In addition to its browser, Mozilla also develops a range of other products and services, including a mobile operating system, a password manager, and a virtual private network (VPN) service.
Learn more about Mozilla
Size
1,000 employees
Industry
Founded
1998

Similar Jobs

More Jobs at Mozilla

More Information Technology Jobs

Find similar Staff Security Engineer jobs: