> Markdown version of [/jobs/ext/2037332-security-engineer](https://www.wearedevelopers.com/jobs/ext/2037332-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Engineer - **Company:** Mozilla Corporation - **Location:** United States (Remote available) - **Experience:** Expert - **Salary:** $139,000.0 - $218,000.0 - **Contract:** Permanent contract - **Skills:** Cyber Security, Disk Controller, Service-Oriented Architecture, Information Security Management System - **Published:** August 12, 2026 - **Apply:** https://www.workingnomads.com/job/go/1787040/ ## About the Role * 5 years of experience in information security, GRC, or compliance-focused roles. * Deep familiarity with ISO 27001 and SOC 2 Trust Services Criteria, gained through meaningful involvement in audits from readiness through certification. * Comfort operating across the full breadth of an ISMS-SoA maintenance, Management Review Meetings, and System Description authorship. * Demonstrated experience writing and revising security policies, including running cross-functional review cycles to gain organization-wide buy-in and adoption. * Experience tracking gaps and remediation plans and connecting that work to an organization's broader compliance and risk program. * Excellent cross-functional collaboration skills-comfortable working with engineers, product managers, legal, and executive stakeholders, and able to translate compliance requirements into practical, actionable workflows. * Ability to ramp up quickly and operate with a high degree of independence. * Comfort building processes where none yet exist. * Strong written and verbal communication skills; ability to represent Mozilla credibly and confidently in front of external auditors. * Relevant industry certifications (e.g., CISA, CISSP, ISO 27001 Lead Auditor/Implementer) are a plus. ## Description This role is part of the Governance, Risk & Compliance (GRC) function within Mozilla's Security team. The Security team supports Product, Enterprise, and GRC functions across the organization, aligned with the mission to build a safe and secure internet. This role is responsible for maintaining and advancing Mozilla's Information Security Management System (ISMS) and supporting our ISO 27001 and SOC 2 Type 2 compliance programs - from policy and control design through audit readiness and certification. The ideal candidate has hands-on experience across the full breadth of a compliance program, is comfortable building process where none yet exists, and works well with a wide range of cross-functional stakeholders. What you'll do: * Maintain and mature the ISMS, including the Statement of Applicability (SoA), risk treatment plans, and the Management Review Meeting (MRM) process and cadence. * Support ISO 27001 and SOC 2 Type 2 audit execution-helping determine scope, preparing evidence and narrative artifacts, participating in auditor interviews and walkthroughs, and resolving auditor findings. * Contribute to the SOC 2 System Description and other audit-specific narrative documentation, ensuring they accurately reflect the organization's actual control environment. * Track gaps and remediation efforts arising from readiness assessments and audits. * Lead the policy program-driving policy creation, revision, and cross-functional review cycles to keep the security policy set current, enforceable, and audit-ready. * Support compliance scaling as additional products or business units pursue readiness assessments and certification. * Support the internal audit function, partnering with internal or third-party resources as needed to meet ISO 27001's internal audit requirements. * Partner closely with Engineering, IT, Legal, Privacy, People teams, and product leadership to gather evidence, drive control ownership, and translate compliance requirements into practical, adoptable practices. * Advise the GRC manager and broader Security leadership on audit risk, certification readiness, and compliance program strategy., * Welcoming differences * Being relationship-minded * Practicing responsible participation * Having grit ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Why Git Still Matters](https://www.wearedevelopers.com/videos/100288-why-git-still-matters) - [Enterprise Python: Software That Lives Long And Prosper](https://www.wearedevelopers.com/videos/946-enterprise-python-software-that-lives-long-and-prosper) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [Crafting Custom Frameworks with Rust: A Deep Dive into Procedural Macros](https://www.wearedevelopers.com/videos/849-crafting-custom-frameworks-with-rust-a-deep-dive-into-procedural-macros) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Dev Digest 129 - Now that's what I call private data!](https://www.wearedevelopers.com/magazine/468-dev-digest-129-now-that-s-what-i-call-private-data) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing)