Senior Security GRC Engineer — ISO 27001 & SOC 2

Mozilla

Toronto

On-site

CAD 128,000 - 171,000

Full time

14 days+
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

Performance-based bonus
Comprehensive medical, dental, vision
Retirement contributions
Wellness days
Holidays & birthday day off
Home office stipend
Professional development budget
Parental leave
Employee referral bonus

Job summary

Mozilla is seeking a seasoned GRC/Information Security professional to maintain Mozilla's ISMS and lead ISO 27001 and SOC 2 Type 2 readiness. You will work with Engineering, Legal, Privacy and product leaders to translate compliance requirements into practical, auditable practices.

The role requires hands-on experience across the full compliance program, policy development, and documentation, with the ability to drive audits from readiness through certification.

Qualifications

  • 5+ years of experience in information security, GRC, or compliance-focused roles.
  • Deep familiarity with ISO 27001 and SOC 2 criteria, gained through audits from readiness through certification.
  • Experience maintaining ISMS components (SoA, MRM, System Description).
  • Experience writing and revising security policies with cross-functional reviews.
  • Experience tracking gaps/remediation and linking to risk programs.
  • Excellent cross-functional collaboration with engineering, product, legal, and executive stakeholders.
  • Ability to ramp up quickly and work independently; comfortable building processes where none exist.
  • Strong written and verbal communication; credible in front of external auditors.
  • Industry certifications (e.g., CISA, CISSP, ISO 27001 Lead Auditor/Implementer) are a plus.

Responsibilities

  • Maintain and mature the ISMS, including SoA, risk treatment plans, and MRM cadence.
  • Support ISO 27001 and SOC 2 Type 2 audit execution—define scope, prepare evidence, participate in interviews, and resolve findings.
  • Contribute to SOC 2 System Description and audit narratives to reflect the control environment.
  • Track gaps and remediation from readiness assessments and audits.
  • Lead the policy program: create, revise, and drive cross-functional review cycles.
  • Support scaling of compliance as products/business units pursue readiness and certification.
  • Assist internal audit with ISO 27001 requirements; coordinate with internal/third-party resources.
  • Collaborate with Engineering, IT, Legal, Privacy, People, and product leadership to translate requirements into practical workflows.
  • Advise GRC manager and Security leadership on audit risk, readiness, and program strategy.

Skills

Information security
GRC
Audit coordination
Policy management
Cross-functional
ISO 27001
SOC 2 readiness
Communication
Independent work
Risk management

Education

Bachelor's degree in information security

Tools

ISO 27001 lead auditor/implementer
CISA
CISSP

Job description

Mozilla is seeking a seasoned GRC/Information Security professional to maintain Mozilla's ISMS and lead ISO 27001 and SOC 2 Type 2 readiness. You will work with Engineering, Legal, Privacy and product leaders to translate compliance requirements into practical, auditable practices.

The role requires hands-on experience across the full compliance program, policy development, and documentation, with the ability to drive audits from readiness through certification.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Staff Security GRC Engineer
Staff Security GRC Engineer

Mozilla • Toronto

On-site
CAD 128,000 - 171,000
Performance-based bonus
Comprehensive medical, dental, vision
Retirement contributions
+6
Staff Security Engineer New Remote Canada
Staff Security Engineer New Remote Canada

Mozilla Corporation • Canada

Remote
CAD 116,000 - 171,000
Bonus plans
Medical coverage
Retirement contributions
+6
Security GRC Specialist - SOC 2 & ISO 27001 Compliance
Security GRC Specialist - SOC 2 & ISO 27001 Compliance

Equisoft Inc. (Canada) • Montreal (administrative region)

Hybrid
CAD 90,000 - 130,000
Educational Support
Medical
Dental
+4
InfoSec & Compliance Lead — ISO 27001 / SOC 2
InfoSec & Compliance Lead — ISO 27001 / SOC 2

Socket.dev • Mississauga

On-site
CAD 120,000 - 180,000
Senior GRC Manager: Audit, Risk & Compliance Leader
Senior GRC Manager: Audit, Risk & Compliance Leader

Fullscript • Ottawa

Hybrid
CAD 140,000 - 165,000
RRSP match program
Flexible benefits package
Training budget and learning
+2
Senior Manager, Cybersecurity & GRC
Senior Manager, Cybersecurity & GRC

Axiom Global Technologies • Mississauga

On-site
CAD 150,000 - 210,000
IT Governance, Risk, and Compliance Analyst
IT Governance, Risk, and Compliance Analyst

Jobtailor • Ottawa

On-site
CAD 90,000 - 120,000
GRC Security Specialist — Hybrid (Québec City)
GRC Security Specialist — Hybrid (Québec City)

Equisoft • Montreal (administrative region)

Hybrid
CAD 90,000 - 130,000
Hybrid work in Québec City
Benefits from day 1: medical, dental,
Educational support
Senior Cyber Security Analyst - GRC
Senior Cyber Security Analyst - GRC

Metro Supply Chain • Mississauga

On-site
CAD 105,000 - 125,000
Gestionnaire GRC – ISMS/ISO27001 & SOC2 | Télétravail
Gestionnaire GRC – ISMS/ISO27001 & SOC2 | Télétravail

Plusgrade • Montreal

On-site
CAD 85,000 - 115,000