ISMS & GRC Engineer (ISO 27001 / SOC 2)

Mozilla

Greater London

On-site

GBP 70,000 - 110,000

Full time

14 days+
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Health benefits
Mental health support
Time off & holidays
Parental leave
Performance bonus
Professional development budget
Life/AD&D insurance
Wellbeing stipend
Referral bonus
Home office stipend

Job summary

Mozilla in London is seeking a senior GRC/ISMS professional to maintain and advance our information security management system. You will design and implement policy, drive audit readiness, and partner with Engineering, Legal, Privacy, and product leadership to embed compliance into everyday practices.

The role requires hands-on experience across ISO 27001, SOC 2 Type 2, and a track record of leading cross-functional policy cycles. Hybrid work and UK-based security leadership support the function.

Qualifications

  • 5+ years of information security, GRC, or compliance-focused roles.
  • Hands-on experience across the full breadth of a compliance program.
  • Experience writing and revising security policies and leading policy cycles.

Responsibilities

  • Maintain and mature the ISMS, including SoA, risk treatment plans, and MRM cadence.
  • Support ISO 27001 and SOC 2 Type 2 audits from scoping to evidence and auditor interviews.
  • Contribute to SOC 2 System Description and audit narratives reflecting control environment.
  • Track gaps and remediation from readiness assessments and audits.
  • Lead policy program, driving policy creation, revision, and cross-functional reviews.
  • Collaborate with Engineering, IT, Legal, Privacy, People teams, and product leadership to translate requirements into practices.
  • Advise GRC manager and Security leadership on audit risk and certification readiness.

Skills

InfoSec
GRC
Policy writing
Audit readiness
Cross-functional collaboration
ISO 27001
SOC 2
ISMS
Risk management

Job description

Mozilla in London is seeking a senior GRC/ISMS professional to maintain and advance our information security management system. You will design and implement policy, drive audit readiness, and partner with Engineering, Legal, Privacy, and product leadership to embed compliance into everyday practices.

The role requires hands-on experience across ISO 27001, SOC 2 Type 2, and a track record of leading cross-functional policy cycles. Hybrid work and UK-based security leadership support the function.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Staff Security GRC Engineer
Staff Security GRC Engineer

Mozilla • Greater London

On-site
GBP 70,000 - 110,000
Health benefits
Mental health support
Time off & holidays
+7
Security Manager: PCI & ISO 27001 GRC Lead
Security Manager: PCI & ISO 27001 GRC Lead

ISR RECRUITMENT LIMITED • Leeds

Hybrid
GBP 60,000 - 70,000
Excellent company benefits and Incenti
ISMS & GRC Lead — Hybrid Role in Manchester
ISMS & GRC Lead — Hybrid Role in Manchester

Vix Technology & Kuba • Manchester

Hybrid
GBP 55,000 - 75,000
Hybrid work model
GRC Security Lead - ISO 27001 & Vendor Risk (Hybrid UK)
GRC Security Lead - ISO 27001 & Vendor Risk (Hybrid UK)

GWI • Greater London

Hybrid
GBP 70,000 - 100,000
25 days annual leave
Health cash plan
4% pension matching
+6
IT GRC Senior Analyst
IT GRC Senior Analyst

Nigel Wright Recruitment • Newcastle upon Tyne

Hybrid
GBP 70,000 - 90,000
Hybrid work policy
InfoSec GRC Manager: ISO27001, Risk & Policy
InfoSec GRC Manager: ISO27001, Risk & Policy

AJ Bell • Manchester

Hybrid
GBP 65,000 - 85,000
Security & GRC Lead - Hybrid UK
Security & GRC Lead - Hybrid UK

Vix Technology • Manchester

Hybrid
GBP 55,000 - 75,000
Hybrid London GRC & ISMS Lead
Hybrid London GRC & ISMS Lead

Walkers • Greater London

Hybrid
GBP 85,000 - 110,000
Information Security Manager - HYBRID
Information Security Manager - HYBRID

Proactive Appointments • Cambridgeshire and Peterborough

On-site
GBP 60,000 - 90,000
InfoSec Compliance Lead - ISO 27001 & SOC2, Client-Facing
InfoSec Compliance Lead - ISO 27001 & SOC2, Client-Facing

ION Group • Greater London

Hybrid
GBP 70,000 - 110,000