Staff Security GRC Engineer

Mozilla

Greater London

On-site

GBP 70,000 - 110,000

Full time

14 days+
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Benefits offered by this job

Health benefits
Mental health support
Time off & holidays
Parental leave
Performance bonus
Professional development budget
Life/AD&D insurance
Wellbeing stipend
Referral bonus
Home office stipend

Job summary

Mozilla in London is seeking a senior GRC/ISMS professional to maintain and advance our information security management system. You will design and implement policy, drive audit readiness, and partner with Engineering, Legal, Privacy, and product leadership to embed compliance into everyday practices.

The role requires hands-on experience across ISO 27001, SOC 2 Type 2, and a track record of leading cross-functional policy cycles. Hybrid work and UK-based security leadership support the function.

Qualifications

  • 5+ years of information security, GRC, or compliance-focused roles.
  • Hands-on experience across the full breadth of a compliance program.
  • Experience writing and revising security policies and leading policy cycles.

Responsibilities

  • Maintain and mature the ISMS, including SoA, risk treatment plans, and MRM cadence.
  • Support ISO 27001 and SOC 2 Type 2 audits from scoping to evidence and auditor interviews.
  • Contribute to SOC 2 System Description and audit narratives reflecting control environment.
  • Track gaps and remediation from readiness assessments and audits.
  • Lead policy program, driving policy creation, revision, and cross-functional reviews.
  • Collaborate with Engineering, IT, Legal, Privacy, People teams, and product leadership to translate requirements into practices.
  • Advise GRC manager and Security leadership on audit risk and certification readiness.

Skills

InfoSec
GRC
Policy writing
Audit readiness
Cross-functional collaboration
ISO 27001
SOC 2
ISMS
Risk management

Job description

  • This role is part of the Governance, Risk & Compliance (GRC) function within Mozilla’s Security team
  • The Security team supports Product, Enterprise, and GRC functions across the organization, aligned with the mission to build a safe and secure internet
  • This role is responsible for maintaining and advancing Mozilla’s Information Security Management System (ISMS) and supporting our ISO 27001 and SOC 2 Type 2 compliance programs — from policy and control design through audit readiness and certification
  • The ideal candidate has hands-on experience across the full breadth of a compliance program, is comfortable building process where none yet exists, and works well with a wide range of cross-functional stakeholders
  • Maintain and mature the ISMS, including the Statement of Applicability (SoA), risk treatment plans, and the Management Review Meeting (MRM) process and cadence
  • Support ISO 27001 and SOC 2 Type 2 audit execution—helping determine scope, preparing evidence and narrative artifacts, participating in auditor interviews and walkthroughs, and resolving auditor findings
  • Contribute to the SOC 2 System Description and other audit-specific narrative documentation, ensuring they accurately reflect the organization’s actual control environment
  • Track gaps and remediation efforts arising from readiness assessments and audits
  • Lead the policy program—driving policy creation, revision, and cross-functional review cycles to keep the security policy set current, enforceable, and audit-ready
  • Support compliance scaling as additional products or business units pursue readiness assessments and certification
  • Support the internal audit function, partnering with internal or third-party resources as needed to meet ISO 27001’s internal audit requirements
  • Partner closely with Engineering, IT, Legal, Privacy, People teams, and product leadership to gather evidence, drive control ownership, and translate compliance requirements into practical, adoptable practices
  • Advise the GRC manager and broader Security leadership on audit risk, certification readiness, and compliance program strategy
Benefits
  • Health and wellness: Mozilla covers medical, dental and vision plan premiums at 100% for U.S. and Canadian employees. Our offerings give you the options you need to manage your health — and your family’s — the way you want.
  • Mental health: Mental health is as important as our physical health. That’s why Mozilla’s health benefits include therapy and coaching sessions to make sure our people have access to the care they need.
  • Time away: With all of life’s demands, time away from work to disconnect and recharge is essential. In addition to country-specific holidays (12 in the U.S. and Canada), vacation and sick time start accruing right away (specifics vary by country). Everyone also takes a pause together on quarterly all-company wellness days, plus you get to celebrate the most personal holiday of all: your birthday.
  • Parental leave: While Mozilla’s parental leave policies vary globally, our U.S. and Canadian-based employees can look forward to 26 weeks of paid leave for childbearing parents and 12 weeks of paid leave for non-childbearing parents.
  • Financial: Mozilla is a private company, so our compensation isn’t tied to stock options or equity plans. Instead, we offer generous, performance-based bonus plans to all regular employees to underscore that we share in our success as one team. As for retirement savings for US and Canadian employees, Mozilla contributes a percentage of your eligible base salary each year to the 401(k) Plan/RRSP (regardless of whether you contribute or not), with 100% vesting.
  • Learning and development: We’re big believers in learning by doing, and we also want to invest in your education and development beyond your role. Every employee is eligible for an annual professional development budget. Mozillians can put it toward technical or management training, certifications, conferences and more.
  • Help when you need it: Life is full of surprises; that’s why it’s important to be prepared. Mozilla provides Life/AD&D and Short and Long Term Disability insurance (offerings may vary by locale) to ensure that you and your family will have a safety net in place should you ever need it.
  • Plus a bit more: A few other benefits include a quarterly wellbeing stipend (to use on those things just for you), an employee referral bonus, internet reimbursement if you’re remote, and a budget for office essentials to make working remotely ergonomically comfortable.

Ability to ramp up quickly and operate with a high degree of independenceDemonstrated experience writing and revising security policies, including running cross-functional review cycles to gain organization-wide buy-in and adoption5 years of experience in information security, GRC, or compliance-focused rolesComfort building processes where none yet existExperience tracking gaps and remediation plans and connecting that work to an organization’s broader compliance and risk programExcellent cross-functional collaboration skills—comfortable working with engineers, product managers, legal, and executive stakeholders, and able to translate compliance requirements into practical, actionable workflowsStrong written and verbal communication skills; ability to represent Mozilla credibly and confidently in front of external auditorsRelevant industry certifications (e.g., CISA, CISSP, ISO 27001 Lead Auditor/Implementer) are a plusDeep familiarity with ISO 27001 and SOC 2 Trust Services Criteria, gained through meaningful involvement in audits from readiness through certificationComfort operating across the full breadth of an ISMS—SoA maintenance, Management Review Meetings, and System Description authorship

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

ISMS & GRC Engineer (ISO 27001 / SOC 2)
ISMS & GRC Engineer (ISO 27001 / SOC 2)

Mozilla • Greater London

On-site
GBP 70,000 - 110,000
Health benefits
Mental health support
Time off & holidays
+7
Senior Staff Product Manager (Browser Control Platform)
Senior Staff Product Manager (Browser Control Platform)

Mozilla • Greater London

On-site
GBP 90,000 - 120,000
Health and dental plans (100% premiums
Mental health support
Parental leave
+5
Senior Staff Product Manager, Browser Control Platform
Senior Staff Product Manager, Browser Control Platform

Mozilla • Greater London

On-site
GBP 111,000 - 148,000
Generous performance-based bonus plans
Medical, dental, and vision coverage
Generous retirement contributions with
+1
Senior Product Security Engineer
Senior Product Security Engineer

Mozilla • Greater London

On-site
GBP 90,000 - 130,000
Health insurance
Mental health support
Paid time off
+5
Compliance Enablement Technical Program Manager
Compliance Enablement Technical Program Manager

Sophos • Oxford

Hybrid
GBP 90,000 - 140,000
Remote-first
Diversity networks
Wellbeing days
GRC Senior Analyst
GRC Senior Analyst

Recruitment • Greater London

On-site
GBP 75,000 - 110,000
Cyber Security Engineer
Cyber Security Engineer

Jobtailor • Greater London

Hybrid
GBP 70,000 - 110,000
Senior InfoSec GRC Specialist
Senior InfoSec GRC Specialist

Clearwater Analytics (CWAN) • England

On-site
GBP 65,000 - 85,000
Sr. Security Engineer - GRC Fintech & Financial Services EU/UK
Sr. Security Engineer - GRC Fintech & Financial Services EU/UK

xAI • Greater London

On-site
GBP 100,000 - 135,000
Information Security Officer
Information Security Officer

Maxwell Bond • Reading

Hybrid
GBP 55,000 - 57,000