GRC Security Engineer — ISO 27001 & SOC 2 Expert

Mozilla

United States

On-site

USD 150,000 - 218,000

Full time

14 days+
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Bonus plan
Healthcare
Retirement plan
Wellness days
Holidays + birthday
Home office stipend
Professional development
Well-being stipend
Parental leave
Referral program
Other benefits

Job summary

Mozilla is seeking a Compliance & ISMS specialist within the Security team to maintain and advance the ISMS, SoA, risk treatment plans, and audit readiness for ISO 27001 and SOC 2 Type 2. You will collaborate across Engineering, Legal, Privacy, People, and product leadership to translate compliance requirements into practical, auditable controls.

The role requires hands-on experience across full compliance programs, with ability to build process where none exists and to drive policy creation,

Qualifications

  • Hands-on experience across the full breadth of a compliance program.
  • Ability to build process where none exists and work with cross-functional stakeholders.
  • Strong written and verbal communication to articulate compliance requirements.
  • Experience in audits from readiness through certification.

Responsibilities

  • Maintain and mature the ISMS, SoA, risk treatment plans, and MRM cadence.
  • Support ISO 27001 and SOC 2 Type 2 audit execution and evidence collection.
  • Contribute to SOC 2 System Description and audit narratives reflecting control environments.
  • Track gaps and remediation from readiness assessments and audits.
  • Lead policy program development, reviews, and keep policies audit-ready.
  • Support scalability as new products/units pursue readiness and certification.
  • Assist internal audits with internal or third-party resources as needed.
  • Collaborate with Engineering, IT, Legal, Privacy, People, and product leadership.
  • Advise GRC manager and Security leadership on audit risk and strategy.

Skills

InfoSec
GRC
ISO 27001
SOC 2
Audit readiness
Policy writing
Cross-functional
ISMS
Certification readiness
Stakeholder mgmt

Job description

Mozilla is seeking a Compliance & ISMS specialist within the Security team to maintain and advance the ISMS, SoA, risk treatment plans, and audit readiness for ISO 27001 and SOC 2 Type 2. You will collaborate across Engineering, Legal, Privacy, People, and product leadership to translate compliance requirements into practical, auditable controls.

The role requires hands-on experience across full compliance programs, with ability to build process where none exists and to drive policy creation,

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

ISMS & Compliance Lead for ISO 27001 & SOC 2
ISMS & Compliance Lead for ISO 27001 & SOC 2

Mozilla Corporation • United States

Remote
USD 120,000 - 160,000
Performance bonus
Medical benefits
Retirement contributions
+2
Remote Security & Compliance Lead (ISO27001/SOC 2)
Remote Security & Compliance Lead (ISO27001/SOC 2)

Mozilla Corporation • United States

Remote
USD 92,000 - 138,000
Generous bonus plans
Medical, dental, and vision coverage
Generous retirement contributions with
+4
GRC Security compliance leader
GRC Security compliance leader

Avantdigitalnow • San Francisco (CA)

On-site
USD 120,000 - 150,000
Staff Security Engineer
Staff Security Engineer

Mozilla Corporation • United States

Remote
USD 92,000 - 138,000
Generous bonus plans
Medical, dental, and vision coverage
Generous retirement contributions with
+4
Remote GRC Specialist - Build ISO 27001 & SOC 2 Compliance
Remote GRC Specialist - Build ISO 27001 & SOC 2 Compliance

United States Digital Space LLC • United States

Remote
USD 110,000 - 165,000
Remote work: 100% remote
Competitive local salary
Equity
+8
Remote GRC Specialist: ISO 27001, GDPR, SOC 2 Champion EU
Remote GRC Specialist: ISO 27001, GDPR, SOC 2 Champion EU

Remotely • United States

Remote
USD 104,000 - 138,000
Remote work 100%
Equity package
Development budget
+5
Security GRC Specialist: ISO 27001 & SOC 2 Leader
Security GRC Specialist: ISO 27001 & SOC 2 Leader

SAP Fioneer • United States

Hybrid
USD 110,000 - 170,000
Infosec or GRC Leader
Infosec or GRC Leader

Avantdigitalnow • San Francisco (CA)

On-site
USD 95,000 - 130,000
Senior GRC Engineer - Automate Compliance & Security
Senior GRC Engineer - Automate Compliance & Security

Cloud Software Group • San Ramon (CA)

On-site
USD 160,000 - 241,000
ISMS & Compliance Leader - ISO 27001 & SOC 2
ISMS & Compliance Leader - ISO 27001 & SOC 2

MSA, The Safety Company • Cranberry Township

On-site
USD 120,000 - 180,000