Skip to content
MozillaMozillaUnited States

Staff Security Engineer

Maintains Mozilla’s information security management system and leads ISO 27001 and SOC 2 compliance activities, including audit readiness, policy governance, remediation tracking, and stakeholder coordination. Requires at least five years in information security, GRC, or compliance and strong audit experience.

Salary not listed
Remote7+ YOESecurity Engineering

About the role

Responsibilities

  • Maintain and mature the Information Security Management System (ISMS), including the Statement of Applicability (SoA), risk treatment plans, and Management Review Meeting (MRM) processes.
  • Support ISO 27001 and SOC 2 Type 2 audits by determining scope, preparing evidence and narrative artifacts, participating in auditor interviews and walkthroughs, and resolving findings.
  • Contribute to SOC 2 system descriptions and other audit documentation that accurately reflects the control environment.
  • Track gaps and remediation efforts from readiness assessments and audits.
  • Lead security policy creation, revision, and cross-functional review cycles.
  • Support compliance scaling as additional products or business units pursue readiness assessments and certification.
  • Support internal audits and ISO 27001 internal-audit requirements.
  • Partner with Engineering, IT, Legal, Privacy, People teams, and product leadership to gather evidence, drive control ownership, and translate requirements into practical workflows.
  • Advise Security leadership on audit risk, certification readiness, and compliance strategy.

Requirements

  • 5 years of experience in information security, GRC, or compliance-focused roles.
  • Deep familiarity with ISO 27001 and SOC 2 Trust Services Criteria, including meaningful participation in audits from readiness through certification.
  • Experience across the breadth of an ISMS, including SoA maintenance, Management Review Meetings, and system-description authorship.
  • Experience writing and revising security policies and leading cross-functional review cycles.
  • Experience tracking gaps and remediation plans within broader compliance and risk programs.
  • Strong cross-functional collaboration skills with engineers, product managers, legal stakeholders, and executives.
  • Ability to translate compliance requirements into practical, actionable workflows.
  • Ability to work independently, ramp quickly, and build processes where none exist.
  • Strong written and verbal communication skills, including credibility with external auditors.

Nice to Have

  • Relevant certifications such as CISA, CISSP, or ISO 27001 Lead Auditor/Implementer.

Compensation and Benefits

  • Performance-based bonus plans for eligible employees.
  • Medical, dental, and vision coverage.
  • Retirement contributions with immediate vesting.
  • Quarterly company wellness days.
  • Country-specific holidays and a birthday day off.
  • Home office stipend.
  • Annual professional development budget.
  • Quarterly well-being stipend.
  • Paid parental leave.
  • Employee referral bonus program.
  • Additional benefits such as life and accidental death and dismemberment insurance, disability coverage, and an employee assistance program; benefits vary by country.

Skills

information securitygovernance, risk & complianceISO 27001SOC 2ismsstatement of applicabilityrisk treatment planssecurity policiesinternal auditscisacisspiso 27001 lead auditor
Addepar

Staff AI Security Engineer

AddeparUnited States

Leads AI security strategy, architecture, governance, and defensive controls across the organization while mentoring security engineers. Requires 9+ years of security engineering experience and deep knowledge of AI, AWS security services, identity protocols, and emerging AI attack frameworks.

Salary not listedRemote9+ YOESecurity Engineering
Snowflake

Staff Software Engineer, Product Security

SnowflakeMenlo Park, CA +1

Leads product security architecture and builds security-critical services, frameworks, and controls across engineering teams. The role requires 10+ years of software engineering experience, deep expertise in secure distributed systems, and strong cross-team technical leadership.

236k – 339k/yrHybrid10+ YOESecurity Engineering
Mozilla

Staff Security Engineer

MozillaUnited States

Leads Mozilla’s security compliance and governance programs, maintaining the ISMS and supporting ISO 27001 and SOC 2 Type 2 audits. The role requires at least five years of information security or GRC experience, strong policy and remediation expertise, and effective cross-functional collaboration.

139k – 218k/yrRemote7+ YOESecurity Engineering
OpenLoop

Sr. Staff IAM Engineer

OpenLoopUnited States

Designs and governs enterprise identity architecture across workforce, customer, partner, non-human, and AI agent identities. The role requires 8+ years in IAM, deep CIAM and Auth0 experience, federation expertise, and the ability to implement secure, auditable controls in regulated environments.

Salary not listedRemote8+ YOESecurity Engineering
Anthropic

Staff+ Software Engineer, Privacy

AnthropicSan Francisco, CA +2

This foundational privacy engineering role designs privacy-preserving architectures, infrastructure, governance systems, and compliance controls for large-scale AI training and inference. It requires substantial software engineering experience, privacy expertise, and technical leadership across engineering, research, legal, and product teams.

405k – 485k/yrHybrid12+ YOESecurity Engineering