Leads Mozilla’s security compliance and governance programs, maintaining the ISMS and supporting ISO 27001 and SOC 2 Type 2 audits. The role requires at least five years of information security or GRC experience, strong policy and remediation expertise, and effective cross-functional collaboration.
139k – 218k/yr
Remote7+ YOESecurity Engineering
About the role
Responsibilities
Maintain and mature the Information Security Management System (ISMS), including the Statement of Applicability (SoA), risk treatment plans, and Management Review Meeting (MRM) processes.
Support ISO 27001 and SOC 2 Type 2 audits, including scope determination, evidence and narrative preparation, auditor interviews and walkthroughs, and resolution of findings.
Contribute to the SOC 2 System Description and other audit documentation.
Track gaps and remediation efforts from readiness assessments and audits.
Lead the security policy program, including policy creation, revision, and cross-functional review cycles.
Support compliance scaling as additional products or business units pursue readiness assessments and certification.
Support internal audits required by ISO 27001.
Partner with Engineering, IT, Legal, Privacy, People teams, and product leadership to gather evidence, drive control ownership, and translate compliance requirements into practical workflows.
Advise Security leadership on audit risk, certification readiness, and compliance strategy.
Requirements
5 years of experience in information security, GRC, or compliance-focused roles.
Deep familiarity with ISO 27001 and SOC 2 Trust Services Criteria, including meaningful involvement in audits from readiness through certification.
Experience across the full breadth of an ISMS, including SoA maintenance, Management Review Meetings, and System Description authorship.
Experience writing and revising security policies and managing cross-functional review cycles.
Experience tracking gaps and remediation plans within broader compliance and risk programs.
Strong cross-functional collaboration and communication skills, including the ability to translate compliance requirements into actionable workflows.
Ability to work independently, ramp quickly, and build processes where none exist.
Ability to represent the organization credibly before external auditors.
Nice to have
CISA, CISSP, ISO 27001 Lead Auditor, or ISO 27001 Lead Implementer certification.
Compensation and benefits
Performance-based bonus plans for eligible employees.
Medical, dental, and vision coverage.
Retirement contributions with immediate vesting.
Company wellness days, paid holidays, and birthday leave.
Home office stipend.
Annual professional development budget.
Well-being stipend.
Paid parental leave.
Employee referral bonus program.
Life and accidental death and dismemberment insurance, disability coverage, and employee assistance program benefits.
Skills
information securityGRCISO 27001SOC 2ismsstatement of applicabilityrisk treatment planssecurity policiesinternal auditcisacisspiso 27001 lead auditoriso 27001 lead implementer
Staff-level product security engineer leading security reviews, threat modeling, penetration testing, and LLM/AI security assessments for Okta's identity platform. Requires deep manual security expertise and strong communication skills.
141k – 248k/yrHybrid7+ YOESecurity Engineering
Member of Technical Staff II
IllumioSunnyvale, CA
Develop containerized microservices in Go for a multi-tenant cloud security platform that processes real-time cloud events and telemetry to deliver security insights and recommendations. Own full SDLC, design, operations, and mentoring while partnering with Product on requirements.
141k – 162k/yrOn-site2+ YOESecurity Engineering
Staff Security Engineer
OktaSan Francisco, CA
Staff Security Engineer embedded in TDI to build centralized security posture analytics, automate issue tracking and remediation, and drive AI-powered risk management across AWS, SaaS apps, and enterprise systems.
134k – 185k/yrOn-site10+ YOESecurity Engineering
Senior Staff Information Security Engineer
NMIUnited States
Senior individual contributor leading security architecture and automated controls across AWS, on-premises, and hybrid infrastructure. The role requires deep AWS security expertise, infrastructure-as-code and CI/CD experience, scripting ability, and cross-functional technical leadership.
145k – 165k/yrRemote7+ YOESecurity Engineering
Staff Cloud Security Engineer
NinjaTraderChicago, IL
Senior individual contributor owning cloud security architecture and guardrails for GCP workloads at a fintech trading platform. Leads threat modeling, edge defenses with Cloudflare/Armor, policy-as-code, incident response, and compliance controls while mentoring engineers.