At a Glance
- Tasks: Maintain and enhance Mozilla's Information Security Management System while supporting compliance programs.
- Company: Join Mozilla, a non-profit-backed tech company shaping the internet for over 25 years.
- Benefits: Enjoy competitive salary, generous bonuses, wellness days, and professional development budgets.
- Other info: Diverse and inclusive workplace committed to making the internet better for everyone.
- Why this job: Make a real impact on internet security and work with passionate teams.
- Qualifications: 5 years in information security or compliance, with strong collaboration skills.
The predicted salary is between 69750 - 85250 £ per year.
Why Mozilla?
Mozilla Corporation is the non-profit-backed technology company that has shaped the internet for the better over the last 25 years.
We make pioneering brands like Firefox, the privacy-minded web browser.
Now, with more than 225 million people around the world using our products each month, we're shaping the next 25 years of technology and helping to reclaim an internet built for people, not companies.
Our work focuses on diverse areas including AI, social media, security and more.
And we're doing this while never losing our focus on our core mission – to make the internet better for people.
The Mozilla Corporation is wholly owned by the non-profit 501(c) Mozilla Foundation.
This means we aren't beholden to any shareholders — only to our mission.
Along with thousands of volunteer contributors and collaborators all over the world, Mozillians design, build and distribute open-source software that enables people to enjoy the internet on their terms.
About this team and role
This role is part of the Governance, Risk & Compliance (GRC) function within Mozilla's Security team.
The Security team supports Product, Enterprise, and GRC functions across the organization, aligned with the mission to build a safe and secure internet.
This role is responsible for maintaining and advancing Mozilla's Information Security Management System (ISMS) and supporting our ISO 27001 and SOC 2 Type 2 compliance programs — from policy and control design through audit readiness and certification.
The ideal candidate has hands-on experience across the full breadth of a compliance program, is comfortable building process where none yet exists, and works well with a wide range of cross-functional stakeholders.
What you'll do
- Maintain and mature the ISMS, including the Statement of Applicability (So A), risk treatment plans, and the Management Review Meeting (MRM) process and cadence.
- Support ISO 27001 and SOC 2 Type 2 audit execution—helping determine scope, preparing evidence and narrative artifacts, participating in auditor interviews and walkthroughs, and resolving auditor findings.
- Contribute to the SOC 2 System Description and other audit-specific narrative documentation, ensuring they accurately reflect the organization's actual control environment.
- Track gaps and remediation efforts arising from readiness assessments and audits.
- Lead the policy program—driving policy creation, revision, and cross-functional review cycles to keep the security policy set current, enforceable, and audit-ready.
- Support compliance scaling as additional products or business units pursue readiness assessments and certification.
- Support the internal audit function, partnering with internal or third-party resources as needed to meet ISO 27001's internal audit requirements.
- Partner closely with Engineering, IT, Legal, Privacy, People teams, and product leadership to gather evidence, drive control ownership, and translate compliance requirements into practical, adoptable practices.
- Advise the GRC manager and broader Security leadership on audit risk, certification readiness, and compliance program strategy.
What you'll bring
- 5 years of experience in information security, GRC, or compliance-focused roles.
- Deep familiarity with ISO 27001 and SOC 2 Trust Services Criteria, gained through meaningful involvement in audits from readiness through certification.
- Comfort operating across the full breadth of an ISMS—So A maintenance, Management Review Meetings, and System Description authorship.
- Demonstrated experience writing and revising security policies, including running cross-functional review cycles to gain organization-wide buy-in and adoption.
- Experience tracking gaps and remediation plans and connecting that work to an organization's broader compliance and risk program.
- Excellent cross-functional collaboration skills—comfortable working with engineers, product managers, legal, and executive stakeholders, and able to translate compliance requirements into practical, actionable workflows.
- Ability to ramp up quickly and operate with a high degree of independence.
- Comfort building processes where none yet exist.
- Strong written and verbal communication skills; ability to represent Mozilla credibly and confidently in front of external auditors.
- Relevant industry certifications (e. g., CISA, CISSP, ISO 27001 Lead Auditor/Implementer) are a plus.
Commitment to our values
- Welcoming differences
- Being relationship-minded
- Practicing responsible participation
- Having grit
What you'll get
- Generous performance-based bonus plans to all eligible employees—we share in our success as one team.
- Rich medical, dental, and vision coverage.
- Generous retirement contributions with 100% immediate vesting (regardless of whether you contribute).
- Quarterly all-company wellness days where everyone takes a pause together.
- Country-specific holidays plus a day off for your birthday.
- One-time home office stipend.
- Annual professional development budget.
- Quarterly well-being stipend.
- Considerable paid parental leave.
- Employee referral bonus program.
- Other benefits (life/AD&D, disability, EAP, etc.—varies by country).
- About Mozilla
Mozilla exists to build the Internet as a public resource accessible to all because we believe that open and free is better than closed and controlled.
When you work at Mozilla, you give yourself a chance to make a difference in the lives of Web users everywhere.
And you give us a chance to make a difference in your life every single day.
Join us to work on the Web as the platform and help create more opportunity and innovation for everyone online.
Commitment to diversity, equity, inclusion, and belonging
Mozilla understands that valuing diverse creative practices and forms of knowledge are crucial to and enrich the company’s core mission.
We encourage applications from everyone, including members of all equity-seeking communities, such as (but certainly not limited to) women, racialized and Indigenous persons, persons with disabilities, persons of all sexual orientations, gender identities, and expressions.
We will ensure that qualified individuals with disabilities are provided reasonable accommodations to participate in the job application or interview process, to perform essential job functions, and to receive other benefits and privileges of employment, as appropriate.
Please contact us at hiringaccommodation@mozilla. com to request accommodation.
We are an equal opportunity employer.
We do not discriminate on the basis of race (including hairstyle and texture), religion (including religious grooming and dress practices), gender, gender identity, gender expression, color, national origin, pregnancy, ancestry, domestic partner status, disability, sexual orientation, age, genetic predisposition, medical condition, marital status, citizenship status, military or veteran status, or any other basis covered by applicable laws.
Mozilla will not tolerate discrimination or harassment based on any of these characteristics or any other unlawful behavior, conduct, or purpose.
- Group: C
- #LI-REMOTE
Hiring Ranges
- Remote UK
- £81,000
- £108,000
- GBP
Staff Security Engineer, GRC employer: Mozilla
At Mozilla Foundation, we pride ourselves on being a people-first employer that champions creativity and innovation in technology. Our remote work culture fosters autonomy and collaboration, allowing you to thrive while contributing to meaningful projects that shape the future of technology governance. With a commitment to employee growth and a focus on impactful global engagements, joining our team means being part of a mission-driven organisation that values your insights and expertise.
StudySmarter Expert Advice🤫
We think this is how you could land Staff Security Engineer, GRC
✨Get Involved in the Cybersecurity Community
Diving into the cybersecurity community is key for landing that full-time gig. Join forums like Reddit's r/cybersecurity or attend local meetups to connect with industry veterans and other job seekers. Networking is everything in this field—don’t just be a passive lurker!
✨Show Off Your Skills with Capture the Flag Competitions
Participate in Capture the Flag (CTF) competitions; these are not just a fun way to boost your skills but also a chance to showcase your talent to potential employers. Many companies, including Mozilla, love seeing candidates who actively engage in these challenges.
✨Tailor Your Online Presence
Make sure your LinkedIn and any professional profiles reflect your cybersecurity expertise. Share your projects, whether they’re personal or from a previous role, to catch the eye of hiring managers. This is how they’ll find your passion and commitment to the field!
✨Apply Directly Through Mozilla
Don’t forget to head straight to our website and check out any openings for cybersecurity roles at Mozilla. Applying directly can sometimes give you an edge, especially if you can mention that you've been following our work or engaging in the community.
We think you need these skills to ace Staff Security Engineer, GRC
Some tips for your application 🫡
Show off your technical skills:In cybersecurity, it's crucial to highlight your technical prowess. Make sure your CV showcases specific skills like network security, penetration testing, or threat analysis. If you have relevant certifications (like CEH or CISSP), pop those on the front page to grab attention!
Tailor your portfolio for the role:Even for a full-time role, a portfolio can set you apart. If you've worked on any cybersecurity projects—be it CTF challenges, security assessments, or research papers—include these in your application. This demonstrates not just your skills, but also your hands-on experience!
Use real-world examples:When writing your cover letter, don’t just stick to your qualifications. Share real-world examples of how you’ve tackled security issues or vulnerabilities. This gives the hiring team at Mozilla insight into your practical problem-solving abilities and makes your application memorable.
Demonstrate your passion for cybersecurity:Cybersecurity is an ever-evolving field, so show us that you’re always learning! Mention any recent courses, webinars, or industry events you’ve attended. This not only exhibits your enthusiasm but also signals to Mozilla that you’re committed to staying ahead in the game.
How to prepare for a job interview at Mozilla
✨Sharpen Your Technical Skills
For a role in cybersecurity, it’s essential to be up-to-date with the latest tools and techniques. Brush up on your knowledge of firewalls, intrusion detection systems, and vulnerability assessment tools. Be ready to discuss specific scenarios where you’ve applied these skills, as hands-on experience can really set us apart in interviews.
✨Prepare for Scenario-Based Questions
Expect the interviewers at Mozilla to throw in some hypothetical situations to see how you’d handle them. Think about common security breaches or incidents and be prepared to explain how you would respond. This not only shows your problem-solving skills but also your understanding of real-world cybersecurity challenges.
✨Highlight Your Certifications
Certifications like CompTIA Security+, CISSP, or CEH can give you a significant edge in a full-time role in cybersecurity. Make sure to mention these during your interview and be prepared to discuss what you learned through those certifications and how they relate to the position at Mozilla.
✨Show Your Passion for Cybersecurity
Since you’re going for a full-time gig, showing genuine enthusiasm for the field can make all the difference. Share any personal projects, blogs, or communities you’re part of that relate to cybersecurity. This not only showcases your passion but also your commitment to staying engaged in this ever-evolving field.