Similar Jobs
See allSenior InfoSec GRC Analyst
Camunda
Global
ISO 27001
SOC 2
GRC
Senior Information Security Specialist
Secfix
Europe
ISO 27001
GRC
Cloud Security
Information Security Lead
Partner Company
Ireland
Information Security
GRC
ISO 27001
Senior GRC Analyst
Compyl
Global
GRC
Audit
Risk Assessment
Compliance Manager
10a Labs
US
Compliance
SOC 2
GDPR
About the role:
- This role is part of the Governance, Risk & Compliance (GRC) function within Mozilla's Security team.
- You will maintain and advance Mozilla's ISMS and support ISO 27001 and SOC 2 Type 2 compliance programs.
What you'll do:
- Maintain and mature the ISMS, including the Statement of Applicability, risk treatment plans, and Management Review Meetings.
- Support ISO 27001 and SOC 2 Type 2 audit execution, from scoping to evidence preparation and resolving findings.
- Lead the policy program and support compliance scaling across products and business units.
What you'll bring:
- 5+ years in information security, GRC, or compliance-focused roles.
- Deep familiarity with ISO 27001 and SOC 2 Trust Services Criteria.
- Excellent cross-functional collaboration skills and ability to operate independently.
What you'll get:
- Generous performance-based bonus plans.
- Rich medical, dental, and vision coverage.
- Generous retirement contributions with immediate vesting, plus professional development budget and home office stipend.
Mozilla Corporation
Mozilla Corporation is a non-profit-backed tech company behind Firefox, focused on making the internet better. With 225+ million monthly users, it is a wholly owned subsidiary of the Mozilla Foundation, promoting privacy, AI, and open-source.