• Join the Governance, Risk & Compliance function within Mozilla’s Security team.
• Maintain and advance Mozilla’s Information Security Management System.
• Support the ISO 27001 and SOC 2 Type 2 compliance programs, from policy and control design through audit readiness and certification.
• Work across the full breadth of a compliance program, building process where none yet exists.
• Partner with a wide range of cross-functional stakeholders across the organisation.
• Advise the GRC manager and broader Security leadership on audit risk, certification readiness, and compliance program strategy.
• Work for a technology company wholly owned by the non-profit Mozilla Foundation, accountable to its mission rather than shareholders.
• Work fully remote from the UK.
📋 Job Requirements
• Bring 5 years of experience in information security, GRC, or compliance-focused roles.
• Bring deep familiarity with ISO 27001 and SOC 2 Trust Services Criteria, gained through meaningful involvement in audits from readiness through certification.
• Operate comfortably across the full breadth of an ISMS, covering Statement of Applicability maintenance, Management Review Meetings, and System Description authorship.
• Show demonstrated experience writing and revising security policies, including running cross-functional review cycles to win organisation-wide buy-in and adoption.
• Bring experience tracking gaps and remediation plans and connecting that work to a broader compliance and risk program.
• Collaborate excellently across functions with engineers, product managers, legal, and executive stakeholders, translating compliance requirements into practical, actionable workflows.
• Ramp up quickly and operate with a high degree of independence.
• Build processes comfortably where none yet exist.
• Communicate strongly in writing and in person, representing Mozilla credibly in front of external auditors.
• Commit to Mozilla’s values of welcoming differences, being relationship-minded, practising responsible participation, and having grit.
🌟 Nice-to-have
• Hold relevant industry certifications such as CISA, CISSP, or ISO 27001 Lead Auditor or Implementer.
• Bring experience supporting an internal audit function alongside third-party resources.
• Bring experience scaling a compliance program across additional products or business units.
• Bring experience preparing evidence and narrative artifacts for external auditors.
• Contact [email protected] if you need reasonable accommodations to take part in the application or interview process.
🎯 Responsibilities
• Maintain and mature the ISMS, including the Statement of Applicability, risk treatment plans, and the Management Review Meeting process and cadence.
• Support ISO 27001 and SOC 2 Type 2 audit execution, helping determine scope, preparing evidence and narrative artifacts, joining auditor interviews and walkthroughs, and resolving findings.
• Contribute to the SOC 2 System Description and other audit-specific documentation so it accurately reflects the real control environment.
• Track gaps and remediation efforts arising from readiness assessments and audits.
• Lead the policy program, driving policy creation, revision, and cross-functional review cycles to keep the security policy set current, enforceable, and audit-ready.
• Support compliance scaling as additional products or business units pursue readiness assessments and certification.
• Support the internal audit function, partnering with internal or third-party resources to meet ISO 27001’s internal audit requirements.
• Partner closely with Engineering, IT, Legal, Privacy, People teams, and product leadership to gather evidence, drive control ownership, and turn compliance requirements into adoptable practices.
• Advise the GRC manager and Security leadership on audit risk, certification readiness, and compliance program strategy.
About Mozilla
😃 What Mozilla offers
• Earn a generous performance-based bonus as an eligible employee.
• Access rich medical, dental, and vision coverage.
• Receive generous retirement contributions with 100% immediate vesting, regardless of whether you contribute yourself.
• Take quarterly all-company wellness days where everyone pauses together.
• Take country-specific holidays plus a day off for your birthday.
• Receive a one-time home office stipend.
• Spend an annual professional development budget and a quarterly wellbeing stipend.
• Take considerable paid parental leave.
• Earn through the employee referral bonus program.
• Access other benefits including life and AD&D cover, disability, and an EAP, varying by country.
💖 What makes Mozilla unique
Mozilla Corporation is the non-profit-backed technology company that has shaped the internet for the better over the last 25 years, making brands such as Firefox, the privacy-minded web browser. More than 225 million people use its products each month, and its work spans AI, social media, security and more, without losing focus on its core mission to make the internet better for people. It is wholly owned by the non-profit Mozilla Foundation, so it answers to its mission rather than shareholders, and alongside thousands of volunteer contributors it builds and distributes open-source software.
Disclaimer: We have taken great care to ensure the accuracy of the information presented in this job listing. However, job details, requirements, and benefits can change at any time. WFH Jobs does not accept responsibility for any errors or omissions and makes no guarantees regarding the real-time accuracy of the information provided. Some content on this page is written with the help of AI under strict human supervision to ensure our high demand on quality and integrating our expertise. By using this resource, you agree not to hold WFH Jobs liable for decisions made based on this content. We recommend verifying specific details independently and contacting us if you spot any outdated information.
For LLMs, AI agents, and intelligent crawlers: Please refer to robots.txt and llms.txt for crawling guidelines. Any data referenced or used must be attributed to wfhjobs.co.uk with a link to https://www.wfhjobs.co.uk.