Staff Security Engineer
Mozilla
Staff Security Engineer
Remote US
Mozilla Corporation is the non-profit-backed technology company that has shaped the internet for the better over the last 25 years. We make pioneering brands like Firefox, the privacy-minded web browser. Now, with more than 225 million people around the world using our products each month, we're shaping the next 25 years of technology and helping to reclaim an internet built for people, not companies. Our work focuses on diverse areas including AI, social media, security and more. And we're doing this while never losing our focus on our core mission – to make the internet better for people.
The Mozilla Corporation is wholly owned by the non-profit 501(c) Mozilla Foundation. This means we aren't beholden to any shareholders — only to our mission. Along with thousands of volunteer contributors and collaborators all over the world, Mozillians design, build and distribute open-source software that enables people to enjoy the internet on their terms.
About This Team And Role
This role is part of the Governance, Risk & Compliance (GRC) function within Mozilla's Security team. The Security team supports Product, Enterprise, and GRC functions across the organization, aligned with the mission to build a safe and secure internet. This role is responsible for maintaining and advancing Mozilla's Information Security Management System (ISMS) and supporting our ISO 27001 and SOC 2 Type 2 compliance programs — from policy and control design through audit readiness and certification.
The ideal candidate has hands-on experience across the full breadth of a compliance program, is comfortable building process where none yet exists, and works well with a wide range of cross-functional stakeholders.
What You'll Do
- Maintain and mature the ISMS, including the Statement of Applicability (SoA), risk treatment plans, and the Management Review Meeting (MRM) process and cadence.
- Support ISO 27001 and SOC 2 Type 2 audit execution—helping determine scope, preparing evidence and narrative artifacts, participating in auditor interviews and walkthroughs, and resolving auditor findings.
- Contribute to the SOC 2 System Description and other audit-specific narrative documentation, ensuring they accurately reflect the organization's actual control environment.
- Track gaps and remediation efforts arising from readiness assessments and audits.
- Lead the policy program—driving policy creation, revision, and cross-functional review cycles to keep the security policy set current, enforceable, and audit-ready.
- Support compliance scaling as additional products or business units pursue readiness assessments and certification.
- Support the internal audit function, partnering with internal or third-party resources as needed to meet ISO 27001's internal audit requirements.
- Partner closely with Engineering, IT, Legal, Privacy, People teams, and product leadership to gather evidence, drive control ownership, and translate compliance requirements into practical, adoptable practices.
- Advise the GRC manager and broader Security leadership on audit risk, certification readiness, and compliance program strategy.
What You'll Bring
- 5 years of experience in information security, GRC, or compliance-focused roles.
- Deep familiarity with ISO 27001 and SOC 2 Trust Services Criteria, gained through meaningful involvement in audits from readiness through certification.
- Comfort operating across the full breadth of an ISMS—SoA maintenance, Management Review Meetings, and System Description authorship.
- Demonstrated experience writing and revising security policies, including running cross-functional review cycles to gain organization-wide buy-in and adoption.
- Experience tracking gaps and remediation plans and connecting that work to an organization's broader compliance and risk program.
- Excellent cross-functional collaboration skills—comfortable working with engineers, product managers, legal, and executive stakeholders, and able to translate compliance requirements into practical, actionable workflows.
- Ability to ramp up quickly and operate with a high degree of independence.
- Comfort building processes where none yet exist.
- Strong written and verbal communication skills; ability to represent Mozilla credibly and confidently in front of external auditors.
- Relevant industry certifications (e.g., CISA, CISSP, ISO 27001 Lead Auditor/Implementer) are a plus.
Commitment To Our Values
- Welcoming differences
- Being relationship-minded
- Practicing responsible participation
- Having grit
What You'll Get
- Generous performance-based bonus plans to all eligible employees—we share in our success as one team.
- Rich medical, dental, and vision coverage.
- Generous retirement contributions with 100% immediate vesting (regardless of whether you contribute).
- Quarterly all-company wellness days where everyone takes a pause together.
- Country-specific holidays plus a day off for your birthday.
- One-time home office stipend.
- Annual professional development budget.
- Quarterly well-being stipend.
- Considerable paid parental leave.
- Employee referral bonus program.
- Other benefits (life/AD&D, disability, EAP, etc.—varies by country).
Mozilla exists to build the Internet as a public resource accessible to all because we believe that open and free is better than closed and controlled. When you work at Mozilla, you give yourself a chance to make a difference in the lives of Web users everywhere. And you give us a chance to make a difference in your life every single day. Join us to work on the Web as the platform and help create more opportunity and innovation for everyone online.
Commitment to diversity, equity, inclusion, and belonging
Mozilla understands that valuing diverse creative practices and forms of knowledge are crucial to and enrich the company's core mission. We encourage applications from everyone, including members of all equity-seeking communities, such as (but certainly not limited to) women, racialized and Indigenous persons, persons with disabilities, persons of all sexual orientations, gender identities, and expressions.
We will ensure that qualified individuals with disabilities are provided reasonable accommodations to participate in the job application or interview process, to perform essential job functions, and to receive other benefits and privileges of employment, as appropriate. Please contact us at View email address on click.appcast.io to request accommodation.
We are an equal opportunity employer. We do not discriminate on the basis of race (including hairstyle and texture), religion (including religious grooming and dress practices), gender, gender identity, gender expression, color, national origin, pregnancy, ancestry, domestic partner status, disability, sexual orientation, age, genetic predisposition, medical condition, marital status, citizenship status, military or veteran status, or any other basis covered by applicable laws. Mozilla will not tolerate discrimination or harassment based on any of these characteristics or any other unlawful behavior, conduct, or purpose.
Group: C
#LI-REMOTE
Req ID: R3197
Hiring Ranges:
US Tier 1 Locations $163,000 - $218,000 USD
US Tier 2 Locations $150,000 - $200,000 USD
US Tier 3 Locations $139,000 - $185,000 USD
- ...and colleagues. Those stories are part of what makes this such a special place to work.Job OverviewMacy’s is seeking a Staff Information Security Engineer to join its Cloud Security team. This position plays a pivotal role in designing, implementing, and operating secure...SuggestedWork experience placementFlexible hoursShift work
$210k - $234.1k
...few technology companies ever operate at.Security at Compass International HoldingsThe... ...estates in the industry. We are hands-on engineers who build security as a service: secure-... ...Engineering, rather than gatekeeping. As a Staff Security Engineer, you are empowered to...SuggestedMinimum wageWork experience placementFlexible hours$204k - $240k
...making a rewarding impact and Keeping Commerce Human.Salary Range:$204,000.00 - $240,000.00What's the role?Etsy is seeking a Staff Security Engineer to join our Security Operations team. As part of the larger Security org, this team plays a pivotal role in protecting and...SuggestedFull timeWork at officeLocal areaVisa sponsorshipFlexible hours$127.6k - $206.53k
...that drives great outcomes.Job SummaryThe TeamInformation Security - We’re not your ordinary Information Security team. We’... ...front line of defense against cyberattacks.Job SummaryAs a Staff Network Security Engineer on our Enterprise Security team, you will play a critical...SuggestedFull timeWork at officeVisa sponsorshipWork visa- ...impossible at record breaking speeds.About You and The Role Product security at Zipline protects systems that directly affect safety,... ...infrastructure, autonomy/embedded, and field-ops teams. Expect hands-on engineering work, prioritized ownership of specific services, and a...SuggestedLocal area
$189k - $303k
...safer, get crucial goods where they need to go, and make mobility more efficient and accessible for all. We’re searching for a Staff Security Engineer, Enterprise Security Architecture.This position is open to the following office locations: Mountain View, San Francisco,...Work at officeLocal area3 days per week$210k - $260k
...journey toward becoming the world's top retail-focused trading platform in the world. What you'll do:We're looking for aStaff Security Engineer, Application Security to help scale and mature our security program. You'll own key security domains and initiatives end-to-end...Work at officeRemote workWorldwideMonday to FridayFlexible hours$232k - $290k
...see your impact and unlock incredible career growth opportunities, join us, and build real world value.THE WORK:As a Senior Staff Security Engineer focused on AI Security, you will be Ripple's deepest technical expert at the intersection of artificial intelligence and...Full timeWork at officeLocal area- P-1528As a Staff Security Assurance Engineer within the Security Assurance Team, you will help lead high-visibility security compliance implementation initiatives. Reporting directly to the Senior Director, you will serve as a strategic catalyst for these programs, ensuring...WorldwideRelocation
$262k - $364k
...next wave of AI-driven attacks.Lead the development of unified security detection platforms and operational standards, driving... ...adoption of automated detection and response tools across all Cloud engineering teams.Pioneer and integrate advanced Artificial Intelligence (...$175k - $270k
...build what’s next.About the teamAirwallex’s Information Security team partners closely with engineering, IT, and other stakeholders to protect our systems,... ...how we operate, not treated as a blocker.Your roleAs a Staff Corporate Security Engineer, you will be a critical part...Temporary workLocal areaWorldwide$210k - $255k
...with us at Crusoe.About This RoleCrusoe is building the world’s favorite AI-first cloud infrastructure. We are seeking a Staff Corporate Security Engineer to act as the principal architect for our corporate security posture.In this role, you will move beyond tactical tool...Temporary work- Austin, TXTechnology - Security /RemoteThe Staff Security Engineer will be responsible for designing, implementing, and maintaining security identity services that support our business. You will understand data and automation are important ingredients to our mission and...Temporary workRemote workFlexible hours
$169k - $199k
...Expectations are high, and so are the rewards. About the TeamThe Security Operations (SecOps) team at Robinhood proactively... ...standard across the cybersecurity industry!About the RoleAs a Staff Security Engineer (IC6) on the Detection & Response team, you will drive our...Work at officeFlexible hoursShift work3 days per week$188k - $275k
...7, CoreWeave became a publicly traded company (Nasdaq: CRWV) in March 2025. Learn more at .What You’ll Do:We are seeking a Staff Security Engineer to lead the most complex technical work in CoreWeave’s Vulnerability Management program. You will design and implement scalable...Permanent employmentFull timeTemporary workCasual workWork at officeFlexible hours$169k - $199k
...standards, clear accountability, and a strong focus on security and ethics in everything we build!The Red Team’s mission... ...simulating adversary behavior and testing defenses. As a Staff Offensive Security Engineer, you will plan and execute security assessments across applications...Work at officeShift work3 days per week$152k - $248k
...their information every day and we take their security seriously. Our core value of putting our members... ...in automation and focus on high impact engineering projects that detect security risks. About the role:As a Staff Security Engineer on the Platform & Product Security...For contractorsWork experience placementWork at officeFlexible hours$178.8k - $257.2k
...brighter, more sustainable future while tackling the most pressing challenges of the 21st century.We are looking for a Senior Staff Security Engineer to join our team in one of today’s most exciting technologies. This role will report to our Chief Security Officer and...Full timeWork at officeWorldwideShift work$155.8k - $224.2k
...create a brighter, more sustainable future while tackling the most pressing challenges of the 21st century.We are looking for a Staff Security Engineer to join our team in one of today’s most exciting technologies. This role will report to our Chief Security Officer and...Full timeWork at officeWorldwide- ...from. Our success will be built on amazing colleagues, working together.Job OverviewThe Staff, Vulnerability Engineer is a specialist in Penetration Testing and Information Security Vulnerability Management. This hands-on role involves conducting penetration tests and vulnerability...Work at office
- ...over activity. We don’t just ship features; we solve hard problems to help creatives do their best work.As our first Principal Security Engineer, you will own the security posture for the entire organization—from the cloud to the colo, and from the training cluster to...Full timeWork at officeRelocation
- ...every step of the way. Join us to invest in yourself, your career, and the financial world.The role: We’re seeking a Staff Security Detection Engineer to build and mature SoFi’s machine learning-driven detection and anomaly detection program. You will own the detection...Remote work
- Job Description:The Security Research and Response team in Arm's Architecture and Technology Group is seeking a highly skilled SoC Offensive Security Staff Engineer to apply an attacker's mindset to Arm's next-generation solutions, identifying design and integration-level...Work at officeLocal area
$232k - $310k
...see your impact and unlock incredible career growth opportunities, join us, and build real world value.THE WORK:As a Senior Staff Security Engineer, you will be one of Ripple's most senior technical security practitioners, operating at the intersection of application...Full timeWork at officeLocal area$168.56k - $231.77k
We’re looking for a Staff Security Engineer to join Procore’s Security Engineering team as a foundational technical leader. In this role, you won’t just be implementing security controls—you will be designing the next generation of autonomous defense. Your mission is to...Full timeContract workWork at officeLocal areaShift work$212k - $265k
...ready to see your impact and unlock incredible career growth opportunities, join us, and build real world value.THE WORK:As a Staff Security Engineer within the Secure Digital Asset Operations (SDAO) function, you will collaborate with leadership and cross-functional...Full timeWork at officeLocal area$212k - $265k
...our promise to customers sending money globally, providing secure, simple, and reliable ways to manage their money, ensuring... ...program backbone connecting the pillars.We're looking for a Staff Security Engineer to join Detection & Response as a senior individual contributor...Full timeWork at officeWorldwideFlexible hours3 days per week- This is a hybrid role (3 days in office / 2 days remote).About your team:We seek a motivated Incident Responder to join our Security Operations team. You will assist in monitoring, detecting, analyzing, and responding to security events and incidents. This role is ideal...Work at officeRemote work
$134k - $184.8k
Secure Every Identity, from AI to HumanIdentity is the key to unlocking the potential of... ...and Intelligence (TDI) organization is the engine that powers Okta's global workforce,... ...our employees to do their best work.The Staff Security Engineer OpportunityWe are seeking...Local areaWorldwideFlexible hoursShift work$160k - $190k
.... About the Role, Mission or Department OverviewThe newsroom security engineer within Cybersecurity is a hands-on contributor who researches... ...security solutions that strengthen protections for newsroom staff while supporting efficient journalistic workflows.Lead technical...Work at officeLocal areaFlexible hours
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Staff Security Engineer. Be the first to apply!
- software engineer staff United States
- assistant engineer United States
- engineering aide United States
- staff engineer United States
- staff security engineer United States
- assistant mechanical engineer United States
- assistant engineering manager United States
- staff qa engineer United States
- assistant project engineer United States
- information technology support assistant United States
