Staff Security GRC Engineer in Leverkusen

Staff Security GRC Engineer in Leverkusen

Leverkusen Vollzeit Kein Homeoffice möglich
M

Overview

In this role, you will advance Mozilla’s Information Security Management System (ISMS) and support ISO 27001 and SOC 2 Type 2 programs. You’ll work with engineering, legal, privacy, and product leadership to translate compliance requirements into practical practices. The role focuses on policy management, audit readiness, evidence collection, and remediation tracking to ensure the security posture scales with the business. You’ll drive cross-functional policy development and partner with stakeholders to sustain certification readiness and control ownership. A meaningful hook is shaping security governance in a global, mission-driven tech environment.

Leistungen / Benefits

  • bonus plans tied to performance
  • medical/dental/vision coverage
  • retirement contributions with 100% vesting
  • home office stipend
  • professional development budget
  • well-being stipend

Verantwortungsbereiche

  • Maintain and mature the ISMS, including SoA, risk treatment plans, and MRM cadence
  • Support ISO 27001 and SOC 2 Type 2 audit execution from scoping to evidence gathering and auditor interviews
  • Contribute to SOC 2 System Description and audit narratives reflecting actual control environment
  • Track gaps and remediation from readiness assessments and audits
  • Lead policy program, driving creation, revision, and cross-functional reviews
  • Support scaling of compliance as new products/business units pursue readiness and certification
  • Coordinate internal audits and partner with internal/third-party resources
  • Collaborate with Engineering, IT, Legal, Privacy, People, and product leadership to drive evidence and practical workflows
  • Advise GRC leadership on audit risk, readiness, and compliance strategy

Zentrale Anforderungen

  • 5 years of experience in information security, GRC, or compliance-focused roles
  • Deep familiarity with ISO 27001 and SOC 2 Trust Services Criteria through audits from readiness to certification
  • Experience with ISMS breadth: SoA maintenance, MRM, System Description authorship
  • Proven ability to write and revise security policies and manage cross-functional reviews
  • Experience tracking gaps and remediation in relation to broader risk and compliance programs
  • Excellent cross-functional collaboration and written/verbal communication skills for external audits
  • Ability to ramp up quickly and work independently; comfortable creating processes where none exist
  • Security certifications (e.g., CISA, CISSP, ISO 27001 Lead Auditor/Implementer) are a plus
  • Commitment to Mozilla values: diversity, collaboration, responsible participation, grit
  • cross-functional collaboration
  • strong written and verbal communication
  • independence and initiative
  • ISO 27001
  • SOC 2 Type 2
  • SoA maintenance

Staff Security GRC Engineer in Leverkusen Arbeitgeber: Mozilla Corporation

Mozilla ist ein hervorragender Arbeitgeber, der seinen Mitarbeitern die Möglichkeit bietet, an einer bedeutenden Mission zu arbeiten: das Internet für alle zugänglich und sicher zu gestalten. Mit einem starken Fokus auf Vielfalt, Gleichheit und Inklusion fördert Mozilla eine offene und unterstützende Arbeitskultur, in der Mitarbeiter durch großzügige Leistungen wie leistungsbasierte Boni, umfassende Gesundheitsversorgung und berufliche Entwicklungsmöglichkeiten wachsen können. Die Remote-Arbeitsoption in Deutschland ermöglicht es den Mitarbeitern, flexibel zu arbeiten und gleichzeitig Teil eines globalen Teams zu sein, das sich leidenschaftlich für die Verbesserung des Internets einsetzt.

M

Kontaktdaten:

Mozilla Corporation Recruiting-Team