Remote Jobs RockRemote Jobs Rock

Staff Security GRC Engineer

🕒 3 days ago
Information SecurityGovernance, Risk & ComplianceISO 27001SOC 2

📜 Description

  • Maintain and mature the ISMS, including the Statement of Applicability (SoA), risk treatment plans, and the Management Review Meeting (MRM) process and cadence.
  • Support ISO 27001 and SOC 2 Type 2 audit execution—helping determine scope, preparing evidence and narrative artifacts, participating in auditor interviews and walkthroughs, and resolving auditor findings.
  • Contribute to the SOC 2 System Description and other audit-specific narrative documentation, ensuring they accurately reflect the organization's actual control environment.
  • Track gaps and remediation efforts arising from readiness assessments and audits.
  • Lead the policy program—driving policy creation, revision, and cross-functional review cycles to keep the security policy set current, enforceable, and audit-ready.
  • Support compliance scaling as additional products or business units pursue readiness assessments and certification.

🛠️ Requirements

  • 5 years of experience in information security, GRC, or compliance-focused roles.
  • Deep familiarity with ISO 27001 and SOC 2 Trust Services Criteria, gained through meaningful involvement in audits from readiness through certification.
  • Comfort operating across the full breadth of an ISMS—SoA maintenance, Management Review Meetings, and System Description authorship.
  • Demonstrated experience writing and revising security policies, including running cross-functional review cycles to gain organization-wide buy-in and adoption.
  • Experience tracking gaps and remediation plans and connecting that work to an organization's broader compliance and risk program.
  • Excellent cross-functional collaboration skills—comfortable working with engineers, product managers, legal, and executive stakeholders, and able to translate compliance requirements into practical, actionable workflows.
  • Ability to ramp up quickly and operate with a high degree of independence.
  • Comfort building processes where none yet exist.
  • Strong written and verbal communication skills; ability to represent Mozilla credibly and confidently in front of external auditors.
  • Relevant industry certifications (e.g., CISA, CISSP, ISO 27001 Lead Auditor/Implementer) are a plus.

Benefits

  • Generous performance-based bonus plans to all eligible employees—we share in our success as one team.
  • Rich medical
  • Dental
  • Vision coverage
  • Generous retirement contributions with 100% immediate vesting (regardless of whether you contribute).
  • Quarterly all-company wellness days where everyone takes a pause together.
  • One-time home office stipend.
  • Annual professional development budget.
  • Quarterly well-being stipend.
Dragos

Senior Threat Detection Engineer

Dragos👥 201 - 500 employees🏢 Computer & Network Security
🔥 2 hours ago

Dragos is seeking a Senior Detection Engineer to join our Detection Engineering team, which plays a pivotal role in our customers' ability to identify and respond to threats targeting their OT environments by turning cyber threat.

ICS CybersecurityThreat DetectionCyber Threat IntelligenceNetwork Packet Analysis

Trusted by Remote Workers