Назад
Company hidden
2 дня назад

Staff Security Engineer (GRC)

65 000 - 87 000
Формат работы
remote (только France)
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
France/UK/US +2 еще
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Staff Security Engineer (GRC) (ISO 27001/SOC 2): Maintaining and advancing Mozilla's Information Security Management System and compliance programs with an accent on audit readiness, policy governance, and risk remediation. Focus on designing controls, preparing audit evidence, resolving findings, and building scalable compliance processes across cross-functional teams.

Location: Remote France

Salary: €65,000–€87,000 EUR per year

Company

hirify.global is a non-profit-backed technology company that develops open-source products such as Firefox to support a safer, more accessible, and people-centered internet.

What you will do

  • Maintain and mature the Information Security Management System, including the Statement of Applicability, risk treatment plans, and Management Review Meeting process.
  • Support ISO 27001 and SOC 2 Type 2 audits by defining scope, preparing evidence and narratives, participating in auditor interviews, and resolving findings.
  • Maintain the SOC 2 System Description and other audit documentation so they accurately reflect the control environment.
  • Lead security policy creation, revision, and cross-functional review cycles.
  • Track compliance gaps and remediation efforts while supporting readiness assessments, certification scaling, and internal audits.
  • Partner with Engineering, IT, Legal, Privacy, People, product leadership, and Security leadership on control ownership and compliance strategy.

Requirements

  • At least 5 years of experience in information security, GRC, or compliance-focused roles.
  • Deep familiarity with ISO 27001 and SOC 2 Trust Services Criteria, including audit readiness and certification.
  • Experience across the full ISMS lifecycle, including SoA maintenance, Management Review Meetings, and System Description authorship.
  • Experience writing and revising security policies, coordinating cross-functional reviews, and tracking remediation plans.
  • Strong collaboration, written communication, verbal communication, and external auditor representation skills.
  • Ability to work independently and build processes where none yet exist.

Nice to have

  • Relevant certifications such as CISA, CISSP, or ISO 27001 Lead Auditor/Implementer.

Culture & Benefits

  • Performance-based bonus plan and country-specific benefits.
  • Medical, dental, and vision coverage.
  • Retirement contributions with immediate vesting.
  • Country-specific holidays, birthday leave, wellness days, and paid parental leave.
  • Home office stipend, professional development budget, and well-being stipend.
  • Additional benefits may include life and disability coverage, employee assistance programs, and referral bonuses.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →