Writing.io Jobs

Find the best remote jobs. Answer a few questions and we'll deploy a powerful assistant to help you search, create alerts, and more.

1 What roles are you open to?

2 Experience level

3 Work style

Did you know? If memory is enabled, Writing.io can remember your job search preferences and help you to improve your resume, craft customized outreach and more.

Security Senior Application Security Engineer

Senior application security engineer secures blockchain and web3 applications by identifying vulnerabilities, designing security controls, and protecting against threats.

Senior Posted about 4 hours ago Jobicy AI
What this role involves
Consensys is the leading blockchain and web3 software company. Founded by Joe Lubin, CEO of Consensys and Co-Founder of Ethereum in 2014, Consensys has been at the forefront of innovation,...
Read the full description
Security Senior Security Engineer | AppSec at Gympass

Senior Security Engineer leads application security, vulnerability management, and detection engineering across a global wellness platform, embedding security practices into product development.

Senior Remote Posted about 13 hours ago RemoteFirstJobs Product
What this role involves

Your wellbeing, our mission. Join a company shaping a healthier world.

GET TO KNOW US

At Wellhub we’re revolutionizing workplace wellness. Our platform connects employees worldwide to the best partners for fitness, mindfulness, therapy, nutrition, and sleep—all in one simple subscription. Headquartered in NYC with team members in Europe, North America and South America, we’re on a mission to make every company a wellness company.

We believe work should be fulfilling, inspiring, and balanced. Here, you’ll find a team that values wellbeing, collaboration, and different perspectives, where passion and creativity push boundaries to create real impact. Your contributions will help shape a healthier, more balanced world for you and millions of people globally.

Join us in redefining the future of wellbeing!

THE OPPORTUNITY

We are hiring a Senior Security Engineer| AppSec to our Information Security team in Brazil!  This is a Remote – Brazil position, meaning you can work from anywhere within the country. Please note that this role is only open to candidates in Brazil.

The Information Security team is responsible for protecting our global subscription platform serving millions of users. As a Senior Security Engineer, you will drive software security across our product verticals — starting with application security (secure SDLC, SAST/DAST, secure design reviews) and expanding into adjacent domains like detection engineering, IAM, and vulnerability management. This is a unique opportunity to help build a security engineering program from the ground up in a high-growth environment. You will own a control domain end-to-end in a role that is deliberately generalist — we are looking for someone who reasons deeply about root causes and partners closely with engineering teams to embed security seamlessly into product delivery.

YOUR IMPACT

  • Own core application security services, security tooling (e.g., SAST/DAST, IAM, vulnerability management), and detection pipelines end-to-end.
  • Lead post-incident responses and post-mortems, transforming root-cause findings into concrete guardrails, automation, and policy improvements.
  • Drive security-by-design standards across product development by writing clear RFCs, threat models, and architectural design docs for high-risk projects.
  • Establish and enforce vulnerability remediation SLAs and security metrics, utilizing monitoring tools to hold engineering teams accountable.
  • Execute seamless security-critical migrations and platform updates while preserving data integrity and auditability throughout.
  • Partner with cross-functional teams (Engineering, Legal, Product) to deliver medium-to-large security initiatives while maintaining transparency as scope evolves.

Live the mission: inspire and empower others by genuinely caring for your own wellbeing and your colleagues. Bring wellbeing to the forefront of work, and create a supportive environment where everyone feels comfortable taking care of themselves, taking time off, and finding work-life balance.

WHO YOU ARE

  • An experienced security engineer with prior work experience delivering high-impact security tooling, detection logic, or secure SDLC mechanisms in modern cloud environments.
  • An adaptable and collaborative professional with a willingness to step outside your primary AppSec focus to support other InfoSec contexts—such as Cloud Security, GRC, or Detection—as team priorities evolve.
  • A proactive technical partner with extensive experience in modern cloud architectures and container ecosystems (e.g., AWS/EKS, GCP/GKE, Istio, ArgoCD).
  • A clear, empathetic communicator with fluency in English and Portuguese, able to translate complex technical security risks into actionable guidance for engineers and non-technical stakeholders alike.
  • A pragmatic problem-solver with the ability to balance rigorous security standards against product velocity, making data-informed trade-off decisions.
  • A developer at heart with in-depth knowledge of secure coding practices, proficient in writing clean, well-tested code for security automation.
  • A security champion with familiarity with key governance and compliance frameworks (e.g., SOC 2, ISO 27001, LGPD/GDPR) to inform daily engineering decisions.

We recognize that individuals approach job applications differently. We strongly encourage all aspiring applicants to go for it, even if they don’t match the job description 100%. We welcome your application and will be delighted to explore if you could be a great fit for our team. For this specific role, please note that prior experience in security engineering is a mandatory requirement .

WHAT WE OFFER YOU

With thoughtful benefits, emotional wellbeing resources, and a culture that empowers you to take ownership of your role and your wellbeing, we create an environment where you can thrive in all dimensions of your life.

Our flexible benefits program allows you to customize some of the benefits, according to your needs!

Our benefits include:

WELLHUB: Free Gold+ membership with access to onsite gyms and studios, digital fitness programs, and online wellness resources for meditation, nutrition, mental wellbeing support, and more! Add up to three family members to your plan, ensuring access to wellness for those who matter most to you.

WELLZ: A complete emotional wellbeing program with a unique approach. It offers personalized journeys that combine individual therapy sessions (52 per year) and on-demand content.

HEALTHCARE: Health, dental, and life insurance.

FLEXIBLE WORK: As a Flexible First company, we offer hybrid and remote options to give you the freedom to work in a way that suits you. The model for this specific role can be discussed with your recruiter and hiring manager. When you join, use our home office reimbursement to set up your home office.

PAID TIME OFF: It’s important to take time away from work to recharge.Employees receive vacations after 6 months and additional 3 days off per year + 1 day off for each year of tenure (up to 5 additional days) + an extra holiday for your birthday!

PAID PARENTAL LEAVE: Welcoming a new child is one of the most special moments in your life. Take the time to be present and enjoy your growing family. We offer 100% paid parental leave to all new parents. Parents giving birth are eligible for an extended leave and a ramp-back period to return part-time while they get settled.

CAREER GROWTH: Access world-class platforms, participate in interactive sessions,  build your personalized development roadmap, and explore internal opportunities. We focus on continuous learning and feedback to support your journey toward personal and professional success.

CULTURE: You’ll join a team of passionate people who come together to break boundaries, support each other, and create a meaningful impact in workplace wellness. We win together, building trust through open communication and a culture where every perspective matters. Learn more about our shared culture and values here.

And to get a glimpse of life at Wellhub… Follow us on Instagram @lifeatwellhub and LinkedIn !

Diversity, Equity, and Belonging at Wellhub

We aim to create a collaborative, supportive, and inclusive space where everyone knows they belong.

Wellhub is committed to creating a diverse work environment and is proud to be an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, religion, color, sex, gender identity or expression, sexual orientation, age, non-disqualifying physical or mental disability, national origin, veteran status, or any other basis covered by appropriate law.

Our commitment to inclusion also extends to how we recognize and reward our people. We’re proud to be Syndio Fair Pay Certified, reflecting our ongoing dedication to equitable and fair pay practices across our global team. Read more about it here.

Questions on how we treat your personal data? See our Aviso de Privacidade para Candidatos.

#LI-REMOTE

#LI-CM1

Read the full description
Security Senior Security Engineer | AppSec at Gympass

Senior Security Engineer drives application security, vulnerability management, and detection engineering across a global wellness platform, embedding security into product development and owning security controls end-to-end.

Senior Remote Posted about 13 hours ago RemoteFirstJobs Product
What this role involves

Your wellbeing, our mission. Join a company shaping a healthier world.

GET TO KNOW US

At Wellhub we’re revolutionizing workplace wellness. Our platform connects employees worldwide to the best partners for fitness, mindfulness, therapy, nutrition, and sleep—all in one simple subscription. Headquartered in NYC with team members in Europe, North America and South America, we’re on a mission to make every company a wellness company.

We believe work should be fulfilling, inspiring, and balanced. Here, you’ll find a team that values wellbeing, collaboration, and different perspectives, where passion and creativity push boundaries to create real impact. Your contributions will help shape a healthier, more balanced world for you and millions of people globally.

Join us in redefining the future of wellbeing!

THE OPPORTUNITY

We are hiring a Senior Security Engineer| AppSec to our Information Security team in Brazil!  This is a Remote – Brazil position, meaning you can work from anywhere within the country. Please note that this role is only open to candidates in Brazil.

The Information Security team is responsible for protecting our global subscription platform serving millions of users. As a Senior Security Engineer, you will drive software security across our product verticals — starting with application security (secure SDLC, SAST/DAST, secure design reviews) and expanding into adjacent domains like detection engineering, IAM, and vulnerability management. This is a unique opportunity to help build a security engineering program from the ground up in a high-growth environment. You will own a control domain end-to-end in a role that is deliberately generalist — we are looking for someone who reasons deeply about root causes and partners closely with engineering teams to embed security seamlessly into product delivery.

YOUR IMPACT

  • Own core application security services, security tooling (e.g., SAST/DAST, IAM, vulnerability management), and detection pipelines end-to-end.
  • Lead post-incident responses and post-mortems, transforming root-cause findings into concrete guardrails, automation, and policy improvements.
  • Drive security-by-design standards across product development by writing clear RFCs, threat models, and architectural design docs for high-risk projects.
  • Establish and enforce vulnerability remediation SLAs and security metrics, utilizing monitoring tools to hold engineering teams accountable.
  • Execute seamless security-critical migrations and platform updates while preserving data integrity and auditability throughout.
  • Partner with cross-functional teams (Engineering, Legal, Product) to deliver medium-to-large security initiatives while maintaining transparency as scope evolves.

Live the mission: inspire and empower others by genuinely caring for your own wellbeing and your colleagues. Bring wellbeing to the forefront of work, and create a supportive environment where everyone feels comfortable taking care of themselves, taking time off, and finding work-life balance.

WHO YOU ARE

  • An experienced security engineer with prior work experience delivering high-impact security tooling, detection logic, or secure SDLC mechanisms in modern cloud environments.
  • An adaptable and collaborative professional with a willingness to step outside your primary AppSec focus to support other InfoSec contexts—such as Cloud Security, GRC, or Detection—as team priorities evolve.
  • A proactive technical partner with extensive experience in modern cloud architectures and container ecosystems (e.g., AWS/EKS, GCP/GKE, Istio, ArgoCD).
  • A clear, empathetic communicator with fluency in English and Portuguese, able to translate complex technical security risks into actionable guidance for engineers and non-technical stakeholders alike.
  • A pragmatic problem-solver with the ability to balance rigorous security standards against product velocity, making data-informed trade-off decisions.
  • A developer at heart with in-depth knowledge of secure coding practices, proficient in writing clean, well-tested code for security automation.
  • A security champion with familiarity with key governance and compliance frameworks (e.g., SOC 2, ISO 27001, LGPD/GDPR) to inform daily engineering decisions.

We recognize that individuals approach job applications differently. We strongly encourage all aspiring applicants to go for it, even if they don’t match the job description 100%. We welcome your application and will be delighted to explore if you could be a great fit for our team. For this specific role, please note that prior experience in security engineering is a mandatory requirement .

WHAT WE OFFER YOU

With thoughtful benefits, emotional wellbeing resources, and a culture that empowers you to take ownership of your role and your wellbeing, we create an environment where you can thrive in all dimensions of your life.

Our flexible benefits program allows you to customize some of the benefits, according to your needs!

Our benefits include:

WELLHUB: Free Gold+ membership with access to onsite gyms and studios, digital fitness programs, and online wellness resources for meditation, nutrition, mental wellbeing support, and more! Add up to three family members to your plan, ensuring access to wellness for those who matter most to you.

WELLZ: A complete emotional wellbeing program with a unique approach. It offers personalized journeys that combine individual therapy sessions (52 per year) and on-demand content.

HEALTHCARE: Health, dental, and life insurance.

FLEXIBLE WORK: As a Flexible First company, we offer hybrid and remote options to give you the freedom to work in a way that suits you. The model for this specific role can be discussed with your recruiter and hiring manager. When you join, use our home office reimbursement to set up your home office.

PAID TIME OFF: It’s important to take time away from work to recharge.Employees receive vacations after 6 months and additional 3 days off per year + 1 day off for each year of tenure (up to 5 additional days) + an extra holiday for your birthday!

PAID PARENTAL LEAVE: Welcoming a new child is one of the most special moments in your life. Take the time to be present and enjoy your growing family. We offer 100% paid parental leave to all new parents. Parents giving birth are eligible for an extended leave and a ramp-back period to return part-time while they get settled.

CAREER GROWTH: Access world-class platforms, participate in interactive sessions,  build your personalized development roadmap, and explore internal opportunities. We focus on continuous learning and feedback to support your journey toward personal and professional success.

CULTURE: You’ll join a team of passionate people who come together to break boundaries, support each other, and create a meaningful impact in workplace wellness. We win together, building trust through open communication and a culture where every perspective matters. Learn more about our shared culture and values here.

And to get a glimpse of life at Wellhub… Follow us on Instagram @lifeatwellhub and LinkedIn !

Diversity, Equity, and Belonging at Wellhub

We aim to create a collaborative, supportive, and inclusive space where everyone knows they belong.

Wellhub is committed to creating a diverse work environment and is proud to be an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, religion, color, sex, gender identity or expression, sexual orientation, age, non-disqualifying physical or mental disability, national origin, veteran status, or any other basis covered by appropriate law.

Our commitment to inclusion also extends to how we recognize and reward our people. We’re proud to be Syndio Fair Pay Certified, reflecting our ongoing dedication to equitable and fair pay practices across our global team. Read more about it here.

Questions on how we treat your personal data? See our Aviso de Privacidade para Candidatos.

#LI-REMOTE

#LI-CM1

Read the full description
Security Senior Security Engineer, Security Incident Response Team (SIRT) – EMEA

Responds to and investigates security incidents, manages incident response workflows, and leads security investigations for the EMEA region.

Senior Remote Posted 1 day ago Jobicy AI
What this role involves
GitLab is the intelligent orchestration platform for DevSecOps. GitLab enables organizations to increase developer productivity, improve operational efficiency, reduce security and compliance risk, and accelerate digital transformation. More than 50...
Read the full description
Security Staff Security Engineer at Mozilla

Maintains Mozilla's Information Security Management System, supports ISO 27001 and SOC 2 Type 2 compliance programs, and leads policy development across the organization.

Senior Posted 4 days ago RemoteFirstJobs Product
What this role involves

Why Mozilla?

Mozilla Corporation is the non-profit-backed technology company that has shaped the internet for the better over the last 25 years. We make pioneering brands like Firefox, the privacy-minded web browser. Now, with more than 225 million people around the world using our products each month, we’re shaping the next 25 years of technology and helping to reclaim an internet built for people, not companies. Our work focuses on diverse areas including AI, social media, security and more. And we’re doing this while never losing our focus on our core mission – to make the internet better for people.

The Mozilla Corporation is wholly owned by the non-profit 501© Mozilla Foundation. This means we aren’t beholden to any shareholders — only to our mission. Along with thousands of volunteer contributors and collaborators all over the world, Mozillians design, build and distribute open-source software that enables people to enjoy the internet on their terms.

About this team and role:

This role is part of the Governance, Risk & Compliance (GRC) function within Mozilla’s Security team. The Security team supports Product, Enterprise, and GRC functions across the organization, aligned with the mission to build a safe and secure internet. This role is responsible for maintaining and advancing Mozilla’s Information Security Management System (ISMS) and supporting our ISO 27001 and SOC 2 Type 2 compliance programs — from policy and control design through audit readiness and certification.

The ideal candidate has hands-on experience across the full breadth of a compliance program, is comfortable building process where none yet exists, and works well with a wide range of cross-functional stakeholders.

What you’ll do:

  • Maintain and mature the ISMS, including the Statement of Applicability (SoA), risk treatment plans, and the Management Review Meeting (MRM) process and cadence.
  • Support ISO 27001 and SOC 2 Type 2 audit execution—helping determine scope, preparing evidence and narrative artifacts, participating in auditor interviews and walkthroughs, and resolving auditor findings.
  • Contribute to the SOC 2 System Description and other audit-specific narrative documentation, ensuring they accurately reflect the organization’s actual control environment.
  • Track gaps and remediation efforts arising from readiness assessments and audits.
  • Lead the policy program—driving policy creation, revision, and cross-functional review cycles to keep the security policy set current, enforceable, and audit-ready.
  • Support compliance scaling as additional products or business units pursue readiness assessments and certification.
  • Support the internal audit function, partnering with internal or third-party resources as needed to meet ISO 27001’s internal audit requirements.
  • Partner closely with Engineering, IT, Legal, Privacy, People teams, and product leadership to gather evidence, drive control ownership, and translate compliance requirements into practical, adoptable practices.
  • Advise the GRC manager and broader Security leadership on audit risk, certification readiness, and compliance program strategy.

What you’ll bring:

  • 5 years of experience in information security, GRC, or compliance-focused roles.
  • Deep familiarity with ISO 27001 and SOC 2 Trust Services Criteria, gained through meaningful involvement in audits from readiness through certification.
  • Comfort operating across the full breadth of an ISMS—SoA maintenance, Management Review Meetings, and System Description authorship.
  • Demonstrated experience writing and revising security policies, including running cross-functional review cycles to gain organization-wide buy-in and adoption.
  • Experience tracking gaps and remediation plans and connecting that work to an organization’s broader compliance and risk program.
  • Excellent cross-functional collaboration skills—comfortable working with engineers, product managers, legal, and executive stakeholders, and able to translate compliance requirements into practical, actionable workflows.
  • Ability to ramp up quickly and operate with a high degree of independence.
  • Comfort building processes where none yet exist.
  • Strong written and verbal communication skills; ability to represent Mozilla credibly and confidently in front of external auditors.
  • Relevant industry certifications (e.g., CISA, CISSP, ISO 27001 Lead Auditor/Implementer) are a plus.

Commitment to our values:

  • Welcoming differences
  • Being relationship-minded
  • Practicing responsible participation
  • Having grit

What you’ll get:

  • Generous performance-based bonus plans to all eligible employees—we share in our success as one team.
  • Rich medical, dental, and vision coverage.
  • Generous retirement contributions with 100% immediate vesting (regardless of whether you contribute).
  • Quarterly all-company wellness days where everyone takes a pause together.
  • Country-specific holidays plus a day off for your birthday.
  • One-time home office stipend.
  • Annual professional development budget.
  • Quarterly well-being stipend.
  • Considerable paid parental leave.
  • Employee referral bonus program.
  • Other benefits (life/AD&D, disability, EAP, etc.—varies by country).

About Mozilla

Mozilla exists to build the Internet as a public resource accessible to all because we believe that open and free is better than closed and controlled. When you work at Mozilla, you give yourself a chance to make a difference in the lives of Web users everywhere. And you give us a chance to make a difference in your life every single day. Join us to work on the Web as the platform and help create more opportunity and innovation for everyone online.

Commitment to diversity, equity, inclusion, and belonging

Mozilla understands that valuing diverse creative practices and forms of knowledge are crucial to and enrich the company’s core mission.  We encourage applications from everyone, including members of all equity-seeking communities, such as (but certainly not limited to) women, racialized and Indigenous persons, persons with disabilities, persons of all sexual orientations, gender identities, and expressions.

We will ensure that qualified individuals with disabilities are provided reasonable accommodations to participate in the job application or interview process, to perform essential job functions, and to receive other benefits and privileges of employment, as appropriate. Please contact us at hiringaccommodation@mozilla.com to request accommodation.

We are an equal opportunity employer. We do not discriminate on the basis of race (including hairstyle and texture), religion (including religious grooming and dress practices), gender, gender identity, gender expression, color, national origin, pregnancy, ancestry, domestic partner status, disability, sexual orientation, age, genetic predisposition, medical condition, marital status, citizenship status, military or veteran status, or any other basis covered by applicable laws.  Mozilla will not tolerate discrimination or harassment based on any of these characteristics or any other unlawful behavior, conduct, or purpose.

Group: C

#LI-REMOTE

Req ID: R3197

Hiring Ranges:

Remote Germany

€81.000—€108.000 EUR

Read the full description
Security Staff Security Engineer at Mozilla

Maintains Mozilla's Information Security Management System, ISO 27001 and SOC 2 compliance programs, and leads security policy development across the organization.

Senior Posted 4 days ago RemoteFirstJobs Product
What this role involves

Why Mozilla?

Mozilla Corporation is the non-profit-backed technology company that has shaped the internet for the better over the last 25 years. We make pioneering brands like Firefox, the privacy-minded web browser. Now, with more than 225 million people around the world using our products each month, we’re shaping the next 25 years of technology and helping to reclaim an internet built for people, not companies. Our work focuses on diverse areas including AI, social media, security and more. And we’re doing this while never losing our focus on our core mission – to make the internet better for people.

The Mozilla Corporation is wholly owned by the non-profit 501© Mozilla Foundation. This means we aren’t beholden to any shareholders — only to our mission. Along with thousands of volunteer contributors and collaborators all over the world, Mozillians design, build and distribute open-source software that enables people to enjoy the internet on their terms.

About this team and role:

This role is part of the Governance, Risk & Compliance (GRC) function within Mozilla’s Security team. The Security team supports Product, Enterprise, and GRC functions across the organization, aligned with the mission to build a safe and secure internet. This role is responsible for maintaining and advancing Mozilla’s Information Security Management System (ISMS) and supporting our ISO 27001 and SOC 2 Type 2 compliance programs — from policy and control design through audit readiness and certification.

The ideal candidate has hands-on experience across the full breadth of a compliance program, is comfortable building process where none yet exists, and works well with a wide range of cross-functional stakeholders.

What you’ll do:

  • Maintain and mature the ISMS, including the Statement of Applicability (SoA), risk treatment plans, and the Management Review Meeting (MRM) process and cadence.
  • Support ISO 27001 and SOC 2 Type 2 audit execution—helping determine scope, preparing evidence and narrative artifacts, participating in auditor interviews and walkthroughs, and resolving auditor findings.
  • Contribute to the SOC 2 System Description and other audit-specific narrative documentation, ensuring they accurately reflect the organization’s actual control environment.
  • Track gaps and remediation efforts arising from readiness assessments and audits.
  • Lead the policy program—driving policy creation, revision, and cross-functional review cycles to keep the security policy set current, enforceable, and audit-ready.
  • Support compliance scaling as additional products or business units pursue readiness assessments and certification.
  • Support the internal audit function, partnering with internal or third-party resources as needed to meet ISO 27001’s internal audit requirements.
  • Partner closely with Engineering, IT, Legal, Privacy, People teams, and product leadership to gather evidence, drive control ownership, and translate compliance requirements into practical, adoptable practices.
  • Advise the GRC manager and broader Security leadership on audit risk, certification readiness, and compliance program strategy.

What you’ll bring:

  • 5 years of experience in information security, GRC, or compliance-focused roles.
  • Deep familiarity with ISO 27001 and SOC 2 Trust Services Criteria, gained through meaningful involvement in audits from readiness through certification.
  • Comfort operating across the full breadth of an ISMS—SoA maintenance, Management Review Meetings, and System Description authorship.
  • Demonstrated experience writing and revising security policies, including running cross-functional review cycles to gain organization-wide buy-in and adoption.
  • Experience tracking gaps and remediation plans and connecting that work to an organization’s broader compliance and risk program.
  • Excellent cross-functional collaboration skills—comfortable working with engineers, product managers, legal, and executive stakeholders, and able to translate compliance requirements into practical, actionable workflows.
  • Ability to ramp up quickly and operate with a high degree of independence.
  • Comfort building processes where none yet exist.
  • Strong written and verbal communication skills; ability to represent Mozilla credibly and confidently in front of external auditors.
  • Relevant industry certifications (e.g., CISA, CISSP, ISO 27001 Lead Auditor/Implementer) are a plus.

Commitment to our values:

  • Welcoming differences
  • Being relationship-minded
  • Practicing responsible participation
  • Having grit

What you’ll get:

  • Generous performance-based bonus plans to all eligible employees—we share in our success as one team.
  • Rich medical, dental, and vision coverage.
  • Generous retirement contributions with 100% immediate vesting (regardless of whether you contribute).
  • Quarterly all-company wellness days where everyone takes a pause together.
  • Country-specific holidays plus a day off for your birthday.
  • One-time home office stipend.
  • Annual professional development budget.
  • Quarterly well-being stipend.
  • Considerable paid parental leave.
  • Employee referral bonus program.
  • Other benefits (life/AD&D, disability, EAP, etc.—varies by country).

About Mozilla

Mozilla exists to build the Internet as a public resource accessible to all because we believe that open and free is better than closed and controlled. When you work at Mozilla, you give yourself a chance to make a difference in the lives of Web users everywhere. And you give us a chance to make a difference in your life every single day. Join us to work on the Web as the platform and help create more opportunity and innovation for everyone online.

Commitment to diversity, equity, inclusion, and belonging

Mozilla understands that valuing diverse creative practices and forms of knowledge are crucial to and enrich the company’s core mission.  We encourage applications from everyone, including members of all equity-seeking communities, such as (but certainly not limited to) women, racialized and Indigenous persons, persons with disabilities, persons of all sexual orientations, gender identities, and expressions.

We will ensure that qualified individuals with disabilities are provided reasonable accommodations to participate in the job application or interview process, to perform essential job functions, and to receive other benefits and privileges of employment, as appropriate. Please contact us at hiringaccommodation@mozilla.com to request accommodation.

We are an equal opportunity employer. We do not discriminate on the basis of race (including hairstyle and texture), religion (including religious grooming and dress practices), gender, gender identity, gender expression, color, national origin, pregnancy, ancestry, domestic partner status, disability, sexual orientation, age, genetic predisposition, medical condition, marital status, citizenship status, military or veteran status, or any other basis covered by applicable laws.  Mozilla will not tolerate discrimination or harassment based on any of these characteristics or any other unlawful behavior, conduct, or purpose.

Group: C

#LI-REMOTE

Req ID: R3197

Hiring Ranges:

Remote France

€65.000—€87.000 EUR

Read the full description
Security Staff Security Engineer at Mozilla

Maintains Mozilla's information security management system, supports ISO 27001 and SOC 2 Type 2 compliance programs, and manages audit readiness across the organization.

Senior Posted 4 days ago RemoteFirstJobs Product
What this role involves

To learn the Hiring Ranges for this position, please select your location from the Apply Now dropdown menu.

To learn more about our Hiring Range System, please click this link.

Why Mozilla?

Mozilla Corporation is the non-profit-backed technology company that has shaped the internet for the better over the last 25 years. We make pioneering brands like Firefox, the privacy-minded web browser. Now, with more than 225 million people around the world using our products each month, we’re shaping the next 25 years of technology and helping to reclaim an internet built for people, not companies. Our work focuses on diverse areas including AI, social media, security and more. And we’re doing this while never losing our focus on our core mission – to make the internet better for people.

The Mozilla Corporation is wholly owned by the non-profit 501© Mozilla Foundation. This means we aren’t beholden to any shareholders — only to our mission. Along with thousands of volunteer contributors and collaborators all over the world, Mozillians design, build and distribute open-source software that enables people to enjoy the internet on their terms.

About this team and role:

This role is part of the Governance, Risk & Compliance (GRC) function within Mozilla’s Security team. The Security team supports Product, Enterprise, and GRC functions across the organization, aligned with the mission to build a safe and secure internet. This role is responsible for maintaining and advancing Mozilla’s Information Security Management System (ISMS) and supporting our ISO 27001 and SOC 2 Type 2 compliance programs — from policy and control design through audit readiness and certification.

The ideal candidate has hands-on experience across the full breadth of a compliance program, is comfortable building process where none yet exists, and works well with a wide range of cross-functional stakeholders.

What you’ll do:

  • Maintain and mature the ISMS, including the Statement of Applicability (SoA), risk treatment plans, and the Management Review Meeting (MRM) process and cadence.
  • Support ISO 27001 and SOC 2 Type 2 audit execution—helping determine scope, preparing evidence and narrative artifacts, participating in auditor interviews and walkthroughs, and resolving auditor findings.
  • Contribute to the SOC 2 System Description and other audit-specific narrative documentation, ensuring they accurately reflect the organization’s actual control environment.
  • Track gaps and remediation efforts arising from readiness assessments and audits.
  • Lead the policy program—driving policy creation, revision, and cross-functional review cycles to keep the security policy set current, enforceable, and audit-ready.
  • Support compliance scaling as additional products or business units pursue readiness assessments and certification.
  • Support the internal audit function, partnering with internal or third-party resources as needed to meet ISO 27001’s internal audit requirements.
  • Partner closely with Engineering, IT, Legal, Privacy, People teams, and product leadership to gather evidence, drive control ownership, and translate compliance requirements into practical, adoptable practices.
  • Advise the GRC manager and broader Security leadership on audit risk, certification readiness, and compliance program strategy.

What you’ll bring:

  • 5 years of experience in information security, GRC, or compliance-focused roles.
  • Deep familiarity with ISO 27001 and SOC 2 Trust Services Criteria, gained through meaningful involvement in audits from readiness through certification.
  • Comfort operating across the full breadth of an ISMS—SoA maintenance, Management Review Meetings, and System Description authorship.
  • Demonstrated experience writing and revising security policies, including running cross-functional review cycles to gain organization-wide buy-in and adoption.
  • Experience tracking gaps and remediation plans and connecting that work to an organization’s broader compliance and risk program.
  • Excellent cross-functional collaboration skills—comfortable working with engineers, product managers, legal, and executive stakeholders, and able to translate compliance requirements into practical, actionable workflows.
  • Ability to ramp up quickly and operate with a high degree of independence.
  • Comfort building processes where none yet exist.
  • Strong written and verbal communication skills; ability to represent Mozilla credibly and confidently in front of external auditors.
  • Relevant industry certifications (e.g., CISA, CISSP, ISO 27001 Lead Auditor/Implementer) are a plus.

Commitment to our values:

  • Welcoming differences
  • Being relationship-minded
  • Practicing responsible participation
  • Having grit

What you’ll get:

  • Generous performance-based bonus plans to all eligible employees—we share in our success as one team.
  • Rich medical, dental, and vision coverage.
  • Generous retirement contributions with 100% immediate vesting (regardless of whether you contribute).
  • Quarterly all-company wellness days where everyone takes a pause together.
  • Country-specific holidays plus a day off for your birthday.
  • One-time home office stipend.
  • Annual professional development budget.
  • Quarterly well-being stipend.
  • Considerable paid parental leave.
  • Employee referral bonus program.
  • Other benefits (life/AD&D, disability, EAP, etc.—varies by country).

About Mozilla

Mozilla exists to build the Internet as a public resource accessible to all because we believe that open and free is better than closed and controlled. When you work at Mozilla, you give yourself a chance to make a difference in the lives of Web users everywhere. And you give us a chance to make a difference in your life every single day. Join us to work on the Web as the platform and help create more opportunity and innovation for everyone online.

Commitment to diversity, equity, inclusion, and belonging

Mozilla understands that valuing diverse creative practices and forms of knowledge are crucial to and enrich the company’s core mission.  We encourage applications from everyone, including members of all equity-seeking communities, such as (but certainly not limited to) women, racialized and Indigenous persons, persons with disabilities, persons of all sexual orientations, gender identities, and expressions.

We will ensure that qualified individuals with disabilities are provided reasonable accommodations to participate in the job application or interview process, to perform essential job functions, and to receive other benefits and privileges of employment, as appropriate. Please contact us at hiringaccommodation@mozilla.com to request accommodation.

We are an equal opportunity employer. We do not discriminate on the basis of race (including hairstyle and texture), religion (including religious grooming and dress practices), gender, gender identity, gender expression, color, national origin, pregnancy, ancestry, domestic partner status, disability, sexual orientation, age, genetic predisposition, medical condition, marital status, citizenship status, military or veteran status, or any other basis covered by applicable laws.  Mozilla will not tolerate discrimination or harassment based on any of these characteristics or any other unlawful behavior, conduct, or purpose.

Group: C

#LI-DNI

Req ID: R3197

Read the full description
Security Staff Security Engineer at Mozilla

Maintains Mozilla's Information Security Management System, supports ISO 27001 and SOC 2 Type 2 compliance programs, and leads security policy development across the organization.

Senior Posted 4 days ago RemoteFirstJobs Product
What this role involves

Why Mozilla?

Mozilla Corporation is the non-profit-backed technology company that has shaped the internet for the better over the last 25 years. We make pioneering brands like Firefox, the privacy-minded web browser. Now, with more than 225 million people around the world using our products each month, we’re shaping the next 25 years of technology and helping to reclaim an internet built for people, not companies. Our work focuses on diverse areas including AI, social media, security and more. And we’re doing this while never losing our focus on our core mission – to make the internet better for people.

The Mozilla Corporation is wholly owned by the non-profit 501© Mozilla Foundation. This means we aren’t beholden to any shareholders — only to our mission. Along with thousands of volunteer contributors and collaborators all over the world, Mozillians design, build and distribute open-source software that enables people to enjoy the internet on their terms.

About this team and role:

This role is part of the Governance, Risk & Compliance (GRC) function within Mozilla’s Security team. The Security team supports Product, Enterprise, and GRC functions across the organization, aligned with the mission to build a safe and secure internet. This role is responsible for maintaining and advancing Mozilla’s Information Security Management System (ISMS) and supporting our ISO 27001 and SOC 2 Type 2 compliance programs — from policy and control design through audit readiness and certification.

The ideal candidate has hands-on experience across the full breadth of a compliance program, is comfortable building process where none yet exists, and works well with a wide range of cross-functional stakeholders.

What you’ll do:

  • Maintain and mature the ISMS, including the Statement of Applicability (SoA), risk treatment plans, and the Management Review Meeting (MRM) process and cadence.
  • Support ISO 27001 and SOC 2 Type 2 audit execution—helping determine scope, preparing evidence and narrative artifacts, participating in auditor interviews and walkthroughs, and resolving auditor findings.
  • Contribute to the SOC 2 System Description and other audit-specific narrative documentation, ensuring they accurately reflect the organization’s actual control environment.
  • Track gaps and remediation efforts arising from readiness assessments and audits.
  • Lead the policy program—driving policy creation, revision, and cross-functional review cycles to keep the security policy set current, enforceable, and audit-ready.
  • Support compliance scaling as additional products or business units pursue readiness assessments and certification.
  • Support the internal audit function, partnering with internal or third-party resources as needed to meet ISO 27001’s internal audit requirements.
  • Partner closely with Engineering, IT, Legal, Privacy, People teams, and product leadership to gather evidence, drive control ownership, and translate compliance requirements into practical, adoptable practices.
  • Advise the GRC manager and broader Security leadership on audit risk, certification readiness, and compliance program strategy.

What you’ll bring:

  • 5 years of experience in information security, GRC, or compliance-focused roles.
  • Deep familiarity with ISO 27001 and SOC 2 Trust Services Criteria, gained through meaningful involvement in audits from readiness through certification.
  • Comfort operating across the full breadth of an ISMS—SoA maintenance, Management Review Meetings, and System Description authorship.
  • Demonstrated experience writing and revising security policies, including running cross-functional review cycles to gain organization-wide buy-in and adoption.
  • Experience tracking gaps and remediation plans and connecting that work to an organization’s broader compliance and risk program.
  • Excellent cross-functional collaboration skills—comfortable working with engineers, product managers, legal, and executive stakeholders, and able to translate compliance requirements into practical, actionable workflows.
  • Ability to ramp up quickly and operate with a high degree of independence.
  • Comfort building processes where none yet exist.
  • Strong written and verbal communication skills; ability to represent Mozilla credibly and confidently in front of external auditors.
  • Relevant industry certifications (e.g., CISA, CISSP, ISO 27001 Lead Auditor/Implementer) are a plus.

Commitment to our values:

  • Welcoming differences
  • Being relationship-minded
  • Practicing responsible participation
  • Having grit

What you’ll get:

  • Generous performance-based bonus plans to all eligible employees—we share in our success as one team.
  • Rich medical, dental, and vision coverage.
  • Generous retirement contributions with 100% immediate vesting (regardless of whether you contribute).
  • Quarterly all-company wellness days where everyone takes a pause together.
  • Country-specific holidays plus a day off for your birthday.
  • One-time home office stipend.
  • Annual professional development budget.
  • Quarterly well-being stipend.
  • Considerable paid parental leave.
  • Employee referral bonus program.
  • Other benefits (life/AD&D, disability, EAP, etc.—varies by country).

About Mozilla

Mozilla exists to build the Internet as a public resource accessible to all because we believe that open and free is better than closed and controlled. When you work at Mozilla, you give yourself a chance to make a difference in the lives of Web users everywhere. And you give us a chance to make a difference in your life every single day. Join us to work on the Web as the platform and help create more opportunity and innovation for everyone online.

Commitment to diversity, equity, inclusion, and belonging

Mozilla understands that valuing diverse creative practices and forms of knowledge are crucial to and enrich the company’s core mission.  We encourage applications from everyone, including members of all equity-seeking communities, such as (but certainly not limited to) women, racialized and Indigenous persons, persons with disabilities, persons of all sexual orientations, gender identities, and expressions.

We will ensure that qualified individuals with disabilities are provided reasonable accommodations to participate in the job application or interview process, to perform essential job functions, and to receive other benefits and privileges of employment, as appropriate. Please contact us at hiringaccommodation@mozilla.com to request accommodation.

We are an equal opportunity employer. We do not discriminate on the basis of race (including hairstyle and texture), religion (including religious grooming and dress practices), gender, gender identity, gender expression, color, national origin, pregnancy, ancestry, domestic partner status, disability, sexual orientation, age, genetic predisposition, medical condition, marital status, citizenship status, military or veteran status, or any other basis covered by applicable laws.  Mozilla will not tolerate discrimination or harassment based on any of these characteristics or any other unlawful behavior, conduct, or purpose.

Group: C

#LI-REMOTE

Req ID: R3197

Hiring Ranges:

Remote UK

£81,000—£108,000 GBP

Read the full description
Security Senior Security Engineer - Detection & Response at EvenUp

Design and build detection and response programs including SIEM architecture, telemetry pipelines, detection content, and incident response playbooks.

Senior Posted 4 days ago RemoteFirstJobs Product
What this role involves

EvenUp is on a mission to close the justice gap using technology and AI. We empower personal injury lawyers and victims to get the justice they deserve. Our products enable law firms to secure faster settlements, higher payouts, and better outcomes for victims injured through no fault of their own in vehicle collisions, accidents, natural disasters, and more.

We are one of the fastest-growing vertical SaaS companies in history, and we are just getting started. EvenUp is backed by top VCs, including Bessemer Venture Partners, Bain Capital Ventures, SignalFire, and Lightspeed. We are looking to expand our team with talented, driven, and collaborative individuals who seek to have a lasting impact. Learn more at www.evenuplaw.com.

Life as an Engineer at EvenUp 🎥

Security at EvenUp is still early enough to shape — and detection and response is the part we’re building next, from the ground up.

We’re looking for a hands-on Senior Security Engineer to build our detection and response program: the telemetry pipelines, the SIEM, the detection content, and the incident response muscle behind them. You won’t inherit a SOC — you’ll design one.

This isn’t a role where you’ll stare at a queue of vendor alerts. The threats that matter most to us don’t come out of any box: they live in our own applications and data flows, and detecting them means partnering with the engineers who build those systems. We believe security should accelerate the business, not slow it down. If you’re excited about treating detection as an engineering discipline, we’d love to chat.

Why this role is exciting

  • Build the program, not just the rules: select the SIEM, design the telemetry architecture, and write the first generation of detections; your technical decisions become the foundation.

  • Detect what actually matters: focus on highest-stakes risks unique to our business, like sensitive data moving to the wrong place, misuse of internal systems, and exposure of health information, as generic detection content cannot address these.

  • Detection as code: detections are written, version-controlled, tested, and reviewed like software.

  • Own incident response: define how EvenUp responds to incidents, including playbooks, tabletop exercises, and post-incident reviews.

  • Direct the vendors, don’t answer to them: when using managed providers for 24⁄7 coverage, you set the requirements, escalation logic, and quality standards.

What You’ll Do

  • Build Our Detection Platform: Lead SIEM evaluation and implementation, design log ingestion and routing pipelines, and make deliberate cost/retention trade-offs across hot search and long-term archive.

  • Engineer High-Signal Detections: Develop and tune detection content across cloud, identity, endpoint, SaaS, and application telemetry — with an emphasis on business-logic detections built on our own products’ audit events.

  • Define the Telemetry Contract: Partner with Engineering and DevOps to specify what our applications and infrastructure must log — the audit events that make our most important risks detectable in the first place.

  • Lead Incident Response: Build and maintain IR playbooks and runbooks, coordinate response during security events, run the annual tabletop exercise, and drive post-incident reviews that actually change things.

  • Detect Data Exposure: Partner with internal teams to detect sensitive data moving where it shouldn’t — including PHI — across applications, endpoints, and SaaS.

  • Manage 24⁄7 Coverage: Define requirements for and direct our managed detection partners, own escalation procedures, and continuously raise the bar on what “monitored” means.

What We Look For

  • 5+ years in security operations, detection engineering, or incident response, including experience building (not just running) a detection and response capability at a startup or high-growth technology company.

  • Hands-on experience implementing or significantly maturing a SIEM, including custom log sources and detection content — not just operating one that was handed to you.

  • Strong detection engineering skills: writing detections in Python, SQL, or a rules DSL, managing them in version control, and measuring their quality.

  • Real incident response experience — you’ve led investigations, written the playbooks, and run the retros.

  • Experience with cloud-native telemetry (AWS/GCP/Azure control plane, identity providers, endpoint, SaaS audit logs).

  • Strong programming or automation skills (Python preferred); comfort building integrations and response automation.

  • Experience partnering directly with software engineers to instrument applications for security visibility is a strong plus.

  • Familiarity with securing or monitoring AI/LLM-powered systems is a strong plus.

  • Experience working with MDR/MSSP providers — and opinions about what they’re good and bad at.

  • A builder mentality — you’d rather engineer the alert away than triage it forever.

  • Relevant security certifications (GIAC/GCIA/GCIH, CISSP, etc.) are a plus, but practical engineering experience matters more.

This is a hybrid role, with an expectation of being in our Toronto office three days per week.

#LI-Hybrid

Benefits & Perks:

As part of our total rewards package, we offer attractive benefits and perks to our employees, including:

  • Choice of medical, dental, and vision insurance plans for you and your family.

  • Additional insurance coverage options for life, accident, or critical illness.

  • Flexible paid time off, sick leave, short-term and long-term disability.

  • 10 US observed holidays, and Canadian statutory holidays by province.

  • A home office stipend.

  • 401(k) for US-based employees and RRSP for Canada-based employees.

  • Paid parental leave.

  • A local in-person meet-up program.

  • Hubs in San Francisco and Toronto.

(Please note the above benefits & perks are for full-time employees)

Notice to Candidates:

To ensure fairness and proper consideration, we do not accept resumes or expressions of interest via email or social media messages. If you’re interested in a role, please submit your application directly through our careers page .

Please note that EvenUp may use AI notetakers and other recording devices in the recruiting process. If you interview with us, with your consent, we may record your conversations and summarize them into notes for internal use. Recording is optional, and declining will not affect your candidacy.

EvenUp is an equal opportunity employer. We are committed to diversity and inclusion in our company. We do not discriminate based on race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status.

Read the full description
Security Staff Security Engineer at Mozilla

Maintains Mozilla's Information Security Management System, manages ISO 27001 and SOC 2 Type 2 compliance programs, and leads policy development across the organization.

Senior Posted 4 days ago RemoteFirstJobs Product
What this role involves

Why Mozilla?

Mozilla Corporation is the non-profit-backed technology company that has shaped the internet for the better over the last 25 years. We make pioneering brands like Firefox, the privacy-minded web browser. Now, with more than 225 million people around the world using our products each month, we’re shaping the next 25 years of technology and helping to reclaim an internet built for people, not companies. Our work focuses on diverse areas including AI, social media, security and more. And we’re doing this while never losing our focus on our core mission – to make the internet better for people.

The Mozilla Corporation is wholly owned by the non-profit 501© Mozilla Foundation. This means we aren’t beholden to any shareholders — only to our mission. Along with thousands of volunteer contributors and collaborators all over the world, Mozillians design, build and distribute open-source software that enables people to enjoy the internet on their terms.

About this team and role:

This role is part of the Governance, Risk & Compliance (GRC) function within Mozilla’s Security team. The Security team supports Product, Enterprise, and GRC functions across the organization, aligned with the mission to build a safe and secure internet. This role is responsible for maintaining and advancing Mozilla’s Information Security Management System (ISMS) and supporting our ISO 27001 and SOC 2 Type 2 compliance programs — from policy and control design through audit readiness and certification.

The ideal candidate has hands-on experience across the full breadth of a compliance program, is comfortable building process where none yet exists, and works well with a wide range of cross-functional stakeholders.

What you’ll do:

  • Maintain and mature the ISMS, including the Statement of Applicability (SoA), risk treatment plans, and the Management Review Meeting (MRM) process and cadence.
  • Support ISO 27001 and SOC 2 Type 2 audit execution—helping determine scope, preparing evidence and narrative artifacts, participating in auditor interviews and walkthroughs, and resolving auditor findings.
  • Contribute to the SOC 2 System Description and other audit-specific narrative documentation, ensuring they accurately reflect the organization’s actual control environment.
  • Track gaps and remediation efforts arising from readiness assessments and audits.
  • Lead the policy program—driving policy creation, revision, and cross-functional review cycles to keep the security policy set current, enforceable, and audit-ready.
  • Support compliance scaling as additional products or business units pursue readiness assessments and certification.
  • Support the internal audit function, partnering with internal or third-party resources as needed to meet ISO 27001’s internal audit requirements.
  • Partner closely with Engineering, IT, Legal, Privacy, People teams, and product leadership to gather evidence, drive control ownership, and translate compliance requirements into practical, adoptable practices.
  • Advise the GRC manager and broader Security leadership on audit risk, certification readiness, and compliance program strategy.

What you’ll bring:

  • 5 years of experience in information security, GRC, or compliance-focused roles.
  • Deep familiarity with ISO 27001 and SOC 2 Trust Services Criteria, gained through meaningful involvement in audits from readiness through certification.
  • Comfort operating across the full breadth of an ISMS—SoA maintenance, Management Review Meetings, and System Description authorship.
  • Demonstrated experience writing and revising security policies, including running cross-functional review cycles to gain organization-wide buy-in and adoption.
  • Experience tracking gaps and remediation plans and connecting that work to an organization’s broader compliance and risk program.
  • Excellent cross-functional collaboration skills—comfortable working with engineers, product managers, legal, and executive stakeholders, and able to translate compliance requirements into practical, actionable workflows.
  • Ability to ramp up quickly and operate with a high degree of independence.
  • Comfort building processes where none yet exist.
  • Strong written and verbal communication skills; ability to represent Mozilla credibly and confidently in front of external auditors.
  • Relevant industry certifications (e.g., CISA, CISSP, ISO 27001 Lead Auditor/Implementer) are a plus.

Commitment to our values:

  • Welcoming differences
  • Being relationship-minded
  • Practicing responsible participation
  • Having grit

What you’ll get:

  • Generous performance-based bonus plans to all eligible employees—we share in our success as one team.
  • Rich medical, dental, and vision coverage.
  • Generous retirement contributions with 100% immediate vesting (regardless of whether you contribute).
  • Quarterly all-company wellness days where everyone takes a pause together.
  • Country-specific holidays plus a day off for your birthday.
  • One-time home office stipend.
  • Annual professional development budget.
  • Quarterly well-being stipend.
  • Considerable paid parental leave.
  • Employee referral bonus program.
  • Other benefits (life/AD&D, disability, EAP, etc.—varies by country).

About Mozilla

Mozilla exists to build the Internet as a public resource accessible to all because we believe that open and free is better than closed and controlled. When you work at Mozilla, you give yourself a chance to make a difference in the lives of Web users everywhere. And you give us a chance to make a difference in your life every single day. Join us to work on the Web as the platform and help create more opportunity and innovation for everyone online.

Commitment to diversity, equity, inclusion, and belonging

Mozilla understands that valuing diverse creative practices and forms of knowledge are crucial to and enrich the company’s core mission.  We encourage applications from everyone, including members of all equity-seeking communities, such as (but certainly not limited to) women, racialized and Indigenous persons, persons with disabilities, persons of all sexual orientations, gender identities, and expressions.

We will ensure that qualified individuals with disabilities are provided reasonable accommodations to participate in the job application or interview process, to perform essential job functions, and to receive other benefits and privileges of employment, as appropriate. Please contact us at hiringaccommodation@mozilla.com to request accommodation.

We are an equal opportunity employer. We do not discriminate on the basis of race (including hairstyle and texture), religion (including religious grooming and dress practices), gender, gender identity, gender expression, color, national origin, pregnancy, ancestry, domestic partner status, disability, sexual orientation, age, genetic predisposition, medical condition, marital status, citizenship status, military or veteran status, or any other basis covered by applicable laws.  Mozilla will not tolerate discrimination or harassment based on any of these characteristics or any other unlawful behavior, conduct, or purpose.

Group: C

#LI-REMOTE

Req ID: R3197

Hiring Ranges:

Canada Tier 1 Locations

$128,000—$171,000 CAD

Canada Tier 2 Locations

$116,000—$155,000 CAD

Read the full description
Security Staff Security Engineer at Mozilla

Maintains Mozilla's information security management system, ISO 27001, and SOC 2 compliance programs while supporting audit execution and cross-functional stakeholder coordination.

Senior Posted 4 days ago RemoteFirstJobs Product
What this role involves

To learn the Hiring Ranges for this position, please select your location from the Apply Now dropdown menu.

To learn more about our Hiring Range System, please click this link.

Why Mozilla?

Mozilla Corporation is the non-profit-backed technology company that has shaped the internet for the better over the last 25 years. We make pioneering brands like Firefox, the privacy-minded web browser. Now, with more than 225 million people around the world using our products each month, we’re shaping the next 25 years of technology and helping to reclaim an internet built for people, not companies. Our work focuses on diverse areas including AI, social media, security and more. And we’re doing this while never losing our focus on our core mission – to make the internet better for people.

The Mozilla Corporation is wholly owned by the non-profit 501© Mozilla Foundation. This means we aren’t beholden to any shareholders — only to our mission. Along with thousands of volunteer contributors and collaborators all over the world, Mozillians design, build and distribute open-source software that enables people to enjoy the internet on their terms.

About this team and role:

This role is part of the Governance, Risk & Compliance (GRC) function within Mozilla’s Security team. The Security team supports Product, Enterprise, and GRC functions across the organization, aligned with the mission to build a safe and secure internet. This role is responsible for maintaining and advancing Mozilla’s Information Security Management System (ISMS) and supporting our ISO 27001 and SOC 2 Type 2 compliance programs — from policy and control design through audit readiness and certification.

The ideal candidate has hands-on experience across the full breadth of a compliance program, is comfortable building process where none yet exists, and works well with a wide range of cross-functional stakeholders.

What you’ll do:

  • Maintain and mature the ISMS, including the Statement of Applicability (SoA), risk treatment plans, and the Management Review Meeting (MRM) process and cadence.
  • Support ISO 27001 and SOC 2 Type 2 audit execution—helping determine scope, preparing evidence and narrative artifacts, participating in auditor interviews and walkthroughs, and resolving auditor findings.
  • Contribute to the SOC 2 System Description and other audit-specific narrative documentation, ensuring they accurately reflect the organization’s actual control environment.
  • Track gaps and remediation efforts arising from readiness assessments and audits.
  • Lead the policy program—driving policy creation, revision, and cross-functional review cycles to keep the security policy set current, enforceable, and audit-ready.
  • Support compliance scaling as additional products or business units pursue readiness assessments and certification.
  • Support the internal audit function, partnering with internal or third-party resources as needed to meet ISO 27001’s internal audit requirements.
  • Partner closely with Engineering, IT, Legal, Privacy, People teams, and product leadership to gather evidence, drive control ownership, and translate compliance requirements into practical, adoptable practices.
  • Advise the GRC manager and broader Security leadership on audit risk, certification readiness, and compliance program strategy.

What you’ll bring:

  • 5 years of experience in information security, GRC, or compliance-focused roles.
  • Deep familiarity with ISO 27001 and SOC 2 Trust Services Criteria, gained through meaningful involvement in audits from readiness through certification.
  • Comfort operating across the full breadth of an ISMS—SoA maintenance, Management Review Meetings, and System Description authorship.
  • Demonstrated experience writing and revising security policies, including running cross-functional review cycles to gain organization-wide buy-in and adoption.
  • Experience tracking gaps and remediation plans and connecting that work to an organization’s broader compliance and risk program.
  • Excellent cross-functional collaboration skills—comfortable working with engineers, product managers, legal, and executive stakeholders, and able to translate compliance requirements into practical, actionable workflows.
  • Ability to ramp up quickly and operate with a high degree of independence.
  • Comfort building processes where none yet exist.
  • Strong written and verbal communication skills; ability to represent Mozilla credibly and confidently in front of external auditors.
  • Relevant industry certifications (e.g., CISA, CISSP, ISO 27001 Lead Auditor/Implementer) are a plus.

Commitment to our values:

  • Welcoming differences
  • Being relationship-minded
  • Practicing responsible participation
  • Having grit

What you’ll get:

  • Generous performance-based bonus plans to all eligible employees—we share in our success as one team.
  • Rich medical, dental, and vision coverage.
  • Generous retirement contributions with 100% immediate vesting (regardless of whether you contribute).
  • Quarterly all-company wellness days where everyone takes a pause together.
  • Country-specific holidays plus a day off for your birthday.
  • One-time home office stipend.
  • Annual professional development budget.
  • Quarterly well-being stipend.
  • Considerable paid parental leave.
  • Employee referral bonus program.
  • Other benefits (life/AD&D, disability, EAP, etc.—varies by country).

About Mozilla

Mozilla exists to build the Internet as a public resource accessible to all because we believe that open and free is better than closed and controlled. When you work at Mozilla, you give yourself a chance to make a difference in the lives of Web users everywhere. And you give us a chance to make a difference in your life every single day. Join us to work on the Web as the platform and help create more opportunity and innovation for everyone online.

Commitment to diversity, equity, inclusion, and belonging

Mozilla understands that valuing diverse creative practices and forms of knowledge are crucial to and enrich the company’s core mission.  We encourage applications from everyone, including members of all equity-seeking communities, such as (but certainly not limited to) women, racialized and Indigenous persons, persons with disabilities, persons of all sexual orientations, gender identities, and expressions.

We will ensure that qualified individuals with disabilities are provided reasonable accommodations to participate in the job application or interview process, to perform essential job functions, and to receive other benefits and privileges of employment, as appropriate. Please contact us at hiringaccommodation@mozilla.com to request accommodation.

We are an equal opportunity employer. We do not discriminate on the basis of race (including hairstyle and texture), religion (including religious grooming and dress practices), gender, gender identity, gender expression, color, national origin, pregnancy, ancestry, domestic partner status, disability, sexual orientation, age, genetic predisposition, medical condition, marital status, citizenship status, military or veteran status, or any other basis covered by applicable laws.  Mozilla will not tolerate discrimination or harassment based on any of these characteristics or any other unlawful behavior, conduct, or purpose.

Group: C

#LI-DNI

Req ID: R3197

Read the full description
Security Staff Security Engineer at Mozilla

Maintains Mozilla's Information Security Management System, leads ISO 27001 and SOC 2 compliance programs, and manages security policies across the organization.

Senior Posted 4 days ago RemoteFirstJobs Product
What this role involves

Why Mozilla?

Mozilla Corporation is the non-profit-backed technology company that has shaped the internet for the better over the last 25 years. We make pioneering brands like Firefox, the privacy-minded web browser. Now, with more than 225 million people around the world using our products each month, we’re shaping the next 25 years of technology and helping to reclaim an internet built for people, not companies. Our work focuses on diverse areas including AI, social media, security and more. And we’re doing this while never losing our focus on our core mission – to make the internet better for people.

The Mozilla Corporation is wholly owned by the non-profit 501© Mozilla Foundation. This means we aren’t beholden to any shareholders — only to our mission. Along with thousands of volunteer contributors and collaborators all over the world, Mozillians design, build and distribute open-source software that enables people to enjoy the internet on their terms.

About this team and role:

This role is part of the Governance, Risk & Compliance (GRC) function within Mozilla’s Security team. The Security team supports Product, Enterprise, and GRC functions across the organization, aligned with the mission to build a safe and secure internet. This role is responsible for maintaining and advancing Mozilla’s Information Security Management System (ISMS) and supporting our ISO 27001 and SOC 2 Type 2 compliance programs — from policy and control design through audit readiness and certification.

The ideal candidate has hands-on experience across the full breadth of a compliance program, is comfortable building process where none yet exists, and works well with a wide range of cross-functional stakeholders.

What you’ll do:

  • Maintain and mature the ISMS, including the Statement of Applicability (SoA), risk treatment plans, and the Management Review Meeting (MRM) process and cadence.
  • Support ISO 27001 and SOC 2 Type 2 audit execution—helping determine scope, preparing evidence and narrative artifacts, participating in auditor interviews and walkthroughs, and resolving auditor findings.
  • Contribute to the SOC 2 System Description and other audit-specific narrative documentation, ensuring they accurately reflect the organization’s actual control environment.
  • Track gaps and remediation efforts arising from readiness assessments and audits.
  • Lead the policy program—driving policy creation, revision, and cross-functional review cycles to keep the security policy set current, enforceable, and audit-ready.
  • Support compliance scaling as additional products or business units pursue readiness assessments and certification.
  • Support the internal audit function, partnering with internal or third-party resources as needed to meet ISO 27001’s internal audit requirements.
  • Partner closely with Engineering, IT, Legal, Privacy, People teams, and product leadership to gather evidence, drive control ownership, and translate compliance requirements into practical, adoptable practices.
  • Advise the GRC manager and broader Security leadership on audit risk, certification readiness, and compliance program strategy.

What you’ll bring:

  • 5 years of experience in information security, GRC, or compliance-focused roles.
  • Deep familiarity with ISO 27001 and SOC 2 Trust Services Criteria, gained through meaningful involvement in audits from readiness through certification.
  • Comfort operating across the full breadth of an ISMS—SoA maintenance, Management Review Meetings, and System Description authorship.
  • Demonstrated experience writing and revising security policies, including running cross-functional review cycles to gain organization-wide buy-in and adoption.
  • Experience tracking gaps and remediation plans and connecting that work to an organization’s broader compliance and risk program.
  • Excellent cross-functional collaboration skills—comfortable working with engineers, product managers, legal, and executive stakeholders, and able to translate compliance requirements into practical, actionable workflows.
  • Ability to ramp up quickly and operate with a high degree of independence.
  • Comfort building processes where none yet exist.
  • Strong written and verbal communication skills; ability to represent Mozilla credibly and confidently in front of external auditors.
  • Relevant industry certifications (e.g., CISA, CISSP, ISO 27001 Lead Auditor/Implementer) are a plus.

Commitment to our values:

  • Welcoming differences
  • Being relationship-minded
  • Practicing responsible participation
  • Having grit

What you’ll get:

  • Generous performance-based bonus plans to all eligible employees—we share in our success as one team.
  • Rich medical, dental, and vision coverage.
  • Generous retirement contributions with 100% immediate vesting (regardless of whether you contribute).
  • Quarterly all-company wellness days where everyone takes a pause together.
  • Country-specific holidays plus a day off for your birthday.
  • One-time home office stipend.
  • Annual professional development budget.
  • Quarterly well-being stipend.
  • Considerable paid parental leave.
  • Employee referral bonus program.
  • Other benefits (life/AD&D, disability, EAP, etc.—varies by country).

About Mozilla

Mozilla exists to build the Internet as a public resource accessible to all because we believe that open and free is better than closed and controlled. When you work at Mozilla, you give yourself a chance to make a difference in the lives of Web users everywhere. And you give us a chance to make a difference in your life every single day. Join us to work on the Web as the platform and help create more opportunity and innovation for everyone online.

Commitment to diversity, equity, inclusion, and belonging

Mozilla understands that valuing diverse creative practices and forms of knowledge are crucial to and enrich the company’s core mission.  We encourage applications from everyone, including members of all equity-seeking communities, such as (but certainly not limited to) women, racialized and Indigenous persons, persons with disabilities, persons of all sexual orientations, gender identities, and expressions.

We will ensure that qualified individuals with disabilities are provided reasonable accommodations to participate in the job application or interview process, to perform essential job functions, and to receive other benefits and privileges of employment, as appropriate. Please contact us at hiringaccommodation@mozilla.com to request accommodation.

We are an equal opportunity employer. We do not discriminate on the basis of race (including hairstyle and texture), religion (including religious grooming and dress practices), gender, gender identity, gender expression, color, national origin, pregnancy, ancestry, domestic partner status, disability, sexual orientation, age, genetic predisposition, medical condition, marital status, citizenship status, military or veteran status, or any other basis covered by applicable laws.  Mozilla will not tolerate discrimination or harassment based on any of these characteristics or any other unlawful behavior, conduct, or purpose.

Group: C

#LI-REMOTE

Req ID: R3197

Hiring Ranges:

Remote Germany

€81.000—€108.000 EUR

Read the full description
Security Staff Security Engineer at Mozilla

Maintains Mozilla's Information Security Management System, leads ISO 27001 and SOC 2 Type 2 compliance programs, and manages security policy development across the organization.

Senior Posted 4 days ago RemoteFirstJobs Product
What this role involves

Why Mozilla?

Mozilla Corporation is the non-profit-backed technology company that has shaped the internet for the better over the last 25 years. We make pioneering brands like Firefox, the privacy-minded web browser. Now, with more than 225 million people around the world using our products each month, we’re shaping the next 25 years of technology and helping to reclaim an internet built for people, not companies. Our work focuses on diverse areas including AI, social media, security and more. And we’re doing this while never losing our focus on our core mission – to make the internet better for people.

The Mozilla Corporation is wholly owned by the non-profit 501© Mozilla Foundation. This means we aren’t beholden to any shareholders — only to our mission. Along with thousands of volunteer contributors and collaborators all over the world, Mozillians design, build and distribute open-source software that enables people to enjoy the internet on their terms.

About this team and role:

This role is part of the Governance, Risk & Compliance (GRC) function within Mozilla’s Security team. The Security team supports Product, Enterprise, and GRC functions across the organization, aligned with the mission to build a safe and secure internet. This role is responsible for maintaining and advancing Mozilla’s Information Security Management System (ISMS) and supporting our ISO 27001 and SOC 2 Type 2 compliance programs — from policy and control design through audit readiness and certification.

The ideal candidate has hands-on experience across the full breadth of a compliance program, is comfortable building process where none yet exists, and works well with a wide range of cross-functional stakeholders.

What you’ll do:

  • Maintain and mature the ISMS, including the Statement of Applicability (SoA), risk treatment plans, and the Management Review Meeting (MRM) process and cadence.
  • Support ISO 27001 and SOC 2 Type 2 audit execution—helping determine scope, preparing evidence and narrative artifacts, participating in auditor interviews and walkthroughs, and resolving auditor findings.
  • Contribute to the SOC 2 System Description and other audit-specific narrative documentation, ensuring they accurately reflect the organization’s actual control environment.
  • Track gaps and remediation efforts arising from readiness assessments and audits.
  • Lead the policy program—driving policy creation, revision, and cross-functional review cycles to keep the security policy set current, enforceable, and audit-ready.
  • Support compliance scaling as additional products or business units pursue readiness assessments and certification.
  • Support the internal audit function, partnering with internal or third-party resources as needed to meet ISO 27001’s internal audit requirements.
  • Partner closely with Engineering, IT, Legal, Privacy, People teams, and product leadership to gather evidence, drive control ownership, and translate compliance requirements into practical, adoptable practices.
  • Advise the GRC manager and broader Security leadership on audit risk, certification readiness, and compliance program strategy.

What you’ll bring:

  • 5 years of experience in information security, GRC, or compliance-focused roles.
  • Deep familiarity with ISO 27001 and SOC 2 Trust Services Criteria, gained through meaningful involvement in audits from readiness through certification.
  • Comfort operating across the full breadth of an ISMS—SoA maintenance, Management Review Meetings, and System Description authorship.
  • Demonstrated experience writing and revising security policies, including running cross-functional review cycles to gain organization-wide buy-in and adoption.
  • Experience tracking gaps and remediation plans and connecting that work to an organization’s broader compliance and risk program.
  • Excellent cross-functional collaboration skills—comfortable working with engineers, product managers, legal, and executive stakeholders, and able to translate compliance requirements into practical, actionable workflows.
  • Ability to ramp up quickly and operate with a high degree of independence.
  • Comfort building processes where none yet exist.
  • Strong written and verbal communication skills; ability to represent Mozilla credibly and confidently in front of external auditors.
  • Relevant industry certifications (e.g., CISA, CISSP, ISO 27001 Lead Auditor/Implementer) are a plus.

Commitment to our values:

  • Welcoming differences
  • Being relationship-minded
  • Practicing responsible participation
  • Having grit

What you’ll get:

  • Generous performance-based bonus plans to all eligible employees—we share in our success as one team.
  • Rich medical, dental, and vision coverage.
  • Generous retirement contributions with 100% immediate vesting (regardless of whether you contribute).
  • Quarterly all-company wellness days where everyone takes a pause together.
  • Country-specific holidays plus a day off for your birthday.
  • One-time home office stipend.
  • Annual professional development budget.
  • Quarterly well-being stipend.
  • Considerable paid parental leave.
  • Employee referral bonus program.
  • Other benefits (life/AD&D, disability, EAP, etc.—varies by country).

About Mozilla

Mozilla exists to build the Internet as a public resource accessible to all because we believe that open and free is better than closed and controlled. When you work at Mozilla, you give yourself a chance to make a difference in the lives of Web users everywhere. And you give us a chance to make a difference in your life every single day. Join us to work on the Web as the platform and help create more opportunity and innovation for everyone online.

Commitment to diversity, equity, inclusion, and belonging

Mozilla understands that valuing diverse creative practices and forms of knowledge are crucial to and enrich the company’s core mission.  We encourage applications from everyone, including members of all equity-seeking communities, such as (but certainly not limited to) women, racialized and Indigenous persons, persons with disabilities, persons of all sexual orientations, gender identities, and expressions.

We will ensure that qualified individuals with disabilities are provided reasonable accommodations to participate in the job application or interview process, to perform essential job functions, and to receive other benefits and privileges of employment, as appropriate. Please contact us at hiringaccommodation@mozilla.com to request accommodation.

We are an equal opportunity employer. We do not discriminate on the basis of race (including hairstyle and texture), religion (including religious grooming and dress practices), gender, gender identity, gender expression, color, national origin, pregnancy, ancestry, domestic partner status, disability, sexual orientation, age, genetic predisposition, medical condition, marital status, citizenship status, military or veteran status, or any other basis covered by applicable laws.  Mozilla will not tolerate discrimination or harassment based on any of these characteristics or any other unlawful behavior, conduct, or purpose.

Group: C

#LI-REMOTE

Req ID: R3197

Hiring Ranges:

Remote France

€65.000—€87.000 EUR

Read the full description
Security Staff Security Engineer at Mozilla

Manages Mozilla's information security management system, ISO 27001 and SOC 2 compliance programs, and security policy across the organization.

Senior Posted 4 days ago RemoteFirstJobs Product
What this role involves

Why Mozilla?

Mozilla Corporation is the non-profit-backed technology company that has shaped the internet for the better over the last 25 years. We make pioneering brands like Firefox, the privacy-minded web browser. Now, with more than 225 million people around the world using our products each month, we’re shaping the next 25 years of technology and helping to reclaim an internet built for people, not companies. Our work focuses on diverse areas including AI, social media, security and more. And we’re doing this while never losing our focus on our core mission – to make the internet better for people.

The Mozilla Corporation is wholly owned by the non-profit 501© Mozilla Foundation. This means we aren’t beholden to any shareholders — only to our mission. Along with thousands of volunteer contributors and collaborators all over the world, Mozillians design, build and distribute open-source software that enables people to enjoy the internet on their terms.

About this team and role:

This role is part of the Governance, Risk & Compliance (GRC) function within Mozilla’s Security team. The Security team supports Product, Enterprise, and GRC functions across the organization, aligned with the mission to build a safe and secure internet. This role is responsible for maintaining and advancing Mozilla’s Information Security Management System (ISMS) and supporting our ISO 27001 and SOC 2 Type 2 compliance programs — from policy and control design through audit readiness and certification.

The ideal candidate has hands-on experience across the full breadth of a compliance program, is comfortable building process where none yet exists, and works well with a wide range of cross-functional stakeholders.

What you’ll do:

  • Maintain and mature the ISMS, including the Statement of Applicability (SoA), risk treatment plans, and the Management Review Meeting (MRM) process and cadence.
  • Support ISO 27001 and SOC 2 Type 2 audit execution—helping determine scope, preparing evidence and narrative artifacts, participating in auditor interviews and walkthroughs, and resolving auditor findings.
  • Contribute to the SOC 2 System Description and other audit-specific narrative documentation, ensuring they accurately reflect the organization’s actual control environment.
  • Track gaps and remediation efforts arising from readiness assessments and audits.
  • Lead the policy program—driving policy creation, revision, and cross-functional review cycles to keep the security policy set current, enforceable, and audit-ready.
  • Support compliance scaling as additional products or business units pursue readiness assessments and certification.
  • Support the internal audit function, partnering with internal or third-party resources as needed to meet ISO 27001’s internal audit requirements.
  • Partner closely with Engineering, IT, Legal, Privacy, People teams, and product leadership to gather evidence, drive control ownership, and translate compliance requirements into practical, adoptable practices.
  • Advise the GRC manager and broader Security leadership on audit risk, certification readiness, and compliance program strategy.

What you’ll bring:

  • 5 years of experience in information security, GRC, or compliance-focused roles.
  • Deep familiarity with ISO 27001 and SOC 2 Trust Services Criteria, gained through meaningful involvement in audits from readiness through certification.
  • Comfort operating across the full breadth of an ISMS—SoA maintenance, Management Review Meetings, and System Description authorship.
  • Demonstrated experience writing and revising security policies, including running cross-functional review cycles to gain organization-wide buy-in and adoption.
  • Experience tracking gaps and remediation plans and connecting that work to an organization’s broader compliance and risk program.
  • Excellent cross-functional collaboration skills—comfortable working with engineers, product managers, legal, and executive stakeholders, and able to translate compliance requirements into practical, actionable workflows.
  • Ability to ramp up quickly and operate with a high degree of independence.
  • Comfort building processes where none yet exist.
  • Strong written and verbal communication skills; ability to represent Mozilla credibly and confidently in front of external auditors.
  • Relevant industry certifications (e.g., CISA, CISSP, ISO 27001 Lead Auditor/Implementer) are a plus.

Commitment to our values:

  • Welcoming differences
  • Being relationship-minded
  • Practicing responsible participation
  • Having grit

What you’ll get:

  • Generous performance-based bonus plans to all eligible employees—we share in our success as one team.
  • Rich medical, dental, and vision coverage.
  • Generous retirement contributions with 100% immediate vesting (regardless of whether you contribute).
  • Quarterly all-company wellness days where everyone takes a pause together.
  • Country-specific holidays plus a day off for your birthday.
  • One-time home office stipend.
  • Annual professional development budget.
  • Quarterly well-being stipend.
  • Considerable paid parental leave.
  • Employee referral bonus program.
  • Other benefits (life/AD&D, disability, EAP, etc.—varies by country).

About Mozilla

Mozilla exists to build the Internet as a public resource accessible to all because we believe that open and free is better than closed and controlled. When you work at Mozilla, you give yourself a chance to make a difference in the lives of Web users everywhere. And you give us a chance to make a difference in your life every single day. Join us to work on the Web as the platform and help create more opportunity and innovation for everyone online.

Commitment to diversity, equity, inclusion, and belonging

Mozilla understands that valuing diverse creative practices and forms of knowledge are crucial to and enrich the company’s core mission.  We encourage applications from everyone, including members of all equity-seeking communities, such as (but certainly not limited to) women, racialized and Indigenous persons, persons with disabilities, persons of all sexual orientations, gender identities, and expressions.

We will ensure that qualified individuals with disabilities are provided reasonable accommodations to participate in the job application or interview process, to perform essential job functions, and to receive other benefits and privileges of employment, as appropriate. Please contact us at hiringaccommodation@mozilla.com to request accommodation.

We are an equal opportunity employer. We do not discriminate on the basis of race (including hairstyle and texture), religion (including religious grooming and dress practices), gender, gender identity, gender expression, color, national origin, pregnancy, ancestry, domestic partner status, disability, sexual orientation, age, genetic predisposition, medical condition, marital status, citizenship status, military or veteran status, or any other basis covered by applicable laws.  Mozilla will not tolerate discrimination or harassment based on any of these characteristics or any other unlawful behavior, conduct, or purpose.

Group: C

#LI-REMOTE

Req ID: R3197

Hiring Ranges:

US Tier 1 Locations

$163,000—$218,000 USD

US Tier 2 Locations

$150,000—$200,000 USD

US Tier 3 Locations

$139,000—$185,000 USD

Read the full description
Security Staff Security Engineer at Mozilla

Maintains Mozilla's Information Security Management System, leads ISO 27001 and SOC 2 compliance programs, and manages security policy frameworks across the organization.

Senior Posted 4 days ago RemoteFirstJobs Product
What this role involves

Why Mozilla?

Mozilla Corporation is the non-profit-backed technology company that has shaped the internet for the better over the last 25 years. We make pioneering brands like Firefox, the privacy-minded web browser. Now, with more than 225 million people around the world using our products each month, we’re shaping the next 25 years of technology and helping to reclaim an internet built for people, not companies. Our work focuses on diverse areas including AI, social media, security and more. And we’re doing this while never losing our focus on our core mission – to make the internet better for people.

The Mozilla Corporation is wholly owned by the non-profit 501© Mozilla Foundation. This means we aren’t beholden to any shareholders — only to our mission. Along with thousands of volunteer contributors and collaborators all over the world, Mozillians design, build and distribute open-source software that enables people to enjoy the internet on their terms.

About this team and role:

This role is part of the Governance, Risk & Compliance (GRC) function within Mozilla’s Security team. The Security team supports Product, Enterprise, and GRC functions across the organization, aligned with the mission to build a safe and secure internet. This role is responsible for maintaining and advancing Mozilla’s Information Security Management System (ISMS) and supporting our ISO 27001 and SOC 2 Type 2 compliance programs — from policy and control design through audit readiness and certification.

The ideal candidate has hands-on experience across the full breadth of a compliance program, is comfortable building process where none yet exists, and works well with a wide range of cross-functional stakeholders.

What you’ll do:

  • Maintain and mature the ISMS, including the Statement of Applicability (SoA), risk treatment plans, and the Management Review Meeting (MRM) process and cadence.
  • Support ISO 27001 and SOC 2 Type 2 audit execution—helping determine scope, preparing evidence and narrative artifacts, participating in auditor interviews and walkthroughs, and resolving auditor findings.
  • Contribute to the SOC 2 System Description and other audit-specific narrative documentation, ensuring they accurately reflect the organization’s actual control environment.
  • Track gaps and remediation efforts arising from readiness assessments and audits.
  • Lead the policy program—driving policy creation, revision, and cross-functional review cycles to keep the security policy set current, enforceable, and audit-ready.
  • Support compliance scaling as additional products or business units pursue readiness assessments and certification.
  • Support the internal audit function, partnering with internal or third-party resources as needed to meet ISO 27001’s internal audit requirements.
  • Partner closely with Engineering, IT, Legal, Privacy, People teams, and product leadership to gather evidence, drive control ownership, and translate compliance requirements into practical, adoptable practices.
  • Advise the GRC manager and broader Security leadership on audit risk, certification readiness, and compliance program strategy.

What you’ll bring:

  • 5 years of experience in information security, GRC, or compliance-focused roles.
  • Deep familiarity with ISO 27001 and SOC 2 Trust Services Criteria, gained through meaningful involvement in audits from readiness through certification.
  • Comfort operating across the full breadth of an ISMS—SoA maintenance, Management Review Meetings, and System Description authorship.
  • Demonstrated experience writing and revising security policies, including running cross-functional review cycles to gain organization-wide buy-in and adoption.
  • Experience tracking gaps and remediation plans and connecting that work to an organization’s broader compliance and risk program.
  • Excellent cross-functional collaboration skills—comfortable working with engineers, product managers, legal, and executive stakeholders, and able to translate compliance requirements into practical, actionable workflows.
  • Ability to ramp up quickly and operate with a high degree of independence.
  • Comfort building processes where none yet exist.
  • Strong written and verbal communication skills; ability to represent Mozilla credibly and confidently in front of external auditors.
  • Relevant industry certifications (e.g., CISA, CISSP, ISO 27001 Lead Auditor/Implementer) are a plus.

Commitment to our values:

  • Welcoming differences
  • Being relationship-minded
  • Practicing responsible participation
  • Having grit

What you’ll get:

  • Generous performance-based bonus plans to all eligible employees—we share in our success as one team.
  • Rich medical, dental, and vision coverage.
  • Generous retirement contributions with 100% immediate vesting (regardless of whether you contribute).
  • Quarterly all-company wellness days where everyone takes a pause together.
  • Country-specific holidays plus a day off for your birthday.
  • One-time home office stipend.
  • Annual professional development budget.
  • Quarterly well-being stipend.
  • Considerable paid parental leave.
  • Employee referral bonus program.
  • Other benefits (life/AD&D, disability, EAP, etc.—varies by country).

About Mozilla

Mozilla exists to build the Internet as a public resource accessible to all because we believe that open and free is better than closed and controlled. When you work at Mozilla, you give yourself a chance to make a difference in the lives of Web users everywhere. And you give us a chance to make a difference in your life every single day. Join us to work on the Web as the platform and help create more opportunity and innovation for everyone online.

Commitment to diversity, equity, inclusion, and belonging

Mozilla understands that valuing diverse creative practices and forms of knowledge are crucial to and enrich the company’s core mission.  We encourage applications from everyone, including members of all equity-seeking communities, such as (but certainly not limited to) women, racialized and Indigenous persons, persons with disabilities, persons of all sexual orientations, gender identities, and expressions.

We will ensure that qualified individuals with disabilities are provided reasonable accommodations to participate in the job application or interview process, to perform essential job functions, and to receive other benefits and privileges of employment, as appropriate. Please contact us at hiringaccommodation@mozilla.com to request accommodation.

We are an equal opportunity employer. We do not discriminate on the basis of race (including hairstyle and texture), religion (including religious grooming and dress practices), gender, gender identity, gender expression, color, national origin, pregnancy, ancestry, domestic partner status, disability, sexual orientation, age, genetic predisposition, medical condition, marital status, citizenship status, military or veteran status, or any other basis covered by applicable laws.  Mozilla will not tolerate discrimination or harassment based on any of these characteristics or any other unlawful behavior, conduct, or purpose.

Group: C

#LI-REMOTE

Req ID: R3197

Hiring Ranges:

Canada Tier 1 Locations

$128,000—$171,000 CAD

Canada Tier 2 Locations

$116,000—$155,000 CAD

Read the full description
Security Senior Engineering Manager, Security & IT at Fingerprint

Senior manager unifies security, IT operations, and compliance functions, leading a team of 4 while establishing strategic security posture for enterprise fraud detection platform.

Senior Remote Posted 4 days ago RemoteFirstJobs Product
What this role involves

Fingerprint empowers developers to stop online fraud at the source.

We work on turning radical new ideas in the fraud detection space into reality. Our products are developer-focused and our clients range from solo developers to publicly traded companies. We are a globally dispersed, 100% remote company with a strong open-source focus. Our flagship open-source project is FingerprintJS (27K stars on GitHub).

We have raised $77M and are backed by Craft Ventures (previously invested in Tesla, Facebook, Airbnb ), Nexus Venture Partners (previously invested in Postman, Apollo.io, MinIO, Druva) and Uncorrelated Ventures (previously invested in Redis, Rollbar & Gradle).

We have noticed a rise in recruiting impersonations across the industry, where scammers attempt to access candidates’ personal and financial information through fake interviews and offers. All Fingerprint recruiting email communications will always come from the @fingerprint.com domain. Any outreach claiming to be from Fingerprint via other sources should be ignored.

The Role in Context

Fingerprint’s security, IT, and compliance function is more mature than most companies of this size: SOC 2 Type 2 + HIPAA achieved, a comprehensive policy suite in place, and solid IT operations running globally. What the function now needs is strategic leadership: someone who can unify security posture, IT operations, and compliance under a coherent strategy, mature each discipline to the next level, and be the credible voice of security and compliance to the rest of the engineering org and to enterprise customers.

We’re looking for a Senior Manager, Security & IT to own this function end-to-end, reporting directly to the VP of Engineering. You will manage 4 people across three disciplines: application security, IT operations, and compliance.

This is a VP-direct role with high autonomy and high visibility. Enterprise customers — many of whom are financial institutions and large-scale fraud prevention operators — regularly ask about Fingerprint’s security posture. You’ll be the person who owns that answer.

Your Mission

  • Unify and mature the function — Security, IT, and compliance have operated as separate workstreams. You create a coherent strategy across all three, with shared standards, shared risk language, and a roadmap that scales with the business
  • Own the security posture — Application security, zero-trust principles, vulnerability management, and security-by-default practices across the engineering org — you set the standard, you hold it, and you work across teams to embed it
  • Scale the compliance program — The next horizon is expanding scope, maturing evidence collection, and positioning Fingerprint for compliance requirements as enterprise deals grow
  • Run reliable IT operations — 100% remote, globally distributed engineering org. IT operations is a critical function that serves every Fingerprint employee. You own the tooling, the processes, and the reliability of those systems
  • Be the security voice to customers and leadership — Enterprise customers, prospects, and partners regularly evaluate Fingerprint’s security posture. You represent it credibly, own the security questionnaire process, and communicate risk and posture to the VP and leadership team

What You’ll Do

Security Strategy & Application Security

  • Define and own Fingerprint’s application security roadmap: vulnerability management, penetration testing program, security review process for new features and architectural changes
  • Build security-by-default practices into engineering workflows — not as a gate, but as a capability every engineering team has
  • Own the vendor security assessment process — Fingerprint handles sensitive customer data for major enterprise customers; you ensure third parties meet the bar
  • Define zero-trust security principles and ensure they’re embedded in the Cloud Platform and engineering org

Compliance & GRC

  • Own the SOC 2 Type 2 annual audit cycle — evidence collection, auditor management, control maturation
  • Drive the roadmap for compliance expansion: evaluate and prioritize future frameworks (ISO 27001, GDPR, customer-specific requirements from enterprise deals)
  • Manage the Compliance Lead — support their growth while giving them the leadership context that makes their technical compliance work more impactful
  • Be the compliance voice in enterprise sales cycles — security questionnaires, customer due diligence calls, contractual security requirements
  • Own the policy framework: ensure Fingerprint’s policy suite (already well-established) stays current, complete, and actually embedded in how teams work

IT Operations

  • Manage the Lead IT Engineer — they run day-to-day IT operations for a globally distributed engineering org; your job is to give them strategic direction and organizational context
  • Own IT strategy: tooling decisions, access management (Okta, SCIM/SAML provisioning), endpoint management, identity governance
  • Ensure IT operations scales with engineering headcount growth — proactive capacity planning, not reactive ticket-handling
  • Define IT security policies and enforce them: device management, access reviews, offboarding rigor

Cross-functional Leadership & Communication

  • Proactively communicate security posture, compliance status, and IT health to the VP Engineering — come with recommendations, not status updates
  • Partner with the Cloud Platform Sr. Manager on infrastructure security: network security, IAM standards, security logging and alerting
  • Work with Engineering leadership to embed security practices across product teams — not as a compliance checkpoint but as a capability they value
  • Represent Fingerprint’s security and compliance posture to enterprise customers, prospects, and auditors

What We’re Looking For

Required

  • 7+ years in security, IT, or GRC with at least 3 years managing a team — you’ve led people, made hard calls, and developed practitioners
  • Breadth across the three disciplines: Genuine fluency across application security, IT operations, and compliance/GRC
  • Application security depth: OWASP familiarity, vulnerability management programs (Snyk or equivalent), security review processes for engineering teams — you’re credible in a room with senior engineers talking about AppSec
  • IT operations leadership: Identity and access management (Okta or equivalent), endpoint management, remote workforce IT at scale
  • Strategic communicator: You translate security and compliance complexity into business language for leadership and customers — risk framing, not technical jargon

Preferred

  • SOC 2 ownership experience: You’ve run or been the primary owner of a SOC 2 audit cycle — not just participated in one. You understand what good evidence looks like, how to manage auditor relationships, and how to build sustainable control operations vs. annual scramble mode
  • Additional compliance frameworks: ISO 27001, GDPR, HIPAA experience — particularly relevant given Fingerprint’s enterprise customer base in financial services and healthcare
  • Security tooling stack familiarity: Snyk (vulnerability management), Wiz (cloud security posture), Cloudflare (WAF/edge), Okta — these are live in Fingerprint’s environment
  • Enterprise security questionnaire experience: You’ve answered rigorous due diligence questionnaires from financial institution InfoSec teams and know what “good” looks like on both sides of that process
  • Experience in a high-growth SaaS company where security had to keep pace with rapid product and customer growth without becoming a bottleneck

The Unique Shape of This Role

This role deliberately spans three disciplines that are often separated at larger companies. At Fingerprint’s scale, that breadth is a feature, not a bug: the person who owns compliance also owns the security posture that makes compliance meaningful, and the person who owns IT operations also owns the identity and access foundation that security depends on. You won’t have the luxury of optimizing one function at the expense of the others.

What this means in practice: you need to be comfortable setting direction across domains where your team members have more operational depth than you do. We don’t expect you to be the deepest technical expert in AppSec, IT operations, and GRC simultaneously — your team covers that depth. What we do expect is that you understand each domain well enough to set direction, evaluate the work, and make hard prioritization calls across all three. The judgment to know when to rely on your team vs. when to drive the decision yourself is what distinguishes the right candidate from someone who is simply strong in one area.

This isn’t a role for someone who wants to be a player-coach in one discipline. It’s a role for someone who has moved past that — who leads through strategy, communication, and people development, not through personal technical execution.

Why This Role?

  • VP direct line with genuine autonomy: You own the function. You come to the VP with recommendations, not requests for direction
  • A strong team already in place: The Lead IT Engineer and Compliance Lead are capable, experienced practitioners. You’re not building from scratch — you’re giving them strategic leadership and maturing what they’ve already built
  • High customer visibility: Fingerprint serves major enterprise customers in financial services, fraud prevention, and beyond. Security posture is a real differentiator in enterprise sales, and you’re the person who owns it
  • Compliance maturity to build on: SOC 2 Type 2 + HIPAA is already achieved. The next horizon — expanded frameworks, deeper enterprise compliance requirements — is yours to define
  • A function that’s finally getting its own leadership: Security and IT have been embedded in a larger infrastructure group without dedicated management. This role exists because Fingerprint recognizes these functions need focused, strategic leadership to reach the next level

Compensation Range

For US-based employees, the cash compensation range for this role is $177,000 – $240,000. We set standard ranges for all US roles based on function, level, and geographic location, benchmarked against similar stage growth companies. To comply with local legislation and provide greater transparency, we share salary ranges on all job postings. However, these ranges are specific to the hiring location and may differ within or outside the US.

We have noticed a rise in recruiting impersonations across the industry, where scammers attempt to access candidates’ personal and financial information through fake interviews and offers. All Fingerprint recruiting email communications will always come from the @fingerprint.com domain. Any outreach claiming to be from Fingerprint via other sources should be ignored.

Offers vary depending on, but not limited to, relevant experience, education, certifications/licenses, skills, training, and market conditions.

Due to regulatory and security reasons, there’s a small number of countries where we cannot have Fingerprint teammates based. Additionally, because Fingerprint is an all-remote company and people can join our workforce from almost any country, we do not sponsor visas. Fingerprint teammates need to be authorized to work from their home location.

We are dedicated to creating an inclusive work environment for everyone. We embrace and celebrate the unique experiences, perspectives and cultural backgrounds that each employee brings to our workplace. Fingerprint strives to foster an environment where our employees feel respected, valued and empowered, and our team members are at the forefront in helping us promote and sustain an inclusive workplace. We highly encourage people from underrepresented groups in tech to apply.

If you are applying as a resident of California, please read our CCPA notice here

If you are applying as a resident of the EU, please read our GDPR notice here

Read the full description
Security Staff Security Engineer at Mozilla

Maintains and matures Mozilla's Information Security Management System, supports ISO 27001 and SOC 2 Type 2 compliance programs, and ensures audit readiness across the organization.

Senior Posted 4 days ago RemoteFirstJobs Product
What this role involves

To learn the Hiring Ranges for this position, please select your location from the Apply Now dropdown menu.

To learn more about our Hiring Range System, please click this link.

Why Mozilla?

Mozilla Corporation is the non-profit-backed technology company that has shaped the internet for the better over the last 25 years. We make pioneering brands like Firefox, the privacy-minded web browser. Now, with more than 225 million people around the world using our products each month, we’re shaping the next 25 years of technology and helping to reclaim an internet built for people, not companies. Our work focuses on diverse areas including AI, social media, security and more. And we’re doing this while never losing our focus on our core mission – to make the internet better for people.

The Mozilla Corporation is wholly owned by the non-profit 501© Mozilla Foundation. This means we aren’t beholden to any shareholders — only to our mission. Along with thousands of volunteer contributors and collaborators all over the world, Mozillians design, build and distribute open-source software that enables people to enjoy the internet on their terms.

About this team and role:

This role is part of the Governance, Risk & Compliance (GRC) function within Mozilla’s Security team. The Security team supports Product, Enterprise, and GRC functions across the organization, aligned with the mission to build a safe and secure internet. This role is responsible for maintaining and advancing Mozilla’s Information Security Management System (ISMS) and supporting our ISO 27001 and SOC 2 Type 2 compliance programs — from policy and control design through audit readiness and certification.

The ideal candidate has hands-on experience across the full breadth of a compliance program, is comfortable building process where none yet exists, and works well with a wide range of cross-functional stakeholders.

What you’ll do:

  • Maintain and mature the ISMS, including the Statement of Applicability (SoA), risk treatment plans, and the Management Review Meeting (MRM) process and cadence.
  • Support ISO 27001 and SOC 2 Type 2 audit execution—helping determine scope, preparing evidence and narrative artifacts, participating in auditor interviews and walkthroughs, and resolving auditor findings.
  • Contribute to the SOC 2 System Description and other audit-specific narrative documentation, ensuring they accurately reflect the organization’s actual control environment.
  • Track gaps and remediation efforts arising from readiness assessments and audits.
  • Lead the policy program—driving policy creation, revision, and cross-functional review cycles to keep the security policy set current, enforceable, and audit-ready.
  • Support compliance scaling as additional products or business units pursue readiness assessments and certification.
  • Support the internal audit function, partnering with internal or third-party resources as needed to meet ISO 27001’s internal audit requirements.
  • Partner closely with Engineering, IT, Legal, Privacy, People teams, and product leadership to gather evidence, drive control ownership, and translate compliance requirements into practical, adoptable practices.
  • Advise the GRC manager and broader Security leadership on audit risk, certification readiness, and compliance program strategy.

What you’ll bring:

  • 5 years of experience in information security, GRC, or compliance-focused roles.
  • Deep familiarity with ISO 27001 and SOC 2 Trust Services Criteria, gained through meaningful involvement in audits from readiness through certification.
  • Comfort operating across the full breadth of an ISMS—SoA maintenance, Management Review Meetings, and System Description authorship.
  • Demonstrated experience writing and revising security policies, including running cross-functional review cycles to gain organization-wide buy-in and adoption.
  • Experience tracking gaps and remediation plans and connecting that work to an organization’s broader compliance and risk program.
  • Excellent cross-functional collaboration skills—comfortable working with engineers, product managers, legal, and executive stakeholders, and able to translate compliance requirements into practical, actionable workflows.
  • Ability to ramp up quickly and operate with a high degree of independence.
  • Comfort building processes where none yet exist.
  • Strong written and verbal communication skills; ability to represent Mozilla credibly and confidently in front of external auditors.
  • Relevant industry certifications (e.g., CISA, CISSP, ISO 27001 Lead Auditor/Implementer) are a plus.

Commitment to our values:

  • Welcoming differences
  • Being relationship-minded
  • Practicing responsible participation
  • Having grit

What you’ll get:

  • Generous performance-based bonus plans to all eligible employees—we share in our success as one team.
  • Rich medical, dental, and vision coverage.
  • Generous retirement contributions with 100% immediate vesting (regardless of whether you contribute).
  • Quarterly all-company wellness days where everyone takes a pause together.
  • Country-specific holidays plus a day off for your birthday.
  • One-time home office stipend.
  • Annual professional development budget.
  • Quarterly well-being stipend.
  • Considerable paid parental leave.
  • Employee referral bonus program.
  • Other benefits (life/AD&D, disability, EAP, etc.—varies by country).

About Mozilla

Mozilla exists to build the Internet as a public resource accessible to all because we believe that open and free is better than closed and controlled. When you work at Mozilla, you give yourself a chance to make a difference in the lives of Web users everywhere. And you give us a chance to make a difference in your life every single day. Join us to work on the Web as the platform and help create more opportunity and innovation for everyone online.

Commitment to diversity, equity, inclusion, and belonging

Mozilla understands that valuing diverse creative practices and forms of knowledge are crucial to and enrich the company’s core mission.  We encourage applications from everyone, including members of all equity-seeking communities, such as (but certainly not limited to) women, racialized and Indigenous persons, persons with disabilities, persons of all sexual orientations, gender identities, and expressions.

We will ensure that qualified individuals with disabilities are provided reasonable accommodations to participate in the job application or interview process, to perform essential job functions, and to receive other benefits and privileges of employment, as appropriate. Please contact us at hiringaccommodation@mozilla.com to request accommodation.

We are an equal opportunity employer. We do not discriminate on the basis of race (including hairstyle and texture), religion (including religious grooming and dress practices), gender, gender identity, gender expression, color, national origin, pregnancy, ancestry, domestic partner status, disability, sexual orientation, age, genetic predisposition, medical condition, marital status, citizenship status, military or veteran status, or any other basis covered by applicable laws.  Mozilla will not tolerate discrimination or harassment based on any of these characteristics or any other unlawful behavior, conduct, or purpose.

Group: C

#LI-DNI

Req ID: R3197

Read the full description
Security Cyber Security Engineer / Information Systems Security Engineer (ISSE) at OpenTeams

Leads cybersecurity architecture, RMF activities, and compliance for government systems while designing supply chain security controls and integrating security into CI/CD pipelines.

Senior Remote Posted 6 days ago RemoteFirstJobs Product
What this role involves

Who We Are

We exist to unlock human potential.

Too often, AI drains it—drains budgets, drains energy resources, drains ownership of data. OpenTeams was founded to change that. We build AI that empowers. Our models are energy-efficient, cost-effective, and fully yours.

Our ethos is open source. That means freedom, trust, and accountability are built into every line of code. We reinvest 3% of our profits back into the open-source community, because we believe tech is most powerful when it serves everyone.

At our core, we value freedom, teamwork, accountability, and uncompromising quality. If you want to challenge the status quo, and shape tools that set people free, OpenTeams is the place to do it.

Location: Remote (US) with travel to customer sites as required (Washington Metro Area preferred)

Employment Type: Full-time

Clearance: Active TS/SCI required

Role Summary

The Cyber Security Engineer / ISSE owns the security architecture and accreditation posture of the depot. This role leads RMF activities, embeds security controls into engineering workflows, and serves as the primary security interface with government assessors and authorizing officials.

Responsibilities

  • Lead RMF activities: control selection, implementation evidence, POA&M management, and ATO support
  • Design and implement supply chain security controls: SBOM generation, artifact signing, vulnerability scanning, and provenance attestation
  • Perform threat modeling and security reviews of depot architecture and workflows
  • Integrate security tooling into CI/CD pipelines and enforce policy gates
  • Support cross-domain and classified environment requirements, including secure transfer procedures
  • Interface with government ISSMs, assessors, and authorizing officials

Required Qualifications

  • Active TS/SCI clearance
  • Experience with Xacta, eMASS, or CSAM
  • 6+ years in cyber security or ISSE roles supporting DoD or IC systems
  • Hands-on experience with RMF, NIST 800-53, and eMASS or equivalent
  • Experience with DevSecOps tooling: container scanning, SAST/DAST, signing, and policy enforcement
  • IAT/IAM Level II or III certification per DoD 8140 (for example Security+, CISSP, or CISM)

Preferred Qualifications

  • Experience securing AI/ML systems or software supply chains at scale
  • Familiarity with cATO approaches and continuous monitoring
  • Experience with IL5/IL6 or cross-domain solutions

Grow With Us

At OpenTeams, growth isn’t just about the company—it’s about you.

We believe the best careers are built at the edge of your potential. That is where new tools, ideas, and technologies change the world. Here, you’ll work alongside pioneers of AI, solving problems that matter: making AI more transparent, more ethical, and more empowering. As your skills grow, our career framework provides a pathway and recognition of that increased impact.

Opportunities aren’t limited by geography. You’ll collaborate with global experts, contribute to open source projects that power the world’s technology, and stretch your skills daily.  That global perspective and diversity makes our solution more universal and robust.  We are committed to continuing to celebrate diversity on our team.

Supported people are successful people.  We offer 100% employer paid medical premiums for employees and self-managed PTO with a minimum time off requirement, so that our teams are able to do their best work.

We invest  in curiosity, creativity, and ownership. That means you’ll be trusted to boldly innovate, supported to learn fast, and celebrated for successful collaboration.

Commitment to diversity, equity, inclusion, and belonging

OpenTeams understands that valuing diverse creative practices and forms of knowledge is crucial to and enriches the company’s core mission. We encourage applications from everyone, including members of all equity-seeking communities, such as (but certainly not limited to) women, racialized and Indigenous persons, disabled people, persons of all sexual orientations, gender identities and expressions.

We are an equal opportunity employer - all qualified applicants will receive equal consideration for recruitment, interviews, employment, training, compensation, promotion, and related activities. We do not discriminate based on race, religion, gender, gender identity, gender expression, color, national origin, pregnancy, ancestry, domestic partner status, disability, sexual orientation, age, genetic predisposition, medical condition, marital status, citizenship status, military or veteran status, or any other basis covered by applicable laws. OpenTeams will not tolerate discrimination or harassment based on these characteristics or any other unlawful behavior, conduct, or purpose.

Read the full description
Security Senior Cloud Security Engineer at Rescale

Design and harden cloud infrastructure, identity systems, and security automation pipelines while evaluating AI-assisted tools and responding to security incidents.

Senior Posted 6 days ago RemoteFirstJobs Product
What this role involves

About Rescale

Rescale is pioneering the future of engineering and scientific discovery. As the leader in digital engineering, we’re transforming how products are developed—through intelligent automation, applied AI, data management, and the integration of the world’s largest network of engineering and R&D applications. Joining Rescale means becoming part of a diverse, collaborative, and mission-driven team that’s unlocking faster innovation across industries like aerospace, energy, life sciences, and manufacturing. We’re solving complex challenges that traditional HPC can’t—and we’re seeking passionate, curious minds to help build the next wave of breakthroughs.

We’re hiring a Senior Cloud Security Engineer to help secure the cloud infrastructure, identity systems, and internal tooling that our platform and our company run on. You’ll work across AWS, Okta, GitHub Enterprise, and increasingly AI-assisted and agentic tooling our employees use daily. This is a hands-on role: you’ll be writing Terraform, querying logs, and designing IAM policy, not just reviewing other people’s work.

What you’ll work on:

  • Design, build, and harden cloud infrastructure and identity systems

  • Build and maintain security automation and detection pipelines

  • Evaluate and help secure the growing set of AI-assisted and agentic tools used internally (e.g., Claude Code, MCP servers, LLM-driven automation)

  • Investigate and respond to security findings, including triaging authentication anomalies, reviewing access logs, and querying data via tools like Athena, CloudTrail Lake, or Superset.

  • Contribute to Infrastructure-as-Code (Terraform) for security controls, identity provisioning, and compliance-relevant configuration and monitoring.

  • Support secure network and cloud deployment designs for enterprise customer environments, partnering with engineering and customer-facing teams on requirements.

  • Research emerging cloud-native and AI security capabilities (including AI-enabled attack techniques) and translate findings into practical controls and internal guidance.

  • Write internal documentation, runbooks, and playbooks to scale security practices across the team.

What we’re looking for:

  • 5+ years of experience in cloud-native security or DevSecOps.

  • 3+ years of experience with Bash or Python.

  • Deep, hands-on experience with a major cloud provider (AWS, Azure, GCP, or OCI.

  • Experience with Infrastructure-as-Code (Terraform or similar) and identity/access management platforms (Okta, Azure AD, or similar).

  • Real exposure to at least one of: OAuth/token architecture, AI/LLM-assisted tooling security, or agentic workflow design

  • Solid understanding of operating systems and networking fundamentals.

  • Bachelor’s degree in Computer Science or related field, or equivalent practical experience, but not required if you have the experience above.

Rescale is an equal opportunities employer and welcomes applications from all qualified persons regardless of their race, sex, disability, religion/belief, sexual orientation or age. As part of our standard hiring process for new employees, employment with Rescale will be contingent upon successful completion of a comprehensive background check. Here at Rescale, we are committed to being transparent in our policies around candidate privacy. For more details on the information Rescale collects in your application, please view the Rescale Applicant Privacy Policy here.

Read the full description
Security Senior Cloud Security Engineer at Rescale

Designs and hardens cloud infrastructure, builds security automation pipelines, and secures AI-assisted tooling across AWS and identity systems.

Senior Posted 6 days ago RemoteFirstJobs Product
What this role involves

About Rescale

Rescale is pioneering the future of engineering and scientific discovery. As the leader in digital engineering, we’re transforming how products are developed—through intelligent automation, applied AI, data management, and the integration of the world’s largest network of engineering and R&D applications. Joining Rescale means becoming part of a diverse, collaborative, and mission-driven team that’s unlocking faster innovation across industries like aerospace, energy, life sciences, and manufacturing. We’re solving complex challenges that traditional HPC can’t—and we’re seeking passionate, curious minds to help build the next wave of breakthroughs.

We’re hiring a Senior Cloud Security Engineer to help secure the cloud infrastructure, identity systems, and internal tooling that our platform and our company run on. You’ll work across AWS, Okta, GitHub Enterprise, and increasingly AI-assisted and agentic tooling our employees use daily. This is a hands-on role: you’ll be writing Terraform, querying logs, and designing IAM policy, not just reviewing other people’s work.

What you’ll work on:

  • Design, build, and harden cloud infrastructure and identity systems

  • Build and maintain security automation and detection pipelines

  • Evaluate and help secure the growing set of AI-assisted and agentic tools used internally (e.g., Claude Code, MCP servers, LLM-driven automation)

  • Investigate and respond to security findings, including triaging authentication anomalies, reviewing access logs, and querying data via tools like Athena, CloudTrail Lake, or Superset.

  • Contribute to Infrastructure-as-Code (Terraform) for security controls, identity provisioning, and compliance-relevant configuration and monitoring.

  • Support secure network and cloud deployment designs for enterprise customer environments, partnering with engineering and customer-facing teams on requirements.

  • Research emerging cloud-native and AI security capabilities (including AI-enabled attack techniques) and translate findings into practical controls and internal guidance.

  • Write internal documentation, runbooks, and playbooks to scale security practices across the team.

What we’re looking for:

  • 5+ years of experience in cloud-native security or DevSecOps.

  • 3+ years of experience with Bash or Python.

  • Deep, hands-on experience with a major cloud provider (AWS, Azure, GCP, or OCI.

  • Experience with Infrastructure-as-Code (Terraform or similar) and identity/access management platforms (Okta, Azure AD, or similar).

  • Real exposure to at least one of: OAuth/token architecture, AI/LLM-assisted tooling security, or agentic workflow design

  • Solid understanding of operating systems and networking fundamentals.

  • Bachelor’s degree in Computer Science or related field, or equivalent practical experience, but not required if you have the experience above.

Rescale is an equal opportunities employer and welcomes applications from all qualified persons regardless of their race, sex, disability, religion/belief, sexual orientation or age. As part of our standard hiring process for new employees, employment with Rescale will be contingent upon successful completion of a comprehensive background check. Here at Rescale, we are committed to being transparent in our policies around candidate privacy. For more details on the information Rescale collects in your application, please view the Rescale Applicant Privacy Policy here.

Read the full description