Compliance Program Manager, Governance, Risk & Compliance (GRC)
CanadaJob Description
Key Skills Required
Master these to land this role
Want to know if you're a match for this job?
About this team and role:
This role is part of the Governance, Risk & Compliance (GRC) function within Mozilla's Security team. The Security team supports Product, Enterprise, and GRC functions across the organization, aligned with the mission to build a safe and secure internet. This role is responsible for maintaining and advancing Mozilla's Information Security Management System (ISMS) and supporting our ISO 27001 and SOC 2 Type 2 compliance programs — from policy and control design through audit readiness and certification.
The ideal candidate has hands-on experience across the full breadth of a compliance program, is comfortable building process where none yet exists, and works well with a wide range of cross-functional stakeholders.
What you'll do:
- Maintain and mature the ISMS, including the Statement of Applicability (SoA), risk treatment plans, and the Management Review Meeting (MRM) process and cadence.
- Support ISO 27001 and SOC 2 Type 2 audit execution—helping determine scope, preparing evidence and narrative artifacts, participating in auditor interviews and walkthroughs, and resolving auditor findings.
- Contribute to the SOC 2 System Description and other audit-specific narrative documentation, ensuring they accurately reflect the organization's actual control environment.
- Track gaps and remediation efforts arising from readiness assessments and audits.
- Lead the policy program—driving policy creation, revision, and cross-functional review cycles to keep the security policy set current, enforceable, and audit-ready.
- Support compliance scaling as additional products or business units pursue readiness assessments and certification.
- Support the internal audit function, partnering with internal or third-party resources as needed to meet ISO 27001's internal audit requirements.
- Partner closely with Engineering, IT, Legal, Privacy, People teams, and product leadership to gather evidence, drive control ownership, and translate compliance requirements into practical, adoptable practices.
- Advise the GRC manager and broader Security leadership on audit risk, certification readiness, and compliance program strategy.
What you'll bring:
- 5 years of experience in information security, GRC, or compliance-focused roles.
- Deep familiarity with ISO 27001 and SOC 2 Trust Services Criteria, gained through meaningful involvement in audits from readiness through certification.
- Comfort operating across the full breadth of an ISMS—SoA maintenance, Management Review Meetings, and System Description authorship.
- Demonstrated experience writing and revising security policies, including running cross-functional review cycles to gain organization-wide buy-in and adoption.
- Experience tracking gaps and remediation plans and connecting that work to an organization's broader compliance and risk program.
- Excellent cross-functional collaboration skills—comfortable working with engineers, product managers, legal, and executive stakeholders, and able to translate compliance requirements into practical, actionable workflows.
- Ability to ramp up quickly and operate with a high degree of independence.
- Comfort building processes where none yet exist.
- Strong written and verbal communication skills; ability to represent Mozilla credibly and confidently in front of external auditors.
- Relevant industry certifications (e.g., CISA, CISSP, ISO 27001 Lead Auditor/Implementer) are a plus.
Commitment to our values:
- Welcoming differences
- Being relationship-minded
- Practicing responsible participation
- Having grit
What you'll get:
- Generous performance-based bonus plans to all eligible employees—we share in our success as one team.
- Rich medical, dental, and vision coverage.
- Generous retirement contributions with 100% immediate vesting (regardless of whether you contribute).
- Quarterly all-company wellness days where everyone takes a pause together.
- Country-specific holidays plus a day off for your birthday.
- One-time home office stipend.
- Annual professional development budget.
- Quarterly well-being stipend.
- Considerable paid parental leave.
- Employee referral bonus program.
- Other benefits (life/AD&D, disability, EAP, etc.—varies by country).
How would you rate this job post?
See what other professionals think about this role.
Similar Opportunities
More Openings at Mozilla
Mozilla
View Company ProfileMozilla is a global, grassroots community of people dedicated to making the web open, a global resource for all, and a healthy alternative to the closed, proprietary, and often exploitative web. We are best known for the Firefox web browser. We believe the internet is a public resource, not a commodity to be privately controlled. We are a non-profit organization, and our mission is to ensure the Internet remains a powerful force for good in the world.
Safety First
- Never pay for a job application.
- Do not share sensitive bank info.
- Verify the client before starting work.



