Senior Compliance Analyst
BrowserStack · Mumbai Metropolitan Region
- Experience1–5 yrs
- SalaryNot disclosed
- Work moderemote
- Leveljunior
- Posted17 Sept 2026
About BrowserStack
BrowserStack is hiring in Mumbai Metropolitan Region in technology software. This role looks for around 1+ years of experience.
Skills
- SOC 2
- ISO 27001
- ISO 27701
- ISO 42001
- GDPR
- audit planning
- evidence collection
- control testing
- control implementation
- remediation
- auditor coordination
- customer security questionnaires
- security assurance
- contract review
- Jira
- Confluence
The role
A compliance analyst at a technology software company manages security and privacy compliance frameworks, audit programs, and customer security assurance. The role translates regulatory requirements into practical controls and evaluates technical evidence for audits and contract reviews, using Jira and Confluence for compliance operations.
Full job description
Role in a NutshellBrowserStack's Compliance team owns the company's compliance posture across the securityand privacy frameworks it operates under globally, making that posture verifiable to customers,auditors, and regulators.As a Compliance Analyst, you will work across certification audits, framework implementation,customer security assurance, contract review, and compliance operations. Depending on yourexperience, you may support or independently own different parts of these processes.We are looking for someone who is self-motivated, takes ownership of problems rather than justtasks, and enjoys turning ambiguous requirements into practical processes. This role offers theopportunity to build deep expertise in compliance while gradually taking ownership of largerareas of the function.
This role requires you to work remotely, based out of Mumbai. Relocation to Mumbai is mandatory.
The level of ownership will vary based on your experience, with opportunities to progressivelytake ownership of larger areas of the compliance program.Responsibilities● Support and, based on experience, independently manage BrowserStack's compliance certifications and audit cycles, including audit planning, evidence collection, control testing, documentation, remediation, and auditor coordination.● Implement and maintain controls for frameworks such as SOC 2, ISO 27001, ISO 27701, ISO 42001, and applicable data privacy regulations, working closely with control owners across the organization.● Track audit, framework, and remediation action items through closure and maintain an accurate and up-to-date view of BrowserStack's control environment.● Translate framework and regulatory requirements into practical, workable controls in collaboration with Engineering, Product, IT, Legal, and other teams.● Respond to customer security questionnaires, RFIs, and security assurance requests, including handling more complex or technical questions as experience grows.● Maintain and improve the internal knowledge base used to support customer security responses, ensuring information remains accurate as the product, controls, and certifications evolve.● Contribute to BrowserStack's public-facing security documentation and Trust Center, ensuring that published information accurately reflects the company's actual control environment.● Review vendor and customer contracts for security, privacy, and compliance risks against established review standards and support the development of reusable review guidelines and clause libraries.● Partner with Engineering, Product, and Customer-facing teams to understandtechnical or product-specific compliance requirements and translate them into clear, reusable responses.● Read and evaluate security documentation, audit reports, architecture diagrams, and related evidence to determine whether they adequately support compliancerequirements or customer-facing claims.● Identify recurring gaps, manual processes, or inefficiencies across compliance operations and propose practical improvements to processes, documentation, or tooling.● Work with tools such as Jira and Confluence to manage compliance workflows, documentation, and action items.● Contribute to the evaluation and adoption of GRC, continuous compliance, Trust Center, questionnaire management, and contract review tools.
Requirements● 1–5 years of experience in compliance, GRC, security assurance, IT audit, information security, or a related field, ideally in a B2B SaaS or technology environment.● Working knowledge of security and privacy frameworks and regulations such as SOC 2, ISO 27001, ISO 27701, ISO 42001, GDPR, or equivalent, with the ability to interpret and apply these requirements to practical compliance activities.● Hands-on experience with, or exposure to, audit and compliance activities such as audit planning, evidence collection, control testing, control implementation, documentation, remediation, or auditor coordination.● Ability to translate framework and regulatory requirements into practical, workable controls and collaborate with teams across Engineering, Product, IT, Legal, and other functions to implement them.● Ability to read and interpret security documentation, audit reports, architecture diagrams, cloud configurations, and other technical information well enough to assess whether evidence adequately supports a compliance requirement.● Experience responding to or supporting customer security questionnaires, RFIs, and security assurance requests, with the ability to communicate technical and compliance information clearly to non-technical audiences.● Strong written and verbal communication skills, with the ability to translate technical,security, privacy, and legal concepts into clear, customer-ready and auditor-ready language.● Strong ownership and problem-solving mindset, with the ability to identify gaps,investigate root causes, and drive issues through to resolution rather than simplycompleting assigned tasks.● Ability to manage multiple compliance activities, maintain accurate documentation, and track audit, framework, and remediation action items through closure.● Comfortable working with collaborative tools such as Jira and Confluence for documentation, workflow management, and compliance tracking.● Exposure to or experience with GRC and continuous compliance platforms, Trust Center or security questionnaire tooling, or contract review tooling is a plus.● Exposure to vendor and customer contract reviews from a security, privacy, or compliance perspective is a plus.● Experience working directly with auditors, control owners, Engineering, Product, or Customer-facing teams to resolve compliance requirements is a plus.● Professional certifications such as CISA, CISM, CRISC, ISO 27001 Lead Auditor/Lead Implementer, or CIPP/E are a plus.
What You'll Get to Work On
This role provides exposure across the broader compliance function, including:● Security and privacy compliance frameworks● Certification and audit programs● Control design and implementation● Customer security assurance● Security questionnaires and RFIs● Contract and compliance reviews● Trust Center and security documentation● Compliance processes, automation, and tooling