Compliance Senior Analyst
BrowserStack · Mumbai Remote
Free to search · AI fit score against your CV · tailor your résumé in one click
BrowserStack · Mumbai Remote
Who are we and what do we do? BrowserStack is the world’s leading cloud-based software testing platform, empowering over 50,000 customers—including Amazon, Microsoft, Meta, and Google—to deliver high-quality software at speed. Founded in 2011 by Ritesh Arora and Nakul Aggarwal, the company has grown to support more than two million tests daily across 22 global data centers, providing instant access to 35,000+ real devices and browsers. With over 1,200 employees and a remote-first approach, BrowserStack operates at the intersection of scale, reliability, and innovation. Its suite of products spans manual and automated testing, visual regression, accessibility, and test management—all designed to simplify the testing process for modern development teams. Behind the scenes, BrowserStack continues to push the boundaries with AI capabilities like smart test case generation and design, flakiness detection, auto-healing and more —helping teams reduce maintenance overhead, debug faster, and catch issues earlier in the development lifecycle. Recognized for its innovation and growth, BrowserStack has been named to the Forbes Cloud 100 list for four consecutive years. With backing from investors like Accel, Bond, and Insight Partners, the company continues to expand its product offerings and global footprint. Joining BrowserStack means being part of a mission-driven team dedicated to shaping the future of software testing. Location: This is a remote position; however, the role requires the candidate to be based in Mumbai.Role in a Nutshell BrowserStack's Compliance team owns the company's compliance posture across the security and privacy frameworks it operates under globally, making that posture verifiable to customers, auditors, and regulators. As a Compliance Analyst, you will work across certification audits, framework implementation, customer security assurance, contract review, and compliance operations. Depending on your experience, you may support or independently own different parts of these processes. We are looking for someone who is self-motivated, takes ownership of problems rather than just tasks, and enjoys turning ambiguous requirements into practical processes. This role offers the opportunity to build deep expertise in compliance while gradually taking ownership of larger areas of the function. The level of ownership will vary based on your experience, with opportunities to progressively take ownership of larger areas of the compliance program. Responsibilities ● Support and, based on experience, independently manage BrowserStack's compliance certifications and audit cycles, including audit planning, evidence collection, control testing, documentation, remediation, and auditor coordination. ● Implement and maintain controls for frameworks such as SOC 2, ISO 27001, ISO 27701, ISO 42001, and applicable data privacy regulations, working closely with control owners across the organization. ● Track audit, framework, and remediation action items through closure and maintain an accurate and up-to-date view of BrowserStack's control environment. ● Translate framework and regulatory requirements into practical, workable controls in collaboration with Engineering, Product, IT, Legal, and other teams. ● Respond to customer security questionnaires, RFIs, and security assurance requests, including handling more complex or technical questions as experience grows. ● Maintain and improve the internal knowledge base used to support customer security responses, ensuring information remains accurate as the product, controls, and certifications evolve. ● Contribute to BrowserStack's public-facing security documentation and Trust Center, ensuring that published information accurately reflects the company's actual control environment. ● Review vendor and customer contracts for security, privacy, and compliance risks against established review standards and support the development of reusable review guidelines and clause libraries. ● Partner with Engineering, Product, and Customer-facing teams to understand technical or product-specific compliance requirements and translate them into clear, reusable responses. ● Read and evaluate security documentation, audit reports, architecture diagrams, and related evidence to determine whether they adequately support compliance requirements or customer-facing claims. ● Identify recurring gaps, manual processes, or inefficiencies across compliance operations and propose practical improvements to processes, documentation, or tooling. ● Work with tools such as Jira and Confluence to manage compliance workflows, documentation, and action items. ● Contribute to the evaluation and adoption of GRC, continuous compliance, Trust Center, questionnaire management, and contract review tools. Requirements ● 1–5 years of experience in compliance, GRC, security assurance, IT audit, information security, or a related field, ideally in a B2B SaaS or technology environment. ● Working knowledge of security and privacy frameworks and regulations such as SOC 2, ISO 27001, ISO 27701, ISO 42001, GDPR, or equivalent, with the ability to interpret and apply these requirements to practical compliance activities. ● Hands-on experience with, or exposure to, audit and compliance activities such as audit planning, evidence collection, control testing, control implementation, documentation, remediation, or auditor coordination.