Sr. Compliance Analyst (Compliance Management, ISO27001, ISO 27018, SOC)

Cloud Operations Chandigarh, India


For over 10 years, Zscaler has been disrupting and transforming the security industry. Our 100% purpose-built cloud platform delivers the entire gateway security stack as a service through 150 global data centers to securely connect users to their applications, regardless of device, location, or network in over 185 countries protecting over 3,900 companies and have detected 100 Million threats/day. 

We work in a fast-paced, dynamic and make it happen culture. Our people are some of the brightest and passionate in the industry that thrives on being the first to solve problems.  We are always looking to hire highly passionate, collaborative and humble people that want to make a difference.


Position: Sr. Compliance Analyst

Location: Chandigarh, India


As a Senior Compliance Analyst, you will have the opportunity to meaningfully impact how our organization scales by supporting Zscaler’s Compliance program in accordance with ISO, SOC 2, CSA STAR, and Privacy programs. Join industry-leading professionals to ensure that our processes, infrastructure, and product are designed, operated, maintained and protected in accordance with these certifications and security standards as it applies to Zscaler. This role reports to the Leader of the Compliance function and will work closely with the Engineering, Cloud Operations, Customer Care, Partner Liaisons and Product Management.


Responsibilities/What You’ll Do:

  • You will be supporting Zscaler's SOC 2, CSA STAR and ISMS aligned with ISO27001 and ISO 27018 certifications
  • Your primary focus will be Zscaler Vendor Risk Management program to ensure Critical vendor’s risk and compliance posture inline with Zscaler policy
  • You will ensure that Zscaler’s 3rd party vendors are onboarded with proper due diligence in assessing their risk and appropriately mitigated where necessary.
  • You will support Zscaler’s Sales Enablement activities and respond to Customer /Prospects questions on Zscaler Compliance roadmap and posture
  • You will work closely with Engineering, Operations and Customer Care teams to ensure sustenance of existing compliance posture and new compliance initiatives
  • You will take a hands-on approach while participating in all phases of the development lifecycle and operational rollout with a constant focus on improving process and overall quality in compliance with applicable regulatory and benchmark standards mentioned above
  • You will proactively maintain awareness of emerging security vulnerabilities and changes to regulatory and compliance standards
  • Track plan of actions and milestones towards implementation
  • Proactively track and recommend alternative approaches for risk mitigation
  • Establish and ensure the company’s processes are ready to meet initial assessments and are set up for sustainable, long-term operation
  • Communicate program updates to executive staff, product leadership as needed
  • Assist Zscaler teams in their effort to understand and implement accreditation requirements
  • Support ongoing, continuous program efforts by developing and maintaining appropriate information and documentation for compliance with SOC 2, HIPAA, ISO27001 and ISO 27018 standards

Qualifications/Your Background:

  • 5+ years of direct compliance management experience on enterprise products or large enterprise
  • Experience in program or project management, auditing, and/or control framework development and implementation
  • Experience in compliance documentation related to Policy, Procedures and ensuring that committed certification and assessments are delivered on schedule
  • Proven ability to work and effectively prioritize in a highly dynamic work environment
  • You have been part of a compliance program such as ISO, SOC 2, CSA or similar projects in the last 2 years
  • Professional certification such as Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), Certified Information Systems Auditor (CISA) preferred
  • Strong understanding of ISO 27001, SOC 2 principles and Cyber Security Best Practices
  • Solid understanding of software development life cycles and methodologies
  • A clear understanding of cloud computing services/deployment architecture
  • Strong Linux background is a plus
  • Networking knowledge is a plus
  • A record of delivery of process improvement projects with technology processes and/or major tech companies
  • Partners with cross-functional, technically-oriented roles to deliver team goals
  • Thinks about creative ways to apply program management best practices to enable teams to operate more efficiently
  • Excellent communication skills that are clear, logical and compelling to colleagues at all levels
  • Approach challenges with a passion and leverage any and all opportunities to learn
  • Thrive in a team environment where collaboration and knowledge sharing is critical to success
  • Strong problem-solving ability
  • Enjoys solving multifaceted problems with large business impact


Why Zscaler?

  • Zscaler is the world’s leading software-as-a-service security platform
  • We deliver best of breed security services with unprecedented scale
  • 100 Million threats detected a day across 185+ countries
  • Glassdoor rating of 4.7/5.0 + 98% CEO Approval = Exceptional place to work!

People who excel at Zscaler are smart, motivated and share our values. Ask yourself: Do you want to team with the best talent in the industry? Do you want to work on disruptive technology? Do you thrive in a fluid work environment? Do you appreciate a company culture that enables individual and group success and celebrates achievement? If you said yes, we’d love to talk to you about joining our award-winning team.

Learn more at or follow us on Twitter @zscaler. Additional information about Zscaler (NASDAQ: ZS ) is available at  All qualified applicants will receive consideration for employment without regard to race, sex, color, religion, sexual orientation, gender identity, national origin, protected veteran status, or on the basis of disability.