Logo for Zayo Group

Senior Compliance and Audit Analyst

Role overview

Qualifications

  • Bachelor’s degree in Information Systems, Cybersecurity, Risk Management, or a related field
  • Minimum of six (6) years of experience in information security, compliance, customer assurance, audit support, or related role
  • Familiarity with ISO 27001, NIST SP 800-171, GDPR, and SOC 2
  • Strong written communication skills

Responsibilities

  • Respond to customer security inquiries and due diligence requests
  • Review, manage, and track customer security and third party risk requests
  • Coordinate with various stakeholders to gather and validate response content
  • Support Third Party Risk Management activities, including vendor security reviews

Key facts

Other skills

  • Microsoft Office
  • Technical Acumen
  • Detail Oriented
  • Organizational Skills
  • Time Management
  • Collaboration
  • Problem Solving

About the company

Zayo Group logo

Zayo Group

Telecommunications

For over 15 years, Zayo has been the driving force behind the world's most dynamic and forward-thinking enterprises, helping them pave the way to what's next. With a network that stretches over 16.8 million fiber miles and spans an impressive 141,000 route miles, Zayo is not just in the business of connectivity – we're in the business of limitless potential. Imagine a world where possibilities are boundless, where businesses can seamlessly bridge the gap between where they are and where they want to be. That's the world we're creating, one fiber mile at a time. Zayo's tailored connectivity and cutting-edge edge solutions are the heartbeat of carriers, cloud pioneers, data centers, educational institutions, and enterprises alike. From the very core to the cloud to the edge, Zayo is there, powering exceptional experiences that redefine what's achievable. So, are you ready to unlock the true power of connection? Embark on this journey with us and discover how Zayo doesn't just connect dots – we connect destinies. For more information, visit zayo.com.

Company details

Company typeLarge
IndustryTelecommunications
Company size1001 - 5000

Your match analysis

See how your profile stacks up against this role.

We compared the job requirements to your profile to show where you're strong and where you fall short.

Job description

Company Description

Zayo provides mission-critical bandwidth to the world’s most impactful companies, fueling the innovations that are transforming our society. Zayo’s 141,000-mile network in North America and Europe includes extensive metro connectivity to thousands of buildings and data centers. Zayo’s communications infrastructure solutions include dark fiber, private data networks, wavelengths, Ethernet, and dedicated Internet access. Zayo serves wireless and wireline carriers, media, tech, content, finance, healthcare and other large enterprises.

The Senior Compliance and Audit Analyst role supports the organization’s security assurance, customer trust, audit support, and third-party risk management activities. The position is responsible for responding to customer security inquiries, completing security questionnaires, supporting security-related contract reviews, providing approved audit evidence where appropriate, maintaining customer-facing Trust Center content, and assisting with third party risk reviews.

The role works closely with Information Security, Legal, Privacy, Compliance, Procurement, Sales, Product, and business stakeholders to ensure security responses, customer commitments, vendor reviews, evidence, and public-facing security content are accurate, timely, and aligned with organizational policies, standards, and approved practices.

Responsibilities

  • Respond to customer security inquiries, due diligence requests, security questionnaires, and RFP/RFI security sections using approved response content, templates, and guidance.

  • Review, triage, track, and manage assigned customer security, audit evidence, contract review, and third party risk requests through ServiceNow or other approved systems.

  • Coordinate with Security, Legal, Procurement, Sales, Product, business owners, and technical subject matter experts to gather, validate, and approve response content.

  • Prepare clear, accurate, and customer-appropriate responses related to security controls, policies, standards, certifications, audit reports, privacy practices, and compliance activities.

  • Assist with the review of customer and vendor contract language involving information security, privacy, audit rights, incident notification, data protection, compliance obligations, third party requirements, or control commitments.

  • Compare customer and vendor security requirements against organizational policies, standards, approved positions, control capabilities, and risk guidance.

  • Identify non-standard commitments, unclear requirements, control gaps, policy conflicts, or risk indicators and escalate them to the appropriate stakeholders for review.

  • Assist with audit evidence where appropriate, ensuring evidence shared externally is accurate, current, approved, and authorized for release.

  • Coordinate with control owners, audit teams, and internal stakeholders to gather, validate, track, and document audit evidence requests and related approvals.

  • Support Third Party Risk Management (TPRM) activities by assisting with vendor and supplier security reviews, due diligence requests, risk assessments, renewal reviews, and ongoing monitoring activities.

  • Review vendor-provided questionnaires, certifications, audit reports, policies, security documentation, and other assurance materials against established review criteria.

  • Track third party risk assessment status, open questions, required documentation, approvals, risk decisions, exceptions, remediation items, and follow-up actions.

  • Support the development and maintenance of publicly appropriate Trust Center content, including security, compliance, privacy, certification, audit, and assurance materials.

  • Review Trust Center content to help ensure it remains accurate, current, customer-appropriate, and aligned with approved policies, standards, reports, and disclosures.

  • Use and help maintain approved response libraries, standard security language, FAQs, Trust Center materials, third party risk guidance, and customer assurance content.

  • Maintain accurate records of customer inquiries, questionnaire responses, contract review notes, audit evidence, Trust Center updates, third party assessments, escalations, approvals, and final outcomes.

  • Support customer-facing or vendor-related follow-up discussions by preparing materials, documenting questions, and coordinating internal input.

  • Monitor assigned requests to support timely completion, appropriate follow-up, and accurate reporting on status, volume, aging, and recurring themes.

  • Identify recurring customer questions, vendor risk themes, response gaps, evidence request trends, Trust Center content needs, or process issues and share improvement recommendations with the team.

  • Support internal process documentation and guidance related to customer security inquiry handling, security contract review, audit evidence coordination, Trust Center maintenance, and TPRM.

Qualifications

  • Bachelor’s degree in Information Systems, Cybersecurity, Risk Management, or a related field, or equivalent professional experience.

  • Minimum of six (6) years of experience in information security, compliance, customer assurance, third party risk management, audit support, contract support, customer service, vendor management, or a related role.

  • Experience with common controls, control mapping, or cross-framework control alignment is preferred.

  • Familiarity with ISO 27001, NIST SP 800-171, GDPR, and SOC 2 is required.

  • Experience responding to customer security inquiries, due diligence requests, security questionnaires, RFP/RFI security sections, or similar information requests.

  • Familiarity with security-related contract topics, including information security requirements, audit rights, incident notification, data protection, privacy, third party obligations, and compliance requirements.

  • Ability to read and interpret organizational policies, standards, procedures, customer requirements, vendor documentation, audit materials, and contract language.

  • Strong written communication skills, with the ability to provide clear, accurate, and professional responses.

  • Strong attention to detail and the ability to identify inconsistencies, missing information, unclear language, non-standard commitments, or items requiring escalation.

  • Ability to collaborate effectively with Legal, Security, Procurement, Sales, business owners, and technical subject matter experts.

  • Strong organizational, documentation, and time management skills, with the ability to manage multiple requests, reviews, and deadlines.

  • Experience using ServiceNow or similar ticketing, workflow, case management, or risk management tools preferred.

  • Experience supporting third party risk management, vendor due diligence, supplier risk assessments, or vendor security reviews preferred.

  • Proficiency with Microsoft Office, ServiceNow, knowledge management tools, and collaboration platforms.

  • Professional certifications in cybersecurity, compliance, or risk-related areas are preferred but not required.

Estimated base salary range: $95,100 - $146,300 USD/annually.

Work Authorization Requirement: Applicants must be currently authorized to work in the United States on a full-time basis. This position is not eligible for employer-sponsored work authorization, such as OPT, TN, H1B or any other type of work visa, now or in the future.

#LI-MF1

#LI-Remote

The base pay range shown is a guideline and reasonable estimate for this role. It takes into account the wide variety of factors that are considered in making compensation decisions. Actual compensation offered may vary from the posted range based upon geographic location, work experience, skill level, certifications, and other business and organizational needs. Non- sales roles may be eligible to participate in a discretionary annual incentive plan. Sales roles may be eligible to participate in a sales incentive plan.


Additionally, this position may be eligible for certain benefits, such as health insurance, life insurance, disability retirement plans, paid time off.


The posting will be active for a minimum of 3 days. The active posting will continue to extend by 3 days until the position is filled.


Benefits, Rewards & Wellness

  • Excellent Health, Dental & Vision Insurance
  • Retirement 401(k) Savings Plan
  • Generous paid time off policy including paid parental leave



Zayo is an equal opportunity employer to all protected groups, including protected veterans and individuals with disabilities. If you are an individual with a disability and would like to request a reasonable accommodation as part of the employment selection process, please contact us.


This policy applies to all terms and conditions of employment, including recruiting, hiring, placement, promotion, termination, layoff, recall, transfer, leaves of absence, compensation and training.


As part of the application, hiring, onboarding, and/or employment process, Zayo or its affiliates, partners, and vendors may collect, store, and use biometric identifiers and biometric information (collectively, “Biometric Data”), such as fingerprints, facial geometry scans or other unique biological characteristics. Zayo uses CLEAR1, a third-party identity verification service, to verify applicant identity during the hiring process. CLEAR1 may collect Biometric Data, including facial geometry scans and/or other biometric identifiers, to authenticate your identity. Biometric Data will be retained pursuant to CLEAR1’s policies, which can be found here: https://www.clearme.com/clear1-credential-policy-crp. Zayo will not sell, lease, trade, or otherwise profit from any applicant's or employee's Biometric Data. By proceeding with your application, you acknowledge this disclosure. Prior to any collection of Biometric Data — including through CLEAR — you may be presented with a separate consent form and asked to provide your written authorization in accordance with applicable federal, state, and local laws, including the Illinois Biometric Information Privacy Act (BIPA), the Texas Capture or Use of Biometric Identifier Act (CUBI), and other applicable biometric privacy statutes.

Apply once. Then go straight to the hiring manager.

After you apply, unlock the direct contact details of the people who actually make the call. A quick follow-up makes you 5x more likely to land an interview.

MR

Marcus Rivera

Chief Revenue Officer

m.rivera@company.com
linkedin.com/in/marcusrivera
Unlocked after you apply
·

Risk and Compliance Analyst Related jobs

Other jobs at Zayo Group

Premium

Reach out to the hiring manager directly.

Gain access to the contact details of the hiring managers who actually decide, and reach out to network with them directly. That, plus more when you upgrade:

  • Full match report with fit score and gaps
  • Career diagnostics on how recruiters read you
  • Curated company matches and warm intros
  • 48h early access to new roles

Cancel anytime.