Senior Compliance and Audit Analyst
🏢 Zayo Group · all Zayo Group jobs
📍 United States
💰 USD 95,100 - 146,300 / annual
📅 Posted 2026-08-17 · via Himalayas
🏷 Compliance-Analyst,Security-Analyst,Third-Party-Risk-Management,Audit-Analyst,Infosec,Senior-Compliance-Analyst,Senior-Compliance-Auditor,Senior-Audit-Analyst,Compliance-and-Regulatory-Analyst,Senior-Compliance-Specialist,Senior-Compliance-Advisor
Apply on original site ↗Company Description
Zayo provides mission-critical bandwidth to the world’s most impactful companies, fueling the innovations that are transforming our society. Zayo’s 141,000-mile network in North America and Europe includes extensive metro connectivity to thousands of buildings and data centers. Zayo’s communications infrastructure solutions include dark fiber, private data networks, wavelengths, Ethernet, and dedicated Internet access. Zayo serves wireless and wireline carriers, media, tech, content, finance, healthcare and other large enterprises.
The Senior Compliance and Audit Analyst role supports the organization’s security assurance, customer trust, audit support, and third-party risk management activities. The position is responsible for responding to customer security inquiries, completing security questionnaires, supporting security-related contract reviews, providing approved audit evidence where appropriate, maintaining customer-facing Trust Center content, and assisting with third party risk reviews.
The role works closely with Information Security, Legal, Privacy, Compliance, Procurement, Sales, Product, and business stakeholders to ensure security responses, customer commitments, vendor reviews, evidence, and public-facing security content are accurate, timely, and aligned with organizational policies, standards, and approved practices.
Responsibilities
-
Respond to customer security inquiries, due diligence requests, security questionnaires, and RFP/RFI security sections using approved response content, templates, and guidance.
-
Review, triage, track, and manage assigned customer security, audit evidence, contract review, and third party risk requests through ServiceNow or other approved systems.
-
Coordinate with Security, Legal, Procurement, Sales, Product, business owners, and technical subject matter experts to gather, validate, and approve response content.
-
Prepare clear, accurate, and customer-appropriate responses related to security controls, policies, standards, certifications, audit reports, privacy practices, and compliance activities.
-
Assist with the review of customer and vendor contract language involving information security, privacy, audit rights, incident notification, data protection, compliance obligations, third party requirements, or control commitments.
-
Compare customer and vendor security requirements against organizational policies, standards, approved positions, control capabilities, and risk guidance.
-
Identify non-standard commitments, unclear requirements, control gaps, policy conflicts, or risk indicators and escalate them to the appropriate stakeholders for review.
-
Assist with audit evidence where appropriate, ensuring evidence shared externally is accurate, current, approved, and authorized for release.
-
Coordinate with control owners, audit teams, and internal stakeholders to gather, validate, track, and document audit evidence requests and related approvals.
-
Support Third Party Risk Management (TPRM) activities by assisting with vendor and supplier security reviews, due diligence requests, risk assessments, renewal reviews, and ongoing monitoring activities.
-
Review vendor-provided questionnaires, certifications, audit reports, policies, security documentation, and other assurance materials against established review criteria.
-
Track third party risk assessment status, open questions, required documentation, approvals, risk decisions, exceptions, remediation items, and follow-up actions.
-
Support the development and maintenance of publicly appropriate Trust Center content, including security, compliance, privacy, certification, audit, and assurance materials.
-
Review Trust Center content to help ensure it remains accurate, current, customer-appropriate, and aligned with approved policies, standards, reports, and disclosures.
-
Use and help maintain approved response libraries, standard security language, FAQs, Trust Center m