Policy & Compliance Analyst
Listed on 2025-12-23
-
IT/Tech
Cybersecurity, Information Security
Join to apply for the Policy & Compliance Analyst role at Ziply Fiber
Base pay range$80,768.00/yr - $/yr
At Ziply Fiber, our mission is to elevate the connected lives of our communities every day. We are delivering the fastest home internet in the Northwest, with a focus on areas traditionally underserved by mainstream internet companies. And as our state-of-the-art fiber network expands in WA, OR, MT, so does our need for team members who can help us grow and realize our goals.
We may be building internet, but we are reaching real people. We strive to build relationships and provide customers and communities with refreshingly great experiences.
We emphasize our values in all our interactions:
- Genuinely Caring: Our customers and colleagues are people, and quite possibly our neighbors. We put ourselves in their shoes and give them our full attention.
- Empowering You: We empower our customers to choose the products that best meet their needs, and we support our employees to implement solutions that elevate the experiences of our customers and coworkers.
- Innovation and Improvement: We always look for ways to make the experiences of our customers – and each other – better.
- Earning Your Trust: We earn trust by communicating simply and transparently as real people, not as a corporation.
The Policy and Compliance Analyst plays a key role in maintaining Ziply Fiber’s information security posture. This role is responsible for managing the review, publication, and enforcement of internal security policies and procedures. The Analyst supports cross‑functional teams in aligning with regulatory security frameworks such as NIST, SOC 2, SOX, PCI‑DSS, and helps maintain documentation that demonstrates compliance and due diligence.
Responsibilities- Policy Management: Administer the policy lifecycle, including drafting, coordinating reviews, publishing, and updating security policies.
- Collaboration: Work with Legal, IT, and Security to ensure policies align with business and regulatory requirements.
- Documentation: Maintain centralized documentation for audits, assessments, and regulatory reviews.
- Monitoring: Monitor regulatory developments and assist in aligning internal practices accordingly.
- Compliance Monitoring & Enforcement: Assist in monitoring organizational adherence to internal policies, track and report on compliance metrics, arrange and conduct compliance testing, audits and investigations, and ensure compliance with all local, state, and federal laws and regulations.
- Audit & Evidence Management: Assist in preparing and organizing policy and evidence documentation for internal and third‑party audits, generate analyses and reports of compliance testing results, and inform supervisors of compliance violations.
- Compliance Training & Process Improvement: Support compliance initiatives across departments by providing guidance and training, develop, maintain, and deliver compliance training content and programs, and assist with the implementation of new and updated compliance systems, standards, processes, procedures, and policies.
- Perform other duties as required to support the business and evolving organization.
- Bachelor’s degree in Computer Science, Information Technology, Risk Management, Legal Studies, Business, or a related field.
- Minimum of two (2) years of experience in a policy, audit, or compliance analyst role.
- Direct experience managing regulatory requirements (e.g., PCI‑DSS, NIST).
- Experience contributing to cross‑functional compliance projects or initiatives.
- Strong understanding of risk frameworks (e.g., NIST CSF, NIST 800‑171, ISO 27001, SOC 2, SOX).
- Familiarity with GRC platforms or compliance tracking systems.
- Familiarity with legal hold, third‑party risk, and incident response documentation processes.
- Familiarity with business continuity and incident response concepts and procedures.
- Excellent communication and documentation skills, including the ability to present to executives and auditors.
- Preferred industry certifications such as CISA, CRISC, CISSP, or equivalent.
- Strong organizational and analytical skills.
- Excellent…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).