Senior Governance Risk and Compliance (GRC) Analyst
Summary
Lead enterprise-wide risk and compliance programs for an AI cloud provider, focusing on FedRAMP, ISO 27001, and HITRUST certifications while managing third-party risk and regulatory alignment.
With 100% renewable energy, we build, own and operate our data centers and take pride in being at the forefront of sustainable solutions for the ever-evolving applications of high-performance compute. We believe that human progress is invaluable, but it should be done in the right way – responsibly, sustainably and having a positive impact on the communities we operate in.
Responsibilities
- Lead enterprise-wide risk assessment programs, identify strategic risks, recommend mitigation and monitor residual risk.
- Develop and maintain governance frameworks that align business objectives with regulatory/compliance requirements and security best practices.
- Execute the company's FedRAMP authorization program from strategy through implementation.
- Manage relationships with 3PAOs, consultants, and other external partners to facilitate assessments and drive progress.
- Lead the preparation and submission of all FedRAMP deliverables, including the System Security Plan (SSP), policies, procedures, and supporting security documents.
- Develop and maintain security and privacy policies, standards, and control frameworks aligned with ISO 27001, SOC 2, HITRUST, FedRAMP, and other global regulations
- Support policy approvals, exception handling, and attestation processes while identifying opportunities for automation and process improvements.
- Lead and execute enterprise risk assessments, including vendor and process-level reviews.
- Support IREN's Third-Party Risk Management program including vendor assessments, monitoring, and remediation tracking
- Lead readiness and response efforts for ISO 27001, HITRUST, FedRAMP and other audits and certifications.
- Keep abreast of emerging regulatory, technological and business-risks, and drive improvements to the GRC program accordingly.
Requirements
- Bachelor’s (or Master’s) degree in Information Security, Risk, Business or equivalent.
- 5-7 years of experience in cybersecurity, IT program management, or a related field.
- Proven track record leading at least one successful FedRAMP authorization.
- Deep knowledge of the FedRAMP framework, NIST 800-53 controls, and supporting documentation.
- Audit/assessment experience using risk-based frameworks.
- Familiarity with cloud security architecture and adjacent frameworks (SOC 2, ISO 27001, HITRUST, etc.)
- Strong communication and relationship-building skills across technical and executive levels.
- Demonstrated analytical and problem-solving skills, highly organized and detail oriented.
- Experience engaging with government agencies or federal sector stakeholders is highly desirable.
- Relevant certifications (CISM, CISA, CRISC, CISSP, ISO 27001 Lead Implementor) strongly preferred.
Benefits
At IREN, we offer a comprehensive Total Rewards package designed to support your health, well-being, and long-term success. Our Canada package for salaried positions includes:Compensation
- The expected base salary for this role starts at $125-150K annually CAD.
- Actual compensation will be determined based on factors such as experience, qualifications, and market data for the region.
- Total Compensation package may be inclusive of annual incentive bonus, and equity (long-term incentive)
- Relocation assistance (as appliable and based on successful candidate circumstances)
- Medical, dental, and vision insurance coverage – 100% company paid for employees and dependents
- Company-paid life and disability insurance
- Voluntary life and critical illness coverage available
- Employee Assistance Program and virtual health care platform
- RRSP with company match
- Voluntary TFSA
- 3 weeks annually for vacation and paid holidays
- Flexible Work Arrangements
- Opportunities for advancement and internal mobility
- Training and personal development opportunities
- Company events and team-building activities
By applying for this position and submitting your resume and application materials, you consent to the processing of your personal information in accordance with our Job Applicant Privacy Statement available on our website at www.iren.com.