Senior Governance Risk and Compliance (GRC) Analyst
Summary
Leads enterprise risk assessments, develops governance frameworks, and manages FedRAMP authorization. Works with frameworks like FedRAMP, NIST 800-53, ISO 27001, SOC 2, and HITRUST to align business objectives with compliance and security best practices.
IREN is a vertically integrated AI Cloud provider, delivering large-scale data centers and GPU clusters for AI training and inference. IREN’s platform is underpinned by its expansive portfolio of grid-connected land and power in renewable-rich regions across North America, Europe and APAC.
With 100% renewable energy, we build, own and operate our data centers and take pride in being at the forefront of sustainable solutions for the ever-evolving applications of high-performance compute. We believe that human progress is invaluable, but it should be done in the right way – responsibly, sustainably and having a positive impact on the communities we operate in.
At IREN, we offer a highly competitive compensation package that includes base salary, annual performance incentives, and opportunities to build long-term wealth through equity programs. These offerings are part of our broader Total Rewards package, thoughtfully designed to support your health, well-being, and long-term success.
Compensation
We value diverse perspectives and believe that skills can be developed. If you’re passionate about this role, we want to hear from you — whether you meet every criteria or not. Your unique experiences might be exactly what we need!
IE US Operations Inc., the employing entity and proud member of the IREN group is an equal opportunity employer that is committed to creating an inclusive workplace. We are committed to evaluating qualified applicants and do not discriminate against protected characteristics under applicable legislation.
IE US Operations, Inc. “IREN” participates in E-Verify and will provide the federal government with your Form I-9 information to confirm that you are authorized to work in the United States.
By applying for this position and submitting your resume and application materials, you consent to the processing of your personal information in accordance with our Job Applicant Privacy Statement available on our website at www.iren.com.
With 100% renewable energy, we build, own and operate our data centers and take pride in being at the forefront of sustainable solutions for the ever-evolving applications of high-performance compute. We believe that human progress is invaluable, but it should be done in the right way – responsibly, sustainably and having a positive impact on the communities we operate in.
Responsibilities
- Lead enterprise-wide risk assessment programs, identify strategic risks, recommend mitigation and monitor residual risk.
- Develop and maintain governance frameworks that align business objectives with regulatory/compliance requirements and security best practices.
- Execute the company's FedRAMP authorization program from strategy through implementation.
- Manage relationships with 3PAOs, consultants, and other external partners to facilitate assessments and drive progress.
- Lead the preparation and submission of all FedRAMP deliverables, including the System Security Plan (SSP), policies, procedures, and supporting security documents.
- Develop and maintain security and privacy policies, standards, and control frameworks aligned with ISO 27001, SOC 2, HITRUST, FedRAMP, and other global regulations
- Support policy approvals, exception handling, and attestation processes while identifying opportunities for automation and process improvements.
- Lead and execute enterprise risk assessments, including vendor and process-level reviews.
- Support IREN's Third-Party Risk Management program including vendor assessments, monitoring, and remediation tracking
- Lead readiness and response efforts for ISO 27001, HITRUST, FedRAMP and other audits and certifications.
- Keep abreast of emerging regulatory, technological and business-risks, and drive improvements to the GRC program accordingly.
Requirements
- Bachelor’s (or Master’s) degree in Information Security, Risk, Business or equivalent.
- 5-7 years of experience in cybersecurity, IT program management, or a related field.
- Proven track record leading at least one successful FedRAMP authorization.
- Deep knowledge of the FedRAMP framework, NIST 800-53 controls, and supporting documentation.
- Audit/assessment experience using risk-based frameworks.
- Familiarity with cloud security architecture and adjacent frameworks (SOC 2, ISO 27001, HITRUST, etc.)
- Strong communication and relationship-building skills across technical and executive levels.
- Demonstrated analytical and problem-solving skills, highly organized and detail oriented.
- Experience engaging with government agencies or federal sector stakeholders is highly desirable.
- Relevant certifications (CISM, CISA, CRISC, CISSP, ISO 27001 Lead Implementor) strongly preferred.
Benefits
The IREN PackageAt IREN, we offer a highly competitive compensation package that includes base salary, annual performance incentives, and opportunities to build long-term wealth through equity programs. These offerings are part of our broader Total Rewards package, thoughtfully designed to support your health, well-being, and long-term success.
Compensation
- The expected base salary for this role USD$165,000 – 190,000/annum.
- Actual compensation will be determined based on factors such as experience, qualifications, and market data for the region.
- Total Compensation package may be inclusive of annual incentive bonus, equity (long-term incentive).
- Relocation or Living-out-allowance / per diem (as appliable and based on successful candidate circumstances)
- 100% company paid health insurance premiums (medical, dental, and vision) for employees, 75% company paid coverage for dependents
- Company-paid short-term and long-term disability insurance
- Voluntary life, critical illness, and accident coverage available
- Health Savings Accounts (HSA) – when combined with the High Deductible Health Plan
- Employee Assistance Program and wellness resources
- 401(k) retirement plan with company match
- Access to financial planning and legal services
- Paid Time Off (PTO) and paid holidays
- Internal skills training and advancement pathways
- Professional development to support certifications, continuing education, or role related training
- Company events and team-building activities
We value diverse perspectives and believe that skills can be developed. If you’re passionate about this role, we want to hear from you — whether you meet every criteria or not. Your unique experiences might be exactly what we need!
IE US Operations Inc., the employing entity and proud member of the IREN group is an equal opportunity employer that is committed to creating an inclusive workplace. We are committed to evaluating qualified applicants and do not discriminate against protected characteristics under applicable legislation.
IE US Operations, Inc. “IREN” participates in E-Verify and will provide the federal government with your Form I-9 information to confirm that you are authorized to work in the United States.
By applying for this position and submitting your resume and application materials, you consent to the processing of your personal information in accordance with our Job Applicant Privacy Statement available on our website at www.iren.com.