Senior Governance Risk and Compliance (GRC) Analyst

IREN

Vancouver

On-site

CAD 125,000 - 150,000

Full time

14 days+
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Relocation assistance
RRSP with company match
3 weeks vacation and holidays
Flexible Work Arrangements
Equity / long-term incentive

Job summary

IREN in Canada seeks a cybersecurity leader to drive enterprise FedRAMP readiness and governance, aligning security with business objectives. You will manage risk programs and coordinate with regulators, auditors, and partners to ensure compliance and secure cloud services.

Your background includes FedRAMP, NIST 800-53, and ISO frameworks, with strong cross-functional communication. Role supports growth in a sustainability-forward AI Cloud platform.

Qualifications

  • Bachelor’s (or Master’s) degree in Information Security, Risk, Business or equivalent.
  • 5-7 years of experience in cybersecurity, IT program management, or related field.
  • Proven track record leading FedRAMP authorization.
  • Deep knowledge of FedRAMP, NIST 800-53, and supporting documents.
  • Audit/assessment experience using risk-based frameworks.
  • Familiarity with cloud security architecture and related frameworks (SOC 2, ISO 27001, HITRUST).
  • Strong communication across technical and executive levels.
  • Certifications strongly preferred (CISM, CISA, CRISC, CISSP, ISO 27001 Lead Implementor).

Responsibilities

  • Lead enterprise-wide risk assessment programs and monitor residual risk.
  • Develop governance frameworks aligning objectives with regulatory requirements.
  • Execute FedRAMP authorization program from strategy to implementation.
  • Manage relationships with 3PAOs, consultants, and external partners.
  • Prepare and submit SSPs, policies, and security documents.
  • Develop security and privacy policies aligned with ISO 27001, SOC 2, HITRUST, FedRAMP.
  • Support policy approvals, exception handling, and attestation processes.
  • Lead readiness and response for audits and certifications.
  • Stay current on regulatory and technology risks; drive GRC improvements.
  • Support Third-Party Risk Management and vendor assessments.

Skills

FedRAMP
NIST 800-53
ISO 27001
SOC 2
HITRUST
Risk management
Security governance
Audit/assessment
Communication
Cloud security
FedRAMP readiness
Federal/regulatory experience
Project leadership
Certification knowledge (CISM/CISA/CRi

Education

Bachelor’s or Master’s in Information Security or related

Job description

Job Description

IREN is a vertically integrated AI Cloud provider, delivering large-scale data centers and GPU clusters for AI training and inference. IREN’s platform is underpinned by its expansive portfolio of grid-connected land and power in renewable-rich regions across North America, Europe and APAC.


IREN is a vertically integrated AI Cloud provider, delivering large-scale data centers and GPU clusters for AI training and inference. IREN’s platform is underpinned by its expansive portfolio of grid-connected land and power in renewable-rich regions across North America, Europe and APAC.


With 100% renewable energy, we build, own and operate our data centers and take pride in being at the forefront of sustainable solutions for the ever-evolving applications of high-performance compute. We believe that human progress is invaluable, but it should be done in the right way – responsibly, sustainably and having a positive impact on the communities we operate in.



Job Requirements


  • Bachelor’s (or Master’s) degree in Information Security, Risk, Business or equivalent.

  • 5-7 years of experience in cybersecurity, IT program management, or a related field.

  • Proven track record leading at least one successful FedRAMP authorization.

  • Deep knowledge of the FedRAMP framework, NIST 800-53 controls, and supporting documentation.

  • Audit/assessment experience using risk-based frameworks.

  • Familiarity with cloud security architecture and adjacent frameworks (SOC 2, ISO 27001, HITRUST, etc.)

  • Strong communication and relationship-building skills across technical and executive levels.

  • Demonstrated analytical and problem-solving skills, highly organized and detail oriented.

  • Experience engaging with government agencies or federal sector stakeholders is highly desirable.

  • Relevant certifications (CISM, CISA, CRISC, CISSP, ISO 27001 Lead Implementor) strongly preferred.



Job Responsibilities


  • Lead enterprise-wide risk assessment programs, identify strategic risks, recommend mitigation and monitor residual risk.

  • Develop and maintain governance frameworks that align business objectives with regulatory/compliance requirements and security best practices.

  • Execute the company's FedRAMP authorization program from strategy through implementation.

  • Manage relationships with 3PAOs, consultants, and other external partners to facilitate assessments and drive progress.

  • Lead the preparation and submission of all FedRAMP deliverables, including the System Security Plan (SSP), policies, procedures, and supporting security documents.

  • Develop and maintain security and privacy policies, standards, and control frameworks aligned with ISO 27001, SOC 2, HITRUST, FedRAMP, and other global regulations

  • Support policy approvals, exception handling, and attestation processes while identifying opportunities for automation and process improvements.

  • Lead and execute enterprise risk assessments, including vendor and process-level reviews.

  • Support IREN's Third-Party Risk Management program including vendor assessments, monitoring, and remediation tracking

  • Lead readiness and response efforts for ISO 27001, HITRUST, FedRAMP and other audits and certifications.

  • Keep abreast of emerging regulatory, technological and business-risks, and drive improvements to the GRC program accordingly.



Job Benefits

At IREN, we offer a comprehensive Total Rewards package designed to support your health, well-being, and long-term success. Our Canada package for salaried positions includes:


Compensation



  • The expected base salary for this role starts at $125-150K annually CAD.

  • Actual compensation will be determined based on factors such as experience, qualifications, and market data for the region.

  • Total Compensation package may be inclusive of annual incentive bonus, and equity (long-term incentive)

  • Relocation assistance (as appliable and based on successful candidate circumstances)


Health & Wellness



  • Medical, dental, and vision insurance coverage – 100% company paid for employees and dependents

  • Company-paid life and disability insurance

  • Voluntary life and critical illness coverage available

  • Employee Assistance Program and virtual health care platform


Financial Well-Being



  • RRSP with company match

  • Voluntary TFSA


Time Off & Flexibility



  • 3 weeks annually for vacation and paid holidays

  • Flexible Work Arrangements


Growth & Development



  • Opportunities for advancement and internal mobility

  • Training and personal development opportunities


Lifestyle & Culture



  • Company events and team-building activities


Podtech Data Centers Inc., the employing entity and proud member of the IREN Group is an equal opportunity employer that is committed to creating an inclusive workplace. We evaluate qualified applicants without regard to race, colour, religion, age, sex, sexual orientation, gender identity, genetic information, national origin, disability, veteran status, and other legally protected characteristics.


By applying for this position and submitting your resume and application materials, you consent to the processing of your personal information in accordance with our Job Applicant Privacy Statement available on our website at www.iren.com.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Governance Risk and Compliance (GRC) Analyst
Governance Risk and Compliance (GRC) Analyst

Iris Energy • Vancouver

On-site
CAD 105,000 - 125,000
Medical, dental, and vision insurance
Life and disability insurance
RRSP with company match
+5
Data Center Site Manager
Data Center Site Manager

IREN • Mackenzie

On-site
CAD 155,000 - 190,000
Health insurance
Life insurance
Disability coverage
+3
Director, People Relations & Business Enablement
Director, People Relations & Business Enablement

Iris Energy • Vancouver

Hybrid
CAD 180,000 - 200,000
RRSP with company match
Equity / long-term incentive
3 weeks vacation and holidays
+2
Director, People Relations & Business Enablement
Director, People Relations & Business Enablement

Socket.dev • Vancouver

Hybrid
CAD 162,000 - 198,000
RRSP with company match
3 weeks vacation and paid holidays
Flexible Work Arrangements
+2
Senior Technical Infrastructure Program Manager (Sr. TIPM)
Senior Technical Infrastructure Program Manager (Sr. TIPM)

Iris Energy • Canada

Hybrid
CAD 120,000 - 185,000
Relocation assistance
Paid time off
Flexible work arrangements
+1
Data Center Technician
Data Center Technician

IREN • Mackenzie

On-site
CAD 37,000 - 50,000
Relocation assistance
RRSP with company match
Compensation Specialist
Compensation Specialist

IREN • Vancouver

Hybrid
CAD 75,000 - 95,000
Medical, dental, and vision coverage
Company-paid life & disability保险
RRSP with company match
+3
Senior Manager, People Operations & Governance
Senior Manager, People Operations & Governance

Socket.dev • Vancouver

Hybrid
CAD 150,000 - 175,000
Medical Insurance
Dental Insurance
Vision Insurance
+12
Senior Manager, People Operations & Governance
Senior Manager, People Operations & Governance

Iris Energy • Vancouver

Hybrid
CAD 150,000 - 175,000
Health Insurance
RRSP match
Vacation & Holidays
+2
Data Center Technician
Data Center Technician

IREN • Prince George

On-site
CAD 37,195 - 49,593
Competitive hourly rate
RRSP matching program
Comprehensive health and dental coverage
+2