Senior Governance Risk and Compliance (GRC) Analyst

Socket.dev

San Francisco (CA)

On-site

USD 165,000 - 190,000

Full time

14 days+
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

Health insurance
Disability insurance
401(k) retirement plan with company 匹配
Paid time off
Professional development support

Job summary

IREN seeks an experienced security leader to drive enterprise risk programs and FedRAMP authorization across its cloud platforms. You will shape governance aligned with regulatory needs and lead external assessments with 3PAOs and partners.

You will develop security policies matching ISO 27001, SOC 2, HITRUST and other frameworks, while guiding policy approvals and automation opportunities. Strong communications at all levels are essential.

Qualifications

  • Bachelor’s (or Master’s) degree required in information security, risk, business or equivalent.
  • 5–7 years of cybersecurity, IT program management, or related field experience.
  • Proven track record leading at least one FedRAMP authorization.
  • Deep knowledge of FedRAMP, NIST 800-53 controls, and supporting documentation.
  • Audit/assessment experience using risk-based frameworks.
  • Familiarity with cloud security architecture and related frameworks (SOC 2, ISO 27001, HITRUST).
  • Strong communication and relationship-building across technical and executive levels.

Responsibilities

  • Lead enterprise-wide risk assessment programs, identify strategic risks, mitigate and monitor residual risk.
  • Develop and maintain governance frameworks aligning business objectives with regulatory requirements and security best practices.
  • Execute the FedRAMP authorization program from strategy through implementation.
  • Manage relationships with 3PAOs, consultants, and external partners to facilitate assessments and progress.
  • Lead preparation and submission of all FedRAMP deliverables (SSP, policies, procedures, security documents).
  • Develop security and privacy policies and control frameworks aligned with ISO 27001, SOC 2, HITRUST, FedRAMP and other regulations.
  • Support policy approvals, exception handling, and attestation processes while seeking automation opportunities.
  • Lead and execute enterprise risk assessments including vendor/process reviews.
  • Support Third-Party Risk Management activities including vendor assessments and remediation tracking.
  • Lead readiness and response for ISO 27001, HITRUST, FedRAMP audits and certifications.

Skills

FedRAMP knowledge
NIST 800-53 controls
Cloud security architecture
Governance and risk management
Auditing and assessment
Strong communication skills
Regulatory compliance awareness

Education

Bachelor’s or Master’s degree in Information Security, Risk, Business or equivalent

Job description

IREN is a vertically integrated AI Cloud provider, delivering large-scale data centers and GPU clusters for AI training and inference. IREN’s platform is underpinned by its expansive portfolio of grid-connected land and power in renewable-rich regions across North America, Europe and APAC.

With 100% renewable energy, we build, own and operate our data centers and take pride in being at the forefront of sustainable solutions for the ever-evolving applications of high-performance compute. We believe that human progress is invaluable, but it should be done in the right way – responsibly, sustainably and having a positive impact on the communities we operate in.

Qualifications
  • Bachelor’s (or Master’s) degree in Information Security, Risk, Business or equivalent.
  • 5-7 years of experience in cybersecurity, IT program management, or a related field.
  • Proven track record leading at least one successful FedRAMP authorization.
  • Deep knowledge of the FedRAMP framework, NIST 800-53 controls, and supporting documentation.
  • Audit/assessment experience using risk-based frameworks.
  • Familiarity with cloud security architecture and adjacent frameworks (SOC 2, ISO 27001, HITRUST, etc.)
  • Strong communication and relationship-building skills across technical and executive levels.
  • Demonstrated analytical and problem-solving skills, highly organized and detail oriented.
  • Experience engaging with government agencies or federal sector stakeholders is highly desirable.
  • Relevant certifications (CISM, CISA, CRISC, CISSP, ISO 27001 Lead Implementor) strongly preferred.
Responsibilities
  • Lead enterprise-wide risk assessment programs, identify strategic risks, recommend mitigation and monitor residual risk.
  • Develop and maintain governance frameworks that align business objectives with regulatory/compliance requirements and security best practices.
  • Execute the company's FedRAMP authorization program from strategy through implementation.
  • Manage relationships with 3PAOs, consultants, and other external partners to facilitate assessments and drive progress.
  • Lead the preparation and submission of all FedRAMP deliverables, including the System Security Plan (SSP), policies, procedures, and supporting security documents.
  • Develop and maintain security and privacy policies, standards, and control frameworks aligned with ISO 27001, SOC 2, HITRUST, FedRAMP, and other global regulations
  • Support policy approvals, exception handling, and attestation processes while identifying opportunities for automation and process improvements.
  • Lead and execute enterprise risk assessments, including vendor and process-level reviews.
  • Support IREN's Third-Party Risk Management program including vendor assessments, monitoring, and remediation tracking
  • Lead readiness and response efforts for ISO 27001, HITRUST, FedRAMP and other audits and certifications.
  • Keep abreast of emerging regulatory, technological and business-risks, and drive improvements to the GRC program accordingly.
The IREN Package

At IREN, we offer a highly competitive compensation package that includes base salary, annual performance incentives, and opportunities to build long-term wealth through equity programs. These offerings are part of our broader Total Rewards package, thoughtfully designed to support your health, well-being, and long-term success.

Compensation
  • The expected base salary for this role USD$165,000 – 190,000/annum.
    • Actual compensation will be determined based on factors such as experience, qualifications, and market data for the region.
  • Total Compensation package may be inclusive of annual incentive bonus, equity (long-term incentive).
  • Relocation or Living-out-allowance / per diem (as appliable and based on successful candidate circumstances)
Health & Wellness
  • 100% company paid health insurance premiums (medical, dental, and vision) for employees, 75% company paid coverage for dependents
  • Company-paid short-term and long-term disability insurance
  • Voluntary life, critical illness, and accident coverage available
  • Health Savings Accounts (HSA) – when combined with the High Deductible Health Plan
  • Employee Assistance Program and wellness resources
Retirement & Financial Wealth
  • 401(k) retirement plan with company match
  • Access to financial planning and legal services
Time Off & Leave Programs
  • Paid Time Off (PTO) and paid holidays
Growth & Development
  • Internal skills training and advancement pathways
  • Professional development to support certifications, continuing education, or role related training
Community & Culture
  • Company events and team-building activities

We value diverse perspectives and believe that skills can be developed. If you’re passionate about this role, we want to hear from you — whether you meet every criteria or not. Your unique experiences might be exactly what we need!

IE US Operations Inc., the employing entity and proud member of the IREN group is an equal opportunity employer that is committed to creating an inclusive workplace. We are committed to evaluating qualified applicants and do not discriminate against protected characteristics under applicable legislation.

IE US Operations, Inc. “IREN” participates in E-Verify and will provide the federal government with your Form I-9 information to confirm that you are authorized to work in the United States.

By applying for this position and submitting your resume and application materials, you consent to the processing of your personal information in accordance with our Job Applicant Privacy Statement available on our website at www.iren.com.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Data Centre Security Specialist
Data Centre Security Specialist

IREN • Childress (TX)

On-site
USD 85,000 - 125,000
Medical, dental, vision insurance
401(k) with company match
Paid time off
Senior Software Engineer, Platform Engineering
Senior Software Engineer, Platform Engineering

Socket.dev • Seattle (WA)

On-site
USD 152,000 - 228,000
Health insurance
Disability insurance
401(k) match
+1
Director, People Relations & Business Enablement
Director, People Relations & Business Enablement

Iris Energy • San Francisco (CA)

Hybrid
USD 220,000 - 260,000
Health insurance
Disability insurance
401(k) match
+2
Associate Director, Global Environment
Associate Director, Global Environment

Rise Social • Fort Worth (TX)

Hybrid
USD 180,000 - 260,000
Health insurance
401(k) retirement plan with company; 0
Disability insurance
+2
Security Systems Program Manager
Security Systems Program Manager

IREN • Fort Worth (TX)

On-site
USD 120,000 - 180,000
Health insurance
401(k) retirement plan
Paid time off
Associate Director, Operational Excellence
Associate Director, Operational Excellence

Iris Energy • Fort Worth (TX)

Hybrid
USD 120,000 - 180,000
Health Insurance
Life and Disability Insurance
Voluntary coverage options
+3
Associate Director, Operational Excellence
Associate Director, Operational Excellence

Socket.dev • Fort Worth (TX)

Hybrid
USD 180,000 - 240,000
Health insurance
401(k) retirement plan
Paid time off
+2
Staff Software Engineer, Platform Engineering
Staff Software Engineer, Platform Engineering

Iris Energy • Seattle (WA)

On-site
USD 184,000 - 276,000
401(k) retirement plan with company 25
Paid PTO and holidays
Professional development opportunities
+1
Staff Software Engineer, Platform Engineering
Staff Software Engineer, Platform Engineering

Socket.dev • Seattle (WA)

On-site
USD 184,000 - 276,000
Health insurance (corporate)
401(k) with company match
Paid time off
+1
Spare Parts & Senior Manager, RMA Management & AI Hardware
Spare Parts & Senior Manager, RMA Management & AI Hardware

Iris Energy • San Francisco (CA)

On-site
USD 200,000 - 250,000
Health insurance
401(k) matching plan
Paid time off (PTO)
+2