Senior Governance Risk and Compliance (GRC) Analyst

IREN Limited

$125K — $150K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's or Master's degree in Information Security, Risk, Business or equivalent.
  • 5-7 years of experience in cybersecurity, IT program management, or a related field.
  • Proven track record of at least one successful FedRAMP authorization.
  • Deep knowledge of FedRAMP framework and NIST 800-53 controls.
  • Experience with audit/assessment using risk-based frameworks.
  • Strong communication skills across technical and executive levels.
  • Relevant certifications (CISM, CISA, CRISC, CISSP, ISO 27001 Lead Implementor) preferred.

Responsibilities

  • Lead enterprise-wide risk assessment programs and recommend mitigation strategies.
  • Develop governance frameworks aligning business objectives with compliance requirements.
  • Execute the company's FedRAMP authorization program from strategy to implementation.
  • Manage relationships with external partners for assessments.
  • Prepare and submit FedRAMP deliverables, including the System Security Plan (SSP).
  • Develop security and privacy policies aligned with regulations like ISO 27001 and HITRUST.
  • Support policy approvals and identify opportunities for automation.

Benefits

  • Comprehensive health, dental, and vision insurance paid for employees and dependents.
  • Company-paid life and disability insurance, with voluntary options available.
  • RRSP with company matching and voluntary TFSA.
  • Three weeks of annual vacation plus paid holidays and flexible work arrangements.
  • Opportunities for advancement and personal development training.
  • Company events and team-building activities.
Full Job Description
Job description

Job requirements

  • Bachelor's (or Master's) degree in Information Security, Risk, Business or equivalent.
  • 5-7 years of experience in cybersecurity, IT program management, or a related field.
  • Proven track record leading at least one successful FedRAMP authorization.
  • Deep knowledge of the FedRAMP framework, NIST 800-53 controls, and supporting documentation.
  • Audit/assessment experience using risk-based frameworks.
  • Familiarity with cloud security architecture and adjacent frameworks (SOC 2, ISO 27001, HITRUST, etc.)
  • Strong communication and relationship-building skills across technical and executive levels.
  • Demonstrated analytical and problem-solving skills, highly organized and detail oriented.
  • Experience engaging with government agencies or federal sector stakeholders is highly desirable.
  • Relevant certifications (CISM, CISA, CRISC, CISSP, ISO 27001 Lead Implementor) strongly preferred.


Job responsibilities

  • Lead enterprise-wide risk assessment programs, identify strategic risks, recommend mitigation and monitor residual risk.
  • Develop and maintain governance frameworks that align business objectives with regulatory/compliance requirements and security best practices.
  • Execute the company's FedRAMP authorization program from strategy through implementation.
  • Manage relationships with 3PAOs, consultants, and other external partners to facilitate assessments and drive progress.
  • Lead the preparation and submission of all FedRAMP deliverables, including the System Security Plan (SSP), policies, procedures, and supporting security documents.
  • Develop and maintain security and privacy policies, standards, and control frameworks aligned with ISO 27001, SOC 2, HITRUST, FedRAMP, and other global regulations
  • Support policy approvals, exception handling, and attestation processes while identifying opportunities for automation and process improvements.
  • Lead and execute enterprise risk assessments, including vendor and process-level reviews.
  • Support IREN's Third-Party Risk Management program including vendor assessments, monitoring, and remediation tracking
  • Lead readiness and response efforts for ISO 27001, HITRUST, FedRAMP and other audits and certifications.
  • Keep abreast of emerging regulatory, technological and business-risks, and drive improvements to the GRC program accordingly.


Job benefits

At IREN, we offer a comprehensive Total Rewards package designed to support your health, well-being, and long-term success. Our Canada package for salaried positions includes:

Compensation
  • The expected base salary for this role starts at $125-150K annually CAD.
  • Actual compensation will be determined based on factors such as experience, qualifications, and market data for the region.
  • Total Compensation package may be inclusive of annual incentive bonus, and equity (long-term incentive)
  • Relocation assistance (as appliable and based on successful candidate circumstances)
Health & Wellness
  • Medical, dental, and vision insurance coverage - 100% company paid for employees and dependents
  • Company-paid life and disability insurance
  • Voluntary life and critical illness coverage available
  • Employee Assistance Program and virtual health care platform
Financial Well-Being
  • RRSP with company match
  • Voluntary TFSA
Time Off & Flexibility
  • 3 weeks annually for vacation and paid holidays
  • Flexible Work Arrangements
Growth & Development
  • Opportunities for advancement and internal mobility
  • Training and personal development opportunities
Lifestyle & Culture
  • Company events and team-building activities

Similar Jobs

More Information Technology Jobs

Find similar Senior Governance Risk and Compliance (GRC) Analyst jobs: