Job description Job requirements- Bachelor's (or Master's) degree in Information Security, Risk, Business or equivalent.
- 5-7 years of experience in cybersecurity, IT program management, or a related field.
- Proven track record leading at least one successful FedRAMP authorization.
- Deep knowledge of the FedRAMP framework, NIST 800-53 controls, and supporting documentation.
- Audit/assessment experience using risk-based frameworks.
- Familiarity with cloud security architecture and adjacent frameworks (SOC 2, ISO 27001, HITRUST, etc.)
- Strong communication and relationship-building skills across technical and executive levels.
- Demonstrated analytical and problem-solving skills, highly organized and detail oriented.
- Experience engaging with government agencies or federal sector stakeholders is highly desirable.
- Relevant certifications (CISM, CISA, CRISC, CISSP, ISO 27001 Lead Implementor) strongly preferred.
Job responsibilities - Lead enterprise-wide risk assessment programs, identify strategic risks, recommend mitigation and monitor residual risk.
- Develop and maintain governance frameworks that align business objectives with regulatory/compliance requirements and security best practices.
- Execute the company's FedRAMP authorization program from strategy through implementation.
- Manage relationships with 3PAOs, consultants, and other external partners to facilitate assessments and drive progress.
- Lead the preparation and submission of all FedRAMP deliverables, including the System Security Plan (SSP), policies, procedures, and supporting security documents.
- Develop and maintain security and privacy policies, standards, and control frameworks aligned with ISO 27001, SOC 2, HITRUST, FedRAMP, and other global regulations
- Support policy approvals, exception handling, and attestation processes while identifying opportunities for automation and process improvements.
- Lead and execute enterprise risk assessments, including vendor and process-level reviews.
- Support IREN's Third-Party Risk Management program including vendor assessments, monitoring, and remediation tracking
- Lead readiness and response efforts for ISO 27001, HITRUST, FedRAMP and other audits and certifications.
- Keep abreast of emerging regulatory, technological and business-risks, and drive improvements to the GRC program accordingly.
Job benefits The IREN Package
At IREN, we offer a highly competitive compensation package that includes base salary, annual performance incentives, and opportunities to build long-term wealth through equity programs. These offerings are part of our broader Total Rewards package, thoughtfully designed to support your health, well-being, and long-term success.
Compensation
- The expected base salary for this role USD$165,000 - 190,000/annum.
- Actual compensation will be determined based on factors such as experience, qualifications, and market data for the region.
- Total Compensation package may be inclusive of annual incentive bonus, equity (long-term incentive).
- Relocation or Living-out-allowance / per diem (as appliable and based on successful candidate circumstances)
Health & Wellness
- 100% company paid health insurance premiums (medical, dental, and vision) for employees, 75% company paid coverage for dependents
- Company-paid short-term and long-term disability insurance
- Voluntary life, critical illness, and accident coverage available
- Health Savings Accounts (HSA) - when combined with the High Deductible Health Plan
- Employee Assistance Program and wellness resources
Retirement & Financial Wealth
- 401(k) retirement plan with company match
- Access to financial planning and legal services
Time Off & Leave Programs
- Paid Time Off (PTO) and paid holidays
Growth & Development
- Internal skills training and advancement pathways
- Professional development to support certifications, continuing education, or role related training
Community & Culture
- Company events and team-building activities
We value diverse perspectives and believe that skills can be developed. If you're passionate about this role, we want to hear from you - whether you meet every criteria or not. Your unique experiences might be exactly what we need!