Back to job search
IREN logo
IRENVerified Job Source

Senior Governance Risk and Compliance (GRC) Analyst

  • Vancouver, BC
  • Hybrid
  • Posted Aug 14, 2026
  • 1 position

$125,000–$150,000 / year

Opens an external site

Sign in to save this job
Employment type
Full-time
Experience level
Senior · 5+ years
Minimum education
Bachelor’s degree
Posting language
English
Working hours
40 hours per week

Job summary

The Senior GRC Analyst will lead enterprise-wide risk assessment programs and manage the company's FedRAMP authorization strategy. They are responsible for developing governance frameworks and maintaining compliance with standards such as ISO 27001, SOC 2, and HITRUST.

Job details

IREN is a vertically integrated AI Cloud provider, delivering large-scale data centers and GPU clusters for AI training and inference. IREN’s platform is underpinned by its expansive portfolio of grid-connected land and power in renewable-rich regions across North America, Europe and APAC. With 100% renewable energy, we build, own and operate our data centers and take pride in being at the forefront of sustainable solutions for the ever-evolving applications of high-performance compute. We believe that human progress is invaluable, but it should be done in the right way – responsibly, sustainably and having a positive impact on the communities we operate in. * Bachelor’s (or Master’s) degree in Information Security, Risk, Business or equivalent. * 5-7 years of experience in cybersecurity, IT program management, or a related field. * Proven track record leading at least one successful FedRAMP authorization. * Deep knowledge of the FedRAMP framework, NIST 800-53 controls, and supporting documentation. * Audit/assessment experience using risk-based frameworks. * Familiarity with cloud security architecture and adjacent frameworks (SOC 2, ISO 27001, HITRUST, etc.) * Strong communication and relationship-building skills across technical and executive levels. * Demonstrated analytical and problem-solving skills, highly organized and detail oriented. * Experience engaging with government agencies or federal sector stakeholders is highly desirable. * Relevant certifications (CISM, CISA, CRISC, CISSP, ISO 27001 Lead Implementor) strongly preferred. * Lead enterprise-wide risk assessment programs, identify strategic risks, recommend mitigation and monitor residual risk. * Develop and maintain governance frameworks that align business objectives with regulatory/compliance requirements and security best practices. * Execute the company's FedRAMP authorization program from strategy through implementation. * Manage relationships with 3PAOs, consultants, and other external partners to facilitate assessments and drive progress. * Lead the preparation and submission of all FedRAMP deliverables, including the System Security Plan (SSP), policies, procedures, and supporting security documents. * Develop and maintain security and privacy policies, standards, and control frameworks aligned with ISO 27001, SOC 2, HITRUST, FedRAMP, and other global regulations * Support policy approvals, exception handling, and attestation processes while identifying opportunities for automation and process improvements. * Lead and execute enterprise risk assessments, including vendor and process-level reviews. * Support IREN's Third-Party Risk Management program including vendor assessments, monitoring, and remediation tracking * Lead readiness and response efforts for ISO 27001, HITRUST, FedRAMP and other audits and certifications. * Keep abreast of emerging regulatory, technological and business-risks, and drive improvements to the GRC program accordingly. At IREN, we offer a comprehensive Total Rewards package designed to support your health, well-being, and long-term success. Our Canada package for salaried positions includes: Compensation * The expected base salary for this role starts at $125-150K annually CAD. * Actual compensation will be determined based on factors such as experience, qualifications, and market data for the region. * Total Compensation package may be inclusive of annual incentive bonus, and equity (long-term incentive) * Relocation assistance (as appliable and based on successful candidate circumstances) Health & Wellness * Medical, dental, and vision insurance coverage – 100% company paid for employees and dependents * Company-paid life and disability insurance * Voluntary life and critical illness coverage available * Employee Assistance Program and virtual health care platform Financial Well-Being * RRSP with company match * Voluntary TFSA Time Off & Flexibility * 3 weeks annually for vacation and paid holidays * Flexible Work Arrangements Growth & Development * Opportunities for advancement and internal mobility * Training and personal development opportunities Lifestyle & Culture * Company events and team-building activities Podtech Data Centers Inc., the employing entity and proud member of the IREN Group is an equal opportunity employer that is committed to creating an inclusive workplace. We evaluate qualified applicants without regard to race, colour, religion, age, sex, sexual orientation, gender identity, genetic information, national origin, disability, veteran status, and other legally protected characteristics. By applying for this position and submitting your resume and application materials, you consent to the processing of your personal information in accordance with our Job Applicant Privacy Statement available on our website at www.iren.com.

What you’ll do

The Senior GRC Analyst will lead enterprise-wide risk assessment programs and manage the company's FedRAMP authorization strategy. They are responsible for developing governance frameworks and maintaining compliance with standards such as ISO 27001, SOC 2, and HITRUST.

Requirements

Candidates must have a bachelor's or master's degree in Information Security, Risk, or a related field with 5-7 years of experience. A proven track record of leading successful FedRAMP authorizations and deep knowledge of NIST 800-53 controls are required.

Benefits

• Medical insurance • Dental insurance • Vision insurance • Life insurance • Disability insurance • Employee assistance program • Virtual health care • RRSP with company match • Vacation • Paid holidays • Flexible work arrangements • Training and development

Listed skills

  • Communication · Preferred

Other relevant skills

Identified from the job description. Confirm important requirements above.

  • FedRAMP
  • NIST 800-53
  • Risk assessment
  • Governance frameworks
  • ISO 27001
  • SOC 2
  • HITRUST
  • Cybersecurity
  • IT program management
  • Third-party risk management
  • Compliance
  • Cloud security architecture
  • Policy development
  • Audit management
  • Analytical skills
  • Communication
  • Cloud Security Architecture
  • Certified Information System Auditor (CISA)
  • Workplace Inclusivity
  • Relationship Management
  • Virtual Health
  • Third Party Risk Management
  • Business Objectives
  • AI/ML Inference
  • Machine Learning Model Training
  • Security Risk
  • Artificial Intelligence
  • Auditing
  • Automation
  • Certified Information Systems Security Professional
  • Certified Information Security Manager
  • Regulatory Compliance
  • Certified In Risk And Information Systems Control
  • Cyber Security
  • Data Centers
  • Employee Assistance Programs
  • Equities
  • Exception Handling
  • Governance
  • Governance Risk Management And Compliance
  • Renewable Energy
  • ISO/IEC 27001
  • Problem Solving
  • Market Data
  • Program Management
  • Relationship Building
  • Risk Analysis
  • Team Building
  • Vision Insurance
  • Process Improvement

Job areas

  • Technology
  • Security & Safety
  • Management & Leadership
  • Software
  • Energy
  • Risk and Compliance Analyst
  • Compliance Officer / Analyst
  • Legal and Related Associate Professionals
  • Compliance Officers

More jobs you can apply to directly

Similar opportunities posted by employers hiring on Jobs.ca, with no external application form.

Browse all Easy Apply jobs