{"schemaVersion":"jobsearcher.job.v1","id":"da54166d8279f28247754c7f","url":"https://jobsearcher.com/jobs/da54166d8279f28247754c7f","canonicalUrl":"https://jobsearcher.com/jobs/da54166d8279f28247754c7f","title":"GRC Analyst","description":"Ease is hiring a GRC Analyst to support our governance, risk, and compliance program as we mature our security posture and expand into new compliance frameworks. This is a hands-on role at the intersection of security, engineering, and the business — you'll be the operational engine behind how Ease maintains its compliance commitments and earns customer trust.\r\nYou'll work closely with our security engineers and an external CMMC consultant to keep our SOC 2 program healthy, advance our CMMC Level 2 readiness, and bring rigor to how we assess applications, AI tools, and vendors before they enter the environment.\r\nPosition Summary\r\nYou will be the day-to-day driver of compliance work at Ease. You'll support our SOC 2 Type II cycle, conduct security and privacy reviews of new applications and AI tools, run our vendor risk intake, and partner with our CMMC consultant on Level 2 implementation tasks. As we adopt a GRC platform, you'll help drive the rollout and become its primary administrator.\r\nYou are organized, methodical, and a strong written communicator. You can pick up technical concepts quickly, work alongside security engineers without getting lost in the details and turn the messy reality of compliance work into clean process and clear evidence. You enjoy the mix of audit work, project management, and stakeholder communication that comes with GRC.\r\nPosition Location: Hybrid – 3 days in Irvine office\r\nAnnual Salary Range: $110,000 – $135,000\r\nWhat You'll Do\r\nSupport the SOC 2 program. Drive day-to-day execution of the annual Type II cycle, including evidence collection, control walkthroughs, gap remediation tracking, and auditor support.\r\nPartner on CMMC Level 2 implementation. Work alongside our external CMMC consultant and security engineers on System Security Plan (SSP) development, CUI scoping, evidence collection, and C3PAO assessment readiness.\r\nAssess applications and AI tools. Conduct security and privacy reviews on new applications, AI/ML services, and other tools before they enter the environment. Maintain an inventory of AI tools and contribute to our AI governance work.\r\nRun vendor and third-party risk intake. Own the vendor security review process, complete questionnaires, and maintain the vendor risk register.\r\nMaintain policy and procedure. Help author and maintain our security policy library so it stays aligned with SOC 2, CMMC, and how we actually operate.\r\nSupport the risk register. Contribute to formal risk assessments and keep the enterprise risk register current.\r\nCoordinate audit and assessment logistics. Manage evidence requests during audits, schedule walkthroughs, run quarterly access reviews, and track remediation items through closure.\r\nAdminister our GRC platform. Help select and roll out our GRC platform then own day-to-day administration including integrations, control mapping, and evidence automation.\r\nDrive compliance through Jira. Create, route, and monitor security and compliance tickets and partner with engineering on remediation timelines.\r\nAudit change management hygiene. Monitor engineering Jira queues to ensure tickets meet our compliance formatting and content standards, verify that pull requests are properly linked to Jira tickets, and confirm required notes and documentation is captured for each change.\r\nSupport customer trust. Respond to customer security questionnaires and help maintain our trust center content.\r\nRun security awareness. Manage the employee security awareness program, including training assignments, phishing simulations, and completion tracking.\r\nRequired Qualifications & Skills\r\n3+ years of experience in a GRC, security compliance, IT audit, or closely related role.\r\nHands-on experience contributing to SOC 2, ISO 27001, HIPAA, or similar compliance program work.\r\nWorking knowledge of cloud and SaaS security concepts (AWS, Azure, or GCP, plus the common SaaS stack).\r\nExperience completing vendor security assessments and customer security questionnaires.\r\nComfortable working in Jira and other engineering tooling.\r\nStrong written communication, with the ability to write clearly for both engineering and non-technical audiences.\r\nStrong attention to detail and a methodical approach to evidence, documentation, and follow-through.\r\nMust be authorized to access Controlled Unclassified Information (CUI), which generally requires U.S. citizenship or permanent residency.\r\nPreferred Qualifications\r\nExposure to NIST 800-171, DFARS 252.204-7012, CMMC, FedRAMP, or similar federal compliance work.\r\nHands-on experience with a GRC platform such as Drata, Vanta, Hyperproof, or Secureframe.\r\nFamiliarity with AI/ML security and governance concepts, including NIST AI RMF.\r\nFamiliarity with California privacy law (CCPA/CPRA).\r\nIndustry certifications such as CompTIA Security+, CySA+, CISA (or in pursuit), ISO 27001 Foundation, or similar.\r\nAbout Ease\r\nEase.io digitally transforms plant floor audits around the world with EASE, our enterprise-grade mobile platform for quality, safety, and operational audits. The platform combines simplicity and efficiency with powerful performance insights, helping drive quality and safety on the plant floor.\r\nIndustry leaders including Aston Martin, Dana, 3M, Tenneco, and Samsung trust EASE to facilitate and analyze millions of plant floor audits every year. With deployments in more than 40 countries and support for more than 25 languages, EASE has established itself as a category leader in quality management.\r\nHeadquartered in Irvine, California, Ease.io is a dynamic company that continues to grow as it expands its product offerings and market presence.\r\nWhat We Offer\r\nAt Ease, we foster a culture built on respect, humility, and collaboration. We value work-life balance as a core principle, helping ensure you can thrive both professionally and personally. And yes—we believe work should be fun, too.\r\nGrowth and development are part of our DNA. We are committed to investing in your career through ongoing training, mentorship, and a clearly defined path forward. Whether you are sharpening existing skills or exploring new ones, you will have opportunities to learn and advance.\r\nWe prioritize the well-being and happiness of our team. In addition to a competitive compensation package, we offer a generous and comprehensive suite of benefits designed to support your health and peace of mind.\r\nHealth Coverage: Comprehensive medical, dental, and vision plans\r\nLife & AD&D Insurance: Financial protection for you and your loved ones\r\nUnlimited Paid Time Off: Time to recharge and rest when you need it\r\n401(k) with Employer Match: Plan for your future with confidence through our matched retirement savings program\r\nAt Ease, we believe that when our employees are supported, inspired, and empowered, everyone wins.\r\nJ-18808-Ljbffr","company":"Ease","rawCompany":"ease","city":"Irvine","state":"CA","isRemote":false,"isActive":false,"createdAt":"2026-06-25T00:59:52.386Z","occupations":[{"code":"15-1212.00","title":"Information Security Analysts","slug":"information-security-analysts"},{"code":"11-9199.02","title":"Compliance Managers","slug":"compliance-managers"},{"code":"13-1041.00","title":"Compliance Officers","slug":"compliance-officers"}],"industries":[{"code":"541512","title":"Computer Systems Design Services","slug":"computer-systems-design-services"},{"code":"513210","title":"Software Publishers","slug":"software-publishers"},{"code":"541511","title":"Custom Computer Programming Services","slug":"custom-computer-programming-services"}],"jobPosting":{"@context":"https://schema.org","@type":"JobPosting","title":"GRC Analyst","description":"Ease is hiring a GRC Analyst to support our governance, risk, and compliance program as we mature our security posture and expand into new compliance frameworks. This is a hands-on role at the intersection of security, engineering, and the business — you'll be the operational engine behind how Ease maintains its compliance commitments and earns customer trust.\r\nYou'll work closely with our security engineers and an external CMMC consultant to keep our SOC 2 program healthy, advance our CMMC Level 2 readiness, and bring rigor to how we assess applications, AI tools, and vendors before they enter the environment.\r\nPosition Summary\r\nYou will be the day-to-day driver of compliance work at Ease. You'll support our SOC 2 Type II cycle, conduct security and privacy reviews of new applications and AI tools, run our vendor risk intake, and partner with our CMMC consultant on Level 2 implementation tasks. As we adopt a GRC platform, you'll help drive the rollout and become its primary administrator.\r\nYou are organized, methodical, and a strong written communicator. You can pick up technical concepts quickly, work alongside security engineers without getting lost in the details and turn the messy reality of compliance work into clean process and clear evidence. You enjoy the mix of audit work, project management, and stakeholder communication that comes with GRC.\r\nPosition Location: Hybrid – 3 days in Irvine office\r\nAnnual Salary Range: $110,000 – $135,000\r\nWhat You'll Do\r\nSupport the SOC 2 program. Drive day-to-day execution of the annual Type II cycle, including evidence collection, control walkthroughs, gap remediation tracking, and auditor support.\r\nPartner on CMMC Level 2 implementation. Work alongside our external CMMC consultant and security engineers on System Security Plan (SSP) development, CUI scoping, evidence collection, and C3PAO assessment readiness.\r\nAssess applications and AI tools. Conduct security and privacy reviews on new applications, AI/ML services, and other tools before they enter the environment. Maintain an inventory of AI tools and contribute to our AI governance work.\r\nRun vendor and third-party risk intake. Own the vendor security review process, complete questionnaires, and maintain the vendor risk register.\r\nMaintain policy and procedure. Help author and maintain our security policy library so it stays aligned with SOC 2, CMMC, and how we actually operate.\r\nSupport the risk register. Contribute to formal risk assessments and keep the enterprise risk register current.\r\nCoordinate audit and assessment logistics. Manage evidence requests during audits, schedule walkthroughs, run quarterly access reviews, and track remediation items through closure.\r\nAdminister our GRC platform. Help select and roll out our GRC platform then own day-to-day administration including integrations, control mapping, and evidence automation.\r\nDrive compliance through Jira. Create, route, and monitor security and compliance tickets and partner with engineering on remediation timelines.\r\nAudit change management hygiene. Monitor engineering Jira queues to ensure tickets meet our compliance formatting and content standards, verify that pull requests are properly linked to Jira tickets, and confirm required notes and documentation is captured for each change.\r\nSupport customer trust. Respond to customer security questionnaires and help maintain our trust center content.\r\nRun security awareness. Manage the employee security awareness program, including training assignments, phishing simulations, and completion tracking.\r\nRequired Qualifications & Skills\r\n3+ years of experience in a GRC, security compliance, IT audit, or closely related role.\r\nHands-on experience contributing to SOC 2, ISO 27001, HIPAA, or similar compliance program work.\r\nWorking knowledge of cloud and SaaS security concepts (AWS, Azure, or GCP, plus the common SaaS stack).\r\nExperience completing vendor security assessments and customer security questionnaires.\r\nComfortable working in Jira and other engineering tooling.\r\nStrong written communication, with the ability to write clearly for both engineering and non-technical audiences.\r\nStrong attention to detail and a methodical approach to evidence, documentation, and follow-through.\r\nMust be authorized to access Controlled Unclassified Information (CUI), which generally requires U.S. citizenship or permanent residency.\r\nPreferred Qualifications\r\nExposure to NIST 800-171, DFARS 252.204-7012, CMMC, FedRAMP, or similar federal compliance work.\r\nHands-on experience with a GRC platform such as Drata, Vanta, Hyperproof, or Secureframe.\r\nFamiliarity with AI/ML security and governance concepts, including NIST AI RMF.\r\nFamiliarity with California privacy law (CCPA/CPRA).\r\nIndustry certifications such as CompTIA Security+, CySA+, CISA (or in pursuit), ISO 27001 Foundation, or similar.\r\nAbout Ease\r\nEase.io digitally transforms plant floor audits around the world with EASE, our enterprise-grade mobile platform for quality, safety, and operational audits. The platform combines simplicity and efficiency with powerful performance insights, helping drive quality and safety on the plant floor.\r\nIndustry leaders including Aston Martin, Dana, 3M, Tenneco, and Samsung trust EASE to facilitate and analyze millions of plant floor audits every year. With deployments in more than 40 countries and support for more than 25 languages, EASE has established itself as a category leader in quality management.\r\nHeadquartered in Irvine, California, Ease.io is a dynamic company that continues to grow as it expands its product offerings and market presence.\r\nWhat We Offer\r\nAt Ease, we foster a culture built on respect, humility, and collaboration. We value work-life balance as a core principle, helping ensure you can thrive both professionally and personally. And yes—we believe work should be fun, too.\r\nGrowth and development are part of our DNA. We are committed to investing in your career through ongoing training, mentorship, and a clearly defined path forward. Whether you are sharpening existing skills or exploring new ones, you will have opportunities to learn and advance.\r\nWe prioritize the well-being and happiness of our team. In addition to a competitive compensation package, we offer a generous and comprehensive suite of benefits designed to support your health and peace of mind.\r\nHealth Coverage: Comprehensive medical, dental, and vision plans\r\nLife & AD&D Insurance: Financial protection for you and your loved ones\r\nUnlimited Paid Time Off: Time to recharge and rest when you need it\r\n401(k) with Employer Match: Plan for your future with confidence through our matched retirement savings program\r\nAt Ease, we believe that when our employees are supported, inspired, and empowered, everyone wins.\r\nJ-18808-Ljbffr","datePosted":"2026-06-25T00:59:52.386Z","dateModified":"2026-06-25T00:59:52.386Z","hiringOrganization":{"@type":"Organization","name":"Ease","sameAs":"https://jobsearcher.com"},"jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Irvine","addressRegion":"CA","addressCountry":"US"}},"identifier":{"@type":"PropertyValue","name":"JobSearcher","value":"da54166d8279f28247754c7f"},"url":"https://jobsearcher.com/jobs/da54166d8279f28247754c7f"}}