> Markdown version of [/jobs/ext/598075-grc-analyst](https://www.wearedevelopers.com/jobs/ext/598075-grc-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # GRC Analyst - **Company:** Ease Inc - **Location:** Irvine, CA, United States - **Experience:** Experienced - **Salary:** $110,000.0 - $135,000.0 - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Amazon Web Services, JIRA, Microsoft Azure, Software as a Service, Cloud Computing, Cloud Computing Security, CompTIA Security+, Information Technology Audit, Phishing, Azure Machine Learning, Information Security Management System - **Published:** June 21, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=480dac18907a031e ## About the Role Do you have experience in Tooling?, You are organized, methodical, and a strong written communicator. You can pick up technical concepts quickly, work alongside security engineers without getting lost in the details and turn the messy reality of compliance work into clean process and clear evidence. You enjoy the mix of audit work, project management, and stakeholder communication that comes with GRC., * 3+ years of experience in a GRC, security compliance, IT audit, or closely related role. * Hands-on experience contributing to SOC 2, ISO 27001, HIPAA, or similar compliance program work. * Working knowledge of cloud and SaaS security concepts (AWS, Azure, or GCP, plus the common SaaS stack). * Experience completing vendor security assessments and customer security questionnaires. * Comfortable working in Jira and other engineering tooling. * Strong written communication, with the ability to write clearly for both engineering and non-technical audiences. * Strong attention to detail and a methodical approach to evidence, documentation, and follow-through. * Must be authorized to access Controlled Unclassified Information (CUI), which generally requires U.S. citizenship or permanent residency., * Exposure to NIST 800-171, DFARS 252.204-7012, CMMC, FedRAMP, or similar federal compliance work. * Hands-on experience with a GRC platform such as Drata, Vanta, Hyperproof, or Secureframe. * Familiarity with AI/ML security and governance concepts, including NIST AI RMF. * Familiarity with California privacy law (CCPA/CPRA). * Industry certifications such as CompTIA Security+, CySA+, CISA (or in pursuit), ISO 27001 Foundation, or similar. ## Description Ease is hiring a GRC Analyst to support our governance, risk, and compliance program as we mature our security posture and expand into new compliance frameworks. This is a hands-on role at the intersection of security, engineering, and the business - you'll be the operational engine behind how Ease maintains its compliance commitments and earns customer trust. You'll work closely with our security engineers and an external CMMC consultant to keep our SOC 2 program healthy, advance our CMMC Level 2 readiness, and bring rigor to how we assess applications, AI tools, and vendors before they enter the environment., You will be the day-to-day driver of compliance work at Ease. You'll support our SOC 2 Type II cycle, conduct security and privacy reviews of new applications and AI tools, run our vendor risk intake, and partner with our CMMC consultant on Level 2 implementation tasks. As we adopt a GRC platform, you'll help drive the rollout and become its primary administrator., * Support the SOC 2 program. Drive day-to-day execution of the annual Type II cycle, including evidence collection, control walkthroughs, gap remediation tracking, and auditor support. * Partner on CMMC Level 2 implementation. Work alongside our external CMMC consultant and security engineers on System Security Plan (SSP) development, CUI scoping, evidence collection, and C3PAO assessment readiness. * Assess applications and AI tools. Conduct security and privacy reviews on new applications, AI/ML services, and other tools before they enter the environment. Maintain an inventory of AI tools and contribute to our AI governance work. * Run vendor and third-party risk intake. Own the vendor security review process, complete questionnaires, and maintain the vendor risk register. * Maintain policy and procedure. Help author and maintain our security policy library so it stays aligned with SOC 2, CMMC, and how we actually operate. * Support the risk register. Contribute to formal risk assessments and keep the enterprise risk register current. * Coordinate audit and assessment logistics. Manage evidence requests during audits, schedule walkthroughs, run quarterly access reviews, and track remediation items through closure. * Administer our GRC platform. Help select and roll out our GRC platform then own day-to-day administration including integrations, control mapping, and evidence automation. * Drive compliance through Jira. Create, route, and monitor security and compliance tickets and partner with engineering on remediation timelines. * Audit change management hygiene. Monitor engineering Jira queues to ensure tickets meet our compliance formatting and content standards, verify that pull requests are properly linked to Jira tickets, and confirm required notes and documentation are captured for each change. * Support customer trust. Respond to customer security questionnaires and help maintain our trust center content. * Run security awareness. Manage the employee security awareness program, including training assignments, phishing simulations, and completion tracking. ## Related Videos - [Collaboration Quantified: Lessons from Open Source Developer Networks](https://www.wearedevelopers.com/videos/1422-collaboration-quantified-lessons-from-open-source-developer-networks) - [Passkeys: Truly Phishing-Resistant? Implementation and Pitfalls](https://www.wearedevelopers.com/videos/100156-passkeys-truly-phishing-resistant-implementation-and-pitfalls) - [Developer Tools for Microsoft Azure](https://www.wearedevelopers.com/videos/450-developer-tools-for-microsoft-azure) - [Great DevEx and Regulatory Compliance - Possible?](https://www.wearedevelopers.com/videos/1426-great-devex-and-regulatory-compliance-possible) - [AI for Enterprise Developers - Dr. Damir Dobric](https://www.wearedevelopers.com/videos/1831-ai-for-enterprise-developers-dr-damir-dobric) - [Integrate your Cognitive Assistant with 3rd-party DBs and software](https://www.wearedevelopers.com/videos/249-integrate-your-cognitive-assistant-with-3rd-party-dbs-and-software) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [Résumé-Driven Development: How IT trends affect the job market for software developers](https://www.wearedevelopers.com/magazine/59-resume-driven-development-how-it-trends-affect-the-job-market-for-software-developers) - [13 AI Tools for Developers](https://www.wearedevelopers.com/magazine/302-13-ai-tools-for-developers)