1

Grc Auditor Jobs in Riverside, CA (NOW HIRING)

GRC Analyst

Irvine, CA · On-site

$110K - $135K/yr

... auditor support. * Partner on CMMC Level 2 implementation. Work alongside our external CMMC ... Administer our GRC platform. Help select and roll out our GRC platform then own day-to-day ...

... auditor support. * Partner on CMMC Level 2 implementation. Work alongside our external CMMC ... Administer our GRC platform. Help select and roll out our GRC platform then own day-to-day ...

Technology Auditor Location - Irvine, CA Company Overview Hyundai AutoEver America (HAEA) , the ... Knowledge of GRC tooling and workflows. * Language Skills : Excellent stakeholder management and ...

Technology Auditor Location - Irvine, CA Company Overview Hyundai AutoEver America (HAEA) , the ... Knowledge of GRC tooling and workflows. * Language Skills : Excellent stakeholder management and ...

Engage external regulators, auditors, and examiners on AI governance posture; own examination ... Hands-on familiarity with AI governance tooling, GRC platforms, and TPRM workflows. * Familiarity ...

Grc Auditor information

See Riverside, CA salary details

$43.3K

$81.5K

$130.4K

How much do grc auditor jobs pay per year?

As of Jul 25, 2026, the average yearly pay for grc auditor in Riverside, CA is $81,545.00, according to ZipRecruiter salary data. Most workers in this role earn between $61,000.00 and $93,400.00 per year, depending on experience, location, and employer.

What does a GRC auditor do?

A GRC (Governance, Risk, and Compliance) auditor assesses an organization's adherence to regulatory requirements, internal policies, and industry standards. They review controls, perform audits, and recommend improvements to ensure effective risk management and compliance programs, often using tools like audit software and frameworks such as ISO or COBIT.

What is a GRC Auditor?

A GRC Auditor is a professional responsible for evaluating an organization's Governance, Risk Management, and Compliance (GRC) processes. They assess whether the organization is following relevant laws, regulations, and internal policies, and help identify areas of risk or non-compliance. GRC Auditors often conduct audits, review documentation, and provide recommendations to improve controls and ensure the organization meets its regulatory and operational requirements.

What is the difference between Grc Auditor vs Compliance Analyst?

AspectGrc AuditorCompliance Analyst
CertificationsISO 27001 Lead Auditor, CISA, CISMCertified Compliance & Ethics Professional (CCEP), CCEP-I
Work EnvironmentAudit firms, corporate compliance departmentsCorporate compliance teams, regulatory agencies
Industry UsageRisk management, IT, financeRegulatory adherence, policy enforcement

Grc Auditors focus on evaluating an organization’s governance, risk, and compliance frameworks through audits, often requiring certifications like CISA. Compliance Analysts primarily monitor and ensure adherence to regulations and policies, with certifications like CCEP. While both roles operate within compliance, Grc Auditors typically conduct formal audits, whereas Compliance Analysts focus on ongoing compliance monitoring.

Is GRC an entry level job?

A GRC Auditor role is typically not considered entry level; it usually requires some experience in compliance, risk management, or auditing, along with relevant certifications such as CISA or CISSP. Entry-level positions in GRC may be available for those with foundational knowledge and a willingness to learn on the job.

Is GRC a good career?

A GRC Auditor specializes in governance, risk management, and compliance, often working with frameworks like ISO, NIST, or COBIT. It is considered a stable career with demand across industries, requiring knowledge of regulations, audit skills, and certifications such as CISA or CRISC. The role offers opportunities for advancement and specialization in cybersecurity, internal controls, or regulatory compliance.

What are the main challenges GRC Auditors face when ensuring compliance across multiple departments?

GRC Auditors often encounter challenges in standardizing compliance processes across diverse departments, each with their own workflows and risk profiles. Coordinating with various teams to gather accurate data and evidence can be time-consuming, especially when systems are not integrated. Communication and collaboration are crucial, as auditors must often explain regulatory requirements and best practices to non-technical staff. Proactively building strong relationships and clear processes helps overcome these hurdles and ensures smoother audits.

What are the key skills and qualifications needed to thrive as a GRC Auditor, and why are they important?

To thrive as a GRC Auditor, you need a strong understanding of governance, risk management, compliance frameworks, and auditing principles, often supported by a degree in accounting, finance, or a related field. Familiarity with audit management tools, GRC platforms (such as RSA Archer or MetricStream), and certifications like CISA, CRISC, or CISSP are commonly required. Strong analytical thinking, attention to detail, and effective communication are essential soft skills to excel in this role. These competencies ensure comprehensive risk assessments, regulatory compliance, and effective reporting, which are critical for organizational integrity and security.

What type of auditor gets paid the most?

Among auditors, financial auditors and internal auditors with specialized skills or certifications such as CPA or CIA tend to earn the highest salaries. GRC (Governance, Risk, and Compliance) auditors with expertise in regulatory frameworks and risk management also command higher pay, especially with experience and advanced certifications. Salary levels depend on industry, location, and level of responsibility.
What are popular job titles related to Grc Auditor jobs in Riverside, CA? For Grc Auditor jobs in Riverside, CA, the most frequently searched job titles are:
What job categories do people searching Grc Auditor jobs in Riverside, CA look for? The top searched job categories for Grc Auditor jobs in Riverside, CA are:
What cities near Riverside, CA are hiring for Grc Auditor jobs? Cities near Riverside, CA with the most Grc Auditor job openings:
GRC Analyst

GRC Analyst

Ease, Inc

Irvine, CA • On-site

$110K - $135K/yr

Full-time

Medical, Dental, Vision, Life, Retirement, PTO

Posted 9 days ago


Job description

Ease is hiring a GRC Analyst to support our governance, risk, and compliance program as we mature our security posture and expand into new compliance frameworks. This is a hands-on role at the intersection of security, engineering, and the business - you'll be the operational engine behind how Ease maintains its compliance commitments and earns customer trust.
You'll work closely with our security engineers and an external CMMC consultant to keep our SOC 2 program healthy, advance our CMMC Level 2 readiness, and bring rigor to how we assess applications, AI tools, and vendors before they enter the environment.
Position Summary
You will be the day-to-day driver of compliance work at Ease. You'll support our SOC 2 Type II cycle, conduct security and privacy reviews of new applications and AI tools, run our vendor risk intake, and partner with our CMMC consultant on Level 2 implementation tasks. As we adopt a GRC platform, you'll help drive the rollout and become its primary administrator.
You are organized, methodical, and a strong written communicator. You can pick up technical concepts quickly, work alongside security engineers without getting lost in the details and turn the messy reality of compliance work into clean process and clear evidence. You enjoy the mix of audit work, project management, and stakeholder communication that comes with GRC.
Position Location: Hybrid - 3 days in Irvine office
Annual Salary Range: $110,000 - $135,000
What You'll Do
  • Support the SOC 2 program. Drive day-to-day execution of the annual Type II cycle, including evidence collection, control walkthroughs, gap remediation tracking, and auditor support.
  • Partner on CMMC Level 2 implementation. Work alongside our external CMMC consultant and security engineers on System Security Plan (SSP) development, CUI scoping, evidence collection, and C3PAO assessment readiness.
  • Assess applications and AI tools. Conduct security and privacy reviews on new applications, AI/ML services, and other tools before they enter the environment. Maintain an inventory of AI tools and contribute to our AI governance work.
  • Run vendor and third-party risk intake. Own the vendor security review process, complete questionnaires, and maintain the vendor risk register.
  • Maintain policy and procedure. Help author and maintain our security policy library so it stays aligned with SOC 2, CMMC, and how we actually operate.
  • Support the risk register. Contribute to formal risk assessments and keep the enterprise risk register current.
  • Coordinate audit and assessment logistics. Manage evidence requests during audits, schedule walkthroughs, run quarterly access reviews, and track remediation items through closure.
  • Administer our GRC platform. Help select and roll out our GRC platform then own day-to-day administration including integrations, control mapping, and evidence automation.
  • Drive compliance through Jira. Create, route, and monitor security and compliance tickets and partner with engineering on remediation timelines.
  • Audit change management hygiene. Monitor engineering Jira queues to ensure tickets meet our compliance formatting and content standards, verify that pull requests are properly linked to Jira tickets, and confirm required notes and documentation are captured for each change.
  • Support customer trust. Respond to customer security questionnaires and help maintain our trust center content.
  • Run security awareness. Manage the employee security awareness program, including training assignments, phishing simulations, and completion tracking.

Required Qualifications & Skills
  • 3+ years of experience in a GRC, security compliance, IT audit, or closely related role.
  • Hands-on experience contributing to SOC 2, ISO 27001, HIPAA, or similar compliance program work.
  • Working knowledge of cloud and SaaS security concepts (AWS, Azure, or GCP, plus the common SaaS stack).
  • Experience completing vendor security assessments and customer security questionnaires.
  • Comfortable working in Jira and other engineering tooling.
  • Strong written communication, with the ability to write clearly for both engineering and non-technical audiences.
  • Strong attention to detail and a methodical approach to evidence, documentation, and follow-through.
  • Must be authorized to access Controlled Unclassified Information (CUI), which generally requires U.S. citizenship or permanent residency.

Preferred Qualifications
  • Exposure to NIST 800-171, DFARS 252.204-7012, CMMC, FedRAMP, or similar federal compliance work.
  • Hands-on experience with a GRC platform such as Drata, Vanta, Hyperproof, or Secureframe.
  • Familiarity with AI/ML security and governance concepts, including NIST AI RMF.
  • Familiarity with California privacy law (CCPA/CPRA).
  • Industry certifications such as CompTIA Security+, CySA+, CISA (or in pursuit), ISO 27001 Foundation, or similar.

About Ease
Ease.io digitally transforms plant floor audits around the world with EASE, our enterprise-grade mobile platform for quality, safety, and operational audits. The platform combines simplicity and efficiency with powerful performance insights, helping drive quality and safety on the plant floor.
Industry leaders including Aston Martin, Dana, 3M, Tenneco, and Samsung trust EASE to facilitate and analyze millions of plant floor audits every year. With deployments in more than 40 countries and support for more than 25 languages, EASE has established itself as a category leader in quality management.
Headquartered in Irvine, California, Ease.io is a dynamic company that continues to grow as it expands its product offerings and market presence.
What We Offer
At Ease, we foster a culture built on respect, humility, and collaboration. We value work-life balance as a core principle, helping ensure you can thrive both professionally and personally. And yes-we believe work should be fun, too.
Growth and development are part of our DNA. We are committed to investing in your career through ongoing training, mentorship, and a clearly defined path forward. Whether you are sharpening existing skills or exploring new ones, you will have opportunities to learn and advance.
We prioritize the well-being and happiness of our team. In addition to a competitive compensation package, we offer a generous and comprehensive suite of benefits designed to support your health and peace of mind.
Here's a look at what you can expect:
  • Health Coverage: Comprehensive medical, dental, and vision plans
  • Life & AD&D Insurance: Financial protection for you and your loved ones
  • Unlimited Paid Time Off: Time to recharge and rest when you need it
  • 401(k) with Employer Match: Plan for your future with confidence through our matched retirement savings program

At Ease, we believe that when our employees are supported, inspired, and empowered, everyone wins.
#LI-Hybrid