Base Power Company Logo

Base Power Company

GRC Analyst

Posted 5 Hours Ago
Be an Early Applicant
In-Office
Austin, TX, USA
Mid level
In-Office
Austin, TX, USA
Mid level
Manage Base’s security governance, risk, and compliance program across software, hardware, manufacturing, field operations, and energy infrastructure. Responsibilities include running SOC 2 and ISO 27001 programs, collecting evidence, testing controls, coordinating audits, maintaining policies and risk registers, assessing vendors, mapping controls to security frameworks, managing customer security assessments, and delivering security awareness training.
The summary above was generated by AI
About Base

Base is America’s next-generation power company. We’re rebuilding the foundation of modern civilization–electricity–by deploying a vast network of distributed batteries that is transforming today’s fragile, centralized grid into a resilient and abundant system. We are engineers, operators, and creatives solving some of the most complex, interdisciplinary challenges of our time.

About the Role

We are seeking a GRC Analyst to help build and run Base’s security governance, risk, and compliance program as the company scales across software, hardware, manufacturing, field operations, and energy infrastructure. This role will sit on the Security team and help turn security requirements into practical, repeatable processes that support customer trust, regulatory readiness, and operational resilience.

 

The ideal candidate is detail-oriented, organized, and comfortable translating complex security and compliance requirements into clear action plans. This is an opportunity to make GRC more than a checkbox function, helping Base earn trust, reduce risk, and scale securely.

What You'll Do
  • Run Base's compliance programs (SOC 2, ISO 27001, etc.): evidence collection, control testing, and audit coordination

  • Write and maintain security policies and procedures

  • Assess and track vendor and third party risk

  • Maintain the risk register: identify, classify, and remediate risks

  • Support internal and external audits and evidence collection

  • Maintain control mapping against frameworks like NIST CSF, NIST 800-53, CIS Controls and ISO

  • Run periodic risk assessments across business units and systems

  • Own responses to customer and partner security assessments and RFPs

  • Take point on annual security awareness training

  • Coordinate requirements and deadlines across departments

What You'll Bring
  • 3+ years in security compliance, IT audit, or GRC, including at least one SOC 2 cycle owned start to finish

  • Enough technical depth to judge a control yourself - read a SIEM configuration, an identity provider's MFA settings, or a cloud audit log and decide whether it holds up

  • Strong organizational and interpersonal skills to coordinate across teams and stakeholders

  • Hands-on ownership of a GRC platform — Secureframe, Vanta, Drata, or similar — including configuring integrations

  • Experience building and running a third-party risk program

  • Comfortable holding remediation deadlines with engineering or operations in a fast-moving environment

About the Team

GRC is a crucial function embedded in the Security team. This role will have a direct impact on the overall security posture of the company through industry frameworks and controls. Our team operates with clear accountability, tight feedback loops, and a strong bias to action.

Please note: Base is a startup, which means priorities shift and evolve quickly. Your role may expand or change based on the needs of the business at any given time, so the responsibilities listed may not be exhaustive.

Our Values
  • First Principles Thinking: Question assumptions. Principles > rules.

  • Operate at Base Pace: Focus on what matters, act quickly, and learn by doing.

  • Give & Get Feedback: Be direct, be humble, and maintain a growth mindset.

  • Everyone’s an Owner: Follow through on commitments and own results.

  • Strong Opinions, Loosely Held: Drive clarity and make calls with imperfect information.

  • Committed to the Mission: Rebuilding the grid is a big challenge. We work hard because we care deeply about the impact we’re creating. We work in-person. It’s not a 9-to-5. We are all-in.

  • Fun & Optimism Coexist with Grit: Collaboration and celebration coincide with the intensity of building real things.

Do the best work of your life at Base.
HQ

Base Power Company Austin, Texas, USA Office

205 E Riverside Drive, Austin, TX, United States, 78704

Similar Jobs

Yesterday
In-Office
Senior level
Senior level
Automotive • Information Technology • Other • Transportation • Energy
Supports cybersecurity governance, risk management, compliance, and assurance programs. Develops security policies and frameworks, conducts risk assessments, coordinates remediation, and leads audit and questionnaire responses. Reviews cloud, system, and OT architectures; manages documentation, evidence, vulnerability tracking, and third-party risk. Supports incident response, data protection, security awareness, and project security requirements while ensuring compliance with NIST, CMMC, FedRAMP, ITAR, EAR, and other regulations.
Top Skills: Cis ControlsCloud SecurityCmmcCyber EssentialsEarEndpoint ProtectionFedrampIdentity ManagementIndustrial Control Systems (Ics)Iso 27001ItarMicrosoft 365Microsoft DefenderMicrosoft Entra IdMicrosoft PurviewNist Sp 800-171Nist Sp 800-53Operational Technology (Ot)Risk Management Framework (Rmf)Security MonitoringVulnerability Management
Senior level
Insurance • Professional Services • Software • Financial Services
Owns enterprise GRC platform administration and migration, including configuration, access, workflows, integrations, reporting, dashboards, and module rollouts. Builds executive risk analytics and key risk indicator reporting, supports control testing, documents processes, trains users, and drives platform automation. Partners with audit, risk, privacy, cybersecurity, IT, and vendors to improve compliance operations and eliminate redundant tooling.
Top Skills: Ai-Assisted WorkflowsArcherHrisExcelOnspringServicenowSQLWorkiva
Senior level
Marketing Tech
Owns enterprise GRC platform administration and migration, including configuration, workflows, integrations, control mapping, reporting, analytics, and module rollouts. Develops executive dashboards, key risk indicators, findings analyses, documentation, and training. Partners with audit, risk, privacy, cybersecurity, IT, and business stakeholders to improve compliance processes, automate workflows, support control testing, and consolidate redundant technology. Requires hands-on GRC platform administration, migration experience, strong reporting skills, and knowledge of risk and compliance frameworks.
Top Skills: ArcherHitrustIso 27001ExcelNistOnspringServicenowSoc 2SQLWorkiva

What you need to know about the Austin Tech Scene

Austin has a diverse and thriving tech ecosystem thanks to home-grown companies like Dell and major campuses for IBM, AMD and Apple. The state’s flagship university, the University of Texas at Austin, is known for its engineering school, and the city is known for its annual South by Southwest tech and media conference. Austin’s tech scene spans many verticals, but it’s particularly known for hardware, including semiconductors, as well as AI, biotechnology and cloud computing. And its food and music scene, low taxes and favorable climate has made the city a destination for tech workers from across the country.

Key Facts About Austin Tech

  • Number of Tech Workers: 180,500; 13.7% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Dell, IBM, AMD, Apple, Alphabet
  • Key Industries: Artificial intelligence, hardware, cloud computing, software, healthtech
  • Funding Landscape: $4.5 billion in VC funding in 2024 (Pitchbook)
  • Notable Investors: Live Oak Ventures, Austin Ventures, Hinge Capital, Gigafund, KdT Ventures, Next Coast Ventures, Silverton Partners
  • Research Centers and Universities: University of Texas, Southwestern University, Texas State University, Center for Complex Quantum Systems, Oden Institute for Computational Engineering and Sciences, Texas Advanced Computing Center

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account