
GRC Analyst
Austin, TX at a glance
- Rent
- #25 of 51$2,300/mo-15% vs US avg
- Weather
- #13 of 51194 mild days142 hot · 0 cold
- Income tax
- #51 of 51NoneTexas
What you need
- 3+ yrs security compliance/GRC with SOC 2 ownership
- Technical depth to evaluate controls (SIEM, MFA, cloud logs)
- Hands-on GRC platform ownership (Secureframe/Vanta/Drata)
- Third-party risk program build and run experience
- Drive remediation deadlines with engineering/operations
What you'll do
- Run SOC 2/ISO 27001 compliance programs and audits
- Write and maintain security policies and procedures
- Assess and track vendor/third-party risk
- Maintain risk register and control mappings (NIST, CIS, ISO)
- Own customer/partner security assessments and RFPs
About Base
Base is America’s next-generation power company. We’re rebuilding the foundation of modern civilization–electricity–by deploying a vast network of distributed batteries that is transforming today’s fragile, centralized grid into a resilient and abundant system. We are engineers, operators, and creatives solving some of the most complex, interdisciplinary challenges of our time.
About the Role
We are seeking a GRC Analyst to help build and run Base’s security governance, risk, and compliance program as the company scales across software, hardware, manufacturing, field operations, and energy infrastructure. This role will sit on the Security team and help turn security requirements into practical, repeatable processes that support customer trust, regulatory readiness, and operational resilience.
The ideal candidate is detail-oriented, organized, and comfortable translating complex security and compliance requirements into clear action plans. This is an opportunity to make GRC more than a checkbox function, helping Base earn trust, reduce risk, and scale securely.
What You'll Do
Run Base's compliance programs (SOC 2, ISO 27001, etc.): evidence collection, control testing, and audit coordination
Write and maintain security policies and procedures
Assess and track vendor and third party risk
Maintain the risk register: identify, classify, and remediate risks
Support internal and external audits and evidence collection
Maintain control mapping against frameworks like NIST CSF, NIST 800-53, CIS Controls and ISO
Run periodic risk assessments across business units and systems
Own responses to customer and partner security assessments and RFPs
Take point on annual security awareness training
Coordinate requirements and deadlines across departments
What You'll Bring
3+ years in security compliance, IT audit, or GRC, including at least one SOC 2 cycle owned start to finish
Enough technical depth to judge a control yourself - read a SIEM configuration, an identity provider's MFA settings, or a cloud audit log and decide whether it holds up
Strong organizational and interpersonal skills to coordinate across teams and stakeholders
Hands-on ownership of a GRC platform — Secureframe, Vanta, Drata, or similar — including configuring integrations
Experience building and running a third-party risk program
Comfortable holding remediation deadlines with engineering or operations in a fast-moving environment
About the Team
GRC is a crucial function embedded in the Security team. This role will have a direct impact on the overall security posture of the company through industry frameworks and controls. Our team operates with clear accountability, tight feedback loops, and a strong bias to action.
Please note: Base is a startup, which means priorities shift and evolve quickly. Your role may expand or change based on the needs of the business at any given time, so the responsibilities listed may not be exhaustive.
Our Values
First Principles Thinking: Question assumptions. Principles > rules.
Operate at Base Pace: Focus on what matters, act quickly, and learn by doing.
Give & Get Feedback: Be direct, be humble, and maintain a growth mindset.
Everyone’s an Owner: Follow through on commitments and own results.
Strong Opinions, Loosely Held: Drive clarity and make calls with imperfect information.
Committed to the Mission: Rebuilding the grid is a big challenge. We work hard because we care deeply about the impact we’re creating. We work in-person. It’s not a 9-to-5. We are all-in.
Fun & Optimism Coexist with Grit: Collaboration and celebration coincide with the intensity of building real things.
Do the best work of your life at Base.
Optimize your resume for this job
Get a match score and the keywords you're missing
About Base Power Company
Base is building the future of American power. The grid is the largest, most complex machine in the world. But it’s aging, struggling to keep up with today’s demand, and is unprepared for our electrified future. Base is modernizing the grid as the first engineering-led, technology-driven power company. We’re deploying a nationwide network of distributed batteries that strengthens critical infrastructure and saves Americans money. Our team of engineers, operators, creatives, technicians, and electricians design and deploy systems at speed. If you want to tackle the problem that will define this century and shape the future of American energy, now is the time. Join us.
Similar Security roles


