About this role
**GRC Analyst** **About Base** America's next-generation power company rebuilding the foundation of modern civilization through distributed battery networks and grid resilience. **About the Role** Help build and run Base's security governance, risk, and compliance program as the company scales. Turn security requirements into practical, repeatable processes that support customer trust, regulatory readiness, and operational resilience. **What You'll Do** • Run compliance programs (SOC 2, ISO 27001, etc.): evidence collection, control testing, audit coordination • Write and maintain security policies and procedures • Assess and track vendor and third-party risk • Maintain the risk register: identify, classify, and remediate risks • Support internal and external audits and evidence collection • Maintain control mapping against NIST CSF, NIST 800-53, CIS Controls, ISO • Run periodic risk assessments across business units and systems • Own responses to customer and partner security assessments and RFPs • Coordinate annual security awareness training • Coordinate requirements and deadlines across departments **What You'll Bring** • 3+ years in security compliance, IT audit, or GRC (including at least one complete SOC 2 cycle) • Technical depth to assess controls independently • Strong organizational and interpersonal skills • Hands-on GRC platform experience (Secureframe, Vanta, Drata, or similar) • Experience building and running third-party risk programs • Ability to hold remediation deadlines in a fast-moving environment **Note:** Startup environment means priorities shift quickly. Role may expand based on business needs.
Listing freshness
CronJobs last confirmed this listing 1h ago. If its source stops confirming the opening for seven days, this page is removed from active inventory.