SlipstreamJobsFresh Startup & VC-Backed Jobs

GRC Analyst

Base Power Company - Austin, TX, United States - In-office - posted 2026-09-22

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Base Power is rebuilding America's electricity infrastructure by deploying a distributed battery network to transform the centralized grid into a resilient and abundant system. The company is seeking a GRC Analyst to build and run Base's security governance, risk, and compliance program as it scales across software, hardware, manufacturing, field operations, and energy infrastructure. In this role, you will sit on the Security team and translate security requirements into practical, repeatable processes that support customer trust, regulatory readiness, and operational resilience. You will be responsible for running Base's compliance programs (SOC 2, ISO 27001, etc.), including evidence collection, control testing, and audit coordination. You will write and maintain security policies and procedures, assess and track vendor and third-party risk, and maintain the risk register by identifying, classifying, and remediating risks. Key responsibilities include supporting internal and external audits, maintaining control mapping against frameworks like NIST CSF, NIST 800-53, CIS Controls, and ISO standards, running periodic risk assessments across business units and systems, owning responses to customer and partner security assessments and RFPs, taking point on annual security awareness training, and coordinating requirements and deadlines across departments. Base operates with clear accountability, tight feedback loops, and a strong bias to action. The company values first-principles thinking, operating at pace, direct feedback, ownership, strong opinions loosely held, commitment to mission, and balancing grit with collaboration and celebration. Work is in-person and intensive, reflecting the company's all-in approach to rebuilding the grid. REQUIREMENTS: - 3+ years in security compliance, IT audit, or GRC, including at least one complete SOC 2 cycle owned start to finish - Technical depth to independently judge controls: ability to read SIEM configurations, identity provider MFA settings, or cloud audit logs and assess their effectiveness - Strong organizational and interpersonal skills to coordinate across teams and stakeholders - Hands-on experience with GRC platforms (Secureframe, Vanta, Drata, or similar), including configuring integrations - Experience building and running a third-party risk program - Ability to hold remediation deadlines with engineering or operations in a fast-moving environment

Similar roles