GRC Analyst

Base Power CompanyAustin, TX
Onsite

About The Position

Base is seeking a GRC Analyst to help build and run its security governance, risk, and compliance program as the company scales across software, hardware, manufacturing, field operations, and energy infrastructure. This role will sit on the Security team and help turn security requirements into practical, repeatable processes that support customer trust, regulatory readiness, and operational resilience. The ideal candidate is detail-oriented, organized, and comfortable translating complex security and compliance requirements into clear action plans. This is an opportunity to make GRC more than a checkbox function, helping Base earn trust, reduce risk, and scale securely.

Requirements

  • 3+ years in security compliance, IT audit, or GRC, including at least one SOC 2 cycle owned start to finish
  • Enough technical depth to judge a control yourself - read a SIEM configuration, an identity provider's MFA settings, or a cloud audit log and decide whether it holds up
  • Strong organizational and interpersonal skills to coordinate across teams and stakeholders
  • Hands-on ownership of a GRC platform — Secureframe, Vanta, Drata, or similar — including configuring integrations
  • Experience building and running a third-party risk program
  • Comfortable holding remediation deadlines with engineering or operations in a fast-moving environment

Responsibilities

  • Run Base's compliance programs (SOC 2, ISO 27001, etc.): evidence collection, control testing, and audit coordination
  • Write and maintain security policies and procedures
  • Assess and track vendor and third party risk
  • Maintain the risk register: identify, classify, and remediate risks
  • Support internal and external audits and evidence collection
  • Maintain control mapping against frameworks like NIST CSF, NIST 800-53, CIS Controls and ISO
  • Run periodic risk assessments across business units and systems
  • Own responses to customer and partner security assessments and RFPs
  • Take point on annual security awareness training
  • Coordinate requirements and deadlines across departments
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service