{"id":1120507,"url":"https://alion.io/job/base-power-company-grc-analyst","title":"GRC Analyst","company":{"id":5219,"name":"Base Power Company","domain":"basepower.com","url":"https://alion.io/company/base-power-company","size_band":null,"is_staffing_agency":false,"is_intermediary":false,"ats_vendor":"Ashby","truth_index":{"grade":"B","score":81,"open_postings":20,"ghost_share":0,"stale_share":0.55,"repost_share":0.05,"time_to_fill_p50_days":87,"computed_at":"2026-09-23T05:45:00Z"}},"role":"Security","role_family":"Security","seniority":"middle","employment_type":"full_time","work_mode":"on_site","remote_scope":null,"hiring_geo_confidence":"structured","locations":["Austin, United States"],"countries":["US"],"hiring_countries":[],"hiring_countries_total":0,"salary":null,"salary_estimate":{"min_usd":86000,"max_usd":177000,"period":"year","method":"role_seniority_country_remote_cell","sample_n":194},"experience_years_min":3,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"ISO 27001","optional":false},{"name":"NIST 800-53","optional":false},{"name":"NIST CSF","optional":false},{"name":"SIEM","optional":false},{"name":"SOC 2","optional":false}],"status":"live","first_seen_at":"2026-09-22T16:00:08Z","employer_posted_date":"2026-09-22","last_verified_at":"2026-09-24T01:06:36Z","board_verified":true,"closed_at":null,"days_open":1,"trust":{"level":"ok","repost_count":null,"flags":[],"days_open":1},"description":"About Base\nBase is America’s next-generation power company. We’re rebuilding the foundation of modern civilization-electricity-by deploying a vast network of distributed batteries that is transforming today’s fragile, centralized grid into a resilient and abundant system. We are engineers, operators, and creatives solving some of the most complex, interdisciplinary challenges of our time.\nAbout the Role\nWe are seeking a GRC Analyst to help build and run Base’s security governance, risk, and compliance program as the company scales across software, hardware, manufacturing, field operations, and energy infrastructure. This role will sit on the Security team and help turn security requirements into practical, repeatable processes that support customer trust, regulatory readiness, and operational resilience.\nThe ideal candidate is detail-oriented, organized, and comfortable translating complex security and compliance requirements into clear action plans. This is an opportunity to make GRC more than a checkbox function, helping Base earn trust, reduce risk, and scale securely.\nWhat You'll Do\nRun Base's compliance programs (SOC 2, ISO 27001, etc.): evidence collection, control testing, and audit coordination\n\nWrite and maintain security policies and procedures\n\nAssess and track vendor and third party risk\n\nMaintain the risk register: identify, classify, and remediate risks\n\nSupport internal and external audits and evidence collection\n\nMaintain control mapping against frameworks like NIST CSF, NIST 800-53, CIS Controls and ISO\n\nRun periodic risk assessments across business units and systems\n\nOwn responses to customer and partner security assessments and RFPs\n\nTake point on annual security awareness training\n\nCoordinate requirements and deadlines across departments\n\nWhat You'll Bring\n3+ years in security compliance, IT audit, or GRC, including at least one SOC 2 cycle owned start to finish\n\nEnough technical depth to judge a control yourself - read a SIEM configuration, an identity provider's MFA settings, or a cloud audit log and decide whether it holds up\n\nStrong organizational and interpersonal skills to coordinate across teams and stakeholders\n\nHands-on ownership of a GRC platform - Secureframe, Vanta, Drata, or similar - including configuring integrations\n\nExperience building and running a third-party risk program\n\nComfortable holding remediation deadlines with engineering or operations in a fast-moving environment\n\nAbout the Team\nGRC is a crucial function embedded in the Security team. This role will have a direct impact on the overall security posture of the company through industry frameworks and controls. Our team operates with clear accountability, tight feedback loops, and a strong bias to action.\nPlease note: Base is a startup, which means priorities shift and evolve quickly. Your role may expand or change based on the needs of the business at any given time, so the responsibilities listed may not be exhaustive.\nOur Values\nFirst Principles Thinking: Question assumptions. Principles > rules.\n\nOperate at Base Pace: Focus on what matters, act quickly, and learn by doing.\n\nGive & Get Feedback: Be direct, be humble, and maintain a growth mindset.\n\nEveryone’s an Owner: Follow through on commitments and own results.\n\nStrong Opinions, Loosely Held: Drive clarity and make calls with imperfect information.\n\nCommitted to the Mission: Rebuilding the grid is a big challenge. We work hard because we care deeply about the impact we’re creating. We work in-person. It’s not a 9-to-5. We are all-in.\n\nFun & Optimism Coexist with Grit: Collaboration and celebration coincide with the intensity of building real things.\n\nDo the best work of your life at Base.","description_format":"text","description_chars":3707,"description_truncated":false,"requirements":{"experience_years_min":3,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":null,"security_clearance":false,"languages":[]},"benefits":[],"hiring_locations":[],"hiring_excludes":[],"relocation_offered":false,"industries":["Energy & Utilities"],"lifecycle":[{"event":"open","at":"2026-09-22T18:56:00Z"}],"liveness":{"score":63,"band":"ok","label":"Likely open","p_open":1,"p_active":0.632,"p_room":1,"age_days":0,"expected_fill_days":87,"reasons":["conf:0","stale_co","velocity","win:early","comp:brand"],"computed_at":"2026-09-23T05:45:00Z"},"pay":null,"html_url":"https://alion.io/job/base-power-company-grc-analyst","json_url":"https://alion.io/job/base-power-company-grc-analyst.json","meta":{"generated_at":"2026-09-24T02:54:43Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers"}}