GRC Analyst

Base Power Company

$90K — $110K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • 3+ years in security compliance, IT audit, or GRC with experience owning SOC 2 cycles
  • Technical understanding of SIEM configurations, MFA settings, and cloud audit logs
  • Strong organizational and interpersonal skills for team coordination
  • Experience managing GRC platforms like Secureframe, Vanta, or Drata
  • Proven ability to run a third-party risk program
  • Ability to enforce remediation deadlines in dynamic environments

Responsibilities

  • Run compliance programs such as SOC 2 and ISO 27001, including evidence collection and audit coordination
  • Write and maintain comprehensive security policies and procedures
  • Assess and monitor vendor and third-party risks
  • Maintain an updated risk register by identifying, classifying, and managing risks
  • Support internal and external audit processes and evidence documentation
  • Map controls against recognized frameworks like NIST CSF and ISO
  • Conduct recurring risk assessments across various business units and systems
  • Manage responses to partner security assessments and RFPs
  • Lead annual security awareness training initiatives
  • Coordinate compliance deadlines and requirements across departments

Benefits

  • Opportunity to shape the GRC framework beyond basic compliance
  • Impact on the company's overall security posture
  • Work within a highly accountable and action-oriented team environment
  • Engagement in a fast-paced startup culture where roles adapt to business needs
Full Job Description
About the Role

We are seeking a GRC Analyst to help build and run Base's security governance, risk, and compliance program as the company scales across software, hardware, manufacturing, field operations, and energy infrastructure. This role will sit on the Security team and help turn security requirements into practical, repeatable processes that support customer trust, regulatory readiness, and operational resilience.

The ideal candidate is detail-oriented, organized, and comfortable translating complex security and compliance requirements into clear action plans. This is an opportunity to make GRC more than a checkbox function, helping Base earn trust, reduce risk, and scale securely.

What You'll Do
  • Run Base's compliance programs (SOC 2, ISO 27001, etc.): evidence collection, control testing, and audit coordination
  • Write and maintain security policies and procedures
  • Assess and track vendor and third party risk
  • Maintain the risk register: identify, classify, and remediate risks
  • Support internal and external audits and evidence collection
  • Maintain control mapping against frameworks like NIST CSF, NIST 800-53, CIS Controls and ISO
  • Run periodic risk assessments across business units and systems
  • Own responses to customer and partner security assessments and RFPs
  • Take point on annual security awareness training
  • Coordinate requirements and deadlines across departments


What You'll Bring
  • 3+ years in security compliance, IT audit, or GRC, including at least one SOC 2 cycle owned start to finish
  • Enough technical depth to judge a control yourself - read a SIEM configuration, an identity provider's MFA settings, or a cloud audit log and decide whether it holds up
  • Strong organizational and interpersonal skills to coordinate across teams and stakeholders
  • Hands-on ownership of a GRC platform - Secureframe, Vanta, Drata, or similar - including configuring integrations
  • Experience building and running a third-party risk program
  • Comfortable holding remediation deadlines with engineering or operations in a fast-moving environment


About the Team

GRC is a crucial function embedded in the Security team. This role will have a direct impact on the overall security posture of the company through industry frameworks and controls. Our team operates with clear accountability, tight feedback loops, and a strong bias to action.

Please note: Base is a startup, which means priorities shift and evolve quickly. Your role may expand or change based on the needs of the business at any given time, so the responsibilities listed may not be exhaustive.

Similar Jobs

More Jobs at Base Power Company

More Information Technology Jobs

  • Reynolds & Reynolds
    Director of Engineering
    Reynolds & Reynolds
    North Andover, MA 01845 (Essex County)
  • Program Manager
    $225K — $275K *
    Edgewater Federal Solutions, Inc.
    La Canada Flintridge, CA 91011 (Los Angeles County)
  • Full Stack Python Developer
    $126K — $128K *
    Edgewater Federal Solutions, Inc.
    Washington, DC 20011 (District Of Columbia County)
  • Service Desk Technical Lead
    $175K — $225K *
    Edgewater Federal Solutions, Inc.
    La Canada Flintridge, CA 91011 (Los Angeles County)
  • Flexsteel Industries
    ServiceNow Architect
    $156K — $195K *
    Flexsteel Industries
    Washington, DC 20011 (District Of Columbia County)

Find similar GRC Analyst jobs: