Impress employers and recruiters.
Choose from hundreds of resume examples.

Impress employers and recruiters.
Choose from hundreds of resume examples.
Tailor your resume to this GRC Analyst role.
Rezi rewrites your resume against Base Power Company's job description. Free.

Tailor your resume to this GRC Analyst role.
Rezi rewrites your resume against Base Power Company's job description. Free.
Don't guess if your resume is good enough.
See how it scores against the GRC Analyst posting at Base Power Company — free, in seconds.

Don't guess if your resume is good enough.
See how it scores against the GRC Analyst posting at Base Power Company — free, in seconds.
About the Role
We are seeking a GRC Analyst to help build and run Base’s security governance, risk, and compliance program as the company scales across software, hardware, manufacturing, field operations, and energy infrastructure. This role will sit on the Security team and help turn security requirements into practical, repeatable processes that support customer trust, regulatory readiness, and operational resilience. The ideal candidate is detail-oriented, organized, and comfortable translating complex security and compliance requirements into clear action plans. This is an opportunity to make GRC more than a checkbox function, helping Base earn trust, reduce risk, and scale securely.
Responsibilities
- Run Base's compliance programs (SOC 2, ISO 27001, etc.): evidence collection, control testing, and audit coordination
- Write and maintain security policies and procedures
- Assess and track vendor and third party risk
- Maintain the risk register: identify, classify, and remediate risks
- Support internal and external audits and evidence collection
- Maintain control mapping against frameworks like NIST CSF, NIST 800-53, CIS Controls and ISO
- Run periodic risk assessments across business units and systems
- Own responses to customer and partner security assessments and RFPs
- Take point on annual security awareness training
- Coordinate requirements and deadlines across departments
Requirements
- 3+ years in security compliance, IT audit, or GRC, including at least one SOC 2 cycle owned start to finish
- Enough technical depth to judge a control yourself - read a SIEM configuration, an identity provider's MFA settings, or a cloud audit log and decide whether it holds up
- Strong organizational and interpersonal skills to coordinate across teams and stakeholders
- Hands-on ownership of a GRC platform — Secureframe, Vanta, Drata, or similar — including configuring integrations
- Experience building and running a third-party risk program
- Comfortable holding remediation deadlines with engineering or operations in a fast-moving environment
Location
- In-person
Work Type
- Full-time
Experience Level
- 3+ years
About the Company
- Base is America’s next-generation power company. We’re rebuilding the foundation of modern civilization–electricity–by deploying a vast network of distributed batteries that is transforming today’s fragile, centralized grid into a resilient and abundant system. We are engineers, operators, and creatives solving some of the most complex, interdisciplinary challenges of our time.