Overview
Basis is building the future by redesigning the electrical systems that power homes to fight climate change, reduce household costs, and create a better future. We need incredible people who are bold, creative, sharp, and thoughtful. We move fast and think differently.
The Role
We’re looking for a Security Architect to own and deliver our security strategy across both products and operations. This role is about building security by design and ensuring our platforms and internal systems are robust, resilient, and aligned with key compliance goals like SOC 2, ISO 27001, and IEC 62443. As a senior individual contributor, you’ll set the security blueprint, guide engineering and IT teams, and coordinate with external consultants to turn compliance requirements into practical, auditable controls. Reporting to the Head of Compliance, you’ll translate business risk tolerance into a clear, actionable security roadmap that keeps our products trusted and our operations safe.
Responsibilities you may be involved in include :
- Define and maintain Basis’ security architecture and roadmap, covering both product and operational domains.
- Own the security case, articulating scope, risk posture, and supporting evidence.
- Lead threat modelling and risk assessments to inform design and implementation.
- Guide and coordinate IT and operational security measures (identity & access, monitoring, incident response, staff training), working with IT Operations to ensure these are implemented effectively.
- Translate compliance goals (SOC 2, ISO 27001, IEC 62443) into actionable requirements for engineering and other teams.
- Coordinate and oversee penetration testing, vulnerability management, and vendor / third-party risk reviews.
- Support audit readiness by preparing evidence, documentation, and technical input alongside the Head of Compliance.
- Communicate risks, trade-offs, and mitigations in clear business terms to leadership.
About You
We think you’ll be a fit if you have the following skills or traits :
Background and experience in security architecture across IoT / embedded and cloud systems, ideally with an engineering or systems design foundation.Applied SOC 2, ISO 27001, and IEC 62443 (or similar frameworks) in real product and operational contexts.Experience with risk assessment, threat modeling, and security case development.Proven track record of working with external consultants (pen testing, audits, tooling) and embedding results into delivery.Strategic thinker able to design security roadmaps and balance risk with business priorities.Strong collaborator, credible with engineers and clear with leadership.Pragmatic and adaptable, comfortable in a startup / scale-up environment with resource constraints.Skilled communicator who can translate compliance requirements into engineering terms and explain risks in plain language.Research shows that women and other marginalised groups tend to apply only if they check every box, but we still want to hear from you if you think you have what it takes.
Benefits
A competitive salary and employee share scheme (ESOP)A hybrid work culture with a mix of office days and work-from-home daysUnlimited annual leaveTools of trade, including laptop and headphone allowanceFlexible hours focused on effort and outcomesRegular team events and activitiesOffice dogs and fresh fruit / snacksWell-being programme with 5x free psychology sessions per yearDiversity and inclusion commitments and related policiesParental leave policy with wage top-ups for primary and secondary caregiversLet’s Talk
We’d love to hear from you. No cover letter needed—click apply to answer a few short questions and attach your CV. If you have questions, email Steph at
#J-18808-Ljbffr