Security Architect

About Us
At Basis, we’re not just building a company — we’re building the future. We’re redesigning the electrical systems that power our homes to fight climate change, reduce household costs, and create a better future for generations to come. That means rethinking everything, not just what we build, but how we build it.
To do this, we need incredible people. People who are bold, creative, sharp, and thoughtful. People who care. People who move fast and think differently. That’s where you come in.
The Role
We’re looking for a Security Architect to own and deliver our security strategy across both products and operations. This role is all about building security by design and ensuring our platforms and internal systems are robust, resilient, and aligned with key compliance goals like SOC 2, ISO 27001, and IEC 62443.
As a senior individual contributor, you’ll set the security blueprint, guide engineering and IT teams, and coordinate with external consultants to turn compliance requirements into practical, auditable controls. Reporting to the Head of Compliance, you’ll play a pivotal role in translating business risk tolerance into a clear, actionable security roadmap that keeps our products trusted and our operations safe.
Some of the things that you might be involved in include:
- Define and maintain Basis’ security architecture and roadmap, covering both product and operational domains.
- Own the security case, articulating scope, risk posture, and supporting evidence.
- Lead threat modelling and risk assessments to inform design and implementation.
- Guide and coordinate IT and operational security measures (identity & access, monitoring, incident response, staff training), working with IT Operations to ensure these are implemented effectively.
- Translate compliance goals (SOC 2, ISO 27001, IEC 62443) into actionable requirements for engineering and other teams.
- Coordinate and oversee penetration testing, vulnerability management, and vendor/third-party risk reviews.
- Support audit readiness by preparing evidence, documentation, and technical input alongside the Head of Compliance.
- Communicate risks, trade-offs, and mitigations in clear business terms to leadership.
This is a senior role for someone who is credible, adept at managing stakeholder relationships, and has proven experience delivering real outcomes. We are a small, scrappy start-up which means we need someone willing to roll up their sleeves and get stuck into making our products secure help our engineers and wider teams drive real value to our customers.
About You
We think you’ll be a fit for this role if you have the following skills/or traits:
- Background and experience in security architecture across IoT/embedded and cloud systems, ideally with an engineering or systems design foundation.
- Applied SOC 2, ISO 27001, and IEC 62443 (or similar frameworks) in real product and operational contexts.
- Experience with risk assessment, threat modeling, and security case development.
- Proven track record of working with external consultants (pen testing, audits, tooling) and embedding results into delivery.
- Strategic thinker able to design security roadmaps and balance risk with business priorities.
- Strong collaborator, credible with engineers and clear with leadership.
- Pragmatic and adaptable, comfortable in a startup/scale-up environment with resource constraints.
- Skilled communicator - can translate compliance requirements into engineering terms and explain risks in plain language.
Research shows that while men apply for jobs when they meet ~ 60% of the job criteria, women and other marginalised groups tend to apply only when they check every box. So if you think you have what it takes, but are not sure you check every box, we still want to hear from you 🙌
Benefits
- A competitive salary and employee share scheme (ESOP)
- A hybrid work culture with a mixture of office days for collaborating with your team, and work from home days for deep focus
- Unlimited annual leave so that you can take the time that you need to re-energise
- Tools of trade, including laptop and headphone allowance
- Flexible hours - we focus on effort and outcomes, so adjust your hours around your children, hobbies, or other commitments
- A schedule of fun team events throughout the year (Lego Battlebots, table tennis, themed Friday drinks, and more!)
- Office dogs + steady supply of fresh fruit and snacks in the office
- Access to Clearhead, our well-being programme which gives you 5x free sessions with a psychologist per year
- A commitment to diversity and inclusion: Pride Committee and partnering with Pride Pledge, DEIB Committee, EEO Policy and well-being strategy!
- Parental leave policy that tops up wages to 100% for the primary caregiver for up to 22 weeks and up to 6 weeks for secondary caregivers (conditions apply)
- The opportunity to learn and develop from some of the best and brightest minds in the industry!
Let's Talk!
We’d love to hear from you! No need to submit a cover letter - just click 'apply' to answer a few short questions of ours (we find this gives us more insight) and attach your CV.
If you have any questions about the role, fire them over to Steph at talent@wearebasis.com
- Department
- Engineering
- Role
- Risk and Compliance
- Locations
- Auckland
- Remote status
- Hybrid
- Employment type
- Full-time
- Hybrid - Office/WFH
- Yes