About Base
Base is America’s next-generation power company. We’re rebuilding the foundation of modern civilization–electricity–by deploying a vast network of distributed batteries that is transforming today’s fragile, centralized grid into a resilient and abundant system. We are engineers, operators, and creatives solving some of the most complex, interdisciplinary challenges of our time.
About the Role
We are seeking Software Engineers to build the Identity Provider and Authorization platform that decides who — and what — can access Base's systems.
Base runs on a growing mix of internal apps, cloud infrastructure, and machines that all need to authenticate and authorize safely: employees signing into AWS and GCP, services talking to each other, and devices proving their own identity in the field. This role will own the platform layer that turns fragmented, ad hoc access into a single, auditable identity system.
You will design the core primitives for identity and access: workforce SSO, cloud federation, entitlements-as-code, and workload identity backed by a governed PKI. The ideal candidate is a hands-on engineer who takes security-critical systems seriously, moves fast without cutting corners on least privilege, and can turn a still-forming scope into durable infrastructure other engineers build on.
What You'll Do
Build and operate Okta as Base's workforce identity provider — SSO, SAML/OIDC app integrations, SCIM provisioning, and joiner/mover/leaver lifecycle automation.
Design authentication policy (MFA, device assurance) and authorization primitives (RBAC, least-privilege role catalog, break-glass access) that other teams can safely build on.
Federate cloud access through AWS IAM Identity Center and GCP Workforce Identity Federation, replacing long-lived IAM users and service-account keys with short-lived credentials.
Define and maintain entitlements-as-code: every role, group mapping, and access grant lives in the GitOps monorepo as a reviewable pull request.
Build workload and headless identity infrastructure — private CA/PKI, AWS Roles Anywhere, GCP WIF-X509, and hardware-backed key custody (Secure Enclave, TPM, YubiKey).
Define Identity Assurance Level requirements, per NIST SP 800-63-3, for internal, partner, and service-to-service access.
Partner with IT, security, and application teams to keep identity, groups, and tokens as the shared foundation, while apps continue to own their own authorization business logic.
What You'll Bring
Strong backend engineering experience in Go, Java, or a similar systems language.
Experience designing or operating identity systems — SSO/IdP, authn/authz, entitlements, or workload identity.
Working knowledge of OIDC, SAML, and SCIM, and judgment about when to use each.
Comfort with cryptographic identity primitives — PKI, mTLS, or hardware-backed keys.
High ownership, clear communication, and comfort making durable technical decisions in ambiguous, fast-moving environments, including scope that's still being defined.
About the Team
The Identity Provider and Authorization team decides who — and what — can access Base's systems. We build and operate the workforce identity provider, federate access to cloud and internal infrastructure, define entitlements as code, and issue workload identity from a single governed PKI.
Our scope spans internal and partner access today, with customer-facing (CIAM) and fine-grained ABAC still being scoped, plus the service-to-service and headless identity that keeps Base's growing fleet of software and devices secure. Application teams own their own authorization business logic — we supply the identity, groups, and tokens they build on.
This is a rare opportunity to build the identity layer for one of the fastest-scaling energy companies in the country, from close to zero.
Please note: Base is a startup, which means priorities shift and evolve quickly. Your role may expand or change based on the needs of the business at any given time, so the responsibilities listed may not be exhaustive.
Our Values
First Principles Thinking: Question assumptions. Principles > rules.
Operate at Base Pace: Focus on what matters, act quickly, and learn by doing.
Give & Get Feedback: Be direct, be humble, and maintain a growth mindset.
Everyone’s an Owner: Follow through on commitments and own results.
Strong Opinions, Loosely Held: Drive clarity and make calls with imperfect information.
Committed to the Mission: Rebuilding the grid is a big challenge. We work hard because we care deeply about the impact we’re creating. We work in-person. It’s not a 9-to-5. We are all-in.
Fun & Optimism Coexist with Grit: Collaboration and celebration coincide with the intensity of building real things.