8 days ago
Base Salary
$170k - $200k/yr
Responsibilities
- Lead complex GRC, security, privacy, risk, and AI governance engagements.
- Facilitate client workshops and provide education and expertise to executive stakeholders.
- Assess current-state people, process, and technology capabilities and define target states, priorities, dependencies, and implementation roadmaps.
- Apply relevant security frameworks and regulations to client environments.
- Translate regulatory and security requirements into controls, governance models, policies, procedures, standards, workflows, and measurable objectives.
- Oversee assessment reports, gap analyses, maturity models, risk registers, control mappings, executive briefings, strategic roadmaps, project plans, and operating-model recommendations.
- Build trusted relationships with client sponsors, decision-makers, control owners, and partner teams.
- Advise clients on the governance, risk, security, privacy, and compliance implications of artificial intelligence, machine learning, generative AI, and agentic AI.
- Monitor emerging AI laws, regulations, guidance, standards, and contractual requirements and translate them into practical governance and implementation roadmaps.
- Support opportunity development, solution shaping, proposals, statements of work, level-of-effort estimates, and executive presentations across the sales cycle.
- Help develop and operationalize Trace3’s GRC service portfolio, delivery methodologies, reusable templates, quality standards, and intellectual property.
- Serve as a senior GRC thought leader in client meetings, internal enablement, industry events, partner activities, and published content.
- Track GRC-adjacent technologies and build partnerships across control management, trust centers, third-party risk, risk management, privacy operations, and AI governance.
Requirements
- Bachelor’s degree from an accredited university is required.
- At least 10–15 years of experience in security consulting and enterprise security is required.
- CISSP, CISA, CISM, CIPP, or an equivalent security or privacy certification is strongly desired.
- Extensive expertise in security program maturity assessments, capability-gap identification, target-state definition, and roadmap development is required.
- Extensive knowledge and implementation or assessment experience with industry security and risk management frameworks is required.
- Experience performing IT/IS risk, privacy, and control assessments against leading practices and regulatory requirements is required.
- Working knowledge of cybersecurity best practices and regulatory/compliance landscapes is required.
- Excellent oral, written, communication, workshop facilitation, and executive presentation skills are required; advanced PowerPoint skills are strongly desired.
- Strong organization, attention to detail, time management, prioritization, and deadline management skills are required.
- A proactive, consultative approach to customer and sales requests is required.
- Ability to manage multiple changing priorities in a fast-paced environment is required.
- Ability to travel when needed is required.
Benefits
- Comprehensive medical, dental, and vision plans for employees and dependents.
- 401(k) with employer match, 529 College Savings Plan, Health Savings Account, Life Insurance, and Long-Term Disability.
- Training and development programs.
- Major offices stocked with snacks and beverages.
- Collaborative culture, work-life balance, and generous paid time off.
- Remote position with the ability to travel when needed.
Categories
Solutions Engineering
About Trace3
Trace3 delivers business transformation. We consult on, integrate, and operate convergent solutions across data, security, and cloud that embrace emerging technology and drive measurable business value for our clients.
