
Solution Architect – GRC
Posted Aug 5

Posted Aug 5
This is a fully remote position, open to applicants in Texas.
• Lead intricate GRC, security, privacy, risk, and AI initiatives.
• Facilitate workshops for clients and executive stakeholders.
• Evaluate current capabilities across personnel, processes, and technology to define target states, priorities, dependencies, and implementation roadmaps.
• Apply security and risk frameworks and regulations such as NIST CSF, NIST RMF, NIST 800-53, ISO 27001, ISO 27005, SOC 2, PCI DSS, HIPAA, FFIEC, GLBA, SOX, GDPR, and CMMC.
• Convert regulatory and security requirements into customized control environments, governance models, policies, procedures, standards, guidelines, workflows, and measurable objectives.
• Supervise assessment reports, gap analyses, maturity models, risk registers, control mappings, executive briefings, strategic roadmaps, project plans, and recommendations for operating models.
• Foster trusted relationships with client sponsors, decision-makers, control owners, and partner teams.
• Provide guidance to organizations on governance, risk, security, privacy, and compliance implications of AI, machine learning, generative AI, and agentic AI.
• Keep abreast of emerging AI laws, regulations, guidance, standards, and contractual obligations.
• Transform evolving AI requirements into policies, standards, controls, governance processes, evidence requirements, and implementation roadmaps.
• Assist in defining, maturing, packaging, and operationalizing Trace3’s GRC service portfolio and delivery methodologies.
• Develop reusable approaches, templates, quality standards, and intellectual property.
• Act as a senior GRC thought leader in client meetings, internal enablement sessions, industry events, partner activities, and published materials.
• Monitor GRC-adjacent technologies and establish partnerships with solution and market leaders.
• Bachelor’s degree from an accredited university is required.
• At least 10–15 years of experience in security consulting.
• A minimum of 10–15 years of experience in enterprise security.
• CISSP, CISA, CISM, CIPP, or equivalent security or privacy certification is highly preferred.
• Strong expertise in assessing IT security program maturity and defining target-state roadmaps.
• Extensive knowledge of security and risk management frameworks, including NIST CSF, ISO 27001, ISO 27005, and NIST Risk Management Framework.
• Significant experience implementing or assessing compliance with security and risk management frameworks.
• Experience conducting IT/IS risk, privacy, and control assessments based on best practices and regulatory requirements, including PCI, SOC 2, GDPR, and HIPAA.
• Working knowledge of cybersecurity industry best practices and the regulatory/compliance landscape.
• Comfortable engaging directly with customers.
• Excellent oral, written communication, and presentation skills.
• Ability to present security sessions and workshops to C-level executives and non-technical audiences.
• Advanced PowerPoint presentation skills are strongly desired.
• Highly organized, detail-oriented, and capable of managing time and priorities in a fast-paced environment.
• Ability to take a proactive and consultative approach to customer and sales requests.
• Comfortable managing multiple and shifting priorities while meeting deadlines.
• Willingness to travel as necessary.
• Comprehensive medical, dental, and vision plans for you and your dependents.
• 401(k) Retirement Plan with Employer Match.
• 529 College Savings Plan.
• Health Savings Account.
• Life Insurance.
• Long-Term Disability.
• Competitive Compensation.
• Training and development programs.
• Major offices stocked with snacks and beverages.
• Collaborative and engaging culture.
• Work-life balance and generous paid time off.
Snowflake
Cisco
BCD Travel
Get handpicked remote jobs straight to your inbox weekly.