Sobre este puesto de Solution Architect | GRC (Remote) en Trace3

Who is Trace3?
Trace3 is a leading Transformative IT Authority, providing unique technology solutions and consulting services to our clients. Equipped with elite engineering and dynamic innovation, we empower IT executives and their organizations to achieve competitive advantage through a process of Integrate, Automate, Innovate.
Our culture at Trace3 embodies the spirit of a startup with the advantage of a scalable business. Employees can grow their career and have fun while doing it!
Trace3 is headquartered in Irvine, California. We employ more than 1,200 people all over the United States. Our major field office locations include Denver, Indianapolis, Grand Rapids, Lexington, Los Angeles, Louisville, Texas, San Francisco.
Ready to discover the possibilities that live in technology?
Come Join Us!
Street-Smart - Thriving in Dynamic Times
We are flexible and resilient in a fast-changing environment. We continuously innovate and drive constructive change while keeping a focus on the “big picture.” We exercise sound business judgment in making high-quality decisions in a timely and cost-effective manner. We are highly creative and can dig deep within ourselves to find positive solutions to different problems.
Juice - The “Stuff” it takes to be a Needle Mover
We get things done and drive results. We lead without a title, empowering others through a can-do attitude. We look forward to the goal, mentally mapping out every checkpoint on the pathway to success, and visualizing what the final destination looks and feels like.
Teamwork - Humble, Hungry and Smart
We are humble individuals who understand how our job impacts the company's mission. We treat others with respect, admit mistakes, give credit where it’s due and demonstrate transparency. We “bring the weather” by exhibiting positive leadership and solution-focused thinking. We hug people in their trials, struggles, and failures – not just their success. We appreciate the individuality of the people around us.
JOB SUMMARY:
The Solutions Architect, Governance, Risk, & Compliance, is a client-facing practice expert who combines delivery experience, GRC subject-matter expertise, and thought leadership on the security best practices and programs for Trace3 clients. This role leads complex consulting engagements, advises CIOs, CISOs, risk leaders, privacy leaders, and other executive stakeholders, and helps clients establish resilient, scalable, and compliant security programs.
The Solution Architect, GRC, will provide education and direction on security, risk, privacy, resilience, technologies, compliance, and AI governance. The role also supports the full sales cycle, including opportunity development, solution shaping, proposals, statements of work, level-of-effort estimates, and executive presentations. A key function of this role will be to build deep relationships, gain trust, and enable client success.
SUMMARY OF ESSENTIAL JOB FUNCTIONS:
- Lead complex GRC, security, privacy, risk, and AI engagements
- Facilitate client workshops to provide education and expertise with clients and executive stakeholders.
- Assess current-state capabilities across people, process, and technology and define practical target states, priorities, dependencies, and implementation roadmaps.
- Apply leading frameworks and regulations, including NIST CSF, NIST RMF, NIST 800-53, ISO 27001, ISO 27005, SOC 2, PCI DSS, HIPAA, FFIEC, GLBA, SOX, GDPR, and CMMC, as appropriate to the client environment.
- Translate regulatory and security requirements into tailored control environments, governance models, policies, procedures, standards, guidelines, workflows, and measurable program objectives.
- Oversee high-quality deliverables, including assessment reports, gap analyses, maturity models, risk registers, control mappings, executive briefings, strategic roadmaps, project plans, and operating-model recommendations.
- Maintain trusted relationships with client sponsors, decision-makers, control owners, and partner teams.
- Advise organizations on the governance, risk, security, privacy, and compliance implications of artificial intelligence, machine learning, generative AI, and agentic AI.
- Monitor and inform the practice and its clients on emerging and applicable AI laws, regulations, regulatory guidance, standards, and contractual requirements, including the EU AI Act, U.S. federal and state developments, GDPR-related obligations, and sector-specific requirements.
- Translate evolving AI requirements into practical policies, standards, controls, governance processes, evidence requirements, and implementation roadmaps.
- Help define, mature, package, and operationalize Trace3’s GRC service portfolio and delivery methodologies.
- Establish reusable approaches, templates, quality standards, and intellectual property that improve consistency, scalability, and client outcomes.
- Serve as a senior GRC thought leader in client meetings, internal enablement sessions, industry events, partner activities, and published content.
- Track GRC-adjacent technologies and build partnerships with solution/market leaders on capabilities across control management, trust centers, third-party risk management, risk management, privacy operations, and AI governance.
REQUIRED SKILLS AND EXPERIENCE:
- Bachelor’s degree from an accredited university required
- Minimum of 10-15 years’ experience in security consulting
- Minimum of 10-15 years’ experience in enterprise security
- CISSP, CISA, CISM, CIPP or equivalent security or privacy certification strongly desired
- Strong expertise in assessing the maturity of IT security programs and capabilities to identify a security program’s current state and establishing a roadmap for achieving a defined target state, which accounts for noted capability gaps and affiliated risks
- Extensive knowledge in industry security and risk management frameworks/guidance (e.g., NIST CSF, ISO 27001, ISO 27005, NIST Risk Management Framework, etc.) and extensive experience implementing or assessing against them
- Experience performing IT/IS risk, privacy, and control assessments based on leading practice and regulatory requirements (e.g., PCI, SOC2, GDPR, HIPAA)
- Working knowledge of both industry best practices and regulatory/compliance landscape across common cybersecurity domains
- Motivated self-starter who loves to solve challenging problems and feels comfortable working directly with customers
- Excellent oral, written communication, and presentation skills with an ability to present client security sessions and security workshops to C-Level Executives and non-technical audience, advanced PowerPoint presentation skills strongly desired
- Highly organized, detail-oriented, excellent time management skills, and able to effectively prioritize tasks in a fast-paced, high-volume, and evolving work environment
- Ability to approach customer and sales requests with a proactive and consultative manner; listen and understand user requests and needs and effectively deliver
- Comfortable managing multiple and changing priorities, and meeting deadlines in an entrepreneurial environment
- Ability to travel when needed
The Perks
- Comprehensive medical, dental and vision plans for you and your dependents
- 401(k) Retirement Plan with Employer Match, 529 College Savings Plan, Health Savings Account, Life Insurance, and Long-Term Disability
- Competitive Compensation
- Training and development programs
- Major offices stocked with snacks and beverages
- Collaborative and cool culture
- Work-life balance and generous paid time off
Our Commitment
At the core of Trace3's DNA is our people. We are a diverse group of talented individuals who understand the importance of teamwork and demonstrating leadership, character, and passion in all that we do.
We’re committed to fostering an inclusive workplace where everyone feels respected, valued, and empowered to grow. We recognize that embracing diversity drives innovation, improves outcomes, fosters collaboration, boosts teammate satisfaction, and builds a more inclusive culture.
As an equal opportunity employer, Trace3 bases all employment decisions based on individual qualifications, merit, and business requirements. We do not engage in discrimination on the basis of race, color, religion, sex (including gender identity, sexual orientation, and pregnancy), national origin, age (40 or older), disability, genetic information, or any other characteristic protected by federal, state, or local law.
Any demographic information provided is strictly voluntary, kept confidential in accordance with Equal Employment Opportunity (EEO) regulations, and will not be used in employment decisions, including hiring, promotions, or mentorship programs. We are committed to providing equal employment opportunities for all.
If you require a reasonable accommodation to complete the application process or participate in an interview, please email [email protected].
***To all recruitment agencies: Trace3 does not accept unsolicited agency resumes/CVs. Please do not forward resumes/CVs to our careers email addresses, Trace3 employees or any other company location. Trace3 is not responsible for any fees related to unsolicited resumes/CVs.