Skip to main content
Trace3

Sr. Consultant | GRC/AI/Privacy (Remote)

RemoteUnited States only
Published
Role
Security
Experience
Senior
Employment
Full-time
Company size
Enterprise
$170k–$200k/yr
Check eligibility

Open to US only. Set where you work from to check your eligibility.

No BS summary

Senior GRC/Privacy and AI-governance consultant with 10–15+ years' experience advising C-level clients. Deep expertise with security and privacy frameworks (NIST, ISO, SOC2, PCI, GDPR) and operationalizing controls. Remote (US) or Atlanta, GA; ability to travel.

Core skills

GRCAI governancePrivacy

Required skills

NIST CSFNIST RMFNIST 800-53ISO 27001ISO 27005SOC 2PCI DSSHIPAAFFIECGLBASOXGDPRCMMC

Optional skills

PowerPointCISSPCISACISMCIPP

What you'll do

  • Lead complex GRC, security, privacy, risk, and AI engagements
  • Support the full sales cycle, including opportunity development, solution shaping, proposals, statements of work, level-of-effort estimates, and executive presentations
  • Facilitate client workshops to provide education and expertise with clients and executive stakeholders.
  • Assess current-state capabilities across people, process, and technology and define practical target states, priorities, dependencies, and implementation roadmaps.
  • Apply leading frameworks and regulations, including NIST CSF, NIST RMF, NIST 800-53, ISO 27001, ISO 27005, SOC 2, PCI DSS, HIPAA, FFIEC, GLBA, SOX, GDPR, and CMMC, as appropriate to the client environment.
  • Translate regulatory and security requirements into tailored control environments, governance models, policies, procedures, standards, guidelines, workflows, and measurable program objectives.
  • Oversee high-quality deliverables, including assessment reports, gap analyses, maturity models, risk registers, control mappings, executive briefings, strategic roadmaps, project plans, and operating-model recommendations.
  • Maintain trusted relationships with client sponsors, decision-makers, control owners, and partner teams.
  • Advise organizations on the governance, risk, security, privacy, and compliance implications of artificial intelligence, machine learning, generative AI, and agentic AI.
  • Monitor and inform the practice and its clients on emerging and applicable AI laws, regulations, regulatory guidance, standards, and contractual requirements, including the EU AI Act, U.S. federal and state developments, GDPR-related obligations, and sector-specific requirements.
  • Translate evolving AI requirements into practical policies, standards, controls, governance processes, evidence requirements, and implementation roadmaps.
  • Help define, mature, package, and operationalize Trace3’s GRC service portfolio and delivery methodologies.
  • Establish reusable approaches, templates, quality standards, and intellectual property that improve consistency, scalability, and client outcomes.
  • Serve as a senior GRC thought leader in client meetings, internal enablement sessions, industry events, partner activities, and published content.
  • Track GRC-adjacent technologies and build partnerships with solution/market leaders on capabilities across control management, trust centers, third-party risk management, risk management, privacy operations, and AI governance.

What they require

  • Bachelor’s degree from an accredited university required
  • Minimum of 10-15 years’ experience in security consulting
  • Minimum of 10-15 years’ experience in enterprise security
  • CISSP, CISA, CISM, CIPP or equivalent security or privacy certification strongly desired
  • Strong expertise in assessing the maturity of IT security programs and capabilities to identify a security program’s current state and establishing a roadmap for achieving a defined target state, which accounts for noted capability gaps and affiliated risks
  • Extensive knowledge in industry security and risk management frameworks/guidance (e.g., NIST CSF, ISO 27001, ISO 27005, NIST Risk Management Framework, etc.) and extensive experience implementing or assessing against them
  • Experience performing IT/IS risk, privacy, and control assessments based on leading practice and regulatory requirements (e.g., PCI, SOC2, GDPR, HIPAA)
  • Working knowledge of both industry best practices and regulatory/compliance landscape across common cybersecurity domains
  • Motivated self-starter who loves to solve challenging problems and feels comfortable working directly with customers
  • Excellent oral, written communication, and presentation skills with an ability to present client security sessions and security workshops to C-Level Executives and non-technical audience, advanced PowerPoint presentation skills strongly desired
  • Highly organized, detail-oriented, excellent time management skills, and able to effectively prioritize tasks in a fast-paced, high-volume, and evolving work environment
  • Ability to approach customer and sales requests with a proactive and consultative manner; listen and understand user requests and needs and effectively deliver
  • Comfortable managing multiple and changing priorities, and meeting deadlines in an entrepreneurial environment
  • Ability to travel when needed
  • Ability to travel when needed.

Benefits

  • Comprehensive medical, dental and vision plans for you and your dependents
  • 401(k) Retirement Plan with Employer Match
  • 529 College Savings Plan
  • Health Savings Account
  • Life Insurance
  • Long-Term Disability
  • Competitive Compensation
  • Training and development programs
  • Major offices stocked with snacks and beverages
  • Collaborative and cool culture
  • Work-life balance and generous paid time off

American information technology company and managed service provider

🇺🇸 United StatesIT ConsultingMid-sizetrace3.com
$170k–$200k/yr