Trace3 · Dallas, TX

Solution Architect | GRC (Remote) at Trace3 — Dallas, TX

Full-timeDallas, TX$170,000–$200,000/yearPosted 2026-08-05Apply on Greenhouse

Full job description

Who is Trace3?

Come Join Us!

Teamwork - Humble, Hungry and Smart

JOB SUMMARY:

The Solutions Architect, Governance, Risk, & Compliance, is a client-facing practice expert who combines delivery experience, GRC subject-matter expertise, and thought leadership on the security best practices and programs for Trace3 clients. This role leads complex consulting engagements, advises CIOs, CISOs, risk leaders, privacy leaders, and other executive stakeholders, and helps clients establish resilient, scalable, and compliant security programs.

The Solution Architect, GRC, will provide education and direction on security, risk, privacy, resilience, technologies, compliance, and AI governance. The role also supports the full sales cycle, including opportunity development, solution shaping, proposals, statements of work, level-of-effort estimates, and executive presentations. A key function of this role will be to build deep relationships, gain trust, and enable client success.

SUMMARY OF ESSENTIAL JOB FUNCTIONS:

  • Lead complex GRC, security, privacy, risk, and AI engagements
  • Facilitate client workshops to provide education and expertise with clients and executive stakeholders.
  • Assess current-state capabilities across people, process, and technology and define practical target states, priorities, dependencies, and implementation roadmaps.
  • Apply leading frameworks and regulations, including NIST CSF, NIST RMF, NIST 800-53, ISO 27001, ISO 27005, SOC 2, PCI DSS, HIPAA, FFIEC, GLBA, SOX, GDPR, and CMMC, as appropriate to the client environment.
  • Translate regulatory and security requirements into tailored control environments, governance models, policies, procedures, standards, guidelines, workflows, and measurable program objectives.
  • Oversee high-quality deliverables, including assessment reports, gap analyses, maturity models, risk registers, control mappings, executive briefings, strategic roadmaps, project plans, and operating-model recommendations.
  • Maintain trusted relationships with client sponsors, decision-makers, control owners, and partner teams.
  • Advise organizations on the governance, risk, security, privacy, and compliance implications of artificial intelligence, machine learning, generative AI, and agentic AI.
  • Monitor and inform the practice and its clients on emerging and applicable AI laws, regulations, regulatory guidance, standards, and contractual requirements, including the EU AI Act, U.S. federal and state developments, GDPR-related obligations, and sector-specific requirements.
  • Translate evolving AI requirements into practical policies, standards, controls, governance processes, evidence requirements, and implementation roadmaps.
  • Help define, mature, package, and operationalize Trace3’s GRC service portfolio and delivery methodologies.
  • Establish reusable approaches, templates, quality standards, and intellectual property that improve consistency, scalability, and client outcomes.
  • Serve as a senior GRC thought leader in client meetings, internal enablement sessions, industry events, partner activities, and published content.
  • Track GRC-adjacent technologies and build partnerships with solution/market leaders on capabilities across control management, trust centers, third-party risk management, risk management, privacy operations, and AI governance.

REQUIRED SKILLS AND EXPERIENCE:

  • Bachelor’s degree from an accredited university required
  • Minimum of 10-15 years’ experience in security consulting
  • Minimum of 10-15 years’ experience in enterprise security
  • CISSP, CISA, CISM, CIPP or equivalent security or privacy certification strongly desired
  • Strong expertise in assessing the maturity of IT security programs and capabilities to identify a security program’s current state and establishing a roadmap for achieving a defined target state, which accounts for noted capability gaps and affiliated risks
  • Extensive knowledge in industry security and risk management frameworks/guidance (e.g., NIST CSF, ISO 27001, ISO 27005, NIST Risk Management Framework, etc.) and extensive experience implementing or assessing against them
  • Experience performing IT/IS risk, privacy, and control assessments based on leading practice and regulatory requirements (e.g., PCI, SOC2, GDPR, HIPAA)
  • Working knowledge of both industry best practices and regulatory/compliance landscape across common cybersecurity domains
  • Motivated self-starter who loves to solve challenging problems and feels comfortable working directly with customers
  • Excellent oral, written communication, and presentation skills with an ability to present client security sessions and security workshops to C-Level Executives and non-technical audience, advanced PowerPoint presentation skills strongly desired
  • Highly organized, detail-oriented, excellent time management skills, and able to effectively prioritize tasks in a fast-paced, high-volume, and evolving work environment
  • Ability to approach customer and sales requests with a proactive and consultative manner; listen and understand user requests and needs and effectively deliver
  • Comfortable managing multiple and changing priorities, and meeting deadlines in an entrepreneurial environment
  • Ability to travel when needed

Estimated Pay Range

$170,000—$200,000 USD

The Perks

  • Comprehensive medical, dental and vision plans for you and your dependents
  • 401(k) Retirement Plan with Employer Match, 529 College Savings Plan, Health Savings Account, Life Insurance, and Long-Term Disability
  • Competitive Compensation
  • Training and development programs
  • Major offices stocked with snacks and beverages
  • Collaborative and cool culture
  • Work-life balance and generous paid time off

Our Commitment

If you require a reasonable accommodation to complete the application process or participate in an interview, please email recruiting@trace3.com.

***To all recruitment agencies: Trace3 does not accept unsolicited agency resumes/CVs. Please do not forward resumes/CVs to our careers email addresses, Trace3 employees or any other company location. Trace3 is not responsible for any fees related to unsolicited resumes/CVs.

Required skills

  • generative ai
  • delivery
  • teamwork
  • artificial intelligence
  • machine learning
  • time management
  • communication
  • hipaa
  • sales
  • sox