1

Security Privacy Risk Management Consultant Jobs

Privacy & Disclosure-Risk Analyst

Mclean, VA ยท On-site

$83K - $99K/yr

The Privacy & Disclosure-Risk Analyst will analyze testing results, assess the potential impact of ... risk management guidance Qualifications * Ability to obtain and maintain a government security ...

Privacy & Disclosure-Risk Analyst

Mclean, VA ยท On-site

$85K - $101K/yr

The Privacy & Disclosure-Risk Analyst will analyze testing results, assess the potential impact of ... risk management guidance Qualifications * Ability to obtain and maintain a government security ...

Privacy & Disclosure-Risk Analyst

Mclean, VA ยท On-site

$83K - $99K/yr

We are seeking a Privacy & Disclosure-Risk Analyst responsible for evaluating privacy and data ... risk management guidance * Ability to obtain and maintain a government security clearance

Privacy & Disclosure-Risk Analyst

Bloomington, IL ยท On-site

$78K - $93K/yr

The Privacy & Disclosure-Risk Analyst will analyze testing results, assess the potential impact of ... risk management guidance Qualifications * Ability to obtain and maintain a government security ...

Privacy & Disclosure-Risk Analyst

Mclean, VA ยท On-site

$83K - $99K/yr

The Privacy & Disclosure-Risk Analyst will analyze testing results, assess the potential impact of ... risk management guidance Qualifications * Ability to obtain and maintain a government security ...

next page

Showing results 1-20

Security Privacy Risk Management Consultant information

See salary details

$71K

$117.3K

$151K

How much do security privacy risk management consultant jobs pay per year?

As of Sep 10, 2026, the average yearly pay for security privacy risk management consultant in the United States is $117,293.00, according to ZipRecruiter salary data. Most workers in this role earn between $80,000.00 and $150,000.00 per year, depending on experience, location, and employer.

What cities are hiring for Security Privacy Risk Management Consultant jobs?

Cities with the most Security Privacy Risk Management Consultant job openings:

What are popular job titles related to Security Privacy Risk Management Consultant jobs?

For Security Privacy Risk Management Consultant jobs, the most frequently searched job titles are:

Infographic showing various Security Privacy Risk Management Consultant job openings in the United States as of September 2026, with employment types broken down into 1% As Needed, 84% Full Time, 13% Part Time, and 2% Contract. Highlights an 86% Physical, 2% Hybrid, and 12% Remote job distribution, with an average salary of $117,293 per year, or $56.4 per hour.

Sr. Consultant | GRC/AI/Privacy (Remote)

Dallas, TX โ€ข Remote

Trace3
1 - 5K employees

Full-time

Re-posted 5 days ago


Job description

JOB SUMMARY:

The Solutions Architect, Governance, Risk, & Compliance, is a client-facing practice expert who combines delivery experience, GRC subject-matter expertise, and thought leadership on the security best practices and programs for Trace3 clients. This role leads complex consulting engagements, advises CIOs, CISOs, risk leaders, privacy leaders, and other executive stakeholders, and helps clients establish resilient, scalable, and compliant security programs.

The Solution Architect, GRC, will provide education and direction on security, risk, privacy, resilience, technologies, compliance, and AI governance. The role also supports the full sales cycle, including opportunity development, solution shaping, proposals, statements of work, level-of-effort estimates, and executive presentations. A key function of this role will be to build deep relationships, gain trust, and enable client success.

SUMMARY OF ESSENTIAL JOB FUNCTIONS:

  • Lead complex GRC, security, privacy, risk, and AI engagements
  • Facilitate client workshops to provide education and expertise with clients and executive stakeholders.
  • Assess current-state capabilities across people, process, and technology and define practical target states, priorities, dependencies, and implementation roadmaps.
  • Apply leading frameworks and regulations, including NIST CSF, NIST RMF, NIST 800-53, ISO 27001, ISO 27005, SOC 2, PCI DSS, HIPAA, FFIEC, GLBA, SOX, GDPR, and CMMC, as appropriate to the client environment.
  • Translate regulatory and security requirements into tailored control environments, governance models, policies, procedures, standards, guidelines, workflows, and measurable program objectives.
  • Oversee high-quality deliverables, including assessment reports, gap analyses, maturity models, risk registers, control mappings, executive briefings, strategic roadmaps, project plans, and operating-model recommendations.
  • Maintain trusted relationships with client sponsors, decision-makers, control owners, and partner teams.
  • Advise organizations on the governance, risk, security, privacy, and compliance implications of artificial intelligence, machine learning, generative AI, and agentic AI.
  • Monitor and inform the practice and its clients on emerging and applicable AI laws, regulations, regulatory guidance, standards, and contractual requirements, including the EU AI Act, U.S. federal and state developments, GDPR-related obligations, and sector-specific requirements.
  • Translate evolving AI requirements into practical policies, standards, controls, governance processes, evidence requirements, and implementation roadmaps.
  • Help define, mature, package, and operationalize Trace3's GRC service portfolio and delivery methodologies.
  • Establish reusable approaches, templates, quality standards, and intellectual property that improve consistency, scalability, and client outcomes.
  • Serve as a senior GRC thought leader in client meetings, internal enablement sessions, industry events, partner activities, and published content.
  • Track GRC-adjacent technologies and build partnerships with solution/market leaders on capabilities across control management, trust centers, third-party risk management, risk management, privacy operations, and AI governance.

REQUIRED SKILLS AND EXPERIENCE:

  • Bachelor's degree from an accredited university required
  • Minimum of 10-15 years' experience in security consulting
  • Minimum of 10-15 years' experience in enterprise security
  • CISSP, CISA, CISM, CIPP or equivalent security or privacy certification strongly desired
  • Strong expertise in assessing the maturity of IT security programs and capabilities to identify a security program's current state and establishing a roadmap for achieving a defined target state, which accounts for noted capability gaps and affiliated risks
  • Extensive knowledge in industry security and risk management frameworks/guidance (e.g., NIST CSF, ISO 27001, ISO 27005, NIST Risk Management Framework, etc.) and extensive experience implementing or assessing against them
  • Experience performing IT/IS risk, privacy, and control assessments based on leading practice and regulatory requirements (e.g., PCI, SOC2, GDPR, HIPAA)
  • Working knowledge of both industry best practices and regulatory/compliance landscape across common cybersecurity domains
  • Motivated self-starter who loves to solve challenging problems and feels comfortable working directly with customers
  • Excellent oral, written communication, and presentation skills with an ability to present client security sessions and security workshops to C-Level Executives and non-technical audience, advanced PowerPoint presentation skills strongly desired
  • Highly organized, detail-oriented, excellent time management skills, and able to effectively prioritize tasks in a fast-paced, high-volume, and evolving work environment
  • Ability to approach customer and sales requests with a proactive and consultative manner; listen and understand user requests and needs and effectively deliver
  • Comfortable managing multiple and changing priorities, and meeting deadlines in an entrepreneurial environment
  • Ability to travel when needed