TL
Taylor A. LaCass
Information Security & GRC Leader
Governance, Risk & Compliance|Security Strategy & Operations|Identity, Endpoint & Cloud Security
Executive Profile
Governance, risk, and compliance (GRC) leader and information security executive with 15+ years of experience across high-growth SaaS, regulated insurance, consumer finance, compliance, audit, and enterprise risk. Built and scaled a company's first formal information security, compliance, and enterprise risk program — governance structure, control model, risk lifecycle, and executive reporting — while leading enterprise IT across the US, Canada, UK, and Europe. Hands-on operator with depth across identity, endpoint, cloud and application security, incident readiness, resilience, and regulated-data protection. Known for translating material risk into practical controls that preserve speed, ownership, and customer trust.
Selected Projects
Security & GRC
Information Security & GRC Program — Built From Zero
Trove Recommerce, Inc.
Established the company's first formal information security and GRC (governance, risk & compliance) program for a high-growth SaaS platform serving global retail partners.
- Built the security operations foundation — detection and response, vulnerability management, and incident-response readiness — alongside the governance layer to run it.
- Defined governance structure, policy, control model, risk lifecycle, executive reporting, and remediation processes from the ground up.
- Unified SOC 2 Type II, PCI, GDPR/UK GDPR, and ISO 27001 requirements into one practical control set with accountable ownership.
- Extended governance and control alignment to acquired European operations and distributed service providers during expansion.
Enterprise IT
Enterprise IT Ownership & Scalable SaaS Deployment
Trove Recommerce, Inc.
Own enterprise IT end-to-end — scaling the organization onto SaaS platforms while cutting cost and shifting routine work to self-service.
- Own enterprise IT and internal-systems operations across the US, Canada, UK, and Europe — identity, device management, endpoint protection, and productivity platforms.
- Scaled SaaS platform deployment across a growing, distributed organization to support expansion without proportional headcount growth.
- Reduced IT operating costs through platform consolidation and vendor rationalization.
- Increased employee self-service through automation of onboarding, offboarding, and access requests, cutting manual IT ticket volume.
AI Governance
Enterprise AI Governance & Transformation
Trove Recommerce, Inc.
Directed company-wide adoption of AI tools and built the control layer to govern it — policy, enforcement, visibility, and cost.
- Directed enterprise-wide deployment of AI technologies across the organization.
- Established AI governance policy and cost controls for token spend and usage.
- Implemented AI usage controls at the network layer via Zscaler AI Guard.
- Extended DLP controls through Zscaler to cover AI tool usage.
- Centralized AI-related activity logging through CrowdStrike NG SIEM for visibility and investigation.
Accessibility
WCAG 2.1 AA Accessibility Program
Trove Recommerce — Platform-Wide, Multi-Partner
Full-journey accessibility audit process built for the platform and run across multiple retail-partner storefronts, covering browse, product, cart, and checkout.
- Assessed the complete purchase journey across each storefront rather than the homepage alone.
- Identified systemic, recurring issues across partner sites — including missing descriptive alt text on product imagery, broken heading hierarchy, and accordions missing aria-expanded.
- Findings set the baseline standard for future audits platform-wide: full purchase journey plus brand-specific flows, applied consistently across partners.
Privacy Operations
Data Subject Request Runbook & Deletion Workflow
Trove Recommerce, Inc.
Rebuilt the operational playbook for consumer privacy deletion requests across Security and Engineering.
- Documented a cross-team deletion workflow: Engineering supplies UUIDs, Security executes removal scripts.
- Established opt-out confirmation as a mandatory pre-deletion step.
- Published the consolidated runbook in Markdown, Confluence XML, and a branded Word document.
Risk & Integration
Third-Party & M&A Security Integration
Trove Recommerce — European Expansion
Brought newly acquired European operations and distributed service providers under a single security and control model.
- Managed third-party, partner, and new-market security risk as the company entered new geographies.
- Led technology consolidation and control alignment for acquired European operations.
Core Expertise
- Governance, Risk & Compliance (GRC)
- Security Strategy & Operating Models
- Executive Risk Reporting
- Third-Party Risk
- Business Continuity & Disaster Recovery
- Security Operations & Incident Response
- Identity & Access Management
- Endpoint Security
- Cloud & Application Security
- Vulnerability Management
- Enterprise IT Systems
- Employee Lifecycle
- Team & Provider Leadership
- AI Governance & Security
Technology & Frameworks
- SOC 2 Type II
- PCI
- HIPAA Alignment
- GDPR / UK GDPR
- ISO 27001
- NIST
- ITGC
- Vanta
- Okta
- Jamf
- Hexnode
- CrowdStrike Falcon
- Zscaler
- AWS
- Google Workspace
- Atlassian
Professional Experience
Trove Recommerce, Inc.
Director, IT, Information Security & Compliance
Jun 2021 – Present
Own cybersecurity, enterprise IT, compliance, and privacy for a high-growth SaaS platform supporting global retail partners.
- Built and scaled the company's first formal information security, compliance, and enterprise risk program, defining the strategy, roadmap, policies, control model, risk lifecycle, reporting, and remediation processes.
- Led the company's AI transformation, directing enterprise-wide deployment of AI technologies while establishing AI governance policy, security controls, and cost controls for token spend and usage.
- Own identity, endpoint, and internal-systems operations across the US, Canada, UK, and Europe, including Okta, device management, endpoint protection, productivity platforms, access governance, and employee onboarding and offboarding.
- Direct security operations spanning managed detection and response, SIEM, vulnerability management, penetration testing, incident-response readiness, investigations, escalation, and corrective-action tracking.
- Partner with engineering to strengthen AWS infrastructure, applications, APIs, development practices, and sensitive-data protections; review architecture and drive risk-based remediation without unnecessary product friction.
- Lead SOC 2 Type II, PCI, privacy, and customer-assurance programs and translate GDPR, UK GDPR, ISO 27001, contractual, and enterprise requirements into practical controls and accountable ownership.
- Strengthen operational resilience through business-continuity and disaster-recovery planning, backup validation, recovery procedures, incident playbooks, and recurring testing across critical systems.
- Manage third-party, partner, acquisition, and new-market security risk, including technology consolidation and control alignment for acquired European operations and distributed service providers.
- Make security a practical shared responsibility through clear control ownership, role-based awareness and training, repeatable guidance, and cross-functional remediation.
- Advise executives on material risk and security tradeoffs while leading a lean internal team and managed partners across security, GRC, IT engineering, and user support.
SafeAuto Insurance Company
Information Security Manager
Feb 2020 – Jun 2021
Led information-security risk, governance, and control operations in a regulated consumer insurance environment.
- Owned enterprise information-security risk and governance, aligning security priorities and remediation with legal, regulatory, and business requirements.
- Oversaw control assurance, monitoring, issue remediation, security awareness, and management reporting while partnering across technology and business teams.
- Reported security risk, incidents, control performance, and remediation status to management, improving visibility and accountability across regulated operations.
- Led security and GRC engineering personnel and coordinated internal and external stakeholders to improve control maturity and risk visibility.
IT Audit & Assurance Manager
Nov 2018 – Feb 2020
- Led IT audit, compliance, and risk activities, serving as the primary bridge between external auditors and internal technology and business teams.
- Managed evidence, response development, control assessments, issue resolution, and remediation tracking for IT-related external audits.
- Advanced PCI ROC readiness and IT-control maturity through risk-based reviews and implementation of proportionate mitigation measures; GRC scope also included ITGC audit readiness and COBIT audit readiness aligned with state regulators.
Lyons, Doughty & Veldhuis, P.C./P.A.
Operations & Compliance Manager
Aug 2017 – Nov 2018
Managed Ohio operations and compliance following the firm's acquisition of Cheek Law Offices.
- Led post-acquisition integration of processes, policies, controls, reporting, and compliance practices across regulated consumer-debt operations.
- Prepared client audit responses, led onsite-audit coordination, and improved performance through process-gap analysis, root-cause review, and remediation.
- Managed staff, production analysis, forecasting, and process improvement while maintaining operational continuity through the acquisition.
Cheek Law Offices, LLC
Compliance Manager
Nov 2012 – Aug 2017
- Served as the firm's first compliance manager, building its formal compliance management system, department, policies, procedures, controls, training, monitoring, and executive reporting.
- Conducted audits, investigations, risk assessments, and root-cause reviews; directed corrective and preventive actions across regulated operations.
- Designed employee training and translated FDCPA, FCRA, TCPA, GLBA, client, legal, and ethical requirements into repeatable operating controls.
- Reduced client-audit defects by more than 20% within the first year; operational performance later ranked first among 58 firms for the organization's largest client.
Paralegal
Sep 2009 – Nov 2012
- Supported high-volume consumer-debt litigation, built repeatable documentation and templates, and maintained working knowledge of FDCPA, FCRA, TCPA, and GLBA requirements.
Education
-
Master of Business Administration (MBA)
Concordia University – St. Paul
-
Graduate Certificate, Cyber Security Risk Management
Concordia University – St. Paul
-
Bachelor of Arts, Political Science & Economics
Capital University