Taylor A. LaCass

Information Security & GRC Leader

Governance, Risk & Compliance|Security Strategy & Operations|Identity, Endpoint & Cloud Security

Executive Profile

Governance, risk, and compliance (GRC) leader and information security executive with 15+ years of experience across high-growth SaaS, regulated insurance, consumer finance, compliance, audit, and enterprise risk. Built and scaled a company's first formal information security, compliance, and enterprise risk program — governance structure, control model, risk lifecycle, and executive reporting — while leading enterprise IT across the US, Canada, UK, and Europe. Hands-on operator with depth across identity, endpoint, cloud and application security, incident readiness, resilience, and regulated-data protection. Known for translating material risk into practical controls that preserve speed, ownership, and customer trust.

Selected Projects

Security & GRC

Information Security & GRC Program — Built From Zero

Trove Recommerce, Inc.

Established the company's first formal information security and GRC (governance, risk & compliance) program for a high-growth SaaS platform serving global retail partners.

  • Built the security operations foundation — detection and response, vulnerability management, and incident-response readiness — alongside the governance layer to run it.
  • Defined governance structure, policy, control model, risk lifecycle, executive reporting, and remediation processes from the ground up.
  • Unified SOC 2 Type II, PCI, GDPR/UK GDPR, and ISO 27001 requirements into one practical control set with accountable ownership.
  • Extended governance and control alignment to acquired European operations and distributed service providers during expansion.
Enterprise IT

Enterprise IT Ownership & Scalable SaaS Deployment

Trove Recommerce, Inc.

Own enterprise IT end-to-end — scaling the organization onto SaaS platforms while cutting cost and shifting routine work to self-service.

  • Own enterprise IT and internal-systems operations across the US, Canada, UK, and Europe — identity, device management, endpoint protection, and productivity platforms.
  • Scaled SaaS platform deployment across a growing, distributed organization to support expansion without proportional headcount growth.
  • Reduced IT operating costs through platform consolidation and vendor rationalization.
  • Increased employee self-service through automation of onboarding, offboarding, and access requests, cutting manual IT ticket volume.
AI Governance

Enterprise AI Governance & Transformation

Trove Recommerce, Inc.

Directed company-wide adoption of AI tools and built the control layer to govern it — policy, enforcement, visibility, and cost.

  • Directed enterprise-wide deployment of AI technologies across the organization.
  • Established AI governance policy and cost controls for token spend and usage.
  • Implemented AI usage controls at the network layer via Zscaler AI Guard.
  • Extended DLP controls through Zscaler to cover AI tool usage.
  • Centralized AI-related activity logging through CrowdStrike NG SIEM for visibility and investigation.
Accessibility

WCAG 2.1 AA Accessibility Program

Trove Recommerce — Platform-Wide, Multi-Partner

Full-journey accessibility audit process built for the platform and run across multiple retail-partner storefronts, covering browse, product, cart, and checkout.

  • Assessed the complete purchase journey across each storefront rather than the homepage alone.
  • Identified systemic, recurring issues across partner sites — including missing descriptive alt text on product imagery, broken heading hierarchy, and accordions missing aria-expanded.
  • Findings set the baseline standard for future audits platform-wide: full purchase journey plus brand-specific flows, applied consistently across partners.
Privacy Operations

Data Subject Request Runbook & Deletion Workflow

Trove Recommerce, Inc.

Rebuilt the operational playbook for consumer privacy deletion requests across Security and Engineering.

  • Documented a cross-team deletion workflow: Engineering supplies UUIDs, Security executes removal scripts.
  • Established opt-out confirmation as a mandatory pre-deletion step.
  • Published the consolidated runbook in Markdown, Confluence XML, and a branded Word document.
Risk & Integration

Third-Party & M&A Security Integration

Trove Recommerce — European Expansion

Brought newly acquired European operations and distributed service providers under a single security and control model.

  • Managed third-party, partner, and new-market security risk as the company entered new geographies.
  • Led technology consolidation and control alignment for acquired European operations.

Core Expertise

Technology & Frameworks

Professional Experience

Trove Recommerce, Inc.
Director, IT, Information Security & Compliance Jun 2021 – Present

Own cybersecurity, enterprise IT, compliance, and privacy for a high-growth SaaS platform supporting global retail partners.

  • Built and scaled the company's first formal information security, compliance, and enterprise risk program, defining the strategy, roadmap, policies, control model, risk lifecycle, reporting, and remediation processes.
  • Led the company's AI transformation, directing enterprise-wide deployment of AI technologies while establishing AI governance policy, security controls, and cost controls for token spend and usage.
  • Own identity, endpoint, and internal-systems operations across the US, Canada, UK, and Europe, including Okta, device management, endpoint protection, productivity platforms, access governance, and employee onboarding and offboarding.
  • Direct security operations spanning managed detection and response, SIEM, vulnerability management, penetration testing, incident-response readiness, investigations, escalation, and corrective-action tracking.
  • Partner with engineering to strengthen AWS infrastructure, applications, APIs, development practices, and sensitive-data protections; review architecture and drive risk-based remediation without unnecessary product friction.
  • Lead SOC 2 Type II, PCI, privacy, and customer-assurance programs and translate GDPR, UK GDPR, ISO 27001, contractual, and enterprise requirements into practical controls and accountable ownership.
  • Strengthen operational resilience through business-continuity and disaster-recovery planning, backup validation, recovery procedures, incident playbooks, and recurring testing across critical systems.
  • Manage third-party, partner, acquisition, and new-market security risk, including technology consolidation and control alignment for acquired European operations and distributed service providers.
  • Make security a practical shared responsibility through clear control ownership, role-based awareness and training, repeatable guidance, and cross-functional remediation.
  • Advise executives on material risk and security tradeoffs while leading a lean internal team and managed partners across security, GRC, IT engineering, and user support.
SafeAuto Insurance Company
Information Security Manager Feb 2020 – Jun 2021

Led information-security risk, governance, and control operations in a regulated consumer insurance environment.

  • Owned enterprise information-security risk and governance, aligning security priorities and remediation with legal, regulatory, and business requirements.
  • Oversaw control assurance, monitoring, issue remediation, security awareness, and management reporting while partnering across technology and business teams.
  • Reported security risk, incidents, control performance, and remediation status to management, improving visibility and accountability across regulated operations.
  • Led security and GRC engineering personnel and coordinated internal and external stakeholders to improve control maturity and risk visibility.
IT Audit & Assurance Manager Nov 2018 – Feb 2020
  • Led IT audit, compliance, and risk activities, serving as the primary bridge between external auditors and internal technology and business teams.
  • Managed evidence, response development, control assessments, issue resolution, and remediation tracking for IT-related external audits.
  • Advanced PCI ROC readiness and IT-control maturity through risk-based reviews and implementation of proportionate mitigation measures; GRC scope also included ITGC audit readiness and COBIT audit readiness aligned with state regulators.
Lyons, Doughty & Veldhuis, P.C./P.A.
Operations & Compliance Manager Aug 2017 – Nov 2018

Managed Ohio operations and compliance following the firm's acquisition of Cheek Law Offices.

  • Led post-acquisition integration of processes, policies, controls, reporting, and compliance practices across regulated consumer-debt operations.
  • Prepared client audit responses, led onsite-audit coordination, and improved performance through process-gap analysis, root-cause review, and remediation.
  • Managed staff, production analysis, forecasting, and process improvement while maintaining operational continuity through the acquisition.
Cheek Law Offices, LLC
Compliance Manager Nov 2012 – Aug 2017
  • Served as the firm's first compliance manager, building its formal compliance management system, department, policies, procedures, controls, training, monitoring, and executive reporting.
  • Conducted audits, investigations, risk assessments, and root-cause reviews; directed corrective and preventive actions across regulated operations.
  • Designed employee training and translated FDCPA, FCRA, TCPA, GLBA, client, legal, and ethical requirements into repeatable operating controls.
  • Reduced client-audit defects by more than 20% within the first year; operational performance later ranked first among 58 firms for the organization's largest client.
Paralegal Sep 2009 – Nov 2012
  • Supported high-volume consumer-debt litigation, built repeatable documentation and templates, and maintained working knowledge of FDCPA, FCRA, TCPA, and GLBA requirements.

Education

Contact

Open to conversations on security, compliance, and systems leadership.

Reach out directly — I respond fastest by email.