Senior Manager, Cyber Strategy and Risk Advisory, TPRM
In a world of disruption and increasingly complex business challenges, our professionals bring truth into focus with the Kroll Lens. Our sharp analytical skills, paired with the latest technology, allow us to give our clients clarity—not just answers - in all areas of business. We value the diverse backgrounds and perspectives that enable us to think globally. As part of One team, One Kroll , you’ll contribute to a supportive and collaborative work environment that empowers you to excel.
Through a combination of subject matter expertise, global research capabilities and flexible technology tools, Kroll helps clients take a risk-based approach toward meeting obligations or remediating failures regarding cybersecurity, privacy program maturity and related regulatory mandates. Our engagements include Virtual CISO, regulatory and compliance assessments, strategies and security program design, transactional due-diligence, data-driven framework design and assessments, expert testimony, privacy program building and a myriad of other advisory efforts.
Kroll's Cyber Advisory practice is seeking a Senior Manager to support the continued growth of our Cyber Advisory business, with a primary focus on Third-Party Risk Management (TPRM), cyber risk assessments, governance, resilience, and security program advisory services.
The successful candidate will be a trusted advisor to clients, leading TPRM and cyber risk engagements, supporting executive stakeholders, delivering high-quality advisory services, and helping clients strengthen their security posture, resilience, and regulatory readiness.
This role combines client delivery, project leadership, people management, service development and business development support within Kroll's broader Cyber Advisory practice.
RESPONSIBILITIES:
Kroll’s Cyber Risk team works on over 3,000 cases a year, including some of the most complex and highest profile matters in the world. With experts based around the world, supported by ground-breaking technology, we help protect our client’s data, people, operations and reputation with innovative assessments, investigations and intelligence. We are the only company in the world with the expertise and resources to deliver global, end-to-end cyber risk management, supporting organizations through every step of their journey toward cyber resilience.
We are looking for bright, inquisitive minds who are experienced in and passionate about cybersecurity consulting and advisory services. Our Advisory team responds to our clients’ needs and provide leadership and strategic guidance when and where it is needed the most.
Own delivery and operational performance for managed TPRM programs, including assessment throughput, service level adherence, quality assurance, remediation tracking, client satisfaction, and continuous improvement initiatives.
Support the delivery of high-quality cybersecurity consulting advice and services to a portfolio of clients of varying sectors, size, scope, and complexity.
Lead delivery of cyber-focused Third-Party Risk Management (TPRM) / Managed TPRM engagements across multiple industries and client segments.
Design, assess, and optimize Third-Party Risk Management operating models, governance structures, policies, standards, lifecycle processes, risk-tiering methodologies, and managed service delivery frameworks. Conduct supplier cyber risk assessments, vendor due diligence reviews, and third-party security evaluations.
Assess third-party cybersecurity controls against leading frameworks and industry standards.
Conduct cybersecurity due diligence assessments for mergers, acquisitions, carve-outs, divestitures, and private equity transactions, evaluating cyber risk exposures, operational dependencies, and remediation requirements.
Leverage and advise clients on TPRM, GRC, continuous monitoring, and cyber risk platforms including ServiceNow, Archer, OneTrust, ProcessUnity, Panorays, Black Kite, BitSight, Interos.AI, and similar technologies.
Design assessment workflows, questionnaire rationalization approaches, control mappings, evidence collection processes, and automated risk-scoring methodologies.
Support clients in aligning TPRM programs with evolving regulatory requirements and operational resilience expectations.
Develop executive reporting, board-level dashboards, key risk indicators (KRIs), quantitative risk metrics, portfolio-wide benchmarking, and management reporting that translates technical findings into business, operational, financial, and regulatory impacts.
Lead cybersecurity risk assessments, security program reviews, cyber maturity assessments, and gap analyses.
Assess client environments against frameworks including NIST CSF, ISO 27001, CIS Controls, FFIEC, NYDFS, SOC 2, and other applicable standards.
Develop and enhance cyber risk management frameworks, governance models, policies, standards, procedures, and data-driven risk management processes while providing practical guidance for implementation and operationalization. Help clients identify, prioritize, and remediate cyber and technology risks through practical risk reduction roadmaps.
Support security strategy, operating model design, and cyber transformation initiatives.
Lead supplier resilience, concentration-risk, dependency mapping, fourth-party risk, recovery preparedness, and operational resilience assessments, helping organizations align cyber risk management activities with broader business continuity objectives.
Facilitate workshops with business, technology, security, risk, and resilience stakeholders.
Act as day-to-day engagement lead across multiple client projects.
Manage project teams, workplans, budgets, timelines, deliverables, and quality assurance activities.
Develop trusted client relationships and serve as a key point of contact during engagements.
Support development of proposals, statements of work, and client presentations.
Identify opportunities to expand client relationships across Kroll's broader Cyber Risk and Advisory offerings.
Support creation of thought leadership, market-facing content, and industry presentations.
Mentor, coach, and support junior consultants and managers.
Contribute to methodology development, quality assurance, and practice growth initiatives.
Analyze threat intelligence, attack surface monitoring, security ratings, continuous monitoring data, and assessment results to identify emerging risks, prioritize remediation activities, and support executive decision-making.
Assess risks related to artificial intelligence, generative AI, machine learning, and emerging technologies, including governance, data protection, model risk management, and responsible AI practices.
Effectively communicate findings, reports, training and strategies to technical staff, executive leadership, legal counsel, and to both internal and external clients.
Work with sales and marketing teams to support the development of new business opportunities.
QUALIFICATIONS:
Experience designing, implementing, optimizing, or administering TPRM, GRC, continuous monitoring, or cyber risk management platforms.
Significant experience in cybersecurity consulting, third-party risk management, technology risk, information security, operational resilience, or related advisory services.
Strong experience designing, assessing, implementing, or managing Third-Party Risk Management programs and managed services.
Experience conducting cyber risk assessments, supplier security reviews, or technology risk assessments.
Working knowledge of cybersecurity frameworks and regulatory requirements including NIST CSF, NIST 800-171, ISO 27001, CIS Controls, PCI DSS, HIPAA Security Rule, SOC 2, FFIEC, NYDFS, SEC Cybersecurity Rules, DORA, NIS2, and related global regulations.
Understanding of supplier cyber risk, cloud risk, concentration risk, vendor governance, and resilience concepts.
Experience presenting findings and recommendations to senior client stakeholders.
Ability to manage multiple engagements simultaneously while maintaining quality and client satisfaction.
Experience leading project teams and mentoring junior staff.
Commercially minded with experience supporting proposals, business development, and account growth activities.
Professional qualifications and/or proven experience in IT/ Information Security, TPRM, GRC / Risk Management, Vulnerability Management, Incident Response, and/or Regulatory Compliance roles.
Demonstrated ability to analyze large datasets, develop risk models, create management reporting dashboards, and derive actionable risk insights using tools such as Excel, Tableau, Power BI, SQL, Python, or comparable analytics platforms.
Good knowledge of the security threat landscape, control frameworks and cyber resilience strategies.
Demonstrated ability to design pragmatic risk management, governance, and resilience solutions leveraging people, process, data, and technology.
Strong written and verbal communication and presentation skills, teamwork, and client relationship skills.
Experience in client-facing roles and experience in engaging with senior stakeholders in organizations (desirable but not mandatory).
Experience in high-quality delivery to tight timescales.
Ability to multi-task, prioritize, and manage time effectively.
Experience working with diverse teams
Ability to travel up to 25% as required
Above all, the ideal candidate combines strong cybersecurity knowledge with practical experience managing third-party risk and advising clients on governance, resilience, and risk management challenges.
Successful candidates will be comfortable operating between detailed assessment activities and executive-level discussions, helping clients translate cyber risks into prioritized business actions. They will bring a collaborative approach, strong client-facing skills, and a desire to contribute to the continued growth of Kroll's Cyber Advisory practice.
Healthcare Coverage: Comprehensive medical, dental, and vision plans.
Time Off and Leave Policies: Generous paid time off (PTO), paid company holidays, generous parental and family leave.
Protective Insurances: Life insurance, short- and long-term disability coverage, and accident protection.
Compensation and Rewards: Competitive salary structures, performance-based incentives, and merit-based compensation reviews.
Retirement Plans: 401(k) plans with company matching.
Please note that benefits may vary by region, department and role. We encourage you to speak with your recruiter to learn more about the specific benefits available for your position.
About Kroll
Join the global leader in risk and financial advisory solutions—Kroll. With a nearly century-long legacy, we blend trusted expertise with cutting-edge technology to navigate and redefine industry complexities. As a part of One Team, One Kroll, you'll contribute to a collaborative and empowering environment, propelling your career to new heights. Ready to build, protect, restore and maximize our clients’ value? Your journey begins with Kroll.
We are proud to be an equal opportunity employer and will consider all qualified applicants regardless of gender, gender identity, race, religion, color, nationality, ethnic origin, sexual orientation, marital status, veteran status, age or disability.
#LI-CN1
#LI-Remote
- ...helps clients take a risk-based approach toward... ...compliance assessments, strategies and security program... ...a myriad of other advisory efforts.Kroll's Cyber Advisory practice is seeking a Senior Manager to support the continued... ...Risk Management (TPRM), cyber risk assessments...CyberSeniorRiskTemporary workFlexible hours
$193.5k - $227.7k
...is excited to hire a Cybersecurity - Senior Manager to deliver on full lifecycle Cyber projects for various industries, which may involve strategy & roadmap development, security... ...controls reviews & remediation/hardening, risk advisory, compliance assessments, resiliency...CyberSeniorRiskLocal areaImmediate startFlexible hours2 days per week1 day per week$163.4k - $322.1k
Position Summary Cyber Senior Manager / Senior Manager, Strategy, Growth, and Transformation Are you interested in improving the cyber and organizational risk profiles of leading companies? Do you want to be involved in delivering Cyber services including identifying...CyberSeniorRiskLocal areaVisa sponsorship- ...you to excel.Kroll’s Cyber Risk team works on over 3,0... ...intelligence, and strategic advisory services. Through a... ...assessments, strategies and security program design... ...mature security programs, manage cyber risk, improve... ...Security Director, vCISO, or senior cybersecurity...CyberRiskFull timeTemporary workFlexible hours
$130k - $150k
...About Teneo Teneo is the global CEO advisory firm. We partner with our clients... ...team and expansive network of senior advisors, we provide advisory services... ...transactions and restructuring, management consulting, physical and cyber risk, organizational design, board and...CyberSeniorRiskWork experience placementWork at officeFlexible hours$119k - $193k
...currently looking for a Senior Analyst to conduct... ...strategic advice for risk management leaders and their teams... ...knowledge and expertise in cyber risk quantification;... ..., and business strategy. Expertise in compliance... ...sessions, and custom advisory for risk leaders across...CyberSeniorRiskFull timeFor contractorsRemote work$175k - $300k
The RoleAs a Senior Cyber Broker within Willis’ FINEX practice... ...advice on cyber risk transfer solutions.The... ...and achieve their risk management objectives. This role... ...ResponsibilitiesClient Advisory & Relationship ManagementServe... ..., and renewal strategies. Develop and maintain...CyberSeniorRiskTemporary workLocal areaVisa sponsorshipWork visaFlexible hours$130k - $175k
DescriptionKforce has a client that is seeking a Senior Manager - Risk Advisory in New York, NY.Requirements* Bachelor's degree in relevant discipline (e.g., Accounting, Finance, Statistics, Data Analytics, Auditing, or related field) required* Professional Certification...SeniorRisk- ...Kroll’s Cyber Threat Intelligence (CTI) team... ...experienced Senior Director, Cyber Threat... ...intelligence advisory function embedded... ...for building and managing a team of Embedded... ...dependency for this growth strategy is the integration... ...strategic cyber risk discussions with...CyberSeniorRisk
$90.4k - $168.2k
...KPMG provides audit, tax and advisory services for organizations... ...is currently seeking a Senior Associate, Cyber Operations to join our Enterprise... ...tasks such as incident management, threat hunting, forensic analysis... ...to events and developing risk severity level and...CyberSeniorRiskH1bLocal area$90k - $200k
...Solutions professionals within our Cyber & Data Resilience service... ...s long‑standing expertise in risk, investigations, and complex... ...skilled and experienced Senior Manager with deep eDiscovery expertise... ...leader in risk and financial advisory solutions. With a nearly century...CyberSeniorRiskShift work$110.7k - $218.3k
Position Summary Senior Consultant -... ...Enterprise Operations & Risk Our Deloitte... ...workstreamsAbility to manage and prioritize... ...organization and impact strategy, operations,... ...in a consulting, advisory, or professional services... ...Services Act, Cyber Resilience Act,...CyberSeniorRiskLocal areaVisa sponsorship$163.4k - $322.1k
...strategic consulting, advisory, and delivery... ...case and incident management, and physical security... ...Physical Security Senior Manager works with... ...integrated, risk-based security programs... ...physical security strategy, operating model... ...othersThe teamDeloitte’s Cyber Defense &...CyberSeniorRiskLocal areaVisa sponsorship$105.4k - $207.8k
...Join Deloitte’s Cloud Cyber Risk practice and help organizations... ...As a Cloud Architect, Senior Consultant, you will... ...cloud security strategy, designing secure architectures... ...help organizations manage cyber risk while... ...risk. The team provides advisory and implementation...CyberSeniorRiskLocal areaVisa sponsorship$190.9k - $254.6k
Procurement Senior Manager - Third Party Risk Strategy Job ID: 110961 Atlanta Connecticut - Darien Denver London Miramar New Jersey... ...for shaping and advancing a unified, end-to-end TPRM framework that supports a diverse and global third-party...SeniorRiskHourly payApprenticeshipWork at office- ...a firm. KPMG is currently seeking a Manager or Senior Manager to join our Tax practice. Responsibilities... ...: Provide tax compliance and advisory services to corporations and operating... ...tax service and advice Manage risk and financial performance of engagements...SeniorRiskFull timeLocal area
$104.8k - $192.2k
...and emerging technologies. As a Senior Consultant within EY's Cyber Strategy practice, you will work with clients... ...opportunities to strengthen risk management and governance, and develop practical... ..., professional services, or advisory environment.Knowledge of regulated...CyberSeniorRiskSummer holidayFlexible hours$163.4k - $322.1k
...Join Deloitte’s Cloud Cyber Risk practice and help organizations... ...As a Cloud Security Architect, Senior Manager, you will advise clients on cloud security strategy, architecture, implementation,... ...cyber risk. The team provides advisory and implementation services that...CyberSeniorRiskLocal areaVisa sponsorship$125.8k - $209.7k
...security, governance, and risk management challenges.... ...to AI technologies. As a Senior Consultant within EY’s Cyber practice focused on AI Security... ...implementation work with strategic advisory and architecture... ...prioritized remediation strategies. You will architect and...CyberSeniorRiskImmediate start$150k - $200k
...International is posting for a Senior Manager, Digital Delivery &... ...companies apply cyber-physical solutions that... ..., operating across strategy and execution. Assignments... ...management oversight, advisory, facilities management... ..., dependencies, and risk mitigation strategies...CyberSeniorRiskWorldwide- ...Job Description Job Description The Third-Party Risk Management (TPRM) Senior Analyst is responsible for supporting the effective execution of the TPRM program by ensuring adherence to all phases of the third-party lifecycle. The role focuses on coordination, documentation...SeniorRiskContract workFlexible hours
$150k
...topics including Tech Advisory and Delivery, Architecture... ..., and Technology Risk Management. Our Tech Advisory and... ...to change transforming strategies into leading-edge tech... ...DoAs a Cybersecurity Senior AI Tech Consultant, you... ...architectures.Utilizing cyber risk quantification to...CyberSeniorRiskWork at officeLocal area$100k - $200k
...Senior Resource Manager New York, United States About Teneo Teneo is the global CEO advisory firm. We partner with our clients globally to do... ...consulting, physical and cyber risk, organizational design,... ...center of how Teneo's U.S. Strategy & Communications...CyberSeniorRiskWork at officeFlexible hours3 days per week$120k - $150k
...design, and implement risk-aware security solutions... ...delivering strategic advisory services across cyber risk, governance,... ...compliant AI adoption strategies. Our team helps organizations manage AI-related risks, strengthen... ...the Job As a Senior Consultant within Capco...CyberSeniorRiskFull time$150.4k - $343.6k
...a highly experienced Senior Manager to serve as a lead technical... ...with strategic advisory capabilities to help organizations... ...against traditional cyber threats and emerging... ...security strategies.Your Key ResponsibilitiesInfrastructure... ..., and operational risks.AI-Driven Threat...CyberSeniorRiskSummer holidayFlexible hours$168.75k - $200k
...getting started.Join us to put AI to work for people.Armis from ServiceNow, protects the entire attack surface and manages an organization’s cyber risk exposure in real time. Combined with ServiceNow’s Security and Risk capabilities, as well as Identity Security capabilities...CyberSeniorRiskWork at officeImmediate startRemote workFlexible hours$164k - $242k
...work at the crossroads of cyber security, operational... ...cybersecurity risks, designing and launching... ...partner who goes beyond advisory work to roll up your sleeves... ...complex security issues, manage multiple tasks, and... ...mitigation, isolation or other strategies to protect critical...CyberSeniorRiskPermanent employmentFull timeTemporary workCasual workWork at officeRemote workFlexible hours$158k - $250k
...capabilities spanning strategy, transformation and operational... ...of its UK Leading Management Consultants rankings,... ...Managers & Senior Managers to join the team... ...chain strategyFinance & Risk - financial performance... ...transformation, and commercial advisory topics.Proven ability...SeniorRiskTemporary workLocal areaFlexible hours$105.4k - $207.8k
...AI Security Senior ConsultantOur Deloitte Cyber team understands the... ...powerful solutions and managed services that simplify... ...Senior Consultant, Strategy, Growth & Transformation... ...mitigate/monitor the risks of adopting AI... ...will combine client advisory with structured cyber...CyberSeniorRiskLocal areaWorldwideVisa sponsorship$204.8k - $425.5k
...world.The Cybersecurity Senior Manager (SM2) is responsible for driving strategic cyber solution development,... ...address complex cyber risks while identifying... ...Develop account growth strategies and opportunity roadmaps... ...opportunities.Client Advisory & Transformation LeadershipServe...CyberSeniorRiskContract workSummer holidayImmediate startFlexible hours
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Senior Manager, Cyber Strategy and Risk Advisory, TPRM. Be the first to apply!
- brand strategy manager New York, NY
- director product strategy New York, NY
- director of strategic alliances New York, NY
- sales excellence & strategy manager New York, NY
- strategic planning director New York, NY
- group strategy director New York, NY
- director strategy & business development New York, NY
- strategic director New York, NY
- director of gift planning New York, NY
- director corporate strategy New York, NY



