Director, Cyber Strategy and Risk Advisory, vCISO
Kroll
In a world of disruption and increasingly complex business challenges, our professionals bring truth into focus with the Kroll Lens. Our sharp analytical skills, paired with the latest technology, allow us to give our clients clarity—not just answers—in all areas of business. We value the diverse backgrounds and perspectives that enable us to think globally. As part of One team, One Kroll, you’ll contribute to a supportive and collaborative work environment that empowers you to excel.Kroll’s Cyber Risk team works on over 3,000 cases a year, including some of the most complex and high-profile matters in the world. With experts based globally and supported by advanced technology, we help protect our clients’ data, people, operations, and reputation through assessments, investigations, intelligence, and strategic advisory services. Through a combination of subject matter expertise, global research capabilities and flexible technology tools, Kroll helps clients take a risk-based approach toward meeting obligations or remediating failures regarding cybersecurity, privacy program maturity and related regulatory mandates. Our engagements include Virtual CISO, regulatory and compliance assessments, strategies and security program design, transactional due-diligence, framework assessments, expert testimony, privacy program building and a myriad of other advisory efforts.We are seeking a Director to help lead and grow Kroll's US Virtual CISO and Cyber Advisory practice. This individual will serve as a strategic security leader for a portfolio of clients, acting as a trusted advisor to executive leadership teams, boards, and security stakeholders.The successful candidate will be responsible for delivering and scaling Virtual CISO services, helping organizations strengthen governance, mature security programs, manage cyber risk, improve resilience, and align cybersecurity investments with business objectives. The role combines executive advisory, program leadership, client relationship management, team leadership, and business developmentResponsibilities:As a Director, you will:Serve as the designated Virtual / fractional CISO for a portfolio of clients across multiple industries.Act as a trusted advisor to boards, executive leadership teams, CISOs, CIOs, and risk leaders on cybersecurity strategy, governance, risk, resilience, and regulatory obligations.Provide ongoing cyber leadership and strategic guidance to clients lacking full-time CISO capabilities or requiring additional executive-level support.Develop and present cybersecurity roadmaps aligned to business objectives, risk appetite, regulatory requirements, and technology strategy.Deliver board and executive reporting on cyber risk posture, emerging threats, key initiatives, investment priorities, and program maturity.Lead security strategy development, governance transformation, risk management enhancements, cyber maturity assessments, and security operating model design.Advise clients on security organization structure, target operating models, staffing strategies, and capability development.Guide security investment planning, prioritization and budget justification activities.Support clients in developing and improving security policies, standards, governance frameworks and performance metrics.Lead advisory engagements relating to cyber resilience, third-party risk management, regulatory readiness, incident preparedness, security governance and operational resilience.Support executive management teams in cyber crisis preparation, tabletop exercises, incident response readiness, and recovery planning.Advise on AI governance, AI security, cloud security governance, technology risk management and emerging cyber risks.Lead cyber maturity assessments, security program reviews, risk assessments, and gap analyses against leading industry standards and frameworks such as NIST CSF, ISO 27001, CIS Controls, SOC 2, FFIEC, NYDFS Cybersecurity Regulation, SEC cyber disclosure expectations, HIPAA, and other relevant US regulatory or sector-specific requirements.Identify opportunities to expand vCISO relationships into broader cybersecurity, resilience, technology risk and compliance engagements.Support proposal development, client presentations, account planning and strategic growth initiatives.Contribute to thought leadership and market-facing content focused on cybersecurity leadership, governance and executive risk management.Oversee delivery teams, manage engagement quality, review fieldwork and deliverables, and ensure outputs meet Kroll’s standards for technical depth, commercial relevance, and executive clarity.Mentor and develop consultants supporting vCISO and other adivisory engagements.Establish methodologies, playbooks, reporting models and quality standards for the vCISO service offering.Build strong relationships across Kroll’s global Cyber Risk business to bring the best of the firm to clients and support cross-border opportunities where relevant.Support capability growth across Kroll's broader Cyber Advisory practice.Qualifications:Significant experience in cybersecurity consulting, cyber risk management, information security, technology risk, AI Security/Governance, resilience, regulatory advisory, and/or related professional services roles.Strong experience serving in a CISO, Deputy CISO, Head of Security, Security Director, vCISO, or senior cybersecurity consulting leadership role.Demonstrated ability to engage directly with boards, executive leadership teams, regulators, auditors, investors, and client stakeholders.Experience designing, leading, operating or transforming enterprise cybersecurity programs.Strong understanding of cybersecurity governance, operating models, technology risk, resilience, third-party risk, incident preparedness and security leadership.Proven ability to translate technical cybersecurity issues into business-focused risk and investment decisions.Strong knowledge of cyber strategy, governance, risk management, security operating models, control frameworks, incident readiness, third-party risk, cyber resilience, and security program maturity.Experience advising clients on leading cybersecurity frameworks, standards, and US regulatory or industry requirements, including NIST, ISO 27001, CIS Controls, SOC 2, NYDFS, FFIEC, HIPAA, SEC-related cyber disclosure considerations, and other relevant frameworks.Proven ability to engage confidently with senior executives, boards, CISOs, CIOs, legal counsel, risk leaders, and business stakeholders.Strong commercial mindset, with experience supporting business development, proposals, account growth, client relationship management, and market-facing initiatives.Experience leading, coaching, and developing teams as part of both client delivery and broader practice growth.Excellent written and verbal communication skills, with the ability to produce clear, executive-ready deliverables and present complex topics in a concise, business-focused manner.Ability to manage multiple engagements, priorities, deadlines, and stakeholders effectively.Ability to travel as required to support client delivery, business development, and internal initiatives.Candidate ProfileAbove all, Kroll expects senior candidates to be strategic, commercially minded, intellectually curious, collaborative, and confident operating with senior clients. The successful candidate will be comfortable moving between board-level advisory, hands-on program design, team leadership, and business development.This is an opportunity to play a meaningful role in scaling Kroll’s US Cyber Strategy and Risk Consulting practice, helping clients address their most important cyber, technology, governance, and resilience challenges.Your recruiter will be happy to walk you through your U.S.-specific benefits, which include:Healthcare Coverage: Comprehensive medical, dental, and vision plans.Time Off and Leave Policies: Generous paid time off (PTO), paid company holidays, generous parental and family leave.Protective Insurances: Life insurance, short- and long-term disability coverage, and accident protection.Compensation and Rewards: Competitive salary structures, performance-based incentives, and merit-based compensation reviews.Retirement Plans: 401(k) plans with company matching.Please note that benefits may vary by region, department and role. We encourage you to speak with your recruiter to learn more about the specific benefits available for your position.About Kroll Join the global leader in risk and financial advisory solutions—Kroll. With a nearly century-long legacy, we blend trusted expertise with cutting-edge technology to navigate and redefine industry complexities. As a part of One Team, One Kroll, you'll contribute to a collaborative and empowering environment, propelling your career to new heights. Ready to build, protect, restore and maximize our clients’ value? Your journey begins with Kroll. In order to be considered for a position, you must formally apply via careers.kroll.com.We are proud to be an equal opportunity employer and will consider all qualified applicants regardless of gender, gender identity, race, religion, color, nationality, ethnic origin, sexual orientation, marital status, veteran status, age or disability.The current salary range for this position is $200,000 to $250,000#LI-CN1#LI-RemoteFull timePosting Date: 2026-08-31
$193.5k - $227.7k
...Cybersecurity - Senior Manager to deliver on full lifecycle Cyber projects for various industries, which may involve strategy & roadmap development, security controls reviews & remediation/hardening, risk advisory, compliance assessments, resiliency planning, application...CyberRiskLocal areaImmediate startFlexible hours2 days per week1 day per week- ...technology tools, Kroll helps clients take a risk-based approach toward meeting... ...regulatory and compliance assessments, strategies and security program design,... ...program building and a myriad of other advisory efforts.Kroll's Cyber Advisory practice is seeking a Senior...CyberRiskTemporary workFlexible hours
- Mizuho is seeking a Cyber Security Advisory Lead to act as the trusted security advisor across business and technology leadership... ...You will embed security into decision-making from strategy through delivery, guiding risk decisions, secure‑by‑design guidance, and...CyberRisk
- ...Executive Director, U.S. Insurance Debt Advisory About the Company Leading international... ...science engineering cyber security sustainability... ..., capital, financing, or risk management matters. The... ...investment banking, or insurance strategy, and the ability to mentor...CyberRisk
- ...consistency across Teneo’s Financial Advisory businesses in Australia and... ...closely with: Senior Managing Directors leading Teneo’s Financial... ...in AU and NZ Global Quality & Risk Management team (Global QRM)... ...management consulting, physical and cyber risk, organisational design,...CyberRiskPart timeWork experience placementLocal areaFlexible hours
$150k - $215k
Join Mizuho as the Cyber Security Advisory Lead! In this role you will serve as a trusted advisor to business... ...security expertise into decision-making from strategy through delivery. You will provide advisory services for risk decisions, secure-by-design guidance, and...CyberRiskWork at officeLocal areaRemote workWorldwide- Kroll is the leading independent provider of risk and financial advisory solutions. Across valuation, investigations, cyber, restructuring, regulatory compliance, and corporate... ...of experience in consulting, technology strategy, analytics, product/ops, or a related...CyberRiskTemporary work
$220k - $250k
...help manage and grow our Digital Risks consulting business globally,... ...and information security advisory and response capabilities. The... ...Global Digital Risks consulting strategy, business development, opportunity... ...at the intersection of cyber, forensics and analytics.Advise...CyberRiskFull timeFor subcontractorWork at officeRemote workFlexible hours$161.92k - $202.4k
As a Cyber Strategy & Management Manager, you will get the opportunity to grow and contribute to... ...and privacy, strategy, governance, IT risk, security testing, technology implementation... ...non-attest offerings, including tax and advisory services. In 2025, Grant Thornton formed...CyberRiskInternshipSeasonal workWork at officeLocal areaFlexible hours3 days per week- ...and infrastructure-heavy organizations on cyber risk, resilience, compliance, and regulatory... ...portfolio of cybersecurity, assurance, advisory, and managed services, positioning solutions... ...as a trusted advisor on cybersecurity strategy, risk posture, and maturity progression....CyberRisk
- ...A global intelligence, cyber, and investigations firm... ...consulting, corporate strategy, strategic intelligence... ...assessing the commercial risks attached to a target in... ..., developing their advisory and client management skills... ...there is to Associate Director, where the role...CyberRiskWork at officeWork from homeFlexible hours
$130k - $152.5k
...through critical business strategy and performance-related... .../ Due Diligence / Advisory) to support client engagements... ...managing cybersecurity risk. In this role, you will... ...includes executing cyber due diligence and... ...discussions with CIOs, IT Directors, and legal stakeholders...CyberRiskWork at officeWork from home3 days per week$187.6k - $220.7k
...?West Monroe is looking for an Advisory Architect, Data/AI due diligence... ...advisors/architects (Cloud, Cyber, Software Engineering, infrastructure... ...investment summaries, key risk mitigation analyses, and long-term technology-based strategy for both pre-close and post-close...CyberRiskH1bLocal areaImmediate startFlexible hours- Director AI Strategy and Innovation KeyLogic is seeking an experienced AI Strategy & Innovation Lead... ..., energy systems, materials discovery, cyber, facility operations, and mission... ...value, feasibility, mission impact, and risk. Serve as a primary interface with DOE...CyberRiskRemote work
$102.8k - $176k
...growing our cybersecurity and risk consulting practice. The... ...is responsible for developing cyber and risk consulting accounts... ...engagements into comprehensive advisory partnerships. This position requires... ...risk and digital trust strategies. ESSENTIAL DUTIESCyber & Risk...CyberRiskFull timeContract workWork experience placementInternshipWork at officeLocal area$85k - $95k
...new solution sales Partner with ISS-Corporate advisory teams to deliver insights and strong customer... ...investment opportunities and manage portfolio risks. Our services cover corporate governance, sustainability, cyber risk, and fund intelligence. Majority-owned by...CyberRiskLocal areaWorldwideFlexible hours$101.2k - $129.03k
As an IT Risk Senior Associate (Insurance), you will get the opportunity to grow and contribute... ...of clients’ industry, objectives, strategy, operations, processes, IT systems, and... ...Work collaboratively with colleagues across Advisory Business Lines (ABLs) and with other...RiskWork experience placementWork at office$169.1k - $198.8k
...currently seeking a Manager to join our CFO Advisory team within our Operations Excellence... ..., including developing their application strategy and transformation roadmap. Candidates should... ...relationship, client satisfaction, risk management, and delivery team management...RiskLocal areaImmediate startFlexible hours$168.75k - $200k
...started.Join us to put AI to work for people.Armis from ServiceNow, protects the entire attack surface and manages an organization’s cyber risk exposure in real time. Combined with ServiceNow’s Security and Risk capabilities, as well as Identity Security capabilities from...CyberRiskWork at officeImmediate startRemote workFlexible hours$114.1k - $268.18k
...The KPMG Advisory practice is at the forefront of transformation, offering excellent opportunities... ...management coordination and oversight of Cyber Managed Services delivery of contracted... ..., identifying and communicating issues, risks, dependencies, and opportunities for...CyberRiskFull timeH1bLocal area- ...We are seeking a Managing Director to lead and expand our Cybersecurity Advisory practice serving the Private Equity (... ...portfolio company leadership to assess cyber risk, identify value creation... ...deep expertise in cybersecurity strategy and risk management, a strong network...CyberRisk
- PwC in New York is seeking a Cyber Strategy & Resilience - Cyber Strategy & Transformation Manager to lead teams and client engagements focused... ...compliance and internal controls. You will guide adoption of risk-based cybersecurity frameworks (NIST CSF, ISO/IEC 27001),...CyberRisk
$163.4k - $322.1k
Position Summary Cyber Senior Manager / Senior Manager, Strategy, Growth, and Transformation Are you interested in improving the cyber and organizational risk profiles of leading companies? Do you want to be involved in delivering Cyber services including identifying...CyberRiskLocal areaVisa sponsorship$150k - $250k
...Security Officer (CISO), Technology Risk secures Goldman Sachs against hackers and other cyber threats. We are responsible for... ...EMEA.Within Technology Risk, Advisory is the consultative and technology... ...the Vendor Technology Risk strategy, leading a team that assesses threats...CyberRisk$149.18k - $220k
...started.Join us to put AI to work for people.Armis from ServiceNow, protects the entire attack surface and manages an organization’s cyber risk exposure in real time. Combined with ServiceNow’s Security and Risk capabilities, as well as Identity Security capabilities from...CyberRiskWork at officeImmediate startRemote workFlexible hours$172.79k - $214k
...Cybersecurity Intelligence (Director Financial Services... ...incident, supervisory, and risk intelligence.This role will... ...priorities, and risk mitigation strategies to strengthen cyber preparedness and... ...the development of alerts, advisories, and guidance for DFS-regulated...CyberRiskFull timeTemporary workWork at officeLocal areaRemote work- ...POSITION: Reporting to the Managing Director & Head of Digital Investigations & Cyber Risk, the Managing Director will be... ...to shape the firm’s overall strategy. YOUR BACKGROUND: Minimum... ...investigations in both an investigative and advisory capacity. Experience in...CyberRisk
$168k - $199k
...industry best practices.Develop Comprehensive Strategies: Create security strategies tailored to... ...with stakeholders to identify risks, implement remediation strategies, and ensure... ...guidance for how AI should be used to transform cyber security offense and defense capabilities...CyberRiskFull timeRemote workWorldwide- ...management and client-facing advisory responsibilities within an MSP... ...cybersecurity best practices, security strategy and compliance requirements.... ...such as HIPAA, SOC 2 and cyber insurance requirements. Manage... ...security assessments, risk reviews and security posture improvement...CyberRisk
- ...asset manager on a second line of defense Op Risk hire in New York. This sits within the... ...oversight with a meaningful new product advisory remit. What you'll own: Operational risk... ...Thematic reviews across third-party, change, cyber, and resilience What we're looking for: 8...CyberRisk
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Director, Cyber Strategy and Risk Advisory, vCISO. Be the first to apply!
- data strategy manager New York, NY
- operations planning manager New York, NY
- senior manager strategic initiatives New York, NY
- sales excellence & strategy manager New York, NY
- strategic account manager New York, NY
- strategic business development manager New York, NY
- brand strategy manager New York, NY
- commercial planning manager New York, NY
- director strategic marketing New York, NY
- workforce planning manager New York, NY




