Skip to content

Open nowPosted 39 days ago

Director, Cyber Strategy and Risk Advisory, vCISO

Kroll79 open roles

Pay
$200,000 – $250,000 a year
Where
New York, NY, United States
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowDirector, Cyber Strategy and Risk Advisory, vCISOKroll · New York, NY, United States
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Kroll's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

8.1% of postings close within 7 days. Measured by our own scanner across the market. Kroll postings stay open a median of 5 days.

Share of postings closed within
  1. 1.8%1 day
  2. 3.5%3 days
  3. 8.1%7 days
  4. 15.1%14 days
  5. 33.9%30 days
This job: posted 39 days ago

Kroll median: 5 days open

The posting

Job Description

In a world of disruption and increasingly complex business challenges, our professionals bring truth into focus with the Kroll Lens. Our sharp analytical skills, paired with the latest technology, allow us to give our clients clarity—not just answers—in all areas of business. We value the diverse backgrounds and perspectives that enable us to think globally. As part of One team, One Kroll, you’ll contribute to a supportive and collaborative work environment that empowers you to excel.

Kroll’s Cyber Risk team works on over 3,000 cases a year, including some of the most complex and high-profile matters in the world. With experts based globally and supported by advanced technology, we help protect our clients’ data, people, operations, and reputation through assessments, investigations, intelligence, and strategic advisory services.

Through a combination of subject matter expertise, global research capabilities and flexible technology tools, Kroll helps clients take a risk-based approach toward meeting obligations or remediating failures regarding cybersecurity, privacy program maturity and related regulatory mandates. Our engagements include Virtual CISO, regulatory and compliance assessments, strategies and security program design, transactional due-diligence, framework assessments, expert testimony, privacy program building and a myriad of other advisory efforts.

We are seeking a Director to help lead and grow Kroll's US Virtual CISO and Cyber Advisory practice. This individual will serve as a strategic security leader for a portfolio of clients, acting as a trusted advisor to executive leadership teams, boards, and security stakeholders.

The successful candidate will be responsible for delivering and scaling Virtual CISO services, helping organizations strengthen governance, mature security programs, manage cyber risk, improve resilience, and align cybersecurity investments with business objectives. The role combines executive advisory, program leadership, client relationship management, team leadership, and business development

Responsibilities:

As a Director, you will:

  • Serve as the designated Virtual / fractional CISO for a portfolio of clients across multiple industries.
  • Act as a trusted advisor to boards, executive leadership teams, CISOs, CIOs, and risk leaders on cybersecurity strategy, governance, risk, resilience, and regulatory obligations.
  • Provide ongoing cyber leadership and strategic guidance to clients lacking full-time CISO capabilities or requiring additional executive-level support.
  • Develop and present cybersecurity roadmaps aligned to business objectives, risk appetite, regulatory requirements, and technology strategy.
  • Deliver board and executive reporting on cyber risk posture, emerging threats, key initiatives, investment priorities, and program maturity.
  • Lead security strategy development, governance transformation, risk management enhancements, cyber maturity assessments, and security operating model design.
  • Advise clients on security organization structure, target operating models, staffing strategies, and capability development.
  • Guide security investment planning, prioritization and budget justification activities.
  • Support clients in developing and improving security policies, standards, governance frameworks and performance metrics.
  • Lead advisory engagements relating to cyber resilience, third-party risk management, regulatory readiness, incident preparedness, security governance and operational resilience.
  • Support executive management teams in cyber crisis preparation, tabletop exercises, incident response readiness, and recovery planning.
  • Advise on AI governance, AI security, cloud security governance, technology risk management and emerging cyber risks.
  • Lead cyber maturity assessments, security program reviews, risk assessments, and gap analyses against leading industry standards and frameworks such as NIST CSF, ISO 27001, CIS Controls, SOC 2, FFIEC, NYDFS Cybersecurity Regulation, SEC cyber disclosure expectations, HIPAA, and other relevant US regulatory or sector-specific requirements.
  • Identify opportunities to expand vCISO relationships into broader cybersecurity, resilience, technology risk and compliance engagements.
  • Support proposal development, client presentations, account planning and strategic growth initiatives.
  • Contribute to thought leadership and market-facing content focused on cybersecurity leadership, governance and executive risk management.
  • Oversee delivery teams, manage engagement quality, review fieldwork and deliverables, and ensure outputs meet Kroll’s standards for technical depth, commercial relevance, and executive clarity.
  • Mentor and develop consultants supporting vCISO and other adivisory engagements.
  • Establish methodologies, playbooks, reporting models and quality standards for the vCISO service offering.
  • Build strong relationships across Kroll’s global Cyber Risk business to bring the best of the firm to clients and support cross-border opportunities where relevant.
  • Support capability growth across Kroll's broader Cyber Advisory practice.

Qualifications:

  • Significant experience in cybersecurity consulting, cyber risk management, information security, technology risk, AI Security/Governance, resilience, regulatory advisory, and/or related professional services roles.
  • Strong experience serving in a CISO, Deputy CISO, Head of Security, Security Director, vCISO, or senior cybersecurity consulting leadership role.
  • Demonstrated ability to engage directly with boards, executive leadership teams, regulators, auditors, investors, and client stakeholders.
  • Experience designing, leading, operating or transforming enterprise cybersecurity programs.
  • Strong understanding of cybersecurity governance, operating models, technology risk, resilience, third-party risk, incident preparedness and security leadership.
  • Proven ability to translate technical cybersecurity issues into business-focused risk and investment decisions.
  • Strong knowledge of cyber strategy, governance, risk management, security operating models, control frameworks, incident readiness, third-party risk, cyber resilience, and security program maturity.
  • Experience advising clients on leading cybersecurity frameworks, standards, and US regulatory or industry requirements, including NIST, ISO 27001, CIS Controls, SOC 2, NYDFS, FFIEC, HIPAA, SEC-related cyber disclosure considerations, and other relevant frameworks.
  • Proven ability to engage confidently with senior executives, boards, CISOs, CIOs, legal counsel, risk leaders, and business stakeholders.
  • Strong commercial mindset, with experience supporting business development, proposals, account growth, client relationship management, and market-facing initiatives.
  • Experience leading, coaching, and developing teams as part of both client delivery and broader practice growth.
  • Excellent written and verbal communication skills, with the ability to produce clear, executive-ready deliverables and present complex topics in a concise, business-focused manner.
  • Ability to manage multiple engagements, priorities, deadlines, and stakeholders effectively.
  • Ability to travel as required to support client delivery, business development, and internal initiatives.

Candidate Profile

Above all, Kroll expects senior candidates to be strategic, commercially minded, intellectually curious, collaborative, and confident operating with senior clients. The successful candidate will be comfortable moving between board-level advisory, hands-on program design, team leadership, and business development.

This is an opportunity to play a meaningful role in scaling Kroll’s US Cyber Strategy and Risk Consulting practice, helping clients address their most important cyber, technology, governance, and resilience challenges.

Your recruiter will be happy to walk you through your U.S.-specific benefits, which include:

  • Healthcare Coverage: Comprehensive medical, dental, and vision plans.
  • Time Off and Leave Policies: Generous paid time off (PTO), paid company holidays, generous parental and family leave.
  • Protective Insurances: Life insurance, short- and long-term disability coverage, and accident protection.
  • Compensation and Rewards: Competitive salary structures, performance-based incentives, and merit-based compensation reviews.
  • Retirement Plans: 401(k) plans with company matching.

Please note that benefits may vary by region, department and role. We encourage you to speak with your recruiter to learn more about the specific benefits available for your position.

About Kroll

Join the global leader in risk and financial advisory solutions—Kroll. With a nearly century-long legacy, we blend trusted expertise with cutting-edge technology to navigate and redefine industry complexities. As a part of One Team, One Kroll, you'll contribute to a collaborative and empowering environment, propelling your career to new heights. Ready to build, protect, restore and maximize our clients’ value? Your journey begins with Kroll.

In order to be considered for a position, you must formally apply via careers.kroll.com.

We are proud to be an equal opportunity employer and will consider all qualified applicants regardless of gender, gender identity, race, religion, color, nationality, ethnic origin, sexual orientation, marital status, veteran status, age or disability.

The current salary range for this position is $200,000 to $250,000

#LI-CN1

#LI-Remote

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Kroll's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Kroll's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Kroll's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.