Senior Manager, Cyber Strategy and Risk Advisory, TPRM
Kroll · Remote, New York, United States
About The Role
In a world of disruption and increasingly complex business challenges, our professionals bring truth into focus with the Kroll Lens. Our sharp analytical skills, paired with the latest technology, allow us to give our clients clarity—not just answers - in all areas of business. We value the diverse backgrounds and perspectives that enable us to think globally. As part of One team, One Kroll , you’ll contribute to a supportive and collaborative work environment that empowers you to excel.
Through a combination of subject matter expertise, global research capabilities and flexible technology tools, Kroll helps clients take a risk-based approach toward meeting obligations or remediating failures regarding cybersecurity, privacy program maturity and related regulatory mandates. Our engagements include Virtual CISO, regulatory and compliance assessments, strategies and security program design, transactional due-diligence, data-driven framework design and assessments, expert testimony, privacy program building and a myriad of other advisory efforts.
Kroll's Cyber Advisory practice is seeking a Senior Manager to support the continued growth of our Cyber Advisory business, with a primary focus on Third-Party Risk Management (TPRM), cyber risk assessments, governance, resilience, and security program advisory services.
The successful candidate will be a trusted advisor to clients, leading TPRM and cyber risk engagements, supporting executive stakeholders, delivering high-quality advisory services, and helping clients strengthen their security posture, resilience, and regulatory readiness.
This role combines client delivery, project leadership, people management, service development and business development support within Kroll's broader Cyber Advisory practice.
RESPONSIBILITIES
Kroll’s Cyber Risk team works on over 3,000 cases a year, including some of the most complex and highest profile matters in the world. With experts based around the world, supported by ground-breaking technology, we help protect our client’s data, people, operations and reputation with innovative assessments, investigations and intelligence. We are the only company in the world with the expertise and resources to deliver global, end-to-end cyber risk management, supporting organizations through every step of their journey toward cyber resilience.
We are looking for bright, inquisitive minds who are experienced in and passionate about cybersecurity consulting and advisory services. Our Advisory team responds to our clients’ needs and provide leadership and strategic guidance when and where it is needed the most.
- Own delivery and operational performance for managed TPRM programs, including assessment throughput, service level adherence, quality assurance, remediation tracking, client satisfaction, and continuous improvement initiatives.
- Support the delivery of high-quality cybersecurity consulting advice and services to a portfolio of clients of varying sectors, size, scope, and complexity.
- Lead delivery of cyber-focused Third-Party Risk Management (TPRM) / Managed TPRM engagements across multiple industries and client segments.
- Design, assess, and optimize Third-Party Risk Management operating models, governance structures, policies, standards, lifecycle processes, risk-tiering methodologies, and managed service delivery frameworks. Conduct supplier cyber risk assessments, vendor due diligence reviews, and third-party security evaluations.
- Assess third-party cybersecurity controls against leading frameworks and industry standards.
- Conduct cybersecurity due diligence assessments for mergers, acquisitions, carve-outs, divestitures, and private equity transactions, evaluating cyber risk exposures, operational dependencies, and remediation requirements.
- Leverage and advise clients on TPRM, GRC, continuous monitoring, and cyber risk platforms including ServiceNow, Archer, OneTrust, ProcessUnity, Panorays, Black Kite, BitSight, Interos.AI, and similar technologies.
- Design assessment workflows, questionnaire rationalization approaches, control mappings, evidence collection processes, and automated risk-scoring methodologies.
- Support clients in aligning TPRM programs with evolving regulatory requirements and operational resilience expectations.
- Develop executive reporting, board-level dashboards, key risk indicators (KRIs), quantitative risk metrics, portfolio-wide benchmarking, and management reporting that translates technical findings into business, operational, financial, and regulatory impacts.
- Lead cybersecurity risk assessments, security program reviews, cyber maturity assessments, and gap analyses.
- Assess client environments against frameworks including NIST CSF, ISO 27001, CIS Controls, FFIEC, NYDFS, SOC 2, and other applicable standards.
- Develop and enhance cyber risk management frameworks, governance models, policies, standards, procedures, and data-driven risk management processes while providing practical guidance for implementation and operationalization. Help clients identify, prioritize, and remediate cyber and technology risks through practical risk reduction roadmaps.
- Support security strategy, operating model design, and cyber transformation initiatives.
- Lead supplier resilience, concentration-risk, dependency mapping, fourth-party risk, recovery preparedness, and operational resilience assessments, helping organizations align cyber risk management activities with broader business continuity objectives.
- Facilitate workshops with business, technology, security, risk, and resilience stakeholders.
- Act as day-to-day engagement lead across multiple client projects.
- Manage project teams, workplans, budgets, timelines, deliverables, and quality assurance activities.
- Develop trusted client relationships and serve as a key point of contact during engagements.
- Support development of proposals, statements of work, and client presentations.
- Identify opportunities to expand client relationships across Kroll's broader Cyber Risk and Advisory offerings.
- Support creation of thought leadership, market-facing content, and industry presentations.
- Mentor, coach, and support junior consultants and managers.
- Contribute to methodology development, quality assurance, and practice growth initiatives.
- Analyze threat intelligence, attack surface monitoring, security ratings, continuous monitoring data, and assessment results to identify emerging risks, prioritize remediation activities, and support executive decision-making.
- Assess risks related to artificial intelligence, generative AI, machine learning, and emerging technologies, including governance, data protection, model risk management, and responsible AI practices.
- Effectively communicate findings, reports, training and strategies to technical staff, executive leadership, legal counsel, and to both internal and external clients.
- Work with sales and marketing teams to support the development of new business opportunities.
QUALIFICATIONS
- Experience designing, implementing, optimizing, or administering TPRM, GRC, continuous monitoring, or cyber risk management platforms.
- Significant experience in cybersecurity consulting, third-party risk management, technology risk, information security, operational resilience, or related advisory services.
- Strong experience designing, assessing, implementing, or managing Third-Party Risk Management programs and managed services.
- Experience conducting cyber risk assessments, supplier security reviews, or technology risk assessments.
- Working knowledge of cybersecurity frameworks and regulatory requirements including NIST CSF, NIST 800-171, ISO 27001, CIS Controls, PCI DSS, HIPAA Security Rule, SOC 2, FFIEC, NYDFS, SEC Cybersecurity Rules, DORA, NIS2, and related global regulations.
- Understanding of supplier cyber risk, cloud risk, concentration risk, vendor governance, and resilience concepts.
- Experience presenting findings and recommendations to senior client stakeholders.
- Ability to manage multiple engagements simultaneously while maintaining quality and client satisfaction.
- Experience leading project teams and mentoring junior staff.
- Commercially minded with experience supporting proposals, business development, and account growth activities.
- Professional qualifications and/or proven experience in IT/ Information Security, TPRM, GRC / Risk Management, Vulnerability Management, Incident Response, and/or Regulatory Compliance roles.
- Demonstrated ability to analyze large datasets, develop risk models, create management reporting dashboards, and derive actionable risk insights using tools such as Excel, Tableau, Power BI, SQL, Python, or comparable analytics platforms.
- Good knowledge of the security threat landscape, control frameworks and cyber resilience strategies.
- Demonstrated ability to design pragmatic risk management, governance, and resilience solutions leveraging people, process, data, and technology.
- Strong written and verbal communication and presentation skills, teamwork, and client relationship skills.
- Experience in client-facing roles and experience in engaging with senior stakeholders in organizations (desirable but not mandatory).
- Experience in high-quality delivery to tight timescales.
- Ability to multi-task, prioritize, and manage time effectively.
- Experience working with diverse teams
- Ability to travel up to 25% as required
Above all, the ideal candidate combines strong cybersecurity knowledge with practical experience managing third-party risk and advising clients on governance, resilience, and risk management challenges.
Successful candidates will be comfortable operating between detailed assessment activities and executive-level discussions, helping clients translate cyber risks into prioritized business actions. They will bring a collaborative approach, strong client-facing skills, and a desire to contribute to the continued growth of Kroll's Cyber Advisory practice.
Your recruiter will be happy to walk you through your U.S.-specific benefits, which include
- Healthcare Coverage: Comprehensive medical, dental, and vision plans.
- Time Off and Leave Policies: Generous paid time off (PTO), paid company holidays, generous parental and family leave.
- Protective Insurances: Life insurance, short- and long-term disability coverage, and accident protection.
- Compensation and Rewards: Competitive salary structures, performance-based incentives, and merit-based compensation reviews.
- Retirement Plans: 401(k) plans with company matching.
Please note that benefits may vary by region, department and role. We encourage you to speak with your recruiter to learn more about the specific benefits available for your position.
About Kroll
Join the global leader in risk and financial advisory solutions—Kroll. With a nearly century-long legacy, we blend trusted expertise with cutting-edge technology to navigate and redefine industry complexities. As a part of One Team, One Kroll, you'll contribute to a collaborative and empowering environment, propelling your career to new heights. Ready to build, protect, restore and maximize our clients’ value? Your journey begins with Kroll.
In order to be considered for a position, you must formally apply via careers.kroll.com.
We are proud to be an equal opportunity employer and will consider all qualified applicants regardless of gender, gender identity, race, religion, color, nationality, ethnic origin, sexual orientation, marital status, veteran status, age or disability.
The current salary range for this position is $150,000 to $200,000
#LI-CN1
#LI-Remote
Similar roles you might like
See all →This is an external listing. JobSpring does not represent or verify the employer. Report this listing
