Korn Ferry
Interim Cybersecurity and IT Risk Lead Consultant
An interim senior cybersecurity leader to establish and mature a scalable security, risk, and compliance programme for a rapidly growing infrastructure organisation, partnering with executive, legal, and operations teams.
This interim engagement requires a seasoned cybersecurity professional to build and strengthen the security governance, risk, and compliance function for a high-growth infrastructure organisation. The consultant will serve as the senior internal cybersecurity leader, responsible for designing policy frameworks, a strategic security roadmap, and executive-level risk reporting. The role spans identity and access management, endpoint and cloud security, vulnerability management, incident response, MSSP oversight, and SOX compliance support.
The ideal profile combines hands-on technical depth with strategic leadership, and prior experience in regulated, capital-intensive sectors such as energy, utilities, construction, or critical infrastructure is strongly preferred. The consultant will partner across technology, operations, legal, compliance, and executive leadership to ensure the security programme scales alongside the business. Note: This listing is classified as a hybrid role based in Dallas, TX, with three days onsite per week.
- Assess and implement cybersecurity governance frameworks, policies, and risk management standards aligned to business objectives.
- Lead enterprise-wide cybersecurity risk assessments, remediation initiatives, and SOX compliance activities.
- Oversee IAM, PAM/PIM, and Microsoft Entra programmes to strengthen access governance and privileged account controls.
- Provide oversight of vulnerability management, endpoint security, cloud security, and incident response operations.
- Evaluate, manage, and hold accountable Managed Security Service Providers against defined performance metrics.
- Partner with legal and external counsel on eDiscovery, data governance, and cybersecurity risk matters.
- Ten or more years of progressive experience in cybersecurity, IT risk, information security, or security consulting.
- Demonstrated track record of building or maturing cybersecurity programmes within growing organisations.
- Hands-on experience across IAM, PAM/PIM, endpoint security, cloud security, vulnerability management, and incident response.
- Experience managing MSSPs, third-party security vendors, and external service providers.
- Strong knowledge of cybersecurity governance and control frameworks, including SOX and SEC disclosure requirements.
- Certifications such as CISSP, CISM, CRISC, or GIAC preferred; experience in critical infrastructure or industrial environments is an advantage.
Korn Ferry is a global organisational consulting firm that works with clients to design effective structures, hire the right people, and develop talent. The firm advises on leadership, rewards, and career development across a broad range of industries worldwide.
Trusted by fast-growing companies around the world





