A Director-level vCISO role at Kroll, leading and scaling virtual CISO services and strategic cyber advisory across a portfolio of clients in the US.
Kroll's Cyber Risk practice handles over 3,000 engagements annually, spanning complex advisory, assessment, and investigation mandates for clients globally. This Director role sits within the US Virtual CISO and Cyber Advisory practice, where the successful candidate will serve as a fractional security executive for a portfolio of clients across multiple industries.
The position combines executive advisory, programme leadership, client relationship management, and business development. The Director will guide clients on governance transformation, risk and resilience, regulatory readiness, AI and cloud security governance, and security operating model design, while also contributing to thought leadership and internal capability development.
- Serve as the designated fractional CISO for a portfolio of clients across multiple industries, providing ongoing cyber leadership and strategic guidance.
- Advise boards, executive leadership teams, and senior risk stakeholders on cybersecurity strategy, governance, risk, resilience, and regulatory obligations.
- Develop and present cybersecurity roadmaps aligned to business objectives, risk appetite, and regulatory requirements.
- Lead maturity assessments, security programme reviews, and gap analyses against frameworks including NIST CSF, ISO 27001, CIS Controls, SOC 2, NYDFS, FFIEC, and HIPAA.
- Oversee engagement delivery teams, manage quality standards, and mentor consultants supporting vCISO and advisory engagements.
- Support business development through proposal development, account planning, and client presentations, and establish methodologies and playbooks for the vCISO service offering.
- Significant experience in a CISO, Deputy CISO, Head of Security, vCISO, or senior cybersecurity consulting leadership role.
- Demonstrated ability to engage with boards, executive leadership teams, regulators, auditors, and investors on cybersecurity matters.
- Strong knowledge of cyber governance, risk management, security operating models, incident readiness, third-party risk, and cyber resilience.
- Experience advising on leading frameworks and US regulatory requirements including NIST, ISO 27001, CIS Controls, SOC 2, NYDFS, FFIEC, HIPAA, and SEC cyber disclosure expectations.
- Proven commercial mindset with experience in business development, proposals, account growth, and client relationship management.
- Excellent written and verbal communication skills, with the ability to produce executive-ready deliverables on complex technical topics.
Kroll is a global advisory firm providing services across risk, financial, and corporate advisory matters. Its Cyber Risk team operates on thousands of engagements annually, helping organisations protect their data, people, and operations through assessments, investigations, intelligence, and strategic advisory services.
Trusted by fast-growing companies around the world





