
EMEA Cyber Advisory - Sr. Manager/Manager (UK)
- United Kingdom
- Permanent
- Full-time
- Support the delivery of high-quality cybersecurity consulting advice and services to a portfolio of clients of varying size, scope, and complexity.
- Develop data-driven security and governance frameworks and processes using various platforms and tools to continually assess, treat and manage security risks across client organisations.
- Conduct analysis / prioritization of data collected from attack surface monitoring and cybersecurity surveys, development / presentation of reports to clients/portfolio companies, and participation in regular client meetings to discuss findings and answer questions.
- Design and drive programs and remediation activities across GRC & ICT Risk Management, Incident Reporting, Vulnerability Management, Third Party Risk Management and Security Testing.
- Work closely with clients' security and IT teams to understand their requirements and guide implementation of technologies and processes.
- Undertake implementation, configuration and operationalization activities for new and existing security solutions or services.
- Krolls SMEs and vCISOs continually monitor changes and development across global and regional tech and cyber regulation and legislation, as well as the wider cyber threat landscape to ensure they are kept abreast of the ever-evolving threats, new controls, and requirements.
- Review and uplift of relevant frameworks, policies and procedures and provide practical advice to support the operation of new processes.
- Stay updated on emerging IT security threats and implement appropriate safeguards.
- Effectively communicate findings, reports, training and strategies to technical staff, executive leadership, legal counsel, and to both internal and external clients.
- Support the development of proposals and statements of work for Kroll clients.
- Work with sales and marketing teams to support the development of new business opportunities.
- Excellent interpersonal skills, drive, enthusiasm, and a passion for security.
- Professional qualifications and/or proven experience in IT/ Information Security, GRC / Risk Management, Vulnerability Management, Incident Response, and/or Regulatory Compliance roles.
- Technical acumen in tools such as Excel, Tableau, Power BI, and/or SQL, to empower teams to extract actionable insights and drive informed decision-making
- Good knowledge of the technology and cybersecurity regulatory and compliance landscape and requirements e.g. DORA, NIS2, GDPR, PRA/FCA or similar.
- Good knowledge of the security threat landscape, control frameworks and cyber resilience strategies.
- Ability to multi-task and prioritise, at times, conflicting priorities.
- Enjoys solving problems and designing solutions/capabilities leveraging people, processes and technologies.
- Ability to evaluate and connect business strategy, risk management, cyber strategy, policies and controls.
- Strong written and verbal communication and presentation skills, teamwork, and client relationship skills.
- A broad range of knowledge and understanding of wider commercial, business, and economic issues.
- Experience in client-facing roles and experience in engaging with senior stakeholders in organizations (desirable but not mandatory).
- Experience in high-quality delivery to tight timescales.
- A critical thinker and problem solver with attention to detail and adaptability.
- Outstanding organizational skills.
- Ability to multi-task, prioritize, and manage time effectively.
- Experience working with diverse teams
- Ability to travel up to 25% as required to support response activities