Back to all jobs

Director/Principal, Cyber Advisory

Control Risks

LondonHybridFull Time10+ years
Posted 3 hours ago

Drawing on our global reach and local risk expertise worldwide, our Digital Risks team helps our clients understand the evolving threat landscape, protect their most critical assets effectively respond to crises and maximise the benefits of technology adoption. Thanks to continued growth, we are now looking for a Director or Principal to join our Digital Risks Protect Advisory team in London. As the Director or Principal you will drive business development and consulting engagements in the UK and relevant markets in Europe and the Middle East. You will serve as a trusted advisor to senior executives, manage a portfolio of complex projects, originate new business, and collaborate across Digital Risks practice areas and other service lines to support clients in improving resilience against evolving threats. This role strengthens our ability to guide senior stakeholders through strategic digital risk challenges, deliver high-impact consulting outcomes, and contribute to the development of high-performing teams and the broader Digital Risks practice.

Strategic Advisory & Client Leadership

  • Serve as a trusted advisor to senior executives and boards, providing strategic guidance on digital risk This will cover topics such as resilience, regulatory expectations, evolving technology driven threats and emerging technologies.
  • Translate complex technical and risk insights into clear, commercially relevant recommendations for non-technical audiences.
  • Lead the development and delivery of executive briefings, strategic assessments, and transformation programmes that support clients’ risk and security objectives.

Digital Risk, Cybersecurity & Technology Advisory Delivery

  • Lead and oversee complex consulting engagements across digital risk, including cybersecurity, technology governance, and organisational resilience.
  • Guide the design and execution of maturity assessments, control reviews and risk analyses using leading industry frameworks and regulatory models.
  • Ensure deliverables provide actionable, pragmatic and business aligned recommendations that enhance clients’ risk management and resilience.
  • Provide quality assurance and directional oversight to ensure deliverables meet the highest standards of clarity, insight and practical value.

Regulatory, Governance & Compliance Advisory

  • Advise clients on regional and global regulatory obligations relating to cybersecurity, data governance, technology operations, and third-party risk.
  • Engage relevant external specialists and integrate their outputs to ensure seamless, end-to-end advisory solutions.

Risk, Crisis & Incident Advisory Support

  • Provide senior guidance during digital incidents, investigations, or technology-related crises.
  • Apply principles of crisis management, stakeholder communication and risk assessment to help clients respond to disruptive events.
  • Support scenario planning, simulation exercises and resilience-building initiatives.

Leadership of Consulting Engagements

  • Oversee multiple concurrent projects, ensuring consistent quality, methodological rigour and strong client satisfaction.
  • Lead project teams through scoping, delivery and reporting, ensuring clarity of purpose and alignment with client expectations.
  • Promote cross-service collaboration to deliver integrated, multi-disciplinary solutions.

Client & Market Development

  • Grow and sustain senior client relationships with a particular focus on the UK and relevant markets in Europe, acting as an ambassador for Control Risks.
  • Identify new opportunities, shape proposals and contribute to key account growth.
  • Represent the practice at industry events, conferences and through thought leadership activities.

Practice & People Leadership

  • Coach, mentor and develop consultants at all levels, fostering a high performing, inclusive and collaborative culture.
  • Contribute to the development and improvement of methodologies, frameworks, knowledge assets and service innovation within Digital Risks.
  • Role model firm values, champion cross-regional collaboration and support the Partner in the ongoing development of the practice.
  • Bachelor’s degree in computer science, cybersecurity, information technology, risk management or a related field (or equivalent experience).
  • Significant experience in digital risk, cybersecurity, technology risk, or integrated risk advisory roles.
  • Significant experience advising C-suite and Board-level stakeholders, translating complex technical risk into strategic and commercial implications.
  • Proven ability to lead complex, multi-disciplinary consulting engagements and manage diverse senior stakeholders across regions.
  • Demonstrated success in originating business, growing key accounts, and shaping proposal strategies.
  • Strong understanding of cybersecurity, technology governance, digital resilience, and core security domains. Experience navigating regional regulatory environments (e.g., NIS2, DORA, sectoral regulators e.g. FCA, PRA and privacy frameworks).
  • Demonstrated ability to analyse complex security data and deliver clear, actionable recommendations informed by industry best practices.
  • Proven experience leading, developing, and mentoring teams to deliver high-quality outcomes.
  • Professional certifications such as CISSP, CISM, CRISC, CISA, or cloud-security or privacy-related certifications (preferred but not essential).
  • Experience working across multiple jurisdictions and cultures, ideally within Europe, the Middle East or other complex regulatory markets.
  • Strong communication and executive-level presentation skills, including the ability to articulate strategic point-of-view to non-technical audiences.
  • Experience with emerging digital-risk areas such as AI governance, cloud-native architectures, OT/ICS security, digital supply chain resilience, and / or third-party technology risk.
  • Demonstrated contribution to thought leadership, industry engagement, or external speaking.
  • Strong project and programme management capability, with experience overseeing multi-stream, large-scale transformation or risk uplift programmes.
  • High digital fluency, including comfort with collaboration tools, CRM systems, data-driven insights, and new ways of working.
  • Ability to travel when required for client leadership, business development, and key delivery milestones.
  • Experience providing senior guidance during major incidents or technology-related crises.
  • Control Risks offers a competitively positioned compensation and benefits package that is transparent and summarised in the full job offer.
  • We operate a discretionary global bonus scheme that incentivises, and rewards individuals based on company and individual performance.
  • Control Risks supports hybrid working arrangements, wherever possible, that emphasise the value of in-person time together - in the office and with our clients - while continuing to support flexible and remote working.
  • As an equal opportunities employer, we encourage suitably qualified applicants from a wide range of backgrounds to apply and join us and are fully committed to equal treatment, free from discrimination, of all candidates throughout our recruitment process.

If you require any reasonable adjustments to be made in order to participate fully in the interview process, please let us know and we will be happy to accommodate your needs.

Benefits

Discretionary global bonus schemeHybrid working arrangements