Full-Time

AI Assurance & Governance Manager

Cyber Advisory

Kroll

Kroll

5,001-10,000 employees

Global risk management and investigations consulting

Compensation Overview

$150k - $175k/yr

+ Performance-based incentives + Merit-based compensation reviews + 401(k) matching

Remote in USA

Remote

Category
Consulting (1)
Required Skills
LLM
Power BI
SQL
Machine Learning
OpenAI
RAG
Cybersecurity
Tableau
Cryptography
Databricks
Excel/Numbers/Sheets

Get referred to Kroll

See people who can refer or advise you

Requirements
  • Strong knowledge of AI governance, risk, and security frameworks and standards, including NIST AI RMF, ISO/IEC 42001, OWASP Top 10 for LLM Applications, OWASP GenAI Security Project, CSA AI Security Maturity Model, CSA AI Controls Matrix, MITRE ATLAS, OECD AI Principles, the EU AI Act, and United States regulatory guidance.
  • Experience conducting AI risk assessments, AI control reviews, model governance assessments, or AI compliance evaluations across enterprise environments.
  • Strong understanding of Responsible AI principles, including transparency, explainability, human oversight, accountability, fairness, and model governance.
  • Experience advising executive leadership, risk committees, governance boards, or regulators on AI-related risks, controls, and adoption strategies.
  • Knowledge of enterprise AI technologies including Generative AI, Large Language Models, Retrieval-Augmented Generation, AI agents, and autonomous systems.
  • Experience developing AI policies, standards, governance procedures, operating models, and risk management frameworks.
  • Understanding of core security controls, including network security, identity and access management, cryptography, secure software development lifecycle, cloud security, and security testing.
  • Technical acumen with Excel, Tableau, Power BI, and/or SQL.
  • Knowledge of the security and AI threat landscape, control frameworks, and cyber resilience strategies.
  • Experience delivering high-quality work to tight timescales.
  • Strong written and verbal communication and presentation skills, teamwork, and client relationship skills.
  • Experience working with diverse teams.
Responsibilities
  • Support the delivery of cybersecurity consulting advice and services to a portfolio of clients of varying size, scope, and complexity.
  • Design and implement enterprise AI governance programs, operating models, policies, standards, and controls for agentic AI, Generative AI, machine learning, and autonomous decision-making solutions.
  • Contribute to building and enhancing AI capabilities, service delivery collaboration, methodology development, and the AI risk and security knowledge base.
  • Conduct AI risk assessments across internally developed, procured, and third-party AI systems.
  • Advise clients on establishing AI governance committees, decision-making structures, and accountability frameworks.
  • Support the development of AI inventories, use-case classification methodologies, and risk-tiering approaches.
  • Assess client readiness against frameworks such as NIST AI RMF, the EU AI Act, ISO 42001, OECD AI Principles, and emerging regulatory requirements.
  • Support organizations in implementing practical guardrails around AI adoption while balancing innovation, risk management, and regulatory compliance.
  • Perform AI assurance reviews to evaluate the effectiveness of AI governance, controls, security, and oversight mechanisms.
  • Conduct AI security and assurance assessments, including model security reviews, adversarial testing, Large Language Model security assessments, and evaluation of AI control effectiveness.
  • Collaborate with offensive security and engineering teams to validate AI security controls through targeted testing and technical assessments against emerging threats, including prompt injection, model manipulation, training data poisoning, insecure plugins, excessive agency, data leakage, and supply-chain compromise.
  • Support AI-related services including secure model development, data security, application development, third-party and supply-chain security, and security testing.
  • Work with clients’ governance, security, and information technology teams to understand requirements and guide implementation of technologies and processes.
  • Research advances in AI and machine learning development, AI security and governance, AI in software engineering, the AI regulatory landscape, and AI governance and security frameworks.
  • Monitor changes and developments across global and regional technology and cyber regulation, legislation, and the cyber threat landscape.
  • Review and improve relevant frameworks, policies, and procedures, and provide practical advice to support new processes.
  • Communicate findings, reports, training, and strategies to technical staff, executive leadership, legal counsel, and internal and external clients.
  • Support the development of proposals and statements of work for clients.
  • Work with sales and marketing teams to support new business opportunities.
Desired Qualifications
  • Experience with Microsoft Copilot, Azure AI Foundry, OpenAI, Anthropic Claude, AWS Bedrock, Google Gemini, Databricks, or similar enterprise AI platforms.
  • Experience evaluating third-party AI solutions, AI vendor risk, model risk management, or AI procurement governance.
  • Familiarity with AI governance and assurance platforms such as Credo AI, Holistic AI, ModelOp, and IBM watsonx Governance.
  • Industry experience supporting financial services, healthcare, technology, energy, public sector, or other regulated industries.
  • Relevant certifications such as CISSP, CISM, CRISC, ISO 42001 Lead Implementer or Auditor, CGRC, PMP, or equivalent professional qualifications.

Preparing summary

Company Size

5,001-10,000

Company Stage

N/A

Total Funding

N/A

Headquarters

New York City, New York

Founded

1932

Get referred to Kroll

See people who can refer or advise you

Simplify Jobs

Simplify's Take

What believers are saying

  • APEX targets CFOs under 2026 AI-spend pressure, expanding Kroll’s cyber advisory attach rate.
  • ABC economics strengthens European disputes work as cartel and regulatory cases intensify.
  • Kroll’s 6,500-person platform and forty-plus acquisitions support faster cross-border client coverage.

What critics are saying

  • Kroll Trustee Services faces Hurtigruten disclosure orders in July 2026, widening litigation exposure.
  • CrowdStrike dependence concentrates product strategy and pricing power outside Kroll.
  • Global advisor commoditization pressures margins unless Kroll converts acquisitions into cross-sold recurring revenue.

What makes Kroll unique

  • Kroll’s August 31, 2026 APEX embeds cyber ROI analytics inside CrowdStrike Falcon.
  • Kroll’s July 15, 2026 ABC economics acquisition deepens competition and damages expertise.
  • Fred Crawford became Executive Chairman on May 18, 2026, sharpening services-firm scaling.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Hybrid Work Options

Growth & Insights and Company News

Headcount

6 month growth

17%

1 year growth

17%

2 year growth

17%
PR Newswire
Aug 31st, 2026
Kroll introduces APEX to drive measurable business outcomes from AI investment.

Kroll introduces APEX to drive measurable business outcomes from AI investment. Aug 31, 2026, 10:00 ET NEW YORK and LAS VEGAS, Aug. 31, 2026 /PRNewswire/ - Fal.Con 2026 - Kroll, the leading independent provider of global financial and risk advisory solutions, today announced the launch of Kroll AI Automation Prioritization EXecution (APEX). A new capability developed on the CrowdStrike Falcon(R) platform, Kroll APEX enables organizations to make more informed cyber investment decisions by quantifying the expected operational effort, cost and business value of AI, automation and hybrid approaches. AI represents a significant and growing investment for organizations, yet many lack clear, measurable outcomes for CFOs to evaluate return on investment. "Worldwide spending on AI is forecast to total $2.59 trillion in 2026, a 47% increase year-over-year," according to Gartner, Inc.[1] Kroll APEX, built with Charlotte AI AgentWorks and Falcon Foundry, provides a data-driven decision framework that identifies, prioritizes and evaluates cyber use cases, enabling organizations to determine where AI, automation or a combination of both is most appropriate, before engineering work begins. Kroll works with clients to assess their cyber environment, organizational priorities and operational data through a structured discovery process. Using Kroll's experience across thousands of cyber engagements, alongside client-specific financial and operational inputs, APEX identifies and prioritizes opportunities, estimates implementation effort and expected returns and presents these insights through an intuitive dashboard embedded within the Falcon platform. Clients can use the capability as a strategic assessment or as part of an ongoing advisory engagement, continually refining cyber priorities as their organizations evolve. The result is greater confidence in cyber investment decisions and stronger alignment between security strategy and business objectives. By providing finance and security leaders with a shared view of investment priorities and expected outcomes, APEX helps organizations optimize technology spending, accelerate decision-making and build more resilient cyber programs. "Kroll APEX changes the conversation from 'Should we invest in AI?' to 'Where will AI, automation or human expertise deliver the greatest value?'," said Dave Burg, Global Group Head of Cyber and Data Resilience at Kroll. "With cyber risks mounting and spending accelerating, CFOs and CISOs are under growing pressure to bring financial discipline and operational insight together to make more informed cyber investment decisions. Boards are calling for greater clarity around these decisions, and Kroll provides the insight to prioritize initiatives based on measurable business outcomes rather than guesswork." Kroll APEX reflects the continued evolution of the strategic relationship between Kroll and CrowdStrike, expanding on Kroll's role as a founding member of CrowdStrike's Charlotte AI AgentWorks Ecosystem and Project QuiltWorks. By combining CrowdStrike's AI-native cybersecurity platform with Kroll's advisory expertise, implementation experience and proprietary methodologies, the collaboration enables organizations to make evidence-based decisions that align security investment with broader business priorities. "AI is redefining what's possible in cybersecurity, but value comes from applying it where it can have the greatest impact," said Daniel Bernard, Chief Business Officer at CrowdStrike. "Kroll is combining its deep advisory expertise with the power of Falcon to help customers turn AI ambition into measurable business outcomes. APEX is a great example of how our partners are building on CrowdStrike to drive innovation and deliver more value for customers." To discover how Kroll and CrowdStrike can help your organization maximize the value of its cyber investments, visit kroll.com/crowdstrike. About Kroll As the leading independent provider of financial and risk advisory solutions, Kroll leverages our unique insights, data and technology to help clients stay ahead of complex valuation demands. Kroll's team of more than 6,500 professionals worldwide continues the firm's nearly 100-year history of trusted expertise spanning risk, governance, transactions and valuation. Our advanced solutions and intelligence provide clients the foresight they need to create an enduring competitive advantage. At Kroll, our values define who we are and how we partner with clients and communities. Learn more at kroll.com. [1] Gartner Press Release, "Gartner Forecasts Worldwide AI Spending to Grow 47 Percent in 2026," 19 May 2026. https://www.gartner.com/en/newsroom/press-releases/2026-05-19-gartner-forecasts-worldwide-ai-spending-to-grow-47-percent-in-2026. GARTNER is a trademark of Gartner, Inc. and/or its affiliates SOURCE Kroll

PR Newswire
Aug 31st, 2026
Kroll launches APEX to help firms measure ROI on $2.59T AI spending

Kroll has launched APEX, a capability built on CrowdStrike's Falcon platform that helps organisations evaluate the return on investment from AI and automation in cybersecurity. The tool provides a data-driven framework to identify and prioritise cyber use cases, estimating implementation effort and expected returns before engineering work begins. APEX addresses growing pressure on CFOs and CISOs to justify cyber spending. According to Gartner, worldwide AI spending is forecast to reach $2.59 trillion in 2026, up 47% year-over-year. The capability uses Kroll's experience from thousands of cyber engagements alongside client-specific data to recommend where AI, automation, or human expertise will deliver the greatest value. Results are presented through a dashboard embedded within the Falcon platform. Dave Burg, Kroll's Global Group Head of Cyber and Data Resilience, said APEX brings financial discipline and operational insight together to support more informed investment decisions based on measurable business outcomes.

Consultancy.com.au
Aug 9th, 2026
Cybersecurity veterans launch new Melbourne consultancy MosaicalAI.

Cybersecurity veterans launch new Melbourne consultancy MosaicalAI. 09 August 2026 Consultancy.com.au Former Tesserent senior partner Mark Jones has launched a new AI consultancy in Melbourne alongside fellow cybersecurity expert Alexandre Medarov, which the pair have dubbed MosaicalAI. The motivation behind the launch of MosaicalAI is to support organisations in forging ahead with AI while ensuring the appropriate back-stops are still in place, with its services grouped around leadership coaching, design, build, security, and governance. Together the pair bring over five decades of combined industry experience to their new venture, with Jones most recently working as a director at Thales following its ~$175 million Tesserent acquisition and Medarov leading another AI start-up, dig8italX. "Move too slow and lose the market; move too fast and risk the business," goes the company pitch, with Jones stating; "We started MosaicalAI to help Australian businesses move quickly with AI, but without losing visibility, accountability or control. The AI opportunity is huge, but it needs to be done with the right people, workflows, and governance placed around it." Prior to his five years between Tesserent and Thales (which just sold off its local managed cloud services business to Interactive), Jones served as deputy CISO at Medibank, before which he was A/NZ cyber risk leader at Kroll and spent time in senior roles at a number of energy and financial services firms including Jemena and ANZ in a career dating back to Deloitte in 1998. Medarov meanwhile started his career with a stint at Accenturein Germany, and has since 2006 spent time at Dell EMC, both the University of Auckland and Monash, and in a senior cybersecurity role at Allianz back in Munich, where he had led the locally-based AI security consultancy dig8ital and its off-shoot as CISO and managing director since 2017 but most recently out of London. Now the pair have put their expertise and brains together to form MosaicalAI in Melbourne, which takes its name from the 'mosaic' of, brace yourselves, an AI operating layer "comprised of the tools, portals, reports, and decision surfaces a customer's team uses", including "agents, workflow logic, hand-offs, fallback paths, approvals, and routing and system actions," among other stuff. "Our view is that AI needs to be built with the same discipline that cyber has learned the hard way as to visibility, governance, accountability and clear ownership," Jones says. "There's a lot of noise around AI right now, but for executives, leaders and teams, I think it comes down to two fears: people are not ready, and businesses do not have the right team to build bespoke AI capability." That is where MosaicalAI comes in, the start-up says; "Our work is practical and hands on. We help clients engage their people, build AI into their business, and govern it from day one. We are already working with mid- and upper-middle market firms, and want to help them move at AI speed without creating the technical debt, governance mess, or loss of control that comes from rushing in blindly."

Insolvency Insider
Jul 31st, 2026
Moves and promotions - week of 27 july, 2026.

Moves and promotions - week of 27 july, 2026. Helen Bates has joined Brabners in Leeds as an Insolvency & Restructuring Partner. Helen was previously with Freeths. Read more. Graeme Bain has been promoted to Partner and Head of Restructuring at Johnston Carmichael. Read more. Stuart Deacon and Jonathan Thielmann have joined Kroll in London as Managing Directors. Stuart was previously with A&M, while Jonathan was previously with Interpath. Read more.

El Confidencial
Jul 15th, 2026
Kroll acquires German competition economics firm ABC economics to strengthen cartel expertise

Kroll has acquired ABC economics, a Berlin-based competition economics boutique founded by economist Frank Maier-Rigaud. The German firm specialises in complex transaction advice, damages quantification, cartels, state aid, and telecommunications and energy regulatory matters. ABC economics has around 30 staff and revenues below €10 million annually. The acquisition aims to create synergies across Europe, as competition cases and cartel damage claims often originate with national authorities or the European Commission before branching into claims across multiple member states. This marks Kroll's second acquisition in disputes within a year, following its purchase of arbitration boutique Global Project Strategy in March 2025. The expansion forms part of Kroll's growth strategy under private equity owners Stone Point and Further Global, which acquired the firm in 2020 for $4.2 billion.