Grant Thornton

Cybersecurity M&A Manager

Grant Thornton$161K — $202K *
Business Services
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in Cybersecurity, IT, Computer Science, or related field
  • Minimum 5 years of relevant cybersecurity experience
  • CISSP, CISM, ISACA, CRISC, or similar certifications
  • Strong understanding of compliance frameworks (NIST, ISO, PCI-DSS)
  • Demonstrated experience in Technology M&A and Cyber Due Diligence
  • Excellent executive communication and presentation skills

Responsibilities

  • Lead cybersecurity due diligence and privacy assessments for clients
  • Evaluate security governance and risk management programs
  • Conduct cybersecurity maturity assessments using established frameworks
  • Develop remediation roadmaps and control enhancement recommendations
  • Translate technical findings into actionable insights for clients
  • Support integration planning and cybersecurity strategy initiatives
  • Manage client relationships and mentor junior team members

Benefits

  • Personalized benefits that cater to diverse employee needs
  • Comprehensive medical, dental, and vision insurance plans
  • Employee assistance program available to all staff
  • Discretionary annual bonus based on performance
  • Paid sick leave and holiday compensation for employees
Full Job Description
Job Description

As a Cyber M&A Manager, you will get the opportunity to lead cyber due diligence, privacy assessments, and cybersecurity risk engagements for private equity firms, strategic acquirers, and portfolio companies, helping clients identify risks that may impact deal value, structure, or integration planning. Candidates should have experience assessing cybersecurity, privacy, cloud security, IAM, regulatory compliance, and third-party risk, while translating technical findings into business and transaction-focused insights. This individual will also manage client relationships, mentor teams, contribute to business development efforts, and support the continued growth of our Cyber M&A practice.

From day one, you'll be empowered by the greater Cyber & Risk team to help clients make the moves that will help them achieve their vision and help you achieve more, confidently.

Your day-to-day may include:
  • Adhere to the highest degree of professional standards and strict client confidentiality
  • Lead cybersecurity and privacy assessments across diverse industries and client environments.
  • Evaluate security governance, risk management, privacy, identity and access management, cloud security, third-party risk, incident response, and regulatory compliance programs.
  • Conduct cybersecurity maturity assessments utilizing frameworks such as:
    • NIST Cybersecurity Framework (CSF)
    • NIST 800-53
    • CIS Controls
    • ISO 27001
    • HIPAA
    • GDPR
    • CCPA/CPRA
  • Develop actionable remediation roadmaps, maturity improvement plans, and control enhancement recommendations.
  • Support cybersecurity strategy, risk governance, and transformation initiatives.
  • Lead cyber due diligence workstreams for buy-side, sell-side, and carve-out transactions.
  • Assess target company cybersecurity posture and identify transaction-related risks that may impact valuation, deal structure, integration strategy, or investment thesis.
  • Analyze:
    • Security governance and oversight
    • Control effectiveness
    • Identity and access management
    • Cloud and infrastructure security
    • Vulnerability management
    • Privacy and regulatory compliance
    • Third-party and supply chain risk
    • Incident history and breach exposure
  • Manage Information Request Lists (IRLs) and Due Diligence Requests (DDLs).
  • Translate technical findings into transaction-relevant insights for investors, executives, and deal teams.
  • Quantify cyber risks, remediation costs, and integration considerations.
  • Support post-close integration planning, Day 1 readiness, TSA assessments, separation planning, and 100-day cybersecurity roadmaps.
  • Assist clients in planning and executing remediation plans identified in assessment activities
  • Work with the client to plan an engagement strategy, define objectives, and address technology-related controls risks and issues
  • Proactively interact with key client management to gather information, resolve problems, and make recommendations for improvements
  • Ability to manage multiple engagements and competing priorities in a rapidly growing, fast-paced, interactive, results-based team environment
  • Participate in professional development activities and training sessions on regular basis
  • Manage the team comprising of seniors and associates and maintain professionalism across team
  • Other job duties as assigned

You have the following technical skills and qualifications:
  • Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or a related field is required
  • Minimum 5 years of related cybersecurity experience in a similar consulting practice or function
  • CISSP, CISM, ISACA, CRISC or other related certifications required
  • Understanding of Industry Standards/frameworks such as COBIT, NIST, ISO 27001,and PCI-DSS etc. required
  • Demonstrated experience supporting Technology M&A, Cyber Due Diligence, Technology Due Diligence, Transaction Advisory, or Private Equity portfolio initiatives.
  • Strong understanding of:
    • Cybersecurity governance and risk management
    • Privacy and data protection programs
    • Cloud security
    • Identity and access management
    • Third-party risk management
    • Incident response and resilience
  • Experience leading client-facing engagements and managing teams.
  • Strong executive communication and presentation skills.
  • Exceptional client service, communication, analytical, organizational and project management skills
  • Ability to execute multiple engagements and completing priorities in a rapidly growing team environment
  • Can travel as needed.

The base salary range for this position is between $161,920 and $202,400. Placement within the pay range is at Grant Thornton's discretion, and it is based on multiple factors, including but not limited to, job -related knowledge/skills, experience, business needs, progression within the role, geographic location, and internal equity. At Grant Thornton, compensation decisions are dependent upon the facts and circumstances of each position and candidate.

Benefits:

We understand that your needs, responsibilities and experiences are different, and we think that's a good thing. That's why we support you with personalized and comprehensive benefits that recognize and empower all the identities, roles and aspirations that make you, well, you. For an overview of our benefit offerings, please visit: https://www.grantthornton.com/careers/rewards-and-benefits

  • Benefits for internship positions: Grant Thornton interns are eligible to participate in the firm's medical, dental and vision insurance programs and the firm's employee assistance program. Interns also receive a minimum of 72 hours of paid sick leave, and are paid for firm holidays that fall within their internship period.
  • Benefits for seasonal employee positions: Grant Thornton seasonal employees are eligible to participate in the firm's medical, dental and vision insurance programs and the firm's employee assistance program. Seasonal employees may also be eligible to participate in the firm's 401(k) savings plan and employee retirement plan in accordance with applicable plan terms and eligibility requirements. Seasonal employees receive a minimum of 72 hours of paid sick leave.


Grant Thornton employees may be eligible for a discretionary, annual bonus based on individual and firm performance, subject to the terms, conditions and eligibility criteria of the applicable bonus plan or program. Interns and seasonal employees are not eligible for bonus compensation.

About Grant Thornton

Grant Thornton LLP is the American member firm of Grant Thornton International, the seventh largest accounting network in the world by combined fee income. Grant Thornton LLP is the sixth largest U.S. accounting and advisory organization. The firm operates 59 offices across the US with approximately 8,500 employees, 550 partners, and produces annual revenue in excess of US$1.9 billion. During the 2022 Russian Invasion of Ukraine, The Times reported that Grant Thornton is in line to earn millions of pounds for acting as trustees in a bankruptcy case on behalf of the Russian state-owned DIA, who bypassed sanction regimes to obtain funds and assets from abroad in order to fund the war in Ukraine.
Learn more about Grant Thornton

Similar Jobs

More Jobs at Grant Thornton

More Business Services Jobs

Find similar Cybersecurity M&A Manager jobs: