Director of Risk
- Salary
- $197K–$270KUSD
- Hiring from
- United States
- Work type
- Hybrid
- Posted
- Sep 24, 2026
Heidrick & Struggles is the world’s foremost advisor on executive leadership, driving superior client performance through premier human capital leadership advisory services. For more than 70 years, we’ve delivered value for our clients by leveraging unrivaled expertise to help organizations discover and enable outstanding leaders and teams. Learn more at www.heidrick.com
Job Description:
Who We Are:
Heidrick & Struggles is a premier provider of global leadership advisory and on-demand talent solutions, serving the senior-level talent and consulting needs of the world's top organizations. In our role as trusted leadership advisors, we partner with our clients to develop future-ready leaders and organizations, bringing together our services and offerings in executive search, diversity and inclusion, leadership assessment and development, organization and team acceleration, culture shaping and ondemand, independent talent solutions. Heidrick & Struggles pioneered the profession of executive search more than 70 years ago. Additional information on the firm can be found at www.heidrick.com.
Role:
The Director of Risk is a senior role within the Legal function, accountable for two core pillars of the firm's risk management approach: client/engagement risk, including public sector and government related engagements, and vendor and third-party risk. The role designs, embeds and continuously improves a risk framework that is deliberately proportionate to the size, complexity and global
footprint of the firm — practical, commercially enabling and defensible, rather than bureaucratic. The Director owns the firm's risk register, sets risk appetite and escalation thresholds with senior leadership, and acts as the firm's subject matter expert on federal contractor and public sector obligations. This is a highly collaborative, cross-functional role that partners with Security, Procurement, Finance, Client Operations, Contract Administration and the client-facing business.
Location: Chicago, Washington or would consider remote. Reports to: Assistant General Counsel based in Sydney. Occasional domestic travel may be required.
Responsibilities:
Client/Engagement Risk (including Public Sector)
• Work alongside the Assistant General Counsel to own the end-to-end client/engagement risk and vetting framework, including risk criteria, tiering, vetting standards, escalation thresholds and decision rights for client acceptance and continuance.
• Act as the escalation point for heightened-risk clients, candidates and engagements — assessing sanctions, politically exposed person, adverse media, conflicts of interest, and reputational exposure — and make clear accept, decline or conditional-acceptance recommendations to Legal leadership.
• Partner with Client Operations on bid or no-bid decisions and RFP risk review.
• Establish and maintain risk-based contracting principles, escalation thresholds and approval requirements for non-standard or high-risk client terms.
• Maintain a complete and defensible audit trail of client risk decisions, and support government audits, inspector general and agency inquiries, and client-initiated compliance reviews and due diligence questionnaires.
• Monitor changes to sanctions, export control and screening regimes (OFAC, EU, UK OFSI and equivalents) and to sector-specific regulation affecting our clients, and translate these into practical updates to the vetting criteria.
• Supervise and develop the client vetting workstream and the analysts who support it, driving consistency, quality and turnaround times that meet the commercial needs of the business.
US Federal Contracts Management & Compliance
• Develop and lead the risk review of public sector engagements across US federal, state, local, education, multilateral and non-US government clients, including internal mitigation measures and training for employees involved in these services.
• Own the contract administration lifecycle for US federal prime contracts from solicitation and award through performance, modification, renewal and closeout, maintaining complete and accurate contract files and obligation records.
• Review solicitations, awards, task orders and contract modifications to identify and operationalize applicable Federal Acquisition Regulation (FAR), Defense Federal Acquisition Regulation Supplement (DFARS), General Services Administration and other agency-specific requirements, clauses and reporting obligations.
• Partner with Legal, Finance, Security, Procurement, Human Resources, Client Operations and the business to implement and monitor compliance with federal contracting requirements, including ethics and conduct, procurement integrity, organizational conflicts of interest, safeguarding and cybersecurity, and other contract-specific obligations.
• Identify required subcontractor and vendor flow-down clauses, coordinate their incorporation into agreements, obtain required certifications and representations, and monitor subcontractor compliance throughout performance.
• Track contract changes, performance issues and potential noncompliance; assess disclosure, escalation and remediation requirements with Legal; and maintain a defensible record of corrective actions and management decisions.
Vendor and Third-Party Risk
• Work alongside Procurement to incorporate vendors into the Company’s due diligence framework;
• Partner with Procurement, Security, Finance and Legal to embed risk requirements into contracts, where needed.
Risk Framework, Governance and Reporting
• Own and maintain the enterprise, regional and functional risk registers — including risk
taxonomy, inherent and residual risk scoring, control mapping, named risk owners, mitigation plans and target dates — and drive regular refresh cycles with business and regional leaders.
• Prepare clear, decision-ready risk reporting, dashboards and heat maps for Legal leadership, the Executive Committee and the Audit and Risk Committee of the Board, including emerging risk and horizon scanning.
• Facilitate risk identification and assessment workshops across regions and functions, and strengthen first-line ownership and accountability for risk.
• Develop and deliver practical risk training, guidance notes and playbooks, and champion a pragmatic, commercially aware risk culture across the firm.
• Other duties as assigned.
Required Qualifications:
• Bachelor's degree.
• Minimum of six to ten years of relevant professional experience in risk management, compliance, governance or legal operations, gained in professional services, consulting or a comparable global commercial organisation.
• Demonstrated, hands-on expertise across both client or engagement risk and vendor or third-party risk, including establishing risk-based frameworks, escalation processes and governance.
• Prior experience supporting federal prime or subcontract work, or state and local government contracts.
• Strong working knowledge of and practical experience with interpreting and applying the Federal Acquisition Regulation (FAR) and the Defense Federal Acquisition Regulation Supplement (DFARS), as well as other FAR supplements (e.g., GSAM), together with a practical understanding of state, local and non-US public sector procurement
• Working knowledge of federal contractor compliance requirements relevant to a professional services environment, including ethics and business conduct, conflicts of interest, procurement integrity, lobbying restrictions, records retention, safeguarding of government information and other contract-specific obligations.
• Proven track record of building and maintaining risk registers, risk appetite statements, key risk indicators and board-level risk reporting.
• Strong commitment to ethics, integrity and sound judgment, with the ability to manage confidential and sensitive information responsibly.
• Skilled in gathering, analyzing and synthesizing data from multiple sources to identify key insights, risks and issues, with exceptional attention to detail.
• Demonstrated ability to translate risk requirements into operational processes, approval workflows, contract standards, playbooks, training and technology-enabled controls that are adopted by first-line business teams.
• Proven ability to influence and build trusted relationships with senior stakeholders across all levels and geographies of a global, matrixed organisation.
• Excellent organizational skills, with a demonstrated ability to work independently, manage competing priorities and operate across multiple time zones.
• Excellent communication skills — verbal, written and listening — including the ability to translate complex risk issues into clear, commercial recommendations.
• Highly proficient with technology tools, including GRC, third-party risk and screening platforms, the Microsoft Office suite, and utilizing technology and AI to help streamline and scale processes.
• Based in, or able to work on a hybrid basis from, the firm's Chicago or New York office.
Behavioral Competencies:
• Analytical thinking: assures that risks are evaluated, key issues are identified and detailed analysis is synthesized into clear recommendations.
• Sound judgment: balances risk and commercial opportunity, and knows when to escalate, when to advise and when to decide.
• Relationship building: takes the time to maintain relationships and create new ones, enjoys being part of a team and partners rather than polices.
• Driving results: manages projects, activities and resources according to business and team strategy effectively; multitasks effectively and efficiently.
• Focus on quality: possesses strong personal commitment to quality standards and meeting quality expectations.
• Creative thinking: stays open to new ideas and approaches and sets a personal example of seeking out new and better ways of doing things.
Preferred Qualifications:
• JD, MBA or other relevant advanced degree preferred.
• Professional certification such as CRMA, CRISC, CTPRP, CCEP, CIPP/US or ARM.
• Professional services, staffing or people-based consulting experience preferred.
• Experience operating in a global organisation with EMEA and APAC operations and associated regulatory obligations.
Pay Range Guidelines for this Position:
The salary range for this position is 197000 USD to 270000 USD. Compensation is based on several factors including but not limited to education, work experience and skills. In addition to your salary, Heidrick & Struggles offers discretionary bonuses (subject to eligibility requirements) and a comprehensive benefits package including: medical, dental, vision, disability leave, parental leave, paid time off and 401k contribution (all benefits are subject to eligibility requirements). Note: we have a location based compensation structure; there may be a different range for candidates in other locations.Heidrick & Struggles is an equal opportunity employer committed to hiring qualified protected veterans and individuals with disabilities. All qualified applicants will be considered for employment without regard to race, color, religion, creed, age, sex, national origin, gender identity or expression, sexual orientation, disability, marital status, veteran or military status, or citizenship status.