Chief Information Security Officer
About Man Group
Man Group is a global alternative investment management firm focused on pursuing outperformance for sophisticated clients via our Systematic, Discretionary and Solutions offerings. Man Group is headquartered in London, manages $227.6 billion* and operates across multiple offices globally. Man Group plc is listed on the London Stock Exchange under the ticker EMG.LN and is a constituent of the FTSE 250 Index. Required skills: A builder mindset, comfortable with balancing competing priorities, Demonstrable experience in a senior information security role, ready to step into a full CISO mandate, Deep technical credibility in information security, able to operate at an architectural level and get into the weeds on implementation, Proven ability to drive change outside of a direct reporting line, influencing technology, operations, and business teams to adopt security standards, Strong communicator, comfortable presenting to boards and equally comfortable in a technical design review. Preferred skills: CISSP certification, Experience with identity governance platforms and large-scale IAM transformation programmes, Familiarity with infrastructure-as-code environments (Terraform, GitOps workflows), Experience with hybrid identity environments (Active Directory, Entra ID, SSO platforms), Experience defining security frameworks for emerging technology enablement, Background in a regulated industry, with an appreciation for the governance, operational, and compliance requirements that come with it. Technologies: cloud platforms (e.g., Azure or AWS) and containerization (e.g., Docker, Kubernetes). Responsibilities: Own the information security strategy, aligning security investment to the firm's risk appetite, Drive security culture and awareness across the firm through training, engagement, and communications, Set and enforce security standards across technology, operations, and business departments, not just within InfoSec, Work with teams across the organisation to model secure processes and embed security into their workflows, Enable the safe adoption of AI and emerging technologies by defining practical security guardrails, Own the Information Security and IAM Risks and Controls Self-Assessment (RCSA), ensuring that risks are identified, controls are documented and remediation is tracked, Own the IAM strategy and transformation roadmap, driving the migration from legacy provisioning to a modern, governed identity platform, Directly oversee the identity governance implementation, including application onboarding, lifecycle automation, and access controls, Remediate audit findings related to identity and access management, Chair the Information Security Steering Committee, Present security posture, risk, and programme updates to boards and the Risk and Finance Committee, Provide oversight of third-party risk management in coordination with the dedicated TPRM team, Support SOC-1 audit processes. Seniority: CISO. Domain: Information Security, Identity & Access Management.