Chief Information Security Officer
Man Group
| Company | Man Group |
| Category | Security |
| Location | London |
| Remote | On-site (inferred) |
| Employment | Not stated |
| Level | Executive |
| Salary | Not stated by the employer |
| Posted | 23 Apr 2026 |
| Last verified | 2 Aug 2026 |
| Source | Employer ATS (greenhouse) |
Description
About Man Group
Man Group is a global alternative investment management firm focused on pursuing outperformance for sophisticated clients via our Systematic, Discretionary and Solutions offerings. Powered by talent and advanced technology, our single and multi-manager investment strategies are underpinned by deep research and span public and private markets, across all major asset classes, with a significant focus on alternatives. Man Group takes a partnership approach to working with clients, establishing deep connections and creating tailored solutions to meet their investment goals and those of the millions of retirees and savers they represent.
Headquartered in London, we manage $228.7 billion* and operate across multiple offices globally. Man Group plc is listed on the London Stock Exchange under the ticker EMG.LN and is a constituent of the FTSE 250 Index. Further information can be found at www.man.com
At Man Group, we respect your privacy and we are committed to protecting and safeguarding your Personal Data. We have developed policies and processes which are designed to provide for the security and integrity of your Personal Data. We are committed to Processing your Personal Data fairly and lawfully, and being open and transparent about such Processing. For further information on how we process your data, please see the privacy notice for applicants here
* As at 31 March 2026
The Team
We are looking for a CISO to take full ownership of Information Security and Identity & Access Management at Man Group. This is a leadership role that is as much about driving change across the firm as it is about running the security function. They will set standards, influence behaviour, embed security into business processes, and work with departments across the organisation to raise the bar on how Man Group manages risk.
A Deputy CISO will own day-to-day security operations and policy, allowing the CISO to focus on identity transformation, standards, governance, and driving security culture firm-wide.
Reporting to the Head of Enterprise Risk, the CISO will be responsible for overseeing Identity and Access Management (IAM) Programme, IAM BAU, and Information Security.
Role Responsibilities
Strategy & Standards
Own the information security strategy, aligning security investment to the firm's risk appetite
Drive security culture and awareness across the firm through training, engagement, and communications
Set and enforce security standards across technology, operations, and business departments, not just within InfoSec
Work with teams across the organisation to understand existing process and embed secure access into existing systems
Enable the safe adoption of AI and emerging technologies by defining practical security guardrails
Own the Information Security and IAM Risks and Controls Self-Assessment (RCSA), ensuring that risks are identified, controls are documented and remediation is tracked
Identity & Access Management
Own the IAM strategy and transformation roadmap, driving the migration from legacy provisioning to a modern, governed identity platform
Directly oversee the identity governance implementation, including application onboarding, lifecycle automation, access controls and defining central APIs
Remediate audit findings related to identity and access management
Governance & Reporting
Chair the Information Security Steering Committee
Present security posture, risk, and programme updates to boards and the Risk and Finance Committee
Provide oversight of third-party risk management in coordination with the dedicated TPRM team
Support SOC-1 audit processes
Key Competencies
Essential
A builder mindset, comfortable with balancing competing priorities
Strong understanding of technical security implementations, trade-offs, APIs and architectural design patterns and a working understanding of