
Man Group · London
About Man Group Man Group is a global alternative investment management firm focused on pursuing outperformance for sophisticated clients via our Systematic, D...
About Man Group
Man Group is a global alternative investment management firm focused on pursuing outperformance for sophisticated clients via our
Systematic, Discretionary and Solutions offerings. Powered by talent and advanced technology, our single and multi-manager
investment strategies are underpinned by deep research and span public and private markets, across all major asset classes, with a
significant focus on alternatives. Man Group takes a partnership approach to working with clients, establishing deep connections
and creating tailored solutions to meet their investment goals and those of the millions of retirees and savers they represent.
Headquartered in London, we manage $228.7 billion* and operate across multiple offices globally. Man Group plc is listed on the
London Stock Exchange under the ticker EMG.LN and is a constituent of the FTSE 250 Index. Further information can be found at
www.man.com
At Man Group, we respect your privacy and we are committed to protecting and safeguarding your Personal Data. We have developed
policies and processes which are designed to provide for the security and integrity of your Personal Data. We are committed to
Processing your Personal Data fairly and lawfully, and being open and transparent about such Processing. For further information
on how we process your data, please see the privacy notice for applicants here
The Team
We are looking for a CISO to take full ownership of Information Security and Identity & Access Management at Man Group. This is a
leadership role that is as much about driving change across the firm as it is about running the security function. They will set
standards, influence behaviour, embed security into business processes, and work with departments across the organisation to raise
the bar on how Man Group manages risk.
A Deputy CISO will own day-to-day security operations and policy, allowing the CISO to focus on identity transformation,
standards, governance, and driving security culture firm-wide.
Reporting to the Head of Enterprise Risk, the CISO will be responsible for overseeing Identity and Access Management (IAM)
Programme, IAM BAU, and Information Security.
Role Responsibilities
Strategy & Standards
are documented and remediation is tracked
Identity & Access Management
platform
controls and defining central APIs
Governance & Reporting
Key Competencies
Essential
understanding of modern open-source based application design
adopt security standards
Advantageous
with itith cloud platforms (e.g., Azure or AWS) and containerization (e.g., Docker, Kubernetes)
Inclusion, Work-Life Balance and Benefits at Man Group
You'll thrive in our working environment that champions equality of opportunity. Your unique perspective will contribute to our
success, joining a workplace where inclusion is fundamental and deeply embedded in our culture and values. Through our external
and internal initiatives, partnerships and programmes, you'll find opportunities to grow, develop your talents, and help foster an
inclusive environment for all across our firm and industry. Learn more at www.man.com/diversity.
You'll have opportunities to make a difference through our charitable and global initiatives, while advancing your career through
professional development, and with flexible working arrangements available too. Like all our people, you'll receive two annual
'Mankind' days of paid leave for community volunteering.
Our comprehensive benefits package includes competitive holiday entitlements, pension/401k, life and long-term disability
coverage, group sick pay, enhanced parental leave and long-service leave. Depending on your location, you may also enjoy
additional benefits such as private medical coverage, discounted gym membership options and pet insurance.
Equal Employment Opportunity Policy
Man Group provides equal employment opportunities to all applicants and all employees without regard to race, color, creed,
national origin, ancestry, religion, disability, sex, gender identity and expression, marital status, sexual orientation, military
or veteran status, age or any other legally protected category or status in accordance with applicable federal, state and local
laws.
Man Group is a Disability Confident Committed employer; if you require help or information on reasonable adjustments as you apply
for roles with us, please contact TalentAcquisition@man.com.
WHO WE ARE At Trustly, we're building a smarter, faster, and more secure financial future by revolutionizing the world of payments. As a global leader in Open Banking Payments, we are establishing Pay by Bank as the new standard at checkout, providing unparalleled freedom, speed, and ease to millions of consumers and merchants worldwide. Our Ambition: To build the world’s most disruptive payment network and redefine what the payment experience should feel like. Trustly is a global team of innovators, collaborators, and doers. If you are driven by a strong sense of purpose and thrive in a dynamic, entrepreneurial, and high-growth environment, join us and be part of a team that’s transforming the way the world pays. About the team The Security & Information Technology organization is the backbone of Trustly’s commitment to global financial trust. We are responsible for architecting a resilient security posture and a seamless, AI-native workplace that enables our global workforce to innovate at speed. Our mission is to protect millions of transactions while ensuring that our internal technology ecosystem is as fast, secure, and disruptive as the payment solutions we build for our merchants and customers. About the role Reporting directly to the Global CTO, the Chief Information Security Officer (CISO) & Head of Information Technology will serve as Trustly’s most senior security and internal technology operations executive. This is a dual-scope role: you will own the full information security program - strategy, architecture, risk, and response, while also leading the IT organization that underpins Trustly’s global workforce, including driving our AI productivity journey. You will be a key voice to the C-suite and a trusted advisor to the Board on all matters related to security posture, cyber risk, and technology resilience. You will operate at the intersection of a high-growth, globally distributed fintech and a fast-evolving regulatory and threat landscape, making decisions that have direct implications for our customers, our partners, and our business.
TL;DR: We're looking for an exceptional security leader and executive to build and run the function that will make Lovable the most trusted AI-powered software creation platform Why Lovable? Lovable lets anyone and everyone build software with any language. From solopreneurs to Fortune 100 teams, millions of people use Lovable to transform raw ideas into real products - fast. We are at the forefront of a foundational shift in software creation, which means you have an unprecedented opportunity to change the way the digital world works. Lovable-built applications and websites are visited hundreds of millions of times a month, and our enterprise footprint is compounding fast. And we're just getting started. We're a small, talent-dense team building a generation-defining company from Stockholm. We value extreme ownership, high velocity, and low-ego collaboration. We seek out people who care deeply, ship fast, and are eager to make a dent in the world. What we're looking for 10+ years in information security, including 3+ years leading security at a high-growth SaaS or platform company A track record of building security programs from the ground up, including scaling through SOC 2, ISO 27001, or equivalent enterprise frameworks Deep technical fluency across cloud, application, and infrastructure security — comfortable going hands-on, not just directing others Experience partnering with engineering, legal, and sales to close enterprise deals and pass customer due diligence The judgment and communication skill to translate technical risk into business decisions for an executive team and board Experience securing platforms that generate or execute user-created code, or prior experience as a founding security hire at a startup What you'll do Own Lovable's security strategy and risk management framework end to end, reporting directly to the executive team Build and lead the security organization, starting with our first security engineers and analysts Get Lovable certified against the frameworks our enterprise customers require, including SOC 2 Type II and ISO 27001 Own application, infrastructure, and cloud security — secure SDLC, vulnerability management, incident response Partner with Sales and Customer Success to move security reviews and questionnaires from blocker to closer Build the security-first culture and training that lets a fast-moving engineering org stay fast without cutting corners Be the person our team, our customers, and regulators call when something needs an answer About your application Please submit your application in English. It's our company language, so you'll be speaking lots of it if you join. We treat all candidates equally - if you're interested, please apply through our careers portal.
At Morgan & Morgan, the work we do matters. For millions of Americans, we’re their last line of defense against insurance companies, large corporations or defective goods. From attorneys in all 50 states, to client support staff, creative marketing to operations teams, every member of our firm has a key role to play in the winning fight for consumer rights. Our over 6,000 employees are all united by one mission: For the People. About the Role Morgan & Morgan is the largest plainti/-side law firm in the United States, with 140+ offices nationwide, more than 1,000 lawyers, and over $30 billion recovered for clients. Our scale is matched by a strong culture of speed, innovation, and in-house technology development, where software, data, and AI-enabled platforms are core to how we serve clients and win cases. We operate in a high-stakes, litigation-driven environment where technology decisions directly affect outcomes, reputation, and client trust. As a result, cybersecurity is not a support function it is a core business capability. We are seeking a Chief Information Security Officer (CISO) to lead a modern, business-aligned security program that protects highly sensitive data while enabling rapid software development, AI-driven workflows, and continuous innovation across legal-technology platforms. This role is designed for a security executive who believes strong security should accelerate innovation, not constrain it. The CISO will partner deeply with engineering, product, legal, and operations leaders to embed security into fast-moving delivery cycles through pragmatic guardrails, clear risk ownership, and modern security architecture. Security at Morgan & Morgan plays a direct role in protecting the trust of the people we represent—ensuring our teams can fight for clients without distraction, delay, or doubt. This is an on-site executive leadership role, requiring consistent presence in our Orlando headquarters and active engagement across firm offices. We believe strong security should enable innovation, not slow it down. Our approach is grounded in risk-informed decision-making, pragmatic controls, and shared ownership across technology and the business. We build security as scalable guardrails designed to support rapid software development, AI-driven workflows, and continuous improvement without sacrificing client trust. Key Responsibilities Security Strategy & Risk Leadership • Define and execute a business-aligned cybersecurity strategy that supports firm growth, rapid delivery, and national scale • Establish risk-informed security governance that enables fast, confident decision-making in a high-volume, litigation-driven environment • Translate cyber risk into clear business impact for executive leadership and the Board • Guide security investment decisions that balance velocity, resilience, and client trustRisk Management & Compliance • Lead firm-wide risk assessments, threat modeling, and control maturity evaluations • Own end-to-end incident response strategy, breach readiness, tabletop exercises, and post-incident learning • Partner closely with Legal, Privacy, and Compliance leaders to ensure: • Protection of sensitive client and case data • Defensible security practices suitable for litigation discovery • Alignment with regulatory, contractual, and ethical obligations • Oversee third-party and vendor security risk management at national scale Security Architecture & Engineering Enablement • Design and evolve a scalable security architecture that supports internally built platforms, modern development practices, and AI-enabled legal technology • Embed security into: • Agile software development and CI/CD pipelines • Cloud-native platforms and SaaS ecosystems • AI-enabled legal workflows and analytics platforms • Implement Zero Trust principles using pragmatic, developer-friendly controls • Ensure security controls function as guardrails, not bottlenecks, for engineers and attorneys Security Operations • Oversee security operations including: • Identity & Access Management (IAM) • Endpoint, network, and cloud security • Security monitoring, detection, and response • Continuously improve detection, response time, and operational resilience • Ensure security operations remain resilient and e/ective during high-volume, time- sensitive legal operations • Ensure security capabilities scale e/ectively across 140+ o/ices and 1,000+ lawyersLeadership & Culture • Build, lead, and mentor a high-caliber, hands-on security organization • Establish strong operating models between Security, IT, Engineering, and the business • Set clear expectations and a high bar for execution, accountability, and follow-through across the security function • Champion a culture where security is designed in early, not bolted on late • This role requires a leader who is comfortable operating close to the technology engaging directly with teams, systems, and incidents when needed • Act as a visible, trusted executive leader approachable, decisive, and credible Required Experience • 10+ years in cybersecurity, including senior leadership roles in large, complex environments • Proven success leading security programs in high-data-sensitivity, fast-moving organizations • Demonstrated ability to communicate cyber risk clearly to executive leadership and Boards • Strong working knowledge of: • NIST Cybersecurity Framework (CSF) and/or ISO 27001 • Zero Trust architecture • Incident response and crisis leadership • Cloud and SaaS security at scaleExecutive Mindset • Business-first approach to security focused on outcomes, not checklists • Comfort making tradeo/s and defending decisions at the executive level • Calm, credible leadership during high-pressure situations • High integrity, sound judgment, and strong ethical foundationPreferred Qualifications • CISSP, CISM, or equivalent credentials • Experience supporting AI platforms, analytics, or large-scale digital transformation • Proven partnership with CIOs, General Counsel, and Compliance leadership • Background in product-led, technology-driven organizations (legal tech, fintech, SaaS, or similar) Why Morgan & Morgan • Unmatched scale: Secure operations across 140+ offices nationwide • Real impact: Protect systems supporting more than $30 billion recovered for clients • Innovation focus: Security embedded in rapid software delivery and AI-driven legal tech • Executive influence: Direct involvement in firm-wide risk and investment decisions • Leadership commitment: Security treated as a strategic business capability What We Offer Morgan & Morgan offers a people-first environment grounded in high performance. We provide comprehensive medical, dental, vision, and mental health benefits; generous paid time off; strong onboarding and leadership support; and a culture that values accountability, growth, and results. You’ll work alongside driven professionals who expect excellence and support one another in achieving it. Benefits Morgan & Morgan is a leading personal injury law firm dedicated to protecting the people, not the powerful. This success starts with our staff. For full-time employees, we offer an excellent benefits package including medical and dental insurance, 401(k) plan, paid time off and paid holidays. Equal Opportunity Statement Morgan & Morgan provides equal employment opportunities to all employees and applicants for employment and prohibits discrimination and harassment of any type without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state or local laws. E-Verify This employer participates in E-Verify and will provide the federal government with your Form I-9 information to confirm that you are authorized to work in the U.S. If E-Verify cannot confirm that you are authorized to work, this employer is required to give you written instructions and an opportunity to contact Department of Homeland Security (DHS) or Social Security Administration (SSA) so you can begin to resolve the issue before the employer can take any action against you, including terminating your employment. Employers can only use E-Verify once you have accepted a job offer and completed the I-9 Form. Privacy Policy Here is a link [https://www.forthepeople.com/privacy-policy/] to Morgan & Morgan's privacy policy.