About Man Group

Man Group is a global alternative investment management firm focused on pursuing outperformance for sophisticated clients via our Systematic, Discretionary and Solutions offerings. Powered by talent and advanced technology, our single and multi-manager investment strategies are underpinned by deep research and span public and private markets, across all major asset classes, with a significant focus on alternatives. Man Group takes a partnership approach to working with clients, establishing deep connections and creating tailored solutions to meet their investment goals and those of the millions of retirees and savers they represent.

The Team

Man Group’s business is powered by sophisticated technology with AI accelerating the next generation of transformation. Our technology stack is built on modern open-source components, both enabling day-to-day research and development, and supporting our 24hr trading. With adoption of AI-agents we are investing in security as a first-class concern. Man has a sophisticated AI platform – MAIA – that offers the best foundation models on our modern technology stack. As agents become more powerful, the security platform which supports safe agentic workflows is critical. This senior role will own the security architecture from end-to-end, setting the technical direction for the security platform. This is a hands-on leadership role. You will set direction, make and document key design decisions and stay close to the engineering, building prototypes and reviewing code alongside the engineers who deliver it.

Role Responsibilities

Architecture and Direction * Define and own the target security architecture (components, services and APIs) for internal applications and platforms, covering identity, authorisation and secrets. * Set the Zero Trust roadmap: user and machine identity, just-in-time and least-privilege access, and policy enforcement at the point of use. * Make and record architectural decisions, balancing risk, delivery speed and operating cost. * Publish reference designs and paved-path patterns so that the default for teams is also the secure one.

Engineering Leadership * Lead the design of the security policy engine for scoped time-bound system and data access. * Design and build the platform APIs that applications, AI agents and users call. * Mentor engineers and lead design reviews.

Collaboration * Work with IAM, Infosec, Security Operations and Infrastructure teams so that controls can be monitored, detected and audited. * Working with Developer, Infrastructure and AI platform teams to ensure solutions balance the security and agility requirements of Man. * Explain risk clearly to engineers, senior leadership and non-technical stakeholders, and support audit and regulatory work.

You'll thrive in our working environment that champions equality of opportunity. Your unique perspective will contribute to our success, joining a workplace where inclusion is fundamental and deeply embedded in our culture and values. Through our external and internal initiatives, partnerships and programmes, you'll find opportunities to grow, develop your talents, and help foster an inclusive environment for all across our firm and industry. You'll have opportunities to make a difference through our charitable and global initiatives, while advancing your career through professional development, and with flexible working arrangements available too. Like all our people, you'll receive two annual 'Mankind' days of paid leave for community volunteering. Our comprehensive benefits package includes competitive holiday entitlements, pension/401k, life and long-term disability coverage, group sick pay, enhanced parental leave and long-service leave. Depending on your location, you may also enjoy additional benefits such as private medical coverage, discounted gym membership options and pet insurance.

Required

  • Significant experience in security engineering or architecture, including end-to-end ownership of security architecture for production platforms.
  • Strong Python skills; comfortable with Bash, SQL and log query languages.
  • Policy-as-code (e.g., OPA/Rego, Kyverno, Cedar, OpenFGA, SPIFFE/SPIRE).
  • Infrastructure-as-code and GitOps (Terraform, Ansible, Helm).
  • Deep understanding of authentication, authorisation and secrets management (OIDC/OAuth, Azure AD/Entra ID, vault, Keycloak) and of access control models.

Desirable

  • Security of AI agents and LLM applications (delegated access, tool-use authorisation, prompt injection).
  • Hands-on experience with Kubernetes, Linux and containerised environments, including network policies.
  • Strong grasp of network security controls: firewalls, WAFs, segmentation, TLS termination and egress filtering.
  • A structured approach to threat modelling and risk assessment, and the ability to explain risk clearly to any audience.
  • Experience in financial services or another regulated environment.
Man Group

Man Group