← All roles

Janus Henderson

AI Security Engineer

Tech

Location
London
Opened
Unknown
Closes
No date listed

JANUS HENDERSON ADMINISTRATION UK LIMITED is on the gov.uk register of licensed sponsors.

Rating: A rating

Routes: Global Business Mobility: Senior or Specialist Worker, Skilled Worker

A licence means the employer can sponsor; it does not promise this role is sponsored. Check the posting.

Does Janus Henderson sponsor UK visas? Licence and open roles

About the role

Why work for us? A career at Janus Henderson is more than a job, it’s about investing in a brighter future together. Our Mission at Janus Henderson is to help clients define and achieve superior financial outcomes through differentiated insights, disciplined investments, and world-class service. We will do this by protecting and growing our core business, amplifying our strengths and diversifying where we have the right. Our Values are key to driving our success, and are at the heart of everything we do: Clients Come First - Always | Execution Supersedes Intention | Together We Win | Diversity Improves Results | Truth Builds Trust If our mission, values, and purpose align with your own, we would love to hear from you! Your opportunity This is a hands-on security engineering role for people who are deep in cybersecurity and serious about AI. You will secure the AI systems we are building — AI-enabled applications, models, agents, and the platforms beneath them, across their full lifecycle — acting as a trusted advisor who helps define and evolve the firm’s AI security standards, patterns, and guardrails. The objective is not to create additional process, but to ensure our existing security capabilities evolve alongside AI adoption and remain effective at enterprise scale. Janus Henderson is undertaking a firm-wide AI transformation to become the most technologically sophisticated asset manager in the industry. Our AI capability sits in a single centralised function under the Head of AI, and AI Technology builds and runs it. This role sits in Information Security and reports to the Head of Security Engineering, while your day-to-day work is directed by AI Technology and prioritised against their roadmap. That split is deliberate: security policy, security architecture approval, and security risk acceptance stay with Infosec, and you are the person who exercises them for AI — close enough to the engineering to be useful, independent enough to say no. You will secure Nexus, our agentic workspace where employees and citizen developers build and run AI applications, agents, and shared skills; Accio, our centralised MCP server, which consumes other MCP servers and presents enterprise datasets through one governed interface; the AI model gateway and its routes to external model providers; and our Copilot services. Accio and Nexus matter most: both propagate permissions and data on a user’s or an agent’s behalf, so their trust boundaries have to hold when a request crosses several hops. Throughout, you will balance effective risk management against the velocity needed to deliver AI solutions that drive business value and growth. A secondary focus of the role is partnering with the wider Security function to identify opportunities to leverage AI and automation to improve efficiency, effectiveness, and risk reduction across security operations, engineering, assurance, and governance — so that the controls you design are enforced and evidenced automatically rather than through review meetings. What success looks like Security is designed into AI systems rather than appended. Engineers reach for an approved pattern instead of asking for a bespoke review. The controls you define are implemented as code and secure defaults by AI Engineering and AI Platforms, and you can show they are operating. AI-specific attacks are anticipated and tested for, and you can demonstrate what the firm is and is not exposed to. New models, tools, and Copilot features reach a security decision quickly through a repeatable risk-based path, and when an AI incident happens the lesson lands in a platform default rather than a report. Risk reduction and control effectiveness are evidenced through agreed KPIs, KRIs, and reporting rather than asserted. Your responsibilities Secure the AI estate by design Act as security design authority for AI systems, leading threat modelling, architecture review, and risk assessment for agentic applications, the model gateway, Accio, Nexus, and any novel or high-risk AI initiative, applying STRIDE, PASTA, MITRE ATT&CK, and MITRE ATLAS as appropriate. Define and evolve AI security standards, guardrails, governance controls, and secure-by-design patterns aligned with enterprise requirements and the firm’s risk appetite — co-designed with the Principal AI Architect as reusable, implementable guardrails, and implemented as code and secure defaults by AI Engineering and AI Platforms, working with the AI Governance Implementation Lead, who owns how they land on the platform. Design identity, entitlement, and secrets patterns for non-human identities — agents, tools, MCP servers, connectors, and service principals — with the Senior AI Platform Engineer and enterprise IAM, covering scoped permissions, credential lifetime, rotation, and least privilege across multi-hop requests. Set the trust boundaries and data-egress controls for the AI estate, including what may reach external model providers, and work with data protection owners on classification, DLP enforcement, privacy, and data governance obligations. Test, detect, and respond Run adversarial testing and AI red teaming against models, prompts, agents, and tool chains, covering prompt injection and indirect injection, model manipulation and hijacking, excessive agency, function-call abuse, data leakage from LLM outputs, and privilege escalation between agents. Build detections, security analytics, and telemetry for AI-specific abuse — anomalous tool invocation, credential misuse by agents, unusual data access, and exfiltration through model responses — and integrate them into the firm’s monitoring estate. Support security incident response for AI systems: triage, containment, forensics across prompts, tool calls, and agent decisions, and root cause, feeding each lesson back into platform defaults and evaluation suites. Own security testing in the AI delivery lifecycle, including static analysis, dependency and container scanning, secrets detection, and security gates in CI/CD, so issues surface before release. Assure AI adoption and third-party risk Co-own the risk-based security gate for onboarding new AI products, model providers, versions, and platform features with the Senior AI Platform Engineer and the AI Governance Implementation Lead, conducting security due diligence and risk assessment of AI vendors, platforms, and models — provenance, open-source components, tenancy and data-use terms, security advisories — and testing platform updates before rollout. Decide with the Senior AI Platform Engineer and the Principal AI Architect which Copilot features are released and to whom, withholding capability until the required controls are evidenced; review the solutions Forward Deployed Engineering builds and the platforms built with Percepta so neither reaches production without a security position; and set the guardrails for citizen developers and Copilot Studio makers with AI Enablement. Support Risk and Internal Audit with security evidence, exercise Infosec’s security-control approval and risk-acceptance position for AI, and escalate where residual risk exceeds appetite. Scale the security function with AI and automation Identify and deliver opportunities to apply AI and automation across security operations, engineering, assurance, and governance, building automation with code, APIs, scripting, orchestration platforms, or low-code technologies to automate response workflows, enrich incident data, assist with triage, and drive risk-based vulnerability management. Define and report the KPIs, KRIs, dashboards, and reporting that demonstrate risk reduction, control effectiveness, and operational improvement. Mentor security engineers on AI security and build enough AI literacy across Infosec that this role is not a single point of knowledge. What to expect when you join our firm Hybrid working and reasonable accommodations Generous Holiday policies Excellent Health and Wellbeing benefits including corporat
Apply on the employer's site

More open roles at Janus Henderson