AI Security Engineer

Janus Henderson•Denver, CO
•Hybrid

About The Position

This is a hands-on security engineering role for individuals with deep cybersecurity expertise and a serious interest in AI. The role involves securing AI systems, including AI-enabled applications, models, agents, and their underlying platforms, throughout their entire lifecycle. The position acts as a trusted advisor, contributing to the definition and evolution of the firm’s AI security standards, patterns, and guardrails. The focus is on enhancing existing security capabilities to effectively support AI adoption at an enterprise scale, rather than introducing additional processes. Janus Henderson is undergoing a firm-wide AI transformation to become a leader in technological sophistication within the asset management industry. The AI capability is centralized under the Head of AI, with AI Technology responsible for its development and operation. This role resides within Information Security, reporting to the Head of Security Engineering, but day-to-day work is directed by AI Technology and prioritized according to their roadmap. This structure ensures that security policy, architecture approval, and risk acceptance remain with Information Security, while the engineer applies these principles to AI, maintaining close collaboration with engineering teams while retaining independence. Key areas of focus include securing Nexus (an agentic workspace for AI applications), Accio (a centralized MCP server for enterprise datasets), the AI model gateway, and Copilot services. Accio and Nexus are particularly important due to their role in propagating permissions and data, requiring robust trust boundaries. The role balances effective risk management with the need for rapid delivery of AI solutions that drive business value. A secondary objective is to collaborate with the broader Security function to leverage AI and automation for improving efficiency, effectiveness, and risk reduction across security operations, engineering, assurance, and governance, enabling automated control enforcement and evidence gathering.

Requirements

  • Strong cybersecurity experience across security engineering, application security, product security, cloud security, or security architecture.
  • Hands-on engineering background with a track record of protections that reached production.
  • Solid grasp of security engineering fundamentals, including common attack vectors, defence techniques, and threat modelling.
  • Hands-on experience assessing and securing GenAI, LLM, machine learning, agentic AI, and AI-enabled solutions throughout their lifecycle.
  • Proven ability to lead threat modelling, architecture reviews, and risk assessments for complex technology platforms and services.
  • Strong understanding of AI-specific threats, threat modelling methodologies, adversary frameworks, and risk assessment approaches (e.g., prompt injection, model manipulation, excessive agency, STRIDE, PASTA, MITRE ATT&CK, MITRE ATLAS).
  • Experience defining and evolving AI security standards, guardrails, governance controls, and secure-by-design patterns aligned with enterprise requirements and risk appetite.
  • Experience securing AI agents, MCP integrations, permissions, non-human identities, autonomous workflows, and AI platform integrations.
  • Cloud security depth, ideally Azure (identity and access management, service principals, workload identity, secrets management, RBAC, network controls, logging).
  • Experience securing application delivery, including secure SDLC, CI/CD controls, and code and dependency scanning.
  • Practical experience with AI and LLM systems (prompt engineering, retrieval-augmented generation, function calling, agent-based tools).
  • Proven ability to build and deploy automation using code, APIs, scripting, orchestration platforms, or low-code technologies (e.g., Python, workflow engines, SOAR), integrating security logs, AI models, and platform components.
  • Metrics-driven mindset, with experience defining KPIs, KRIs, dashboards, and reporting.
  • Strong stakeholder engagement and influencing skills, with the ability to translate technical risk into business impact and pragmatic controls.
  • Independence to hold a security position under delivery pressure.

Nice To Haves

  • Familiarity with AI security and governance frameworks including NIST AI RMF, OWASP Top 10 for LLM applications, MITRE ATLAS, ISO/IEC 42001, and the security provisions of the EU AI Act.
  • AI red teaming, adversarial testing, adversarial machine learning, model validation, or offensive security assessments applied to models and tool chains.
  • Experience securing enterprise AI platforms, model gateways, AI development environments, and AI engineering ecosystems.
  • Knowledge of AI security posture management, runtime protection, model monitoring, and AI governance tooling.
  • Knowledge of identity security, including IAM, PAM, identity governance, privileged access management, non-human identities, and workload identities.
  • Experience applying AI and automation to vulnerability management, detection engineering, threat detection, or security operations at scale.
  • Knowledge of security analytics, monitoring, and detection capabilities for AI systems and supporting infrastructure.
  • Understanding of privacy, data governance, regulatory, and responsible AI considerations (e.g., Microsoft Purview, DLP policy design, data classification).
  • Securing agentic workflows, including scoped permissions, approval patterns, and guarding against configuration drift caused by AI assistants.
  • Third-party or model supply-chain risk assessment.
  • Financial services or asset management experience.
  • A certification such as CISSP, GIAC, OSCP, or a cloud security qualification.

Responsibilities

  • Secure the AI estate by design, acting as the security design authority for AI systems.
  • Lead threat modeling, architecture review, and risk assessment for agentic applications, the model gateway, Accio, Nexus, and other AI initiatives, utilizing methodologies like STRIDE, PASTA, MITRE ATT&CK, and MITRE ATLAS.
  • Define and evolve AI security standards, guardrails, governance controls, and secure-by-design patterns in alignment with enterprise requirements and the firm’s risk appetite.
  • Design identity, entitlement, and secrets patterns for non-human identities (agents, tools, MCP servers, connectors, service principals) in collaboration with enterprise IAM.
  • Set trust boundaries and data-egress controls for the AI estate, including restrictions on external model provider access, and collaborate with data protection owners on classification, DLP, privacy, and data governance.
  • Conduct adversarial testing and AI red teaming against models, prompts, agents, and tool chains to identify and mitigate AI-specific threats.
  • Build detections, security analytics, and telemetry for AI-specific abuse and integrate them into the firm’s monitoring systems.
  • Support security incident response for AI systems, including triage, containment, forensics, and root cause analysis, feeding lessons learned back into platform defaults.
  • Own security testing within the AI delivery lifecycle, including static analysis, dependency scanning, secrets detection, and security gates in CI/CD.
  • Co-own the risk-based security gate for onboarding new AI products, model providers, versions, and platform features.
  • Conduct security due diligence and risk assessment of AI vendors, platforms, and models.
  • Determine the release of Copilot features and to whom, ensuring required controls are in place.
  • Review solutions built by Forward Deployed Engineering and platforms built with Percepta to ensure security compliance before production.
  • Set guardrails for citizen developers and Copilot Studio makers.
  • Support Risk and Internal Audit with security evidence and exercise Information Security’s control approval and risk acceptance for AI.
  • Identify and deliver opportunities to apply AI and automation across security operations, engineering, assurance, and governance.
  • Define and report KPIs, KRIs, dashboards, and reporting to demonstrate risk reduction, control effectiveness, and operational improvement.
  • Mentor security engineers on AI security and build AI literacy across Information Security.

Benefits

  • Hybrid working and reasonable accommodations
  • Generous Holiday policies
  • Excellent Health and Wellbeing benefits including corporate membership to Wellhub
  • Paid volunteer time to step away from your desk and into the community
  • Support to grow through professional development courses, tuition/qualification reimbursement and more
  • Maternal/paternal leave benefits and family services
  • Unique employee events and programs including a 14er challenge
  • Complimentary beverages, snacks and all employee Happy Hours
  • Annual Bonus Opportunity
  • Competitive compensation
  • Pension/retirement plans
  • Various health, wellbeing and lifestyle benefits
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service