AI Security Engineer

Janus Henderson Group

City of Westminster

Hybrid

GBP 110,000 - 160,000

Full time

6 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Hybrid working
Health and wellbeing benefits
Volunteer time
Professional development & courses
Parental leave

Job summary

Janus Henderson Group seeks a hands-on Security Engineer for AI systems to champion secure-by-design patterns across the AI estate, model gateway, Nexus, and Copilot services. This role balances risk management with velocity, embedding security controls into the AI lifecycle and governance landscape.

You will define guardrails, lead threat modelling, and drive measurable risk reduction. Collaboration with Enterprise IAM, AI Governance, and security engineering teams is essential to succeed.

Qualifications

  • Extensive security engineering experience across AI systems and cloud platforms.
  • Hands-on with GenAI, LLMs, agentic AI lifecycles, and security controls.
  • Proven ability to lead threat modelling, architecture reviews, and risk assessments.

Responsibilities

  • Design security into AI systems and ensure patterns are landable as code and secure defaults.
  • Lead threat modelling, architecture reviews, and risk assessments for complex platforms and services.
  • Develop detections, analytics, and telemetry for AI-specific abuse and integrate into monitoring estates.
  • Own security testing in the AI delivery lifecycle, including CI/CD gates and dependency scanning.
  • Scale security with AI and automation across security operations, engineering, and governance.

Skills

Cybersecurity
GenAI security
Threat modelling
AI security standards
AI agents security
Cloud security
Secure SDLC
KPIs and reporting
Stakeholder engagement

Job description

Secure the AI estate by design

  • Act as security design authority for AI systems, leading threat modelling, architecture review, and risk assessment for agentic applications, the model gateway, Accio, Nexus, and any novel or high-risk AI initiative, applying STRIDE, PASTA, MITRE ATT&CK, and MITRE ATLAS as appropriate.
  • Define and evolve AI security standards, guardrails, governance controls, and secure-by-design patterns aligned with enterprise requirements and the firm's risk appetite - co-designed with the Principal AI Architect as reusable, implementable guardrails, and implemented as code and secure defaults by AI Engineering and AI Platforms, working with the AI Governance Implementation Lead, who owns how they land on the platform.
  • Design identity, entitlement, and secrets patterns for non-human identities - agents, tools, MCP servers, connectors, and service principals - with the Senior AI Platform Engineer and enterprise IAM, covering scoped permissions, credential lifetime, rotation, and least privilege across multi-hop requests.
  • Set the trust boundaries and data-egress controls for the AI estate, including what may reach external model providers, and work with data protection owners on classification, DLP enforcement, privacy, and data governance obligations.
Test, detect, and respond
  • Run adversarial testing and AI red teaming against models, prompts, agents, and tool chains, covering prompt injection and indirect injection, model manipulation and hijacking, excessive agency, function-call abuse, data leakage from LLM outputs, and privilege escalation between agents.
  • Build detections, security analytics, and telemetry for AI-specific abuse - anomalous tool invocation, credential misuse by agents, unusual data access, and exfiltration through model responses - and integrate them into the firm's monitoring estate.
  • Support security incident response for AI systems: triage, containment, forensics across prompts, tool calls, and agent decisions, and root cause, feeding each lesson back into platform defaults and evaluation suites.
  • Own security testing in the AI delivery lifecycle, including static analysis, dependency and container scanning, secrets detection, and security gates in CI/CD, so issues surface before release.
Assure AI adoption and third-party risk
  • Co-own the risk-based security gate for onboarding new AI products, model providers, versions, and platform features with the Senior AI Platform Engineer and the AI Governance Implementation Lead, conducting security due diligence and risk assessment of AI vendors, platforms, and models - provenance, open-source components, tenancy and data-use terms, security advisories - and testing platform updates before rollout.
  • Decide with the Senior AI Platform Engineer and the Principal AI Architect which Copilot features are released and to whom, withholding capability until the required controls are evidenced; review the solutions Forward Deployed Engineering builds and the platforms built with Percepta so neither reaches production without a security position; and set the guardrails for citizen developers and Copilot Studio makers with AI Enablement.
  • Support Risk and Internal Audit with security evidence, exercise Infosec's security-control approval and risk-acceptance position for AI, and elevate where residual risk exceeds appetite.
Scale the security function with AI and automation
  • Identify and deliver opportunities to apply AI and automation across security operations, engineering, assurance, and governance, building automation with code, APIs, scripting, orchestration platforms, or low-code technologies to automate response workflows, enrich incident data, assist with triage, and drive risk-based vulnerability management.
  • Define and report the KPIs, KRIs, dashboards, and reporting that demonstrate risk reduction, control effectiveness, and operational improvement.
  • Mentor security engineers on AI security and build enough AI literacy across Infosec that this role is not a single point of knowledge.
What to expect when you join our firm
  • Hybrid working and reasonable accommodations
  • Generous Holiday policies
  • Excellent Health and Wellbeing benefits including corporate membership to Wellhub
  • Paid volunteer time to step away from your desk and into the community
  • Support to grow through professional development courses, tuition/qualification reimbursement and more
  • Maternal/paternal leave benefits and family services
  • All employee events including networking opportunities and social activities
  • Lunch allowance for use within our subsidized onsite canteen
Must have skills
  • Strong cybersecurity experience across security engineering, application security, product security, cloud security, or security architecture, with a hands-on engineering background, a track record of protections that reached production, and a solid grasp of security engineering fundamentals - common attack vectors, defence techniques, and threat modelling.
  • Hands-on experience assessing and securing GenAI, LLM, machine learning, agentic AI, and AI-enabled solutions throughout their lifecycle.
  • Proven ability to lead threat modelling, architecture reviews, and risk assessments for complex technology platforms and services.
  • Strong understanding of AI-specific threats, threat modelling methodologies, adversary frameworks, and risk assessment approaches, including prompt injection, model manipulation, excessive agency, STRIDE, PASTA, MITRE ATT&CK, MITRE ATLAS, and equivalent industry practices.
  • Experience defining and evolving AI security standards, guardrails, governance controls, and secure-by-design patterns aligned with enterprise requirements and risk appetite.
  • Experience securing AI agents, MCP integrations, permissions, non-human identities, autonomous workflows, and AI platform integrations.
  • Cloud security depth, ideally Azure - identity and access management, service principals and workload identity, secrets management, RBAC, network controls, and logging - and experience securing application delivery, including secure SDLC, CI/CD controls, and code and dependency scanning.
  • Practical experience with AI and LLM systems - prompt engineering, retrieval-augmented generation, function calling, agent-based tools - and proven ability to build and deploy automation using code, APIs, scripting, orchestration platforms, or low-code technologies such as Python, workflow engines, or SOAR, integrating security logs, AI models, and platform components into cohesive pipelines.
  • Metrics-driven mindset, with experience defining KPIs, KRIs, dashboards, and reporting to demonstrate risk reduction, control effectiveness, and operational improvement.
  • Strong stakeholder engagement and influencing skills, with the ability to translate technical risk into business impact, pragmatic controls, and informed risk decisions - and the independence to hold a security position under delivery pressure.
Nice to have skills
  • Familiarity with AI security and governance frameworks including NIST AI RMF, the OWASP Top 10 for LLM applications, MITRE ATLAS, ISO/IEC 42001, and the security provisions of the EU AI Act.
  • AI red teaming, adversarial testing, adversarial machine learning, model validation, or offensive security assessments applied to models and tool chains.
  • Experience securing enterprise AI platforms, model gateways, AI development environments, and AI engineering ecosystems.
  • Knowledge of AI security posture management, runtime protection, model monitoring, and AI governance tooling.
  • Knowledge of identity security, including IAM, PAM, identity governance, privileged access management, non-human identities, and workload identities.
  • Experience applying AI and automation to vulnerability management, detection engineering, threat detection, or security operations at scale, including risk-based threat prioritisation.
  • Knowledge of security analytics, monitoring, and detection capabilities for AI systems and supporting infrastructure.
  • Understanding of privacy, data governance, regulatory, and responsible AI considerations, including Microsoft Purview, DLP policy design, or data classification across a Microsoft 365 estate.
  • Securing agentic workflows, including scoped permissions, approval patterns, and guarding against configuration drift caused by AI assistants.
  • Third-party or model supply-chain risk assessment; financial services or asset management experience; or a certification such as CISSP, GIAC, OSCP, or a cloud security qualification.

A career at Janus Henderson is more than a job, it's about investing in a brighter future together.

Our Mission at Janus Henderson is to help clients define and achieve superior financial outcomes through differentiated insights, disciplined investments, and world-class service. We will do this by protecting and growing our core business, amplifying our strengths and diversifying where we have the right.

Our Values are key to driving our success, and are at the heart of everything we do: Clients Come First - Always | Execution Supersedes Intention | Together We Win | Diversity Improves Results | Truth Builds Trust

If our mission, values, and purpose align with your own, we would love to hear from you!

Your opportunity This is a hands-on security engineering role for people who are deep in cybersecurity and serious about AI. You will secure the AI systems we are building - AI-enabled applications, models, agents, and the platforms beneath them, across their full lifecycle - acting as a trusted advisor who helps define and evolve the firm's AI security standards, patterns, and guardrails. The objective is not to create additional process, but to ensure our existing security capabilities evolve alongside AI adoption and remain effective at enterprise scale.

Janus Henderson is undertaking a firm-wide AI transformation to become the most technologically sophisticated asset manager in the industry. Our AI capability sits in a single centralised function under the Head of AI, and AI Technology builds and runs it. This role sits in Information Security and reports to the Head of Security Engineering, while your day-to-day work is directed by AI Technology and prioritised against their roadmap. That split is deliberate: security policy, security architecture approval, and security risk acceptance stay with Infosec, and you are the person who exercises them for AI - close enough to the engineering to be useful, independent enough to say no. You will secure Nexus, our agentic workspace where employees and citizen developers build and run AI applications, agents, and shared skills; Accio, our centralised MCP server, which consumes other MCP servers and presents enterprise datasets through one governed interface; the AI model gateway and its routes to external model providers; and our Copilot services. Accio and Nexus matter most: both propagate permissions and data on a user's or an agent's behalf, so their trust boundaries have to hold when a request crosses several hops. Throughout, you will balance effective risk management against the velocity needed to deliver AI solutions that drive business value and growth.

A secondary focus of the role is partnering with the wider Security function to identify opportunities to leverage AI and automation to improve efficiency, effectiveness, and risk reduction across security operations, engineering, assurance, and governance - so that the controls you design are enforced and evidenced automatically rather than through review meetings.

What success looks like
  • Security is designed into AI systems rather than appended. Engineers reach for an approved pattern instead of asking for a bespoke review.
  • The controls you define are implemented as code and secure defaults by AI Engineering and AI Platforms, and you can show they are operating.
  • AI-specific attacks are anticipated and tested for, and you can demonstrate what the firm is and is not exposed to.
  • New models, tools, and Copilot features reach a security decision quickly through a repeatable risk-based path, and when an AI incident happens the lesson lands in a platform default rather than a report.
  • Risk reduction and control effectiveness
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

AI Governance Engineering Lead
AI Governance Engineering Lead

Janus Henderson Group • Greater London

Hybrid
GBP 90,000 - 140,000
Hybrid working
Health and wellbeing benefits
Volunteer time
+3
AI Security Engineer
AI Security Engineer

Janus Henderson Group • Greater London

Hybrid
GBP 90,000 - 140,000
Hybrid working
Health and wellbeing benefits
Paid volunteer time
+2
AI Security Engineer
AI Security Engineer

LGBT Great Careers • Greater London

Hybrid
GBP 90,000 - 130,000
Hybrid working
Health and wellbeing benefits
Lunch allowance
+1
AI Governance Engineering Lead
AI Governance Engineering Lead

Janus Henderson • City of Westminster

On-site
GBP 110,000 - 150,000
Annual discretionary bonus
Health & wellbeing benefits
Pension/retirement plans
+1
AI Security Engineer
AI Security Engineer

Janus Henderson Investors • Greater London

Hybrid
GBP 120,000 - 170,000
Hybrid working
Generous holiday policy
Wellbeing benefits
Senior AI Platform Engineer
Senior AI Platform Engineer

Janus Henderson • City of Westminster

On-site
GBP 85,000 - 130,000
Annual bonus opportunity
Healthcare and wellbeing benefits
Hybrid working
AI Governance Engineering Lead
AI Governance Engineering Lead

Janus Henderson Investors • City Of London

On-site
GBP 120,000 - 180,000
Hybrid working
Generous holiday policies
Health and wellbeing benefits
+5
AI Security Engineer: Build Safe, Scalable AI Platforms
AI Security Engineer: Build Safe, Scalable AI Platforms

LGBT Great Careers • Greater London

Hybrid
GBP 90,000 - 130,000
Hybrid working
Health and wellbeing benefits
Lunch allowance
+1
AI Governance Engineering Lead
AI Governance Engineering Lead

LGBT Great Careers • Greater London

Hybrid
GBP 90,000 - 140,000
Hybrid working
Health & wellbeing benefits
Volunteer time off
+4
AI Security Engineer
AI Security Engineer

Leeds Building Society • Leeds

On-site
GBP 70,000 - 110,000
Hybrid working 2 days in the office
Annual bonus up to 12%
Matched pension up to 10%
+3