AI Governance Engineering Lead

Janus Henderson Investors

Denver (CO)

Hybrid

USD 150,000 - 190,000

Full time

46 hours ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Hybrid working
Health and wellbeing benefits
Wellhub membership
Volunteer time
Professional development assistance
Tuition reimbursement
Parental leave
Employee events
Beverages and snacks

Job summary

Janus Henderson Investors is hiring for a Senior AI Governance Engineer to embed governance into the platform, including policy-as-code, deployment gates, and secure defaults. You will own identity, access, and permission patterns across agents, models, and tools, while building evidence, telemetry, and evaluation layers for risk and audit needs.

You will collaborate with Risk, Legal, Privacy, and Compliance to translate business requirements into technical design, ensuring compliant, scalable,

Qualifications

  • At least six years in software, platform, or security engineering with production experience.
  • Strong Python and SQL skills, plus API, IaC, and CI/CD hands-on ability.
  • Expertise in identity and access management, authentication, authorization, RBAC, and least privilege.
  • Practical knowledge of technical controls, secure defaults, deployment gates, and audit trails.
  • Hands-on cloud experience, ideally Azure, with logging and data protection.
  • Ability to translate stakeholder needs into concrete technical design.
  • Solid understanding of generative AI, agentic systems, prompts, and tool usage.
  • Judgement to apply proportionate controls based on actual risk and clear communication.

Responsibilities

  • Build governance into the platform through policy-as-code, deployment gates, and secure defaults.
  • Design identity, access, and permission patterns across agents, models, and tools.
  • Create evidence, telemetry, and evaluation layers to support risk and audit testing.
  • Collaborate with Risk, Legal, Privacy, and Compliance to translate needs into technical requirements.

Skills

Software engineering
Python
SQL
APIs
IaC
CI/CD
Identity and access management
Security controls
Azure
Stakeholder management
Generative AI
Agentic systems
Risk-based decision making

Tools

OPA / Rego

Job description

Select how often (in days) to receive an alert:

A career at Janus Henderson is more than a job, it’s about investing in a brighter future together .

Our Mission at Janus Henderson is to help clients define and achieve superior financial outcomes through differentiated insights, disciplined investments, and world-class service. We will do this by protecting and growing our core business, amplifying our strengths and diversifying where we have the right.

Our Values are key to driving our success, and are at the heart of everything we do:

Clients Come First - Always | Execution Supersedes Intention | Together We Win | Diversity Improves Results | Truth Builds Trust

If our mission, values, and purpose align with your own, we would love to hear from you!

Your opportunity

This is an engineering role. Janus Henderson is undertaking a firm-wide AI transformation to become the most technologically sophisticated asset manager in the industry, and it has to move quickly inside boundaries that actually hold. Your job is to make those boundaries part of the platform — governance as code and by design, so that engineers and users inherit the right behaviour automatically instead of passing through a review queue at the end.

You will sit within AI Technology and report to the Head of AI Technology. You will not be the firm’s expert on AI regulation, and you do not need to be: Risk has a dedicated AI governance specialist who owns regulatory interpretation, policy, and standards, and Infosec owns security policy and security-control approval. You will work with both, day to day. What we need from you is the engineering half of that partnership — the person who can take what a risk, legal, privacy, or audit specialist tells them they need, work out what it means in a system, and build it.

The controls you build land on our two central platforms: Nexus, our agentic workspace, where employees and citizen developers build and run AI applications, agents, and shared skills; and Accio, our centralised MCP server, which consumes other MCP servers and presents enterprise datasets through one governed interface. In practice that means identity and permissions for agents and tools, policy-as-code and deployment gates, evaluation hooks in the release path, and the telemetry and evidence that show any of it is working — across the model gateway, agent orchestration, and the applications built on top.

The skill that decides whether this role succeeds is translation. You will sit with people whose domains are nothing like yours, understand what they are actually asking for rather than the words they used, and turn it into a technical design they recognise as their requirement. You should be able to hit the ground running on identity, cloud, and controls, and be comfortable that the AI part of the problem is changing faster than anyone’s standards for it.

What success looks like
  • Controls exist as working platform capability rather than documents. Engineers satisfy them through standard paths, without informal interpretation or repeated meetings.
  • Risk, Infosec, and Internal Audit recognise their requirements in what you built, and can test control operation from evidence the platform generates rather than assembled after the event.
  • Every production AI workload has a named owner, risk classification, evaluation record, approved access, operating telemetry, and retrievable release evidence.
  • Low-risk model and software updates move through a repeatable, time-bound path while higher-risk deployments get the scrutiny they require, and when a control fails the lesson lands in a platform default rather than a report.
Your responsibilities

Build governance into the platform

  • Turn the policies, standards, and risk decisions that Risk and Infosec own into reusable controls, policy-as-code, deployment gates, and secure defaults.
  • Create self-service governance patterns and templates so approved teams can build safely without repeated manual approvals, and embed control checks and evidence capture into repositories, CI/CD pipelines, infrastructure-as-code, and deployment workflows.
  • Establish cost, usage, data-access, and model-access boundaries that are enforced by default through the model gateway and platform services.
  • Define a proportionate lifecycle for experiments, pilots, production AI products, model changes, and autonomous agents, and set the release requirements that go with each tier.

Engineer identity, access, and permissions

  • Design and implement identity, authentication, authorisation, and permission patterns for agents, models, tools, connectors, and service accounts, working with enterprise IAM and AI Security.
  • Implement least privilege and entitlement models that hold when a request crosses several systems, including through Accio to downstream MCP servers.
  • Build the approval and human-in-the-loop patterns that high-stakes actions require, while keeping low-risk activity self-service.
  • Implement an auditable framework for agents and end-user-developed applications, covering named ownership, permissions, approved data, testing, change history, and retirement.

Build the evidence, telemetry, and evaluation layer

  • Define and build the event and evidence model needed to reconstruct prompts, model responses, tool calls, agent decisions, approvals, data access, and cost.
  • Work with AI Engineering and AI Platforms to make telemetry consistent across the model gateway, agent orchestration, applications, and external providers.
  • Build evaluation and regression hooks into the release path, with acceptance thresholds for models, prompts, agents, and platform changes, automated wherever practical.
  • Design monitoring for control failures, model drift, anomalous use, permission breaches, and high-risk actions, with clear escalation and remediation paths.
  • Build the dashboards and evidence packs that service owners, Risk, Infosec, and Internal Audit use directly, so assurance does not depend on you being in the room.

Translate across domains, and work across the firm

  • Work with Risk’s AI governance specialist, Infosec, Legal, Compliance, Privacy, Records Management, and TPRM to understand what each needs, and convert it into technical requirements engineers can implement.
  • Write standards and control requirements that are specific enough to build from, and explain back to non-engineers how the platform behaves and why.
  • Advise AI Architecture, AI Engineering, AI Platforms, and Forward Deployed Engineering on control design, and help teams classify use cases and understand which controls apply before they build.
  • Support risk-based onboarding of new foundation models, AI software, and connectors with AI Platforms and AI Security without restarting the process for every low-risk update, and work alongside Percepta so controls and operating knowledge transfer into our ownership.

What to expect when you join our firm

  • Hybrid working and reasonable accommodations
  • Excellent Health and Wellbeing benefits including corporate membership to Wellhub
  • Paid volunteer time to step away from your desk and into the community
  • Support to grow through professional development courses, tuition/qualification reimbursement and more
  • Maternal/paternal leave benefits and family services
  • Unique employee events and programs including a 14er challenge
  • Complimentary beverages, snacks and all employee Happy Hours
Must have skills
  • At least six years in software, platform, or security engineering, with a track record of building and operating things that reached production. This is an engineering role — a policy, audit, or compliance background is not what we are looking for.
  • Strong Python and SQL, and hands‑on ability with APIs, infrastructure as code, and CI/CD. You will build the controls, not specify them for somebody else to build.
  • Real depth in identity and access: authentication, authorisation, RBAC, service principals and workload identity, secrets management, entitlement models, and least privilege.
  • A practical understanding of what a technical control is and how to implement one — preventive and detective controls, secure defaults, deployment gates, and the evidence a control has to produce.
  • Hands‑on experience with a major cloud, ideally Azure, including logging, monitoring, and data‑protection primitives.
  • The ability to work with stakeholders whose domain is not yours — risk, legal, privacy, compliance, audit, security — understand what they actually need rather than the words they used, and turn it into a technical design they recognise as their requirement.
  • Practical knowledge of generative AI and agentic systems: foundation models, prompts, retrieval, tools, connectors, model gateways, and autonomous workflows.
  • Judgement to distinguish a control objective from a preferred implementation and apply proportionate controls based on actual risk, and clear communication — you can write a technical standard an engineer can implement, and explain to a non-engineer why the platform does what it does.
Nice to have skills
  • Policy-as-code tooling such as Open Policy Agent or Rego, and automated evidence or compliance-as-code pipelines.
  • Experience securing or governing agents, tool execution, MCP servers, or other machine-to-machine interfaces.
  • Experience building internal developer platforms, golden-path patterns, or self-service guardrails used by other engineering teams.
  • Snowflake, Microsoft Fabric / OneLake, and governed enterprise data access patterns.
  • Exposure to a regulated environment, or to Internal Audit and independent control testing. Useful context, but we will build the regulatory knowledge around you.
Supervisory responsibilities

No. This is a senior individual-contributor role with authority over the design and implementation of governance controls. The role may lead cross-functional work and coach engineers, but does not line-manage.

Potential for growth

  • Regular training
  • Continuing education courses

Compensation information

The base salary range for this position is $150,000 - $190,000. This range is estimated for this role. Actual pay may be different. This position will be open through [add date]

Colorado law requires an estimated closing date for job postings. Please don't be discouraged from applying if you see this date has passed.

At Janus Henderson Investors we’re committed to an inclusive and supportive environment. We believe diversity improves results and we welcome applications from candidates from all backgrounds. Don’t worry if you don’t think you tick every box, we still want to hear from you! We understand everyone has different commitments and while we can’t accommodate every flexible working request, we’re happy to be asked about work flexibility and our hybrid working environment. If you need any reasonable accommodations during our recruitment process, please get in touch and let us know at recruiter@janushenderson.com .

Annual Bonus Opportunity:Position may be eligible to receive an annual discretionary bonus award from the profit pool. The profit pool is funded based on Company profits. Individual bonuses are determined based on Company, department, team and individual performance.

Benefits:Janus Henderson is committed to offering a comprehensive total rewards package to eligible employees that includes; competitive compensation, pension/retirement plans, and various health, wellbeing and lifestyle benefits. To learn more about our offerings please visit the Why Join Us section on the career page here .

Janus Henderson Investors is an equal opportunity employer.All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability or veteran status. All applications are subject to background checks.

Janus Henderson (including its subsidiaries) will not maintain existing or sponsor new industry registrations or licenses where not supported by an employee’s job functions (as determined by Janus Henderson at its sole discretion).

You should be willing to adhere to the provisions of our Investment Advisory Code of Ethics related to personal securities activities and other disclosure and certification requirements, including past political contributions and political activities. Applicants’ past political contributions or activity may impact applicants’ eligibility for this position.

You will be expected to understand the regulatory obligations of the firm, and abide by the regulated entity requirements and JHI policies applicable for your role.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

AI Governance Engineering Lead
AI Governance Engineering Lead

Janus Henderson Group • Denver (CO), Northern (KY)

Hybrid
USD 150,000 - 190,000
Health and wellbeing benefits
Volunteer time
Tuition reimbursement
+2
Senior AI Platform Engineer
Senior AI Platform Engineer

Socket.dev • Denver (CO)

Hybrid
USD 195,000 - 230,000
Hybrid work environment
Generous holiday policy
Health and wellbeing benefits
Senior AI Platform Engineer
Senior AI Platform Engineer

Janus Henderson Group • Denver (CO), Northern (KY)

Hybrid
USD 195,000 - 230,000
Hybrid working
Health & wellbeing benefits
Volunteer time off
Forward Deployed Engineer
Forward Deployed Engineer

Janus Henderson Investors • Denver (CO)

Hybrid
USD 145,000 - 180,000
Hybrid work arrangement
Wellbeing benefits
Annual bonus potential
Forward Deployed Engineer
Forward Deployed Engineer

Janus Henderson Group • Denver (CO), Northern (KY)

Hybrid
USD 145,000 - 180,000
Health & wellbeing benefits
Volunteer time off
Professional development support
+1
AI Business Partner
AI Business Partner

Janus Henderson Investors • New York (NY)

On-site
USD 110,000 - 200,000
Annual bonus eligibility
Head of AI
Head of AI

Janus Henderson Investors • New York (NY)

Hybrid
USD 250,000 - 300,000
Hybrid work model
Competitive compensation
Head of AI
Head of AI

Janus Henderson Group • Denver (CO), Northern (KY)

Hybrid
USD 250,000 - 300,000
Annual discretionary bonus
Health and wellbeing benefits
Hybrid working
AI Enablement Partner
AI Enablement Partner

Janus Henderson Investors • New York (NY)

On-site
USD 110,000 - 200,000
Hybrid working & accommodations
Volunteer time
Professional development courses
+3
Head of AI
Head of AI

Janus Henderson Investors • Denver (CO)

Hybrid
USD 250,000 - 300,000
Hybrid working
Health and wellbeing benefits
Tuition reimbursement
+2