Identity Security Engineer

Janus Henderson Investors

Denver (CO)

Hybrid

USD 90,000 - 100,000

Full time

10 days ago
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Hybrid working
Health & Wellbeing benefits
Paid volunteer time
Professional development support
Parental leave
Employee events
Complimentary beverages and snacks

Job summary

Janus Henderson Investors is seeking an Identity Security Engineer to design, implement, and operate privileged access management (PAM) controls across on-prem and cloud environments. This role will secure privileged users, service accounts, machine identities, APIs, and AI agents throughout their lifecycles.

You will lead identity threat detection, investigate identity events, and develop automation and governance metrics to strengthen security posture and reduce risk, with strong collaboration

Qualifications

  • Strong understanding of Privileged Access Management (PAM) principles and related concepts.
  • Ability to investigate, triage, and resolve PAM and identity-related incidents and issues.
  • Experience administering and engineering enterprise PAM platforms such as Britive, CyberArk, Delinea or equivalent.
  • Experience designing, implementing and operating privileged access controls across on-prem and cloud environments.
  • Experience onboarding and governing privileged users, service accounts, machine identities, APIs, workload identities and other non-human identities.
  • Experience securing privileged access for automation platforms, cloud workloads, DevOps tooling, and AI agents.
  • Experience configuring identity security and data access governance platforms (Active Directory/Entra ID auditing, permissions analysis, access monitoring, reporting).
  • Strong understanding of IAG concepts and integrations with PAM, ITSM platforms like SailPoint ISC and ServiceNow.

Responsibilities

  • Design, implement and operate PAM controls across on-prem and cloud environments.
  • Secure lifecycle for privileged users, service accounts, machine identities, APIs and other non-human identities.
  • Support identity threat detection and response capabilities and investigate identity-related security events.
  • Develop security metrics and automation to strengthen identity security posture and reduce operational risk.
  • Collaborate with ITSM and identity governance tooling for provisioning workflows and lifecycle management.

Skills

PAM principles
Incident triage
PAM platforms
Privileged access design
Non-human identities
Automation & cloud
AD/Entra auditing
IAG integration
Identity lifecycle
AD/Entra ID
Security metrics

Tools

Britive
CyberArk
Delinea

Job description

Select how often (in days) to receive an alert:

A career at Janus Henderson is more than a job, it’s about investing in a brighter future together .

Our Mission at Janus Henderson is to help clients define and achieve superior financial outcomes through differentiated insights, disciplined investments, and world-class service. We will do this by protecting and growing our core business, amplifying our strengths and diversifying where we have the right.

Our Values are key to driving our success, and are at the heart of everything we do:

Clients Come First - Always | Execution Supersedes Intention | Together We Win | Diversity Improves Results | Truth Builds Trust

If our mission, values, and purpose align with your own, we would love to hear from you!

Your opportunity

The Identity Security Engineer is a hands‑on security engineering role focused on securing privileged access and identities across JHI. The role is primarily responsible for designing, implementing, and operating Privileged Access Management (PAM) controls, ensuring privileged users, service accounts, machine identities, APIs, and emerging AI agents are securely managed throughout their lifecycle. In addition, the engineer will support identity threat detection and response capabilities, investigate identity‑related security events, maintain data access governance tooling, and develop security metrics and automation that strengthen JHI's overall identity security posture and reduce operational risk.

What to expect when you join our firm
  • Hybrid working and reasonable accommodations
  • Excellent Health and Wellbeing benefits including corporate membership to Wellhub
  • Paid volunteer time to step away from your desk and into the community
  • Support to grow through professional development courses, tuition/qualification reimbursement and more
  • Maternal/paternal leave benefits and family services
  • Unique employee events and programs including a 14er challenge
  • Complimentary beverages, snacks and all employee Happy Hours
Must have skills
  • Strong understanding of Privileged Access Management (PAM) principles, including least privilege, just-in-time access, **ephemeral** access, privileged session management, secrets management, and credential vaulting.
  • Ability to investigate, triage, and resolve PAM and identity‑related incidents, requests, and operational issues while driving root‑cause remediation.
  • Experience administering and engineering enterprise PAM platforms such as Britive, CyberArk, Delinea, or equivalent.
  • Experience designing, implementing, and operating privileged access controls across on‑premise and cloud environments.
  • Experience onboarding and governing privileged users, service accounts, machine identities, APIs, workload identities, and other non‑human identities throughout their lifecycle.
  • Experience securing and managing privileged access for automation platforms, cloud workloads, DevOps tooling, and emerging AI/agentic systems.
  • Experience configuring and maintaining identity security and data access governance platforms, including Active Directory/Entra ID auditing, permissions analysis, access monitoring, and security reporting.
  • Strong understanding of Identity Access Governance (IAG) concepts and integrations between PAM, IAG, and ITSM platforms, such as SailPoint Identity Security Cloud (ISC) and ServiceNow, with experience supporting identity lifecycle management, provisioning workflows, and troubleshooting workflow issues.
  • Experience working with Active Directory, Entra ID, federation, authentication, access control, and modern identity security architectures.
  • Experience developing security metrics, KPIs, dashboards, and reporting that measure control effectiveness, operational performance, adoption, and risk reduction in an automated manner.
Nice to have skills
  • Experience with Identity Threat Detection & Response (ITDR) and identity-centric threat monitoring.
  • Experience with User and Entity Behaviour Analytics (UEBA) platforms.
  • Experience creating, tuning, or maintaining identity-focused detections, analytics, and use cases within a SIEM platform.
  • Understanding of identity-focused attack techniques including account compromise, privilege escalation, credential theft, lateral movement, and insider threats.
  • PowerShell and/or Python scripting experience for automation and operational efficiency.
  • Experience integrating identity platforms with SIEM, SOAR, and security operations tooling.
  • Experience monitoring and securing non‑human identities, machine identities, and AI agents.
  • Knowledge of AI agent security, non‑human identity governance, MCP security, delegated permissions, workload identities, and AI‑related identity threats.
Supervisory responsibilities
  • No
Potential for growth
  • Regular training
  • Continuing education courses
Compensation information

The base salary range for this position is $90,000 to $100,000. This range is estimated for this role. Actual pay may be different. This position will be open through October 2026.

Colorado law requires an estimated closing date for job postings. Please don't be discouraged from applying if you see this date has passed.

At Janus Henderson Investors we’re committed to an inclusive and supportive environment. We believe diversity improves results and we welcome applications from candidates from all backgrounds. Don’t worry if you don’t think you tick every box, we still want to hear from you! We understand everyone has different commitments and while we can’t accommodate every flexible working request, we’re happy to be asked about work flexibility and our hybrid working environment. If you need any reasonable accommodations during our recruitment process, please get in touch and let us know at recruiter@janushenderson.com

Annual Bonus Opportunity

Position may be eligible to receive an annual discretionary bonus award from the profit pool. The profit pool is funded based on Company profits. Individual bonuses are determined based on Company, department, team and individual performance.

Benefits

Janus Henderson is committed to offering a comprehensive total rewards package to eligible employees that includes; competitive compensation, pension/retirement plans, and various health, wellbeing and lifestyle benefits. To learn more about our offerings please visit the Why Join Us section on the career page here .

Janus Henderson Investors is an equal opportunity employer

All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability or veteran status. All applications are subject to background checks.

Janus Henderson (including its subsidiaries) will not maintain existing or sponsor new industry registrations or licenses where not supported by an employee’s job functions (as determined by Janus Henderson at its sole discretion).

You should be willing to adhere to the provisions of our Investment Advisory Code of Ethics related to personal securities activities and other disclosure and certification requirements, including past political contributions and political activities. Applicants’ past political contributions or activity may impact applicants’ eligibility for this position.

You will be expected to understand the regulatory obligations of the firm, and abide by the regulated entity requirements and JHI policies applicable for your role.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Identity Security Engineer
Identity Security Engineer

Janus Henderson Group • Denver (CO), Northern (KY)

Hybrid
USD 90,000 - 100,000
Hybrid working
Wellbeing benefits
Volunteer time
+4
Senior Security Analyst
Senior Security Analyst

Janus Henderson Investors • Denver (CO)

On-site
USD 100,000 - 130,000
Hybrid work model
Health and wellbeing benefits
Volunteer time
+4
Senior Security Analyst
Senior Security Analyst

Janus Henderson Group • Denver (CO), Northern (KY)

Hybrid
USD 100,000 - 130,000
AI Governance Engineering Lead
AI Governance Engineering Lead

Janus Henderson Group • Denver (CO), Northern (KY)

Hybrid
USD 150,000 - 190,000
Health and wellbeing benefits
Volunteer time
Tuition reimbursement
+2
AI Governance Engineering Lead
AI Governance Engineering Lead

Janus Henderson Investors • Denver (CO)

Hybrid
USD 150,000 - 190,000
Hybrid working
Health and wellbeing benefits
Wellhub membership
+6
People Operations Analyst
People Operations Analyst

Janus Henderson Group • Denver (CO), Northern (KY)

Hybrid
USD 65,000 - 70,000
Hybrid working
Health & wellbeing benefits
Volunteer time off
+3
Senior Data Engineer
Senior Data Engineer

Janus Henderson Investors • Denver (CO)

Hybrid
USD 140,000 - 149,000
Annual discretionary bonus
Health and wellbeing benefits
Pension/retirement plans
+1
Senior Data Engineer
Senior Data Engineer

Janus Henderson Group • Denver (CO), Northern (KY)

Hybrid
USD 140,000 - 149,000
Hybrid working
Health benefits
Volunteer time
+4
Senior People Business Partner
Senior People Business Partner

Janus Henderson Investors • Denver (CO)

Hybrid
USD 140,000 - 160,000
Hybrid working
Wellbeing benefits
Volunteer time off
+2
Forward Deployed Engineer
Forward Deployed Engineer

Janus Henderson Investors • Denver (CO)

Hybrid
USD 145,000 - 180,000
Hybrid work arrangement
Wellbeing benefits
Annual bonus potential