AI Security Engineer
Adversarial Ai Security
Agent
Ai Security
Application Security
Cloud Platforms
Cybersecurity Tools
Data Security
Engineer
Gen Ai Security
Identity and Access Management
Information Security
InfoSec
Risk Governance
Risk Management
Security
Security Automation
Security Operations
Security Standards
Security Testing
Software Security
Solution Architecture
Job Description
Janus Henderson is seeking a hands-on AI Security Engineer to help secure AI-enabled applications, models, agents, and the platforms that support them across the full lifecycle. Reporting into the Office of the CISO, this role acts as an AI security design authority for agentic systems and related capabilities, bringing threat modeling, guardrails, testing, and risk-based assurance to enterprise-scale deployments.
Working onsite in Denver, CO within the Office of the CISO, you will help define what secure-by-design looks like for AI at the firm, ensuring protections are implemented as code and supported by measurable security outcomes.
Key Responsibilities
- Serve as the security design authority for AI systems by leading threat modelling, architecture review, and risk assessment for agentic applications, the model gateway, and initiatives including Accio and Nexus, applying frameworks such as STRIDE, PASTA, MITRE ATT&CK, and MITRE ATLAS as appropriate.
- Define and evolve AI security standards, guardrails, governance controls, and secure-by-design patterns aligned to enterprise requirements and the firm’s risk appetite, co-designing reusable guardrails with the Principal AI Architect and collaborating with the AI Governance Implementation Lead for platform landing.
- Design identity, entitlement, and secrets patterns for non-human identities including agents, tools, MCP servers, connectors, and service principals, covering scoped permissions, credential lifetime, rotation, and least privilege across multi-hop requests with the Senior AI Platform Engineer and enterprise IAM.
- Establish trust boundaries and data-egress controls for the AI estate, including what external model providers may receive, and work with data protection stakeholders on classification, DLP enforcement, privacy, and data governance obligations.
- Run adversarial testing and AI red teaming for models, prompts, agents, and tool chains, including prompt injection and indirect injection, model manipulation and hijacking, excessive agency, function-call abuse, data leakage from LLM outputs, and privilege escalation between agents.
- Build detections, security analytics, and telemetry for AI-specific abuse such as anomalous tool invocation, credential misuse by agents, unusual data access, and exfiltration through model responses, integrating findings into the firm’s monitoring estate.
- Support security incident response for AI systems through triage, containment, and forensics across prompts, tool calls, and agent decisions, then feed lessons learned back into platform defaults and evaluation suites.
- Own security testing across the AI delivery lifecycle, including static analysis, dependency and container scanning, secrets detection, and security gates in CI/CD to surface issues before release.
- Co-own risk-based security gates for onboarding new AI products, model providers, versions, and platform features, including security due diligence and risk assessment of vendors, platforms, and models (provenance, open-source components, tenancy and data-use terms, security advisories), and testing platform updates before rollout.
- Help determine which Copilot features are released and to whom, ensuring capability release aligns with required controls being evidenced; review Forward Deployed Engineering solutions to help prevent production access without an approved security position, and set guardrails for citizen developer patterns and Copilot Studio builders with AI Enablement.
- Support Risk and Internal Audit with security evidence for AI, including the Infosec control approval and risk-acceptance position, and escalate when residual risk exceeds appetite.
- Identify opportunities to apply AI and automation across security operations, engineering, assurance, and governance, building automation with code, APIs, scripting, orchestration platforms, or low-code technologies to automate response workflows, enrich incident data, assist triage, and enable risk-based vulnerability management.
- Define and report KPIs, KRIs, dashboards, and reporting that demonstrate risk reduction, control effectiveness, and operational improvement.
- Mentor security engineers on AI security and build AI literacy across Infosec to reduce single-point-of-knowledge dependencies.
Required Qualifications
- Strong cybersecurity experience across security engineering, application security, product security, cloud security, or security architecture, with a hands-on engineering background and security protections that reached production.
- Strong grasp of security engineering fundamentals including common attack vectors, defense techniques, and threat modeling.
- Hands-on experience assessing and securing GenAI, LLMs, machine learning, agentic AI, and AI-enabled solutions across their lifecycle.
- Proven ability to lead threat modeling, architecture reviews, and risk assessments for complex platforms and services.
- Strong understanding of AI-specific threats and risk assessment approaches, including prompt injection, model manipulation, excessive agency, STRIDE, PASTA, MITRE ATT&CK, MITRE ATLAS, and equivalent industry practices.
- Experience defining and evolving AI security standards, guardrails, governance controls, and secure-by-design patterns aligned to enterprise requirements and risk appetite.
- Experience securing AI agents, MCP integrations, permissions, non-human identities, autonomous workflows, and AI platform integrations.
- Cloud security depth, ideally Azure, including IAM, service principals and workload identity, secrets management, RBAC, network controls, and logging, plus experience securing application delivery with secure SDLC and CI/CD controls.
- Practical experience with AI and LLM systems, including prompt engineering, retrieval-augmented generation, and function calling, and proven ability to build and deploy automation using code, APIs, scripting, orchestration platforms, or low-code technologies (for example, Python, workflow engines, or SOAR).
- Metrics-driven mindset, including experience defining KPIs, KRIs, dashboards, and reporting to demonstrate risk reduction and control effectiveness.
- Ability to engage stakeholders and translate technical risk into business impact, with independence to hold a security position under delivery pressure.
Technologies
- STRIDE, PASTA, MITRE ATT&CK, MITRE ATLAS
- CI/CD, Azure, RBAC, DLP, MCP
- LLM, GenAI, machine learning, Python, SOAR
- Retrieval-augmented generation, function calling
- NIST AI RMF, OWASP Top 10 for LLM applications, ISO/IEC 42001, EU AI Act
Compensation and Work Model
- Location: Denver, CO (onsite)
- Salary: USD $145,000 - $190,000 per year (base salary range estimated for the role; actual pay may differ)
- Work model: Hybrid working and reasonable accommodations
Benefits
- Generous Holiday policies
- Excellent Health and Wellbeing benefits including corporate membership to Wellhub
- Paid volunteer time and support for professional development (courses, tuition/qualification reimbursement)
- Maternal/paternal leave benefits and family services
- Employee events and programs, including a 14er challenge
- Complimentary beverages, snacks, and all-employee Happy Hours
- Annual Bonus Opportunity
- Pension/retirement plans and various health, wellbeing, and lifestyle benefits
Reporting and Growth
- Supervisory responsibilities: No, individual-contributor role directed by AI Technology; security design authority for AI systems and mentoring responsibilities, but no line management.
- Potential for growth: Mentoring, leadership development programs, regular training, career development services, and continuing education courses.