Impress employers and recruiters.
Choose from hundreds of resume examples.

Impress employers and recruiters.
Choose from hundreds of resume examples.
Tailor your resume to this AI Security Engineer role.
Rezi rewrites your resume against Janus Henderson Investors's job description. Free.

Tailor your resume to this AI Security Engineer role.
Rezi rewrites your resume against Janus Henderson Investors's job description. Free.
Don't guess if your resume is good enough.
See how it scores against the AI Security Engineer posting at Janus Henderson Investors — free, in seconds.

Don't guess if your resume is good enough.
See how it scores against the AI Security Engineer posting at Janus Henderson Investors — free, in seconds.
About the Role
This is a hands-on security engineering role focused on securing AI systems, acting as a trusted advisor to define and evolve AI security standards, patterns, and guardrails. The objective is to ensure security capabilities evolve with AI adoption and remain effective at enterprise scale.
Responsibilities
- Act as security design authority for AI systems, leading threat modelling, architecture review, and risk assessment for agentic applications, the model gateway, Accio, Nexus, and any novel or high-risk AI initiative.
- Define and evolve AI security standards, guardrails, governance controls, and secure-by-design patterns aligned with enterprise requirements and the firm’s risk appetite.
- Design identity, entitlement, and secrets patterns for non-human identities, covering scoped permissions, credential lifetime, rotation, and least privilege across multi-hop requests.
- Set the trust boundaries and data-egress controls for the AI estate, including what may reach external model providers.
- Run adversarial testing and AI red teaming against models, prompts, agents, and tool chains.
- Build detections, security analytics, and telemetry for AI-specific abuse and integrate them into the firm’s monitoring estate.
- Support security incident response for AI systems, including triage, containment, forensics, and root cause analysis.
- Own security testing in the AI delivery lifecycle, including static analysis, dependency and container scanning, secrets detection, and security gates in CI/CD.
- Co-own the risk-based security gate for onboarding new AI products, model providers, versions, and platform features.
- Conduct security due diligence and risk assessment of AI vendors, platforms, and models.
- Decide which Copilot features are released and to whom, withholding capability until the required controls are evidenced.
- Review solutions built by Forward Deployed Engineering and platforms built with Percepta to ensure security.
- Set the guardrails for citizen developers and Copilot Studio makers.
- Support Risk and Internal Audit with security evidence and exercise Infosec’s security-control approval and risk-acceptance position for AI.
- Identify and deliver opportunities to apply AI and automation across security operations, engineering, assurance, and governance.
- Define and report the KPIs, KRIs, dashboards, and reporting that demonstrate risk reduction, control effectiveness, and operational improvement.
- Mentor security engineers on AI security and build AI literacy across Infosec.
Requirements
- Strong cybersecurity experience across security engineering, application security, product security, cloud security, or security architecture, with a hands-on engineering background.
- Hands-on experience assessing and securing GenAI, LLM, machine learning, agentic AI, and AI-enabled solutions throughout their lifecycle.
- Proven ability to lead threat modelling, architecture reviews, and risk assessments for complex technology platforms and services.
- Strong understanding of AI-specific threats, threat modelling methodologies, adversary frameworks, and risk assessment approaches.
- Experience defining and evolving AI security standards, guardrails, governance controls, and secure-by-design patterns.
- Experience securing AI agents, MCP integrations, permissions, non-human identities, autonomous workflows, and AI platform integrations.
- Cloud security depth, ideally Azure — identity and access management, service principals and workload identity, secrets management, RBAC, network controls, and logging.
- Experience securing application delivery, including secure SDLC, CI/CD controls, and code and dependency scanning.
- Practical experience with AI and LLM systems — prompt engineering, retrieval-augmented generation, function calling, agent-based tools.
- Proven ability to build and deploy automation using code, APIs, scripting, orchestration platforms, or low-code technologies such as Python, workflow engines, or SOAR.
- Metrics-driven mindset, with experience defining KPIs, KRIs, dashboards, and reporting to demonstrate risk reduction, control effectiveness, and operational improvement.
- Strong stakeholder engagement and influencing skills, with the ability to translate technical risk into business impact, pragmatic controls, and informed risk decisions.
- Independence to hold a security position under delivery pressure.
- Familiarity with AI security and governance frameworks including NIST AI RMF, the OWASP Top 10 for LLM applications, MITRE ATLAS, ISO/IEC 42001, and the security provisions of the EU AI Act.
- AI red teaming, adversarial testing, adversarial machine learning, model validation, or offensive security assessments applied to models and tool chains.
- Experience securing enterprise AI platforms, model gateways, AI development environments, and AI engineering ecosystems.
- Knowledge of AI security posture management, runtime protection, model monitoring, and AI governance tooling.
- Knowledge of identity security, including IAM, PAM, identity governance, privileged access management, non-human identities, and workload identities.
- Experience applying AI and automation to vulnerability management, detection engineering, threat detection, or security operations at scale.
- Knowledge of security analytics, monitoring, and detection capabilities for AI systems and supporting infrastructure.
- Understanding of privacy, data governance, regulatory, and responsible AI considerations.
- Securing agentic workflows, including scoped permissions, approval patterns, and guarding against configuration drift caused by AI assistants.
- Third-party or model supply-chain risk assessment.
- Financial services or asset management experience.
- A certification such as CISSP, GIAC, OSCP, or a cloud security qualification.
- Willingness to adhere to the provisions of our Investment Advisory Code of Ethics related to personal securities activities and other disclosure and certification requirements.
- Understanding of the regulatory obligations of the firm, and abide by the regulated entity requirements and JHI policies applicable for your role.
Skills
- Cybersecurity
- Security Engineering
- Application Security
- Product Security
- Cloud Security
- Security Architecture
- GenAI
- LLM
- Machine Learning
- Agentic AI
- AI-enabled solutions
- Threat Modelling
- Risk Assessment
- STRIDE
- PASTA
- MITRE ATT&CK
- MITRE ATLAS
- Identity and Access Management (IAM)
- Service Principals
- Workload Identity
- Secrets Management
- Role-Based Access Control (RBAC)
- Network Controls
- Logging
- Secure Software Development Lifecycle (SDLC)
- Continuous Integration/Continuous Deployment (CI/CD)
- Code Scanning
- Dependency Scanning
- Prompt Engineering
- Retrieval-Augmented Generation (RAG)
- Function Calling
- Agent-based Tools
- Python
- Workflow Engines
- Security Orchestration, Automation, and Response (SOAR)
- API Integration
- Scripting
- KPIs
- KRIs
- Dashboards
- Reporting
- Stakeholder Engagement
- Influencing Skills
- NIST AI RMF
- OWASP Top 10 for LLM applications
- ISO/IEC 42001
- EU AI Act
- AI Red Teaming
- Adversarial Testing
- Adversarial Machine Learning
- Model Validation
- Offensive Security Assessments
- AI Security Posture Management
- Runtime Protection
- Model Monitoring
- AI Governance Tooling
- Privileged Access Management (PAM)
- Identity Governance
- Vulnerability Management
- Detection Engineering
- Threat Detection
- Security Operations
- Security Analytics
- Privacy
- Data Governance
- Responsible AI
- Microsoft Purview
- Data Loss Prevention (DLP)
- Data Classification
- Microsoft 365
- Agentic Workflows
- Configuration Drift
- Model Supply-Chain Risk Assessment
- Financial Services
- Asset Management
- CISSP
- GIAC
- OSCP
- Cloud Security Qualification
Location
- Hybrid
Work Type
- Hybrid working
Experience Level
- Individual-contributor role
- Security design authority
- Mentors security engineers
Salary/Compensations
- Position may be eligible to receive an annual discretionary bonus award from the profit pool.
Benefits
- Competitive compensation
- Pension/retirement plans
- Various health, wellbeing and lifestyle benefits
- Hybrid working and reasonable accommodations
- Generous Holiday policies
- Excellent Health and Wellbeing benefits including corporate membership to Wellhub
- Paid volunteer time
- Support to grow through professional development courses, tuition/qualification reimbursement and more
- Maternal/paternal leave benefits and family services
- All employee events including networking opportunities and social activities
- Lunch allowance for use within our subsidized onsite canteen
About the Company
- A career at Janus Henderson is more than a job, it’s about investing in a brighter future together.
- Our Mission at Janus Henderson is to help clients define and achieve superior financial outcomes through differentiated insights, disciplined investments, and world-class service.
- Our Values are key to driving our success, and are at the heart of everything we do: Clients Come First - Always | Execution Supersedes Intention | Together We Win | Diversity Improves Results | Truth Builds Trust
- Janus Henderson is undertaking a firm-wide AI transformation to become the most technologically sophisticated asset manager in the industry.
- Our AI capability sits in a single centralised function under the Head of AI, and AI Technology builds and runs it.
- This role sits in Information Security and reports to the Head of Security Engineering, while your day-to-day work is directed by AI Technology and prioritised against their roadmap.
- Security policy, security architecture approval, and security risk acceptance stay with Infosec, and you are the person who exercises them for AI — close enough to the engineering to be useful, independent enough to say no.
- Janus Henderson Investors is committed to an inclusive and supportive environment.
- We believe diversity improves results and we welcome applications from candidates from all backgrounds.
Equal Opportunity
- Janus Henderson Investors is an equal opportunity employer.
- All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability or veteran status.