AI Governance Engineering Lead
Job Summary
Why work for us
A career at Janus Henderson is more than a job its about investingin a brighter future together.
Our Mission at Janus Henderson is to help clients define and achieve superior financial outcomes through differentiated insights disciplined investments and world-class service. We will do this by protecting and growing our core business amplifying our strengths and diversifying where we have the right.
Our Values are key to driving our success and are at the heart of everything we do:
Clients Come First - Always Execution Supersedes Intention Together We Win Diversity Improves Results Truth Builds Trust
If our mission values and purpose align with your own we would love to hear from you!
This is an engineering role. Janus Henderson is undertaking a firm-wide AI transformation to become the most technologically sophisticated asset manager in the industry and it has to move quickly inside boundaries that actually hold. Your job is to make those boundaries part of the platform governance as code and by design so that engineers and users inherit the right behaviour automatically instead of passing through a review queue at the end.
You will sit within AI Technology and report to the Head of AI Technology. You will not be the firms expert on AI regulation and you do not need to be: Risk has a dedicated AI governance specialist who owns regulatory interpretation policy and standards and Infosec owns security policy and security-control approval. You will work with both day to day. What we need from you is the engineering half of that partnership the person who can take what a risk legal privacy or audit specialist tells them they need work out what it means in a system and build it.
The controls you build land on our two central platforms: Nexus our agentic workspace where employees and citizen developers build and run AI applications agents and shared skills; and Accio our centralised MCP server which consumes other MCP servers and presents enterprise datasets through one governed practice that means identity and permissions for agents and tools policy-as-code and deployment gates evaluation hooks in the release path and the telemetry and evidence that show any of it is working across the model gateway agent orchestration and the applications built on top.
The skill that decides whether this role succeeds is translation. You will sit with people whose domains are nothing like yours understand what they are actually asking for rather than the words they used and turn it into a technical design they recognise as their requirement. You should be able to hit the ground running on identity cloud and controls and be comfortable that the AI part of the problem is changing faster than anyones standards for it.
- Controls exist as working platform capability rather than documents. Engineers satisfy them through standard paths without informal interpretation or repeated meetings.
- Risk Infosec and Internal Audit recognise their requirements in what you built and can test control operation from evidence the platform generates rather than assembled after the event.
- Every production AI workload has a named owner risk classification evaluation record approved access operating telemetry and retrievable release evidence.
- Low-risk model and software updates move through a repeatable time-bound path while higher-risk deployments get the scrutiny they require and when a control fails the lesson lands in a platform default rather than a report.
Build governance into the platform
- Turn the policies standards and risk decisions that Risk and Infosec own into reusable controls policy-as-code deployment gates and secure defaults.
- Create self-service governance patterns and templates so approved teams can build safely without repeated manual approvals and embed control checks and evidence capture into repositories CI/CD pipelines infrastructure-as-code and deployment workflows.
- Establish cost usage data-access and model-access boundaries that are enforced by default through the model gateway and platform services.
- Define a proportionate lifecycle for experiments pilots production AI products model changes and autonomous agents and set the release requirements that go with each tier.
Engineer identity access and permissions
- Design and implement identity authentication authorisation and permission patterns for agents models tools connectors and service accounts working with enterprise IAM and AI Security.
- Implement least privilege and entitlement models that hold when a request crosses several systems including through Accio to downstream MCP servers.
- Build the approval and human-in-the-loop patterns that high-stakes actions require while keeping low-risk activity self-service.
- Implement an auditable framework for agents and end-user-developed applications covering named ownership permissions approved data testing change history and retirement.
Build the evidence telemetry and evaluation layer
- Define and build the event and evidence model needed to reconstruct prompts model responses tool calls agent decisions approvals data access and cost.
- Work with AI Engineering and AI Platforms to make telemetry consistent across the model gateway agent orchestration applications and external providers.
- Build evaluation and regression hooks into the release path with acceptance thresholds for models prompts agents and platform changes automated wherever practical.
- Design monitoring for control failures model drift anomalous use permission breaches and high-risk actions with clear escalation and remediation paths.
- Build the dashboards and evidence packs that service owners Risk Infosec and Internal Audit use directly so assurance does not depend on you being in the room.
Translate across domains and work across the firm
- Work with Risks AI governance specialist Infosec Legal Compliance Privacy Records Management and TPRM to understand what each needs and convert it into technical requirements engineers can implement.
- Write standards and control requirements that are specific enough to build from and explain back to non-engineers how the platform behaves and why.
- Advise AI Architecture AI Engineering AI Platforms and Forward Deployed Engineering on control design and help teams classify use cases and understand which controls apply before they build.
- Support risk-based onboarding of new foundation models AI software and connectors with AI Platforms and AI Security without restarting the process for every low-risk update and work alongside Percepta so controls and operating knowledge transfer into our ownership.
What to expect when you join our firm
- Hybrid working and reasonable accommodations
- Generous Holiday policies
- Excellent Health and Wellbeing benefits including corporate membership to Wellhub
- Paid volunteer time to step away from your desk and into the community
- Support to grow through professional development courses tuition/qualification reimbursement and more
- Maternal/paternal leave benefits and family services
- All employee events including networking opportunities and social activities
- Lunch allowance for use within our subsidized onsite canteen
- At least six years in software platform or security engineering with a track record of building and operating things that reached production. This is an engineering role a policy audit or compliance background is not what we are looking for.
- Strong Python and SQL and hands-on ability with APIs infrastructure as code and CI/CD. You will build the controls not specify them for somebody else to build.
- Real depth in identity and access: authentication authorisation RBAC service principals and workload identity secrets management entitlement models and least privilege.
- A practical understanding of what a technical control is and how to implement one preventive and detective controls secure defaults deployment gates and the evidence a control has to produce.
- Hands-on experience with a major cloud ideally Azure including logging monitoring and data-protection primitives.
- The ability to work with stakeholders whose domain is not yours risk legal privacy compliance audit security understand what they actually need rather than the words they used and turn it into a technical design they recognise as their requirement.
- Practical knowledge of generative AI and agentic systems: foundation models prompts retrieval tools connectors model gateways and autonomous workflows.
- Judgement to distinguish a control objective from a preferred implementation and apply proportionate controls based on actual risk and clear communication you can write a technical standard an engineer can implement and explain to a non-engineer why the platform does what it does.
- Policy-as-code tooling such as Open Policy Agent or Rego and automated evidence or compliance-as-code pipelines.
- Entra ID Microsoft Purview DLP policy design or data classification across a Microsoft 365 estate.
- Experience securing or governing agents tool execution MCP servers or other machine-to-machine interfaces.
- Experience building internal developer platforms golden-path patterns or self-service guardrails used by other engineering teams.
- Snowflake Microsoft Fabric / OneLake and governed enterprise data access patterns.
- Exposure to a regulated environment or to Internal Audit and independent control testing. Useful context but we will build the regulatory knowledge around you.
No. This is a senior individual-contributor role with authority over the design and implementation of governance controls. The role may lead cross-functional work and coach engineers but does not line-manage.
Potential for growth
- Mentoring
- Leadership development programs
- Regular training
- Career development services
- Continuing education courses
At Janus Henderson Investors were committed to an inclusive and supportive environment. We believe diversity improves results and we welcome applications from candidates from all backgrounds. Dont worry if you dont think you tick every box we still want to hear from you! We understand everyone has different commitments and while we cant accommodate every flexible working request were happy to be asked about work flexibility and our hybrid working environment. If you need any reasonable accommodations during our recruitment process please get in touch and let us know at .
Annual Bonus Opportunity:Position may be eligible to receive an annual discretionary bonus award from the profit pool. The profit pool is funded based on Company profits. Individual bonuses are determined based on Company department team and individual performance.
Benefits: Janus Henderson is committed to offering a comprehensive total rewards package to eligible employees that includes; competitive compensation pension/retirement plans and various health wellbeing and lifestyle benefits. To learn more about our offerings please visit the Why Join Us section on the career pagehere.
Janus Henderson Investors is an equal opportunity employer.All qualified applicants will receive consideration for employment without regard to race color religion sex sexual orientation gender identity national origin disability or veteran status. All applications are subject to background checks.
Janus Henderson (including its subsidiaries) will not maintain existing or sponsor new industry registrations or licenses where not supported by an employees job functions (as determined by Janus Henderson at its sole discretion).
You should be willing to adhere to the provisions of our Investment Advisory Code of Ethics related to personal securities activities and other disclosure and certification requirements including past political contributions and political activities. Applicants past political contributions or activity may impact applicants eligibility for this position.
You will be expected to understand the regulatory obligations of the firm and abide by the regulated entity requirements and JHI policies applicable for your role.
Required Experience:
Senior IC
About Company
Janus Henderson, a global asset manager, brings people and ideas together to deliver innovative investment solutions.