EngineerJobs.io
← Back to all jobs

Job Description

Denver, CO (onsite)

Compensation: USD 145,000 - 190,000 per year

In the Office of the CISO at Janus Henderson, this role delivers hands-on AI security engineering that helps secure AI-enabled applications, models, agents, and the underlying platforms across the full lifecycle. You will set the security design direction for agentic systems and help ensure controls are practical, measurable, and repeatable at enterprise scale, with your work translated into code and secure defaults by AI Engineering and AI Platforms.

What you’ll do

  • Serve as an AI security design authority for agentic applications, model gateway capabilities, Accio, Nexus, and other novel or high-risk AI initiatives by leading threat modeling, architecture review, and risk assessment using frameworks such as STRIDE, PASTA, MITRE ATT&CK, and MITRE ATLAS.
  • Define and evolve AI security standards, guardrails, governance controls, and secure-by-design patterns aligned to enterprise requirements and the firm’s risk appetite, co-designed with the Principal AI Architect and implemented as code and secure defaults by AI Engineering and AI Platforms. Coordinate with the AI Governance Implementation Lead on how controls land on the platform.
  • Design identity, entitlement, and secrets patterns for non-human identities such as agents, tools, MCP servers, connectors, and service principals, including scoped permissions, credential lifetime, rotation, and least privilege across multi-hop requests.
  • Set trust boundaries and data egress controls for the AI estate, including what may reach external model providers, and partner with data protection owners on classification, DLP enforcement, privacy, and data governance obligations.
  • Run adversarial testing and AI red teaming across models, prompts, agents, and tool chains, covering prompt injection and indirect injection, model manipulation and hijacking, excessive agency, function-call abuse, data leakage from LLM outputs, and privilege escalation between agents.
  • Build detections, security analytics, and telemetry for AI-specific abuse such as anomalous tool invocation, credential misuse by agents, unusual data access, and exfiltration through model responses, and integrate results into the firm’s monitoring estate.
  • Support security incident response for AI systems including triage, containment, and forensics across prompts, tool calls, and agent decisions, then feed lessons into platform defaults and evaluation suites.
  • Own security testing in the AI delivery lifecycle with static analysis, dependency and container scanning, secrets detection, and security gates in CI/CD so issues are identified before release.
  • Co-own the risk-based security gate for onboarding new AI products, model providers, versions, and platform features, performing security due diligence and risk assessment of AI vendors, platforms, and models (including provenance, open-source components, tenancy/data-use terms, security advisories) and validating platform updates before rollout.
  • Decide with the Senior AI Platform Engineer and Principal AI Architect which Copilot features are released and to whom, withholding capability until required controls are evidenced, and review solutions built by Forward Deployed Engineering and platforms built with Percepta so they do not reach production without a security position. Define guardrails for citizen developers and Copilot Studio makers with AI Enablement.
  • Support Risk and Internal Audit with security evidence and participate in Infosec security-control approval and risk-acceptance for AI, escalating when residual risk exceeds appetite.
  • Identify opportunities to apply AI and automation to security operations, engineering, assurance, and governance, building automation using code, APIs, scripting, orchestration platforms, or low-code technologies to automate response workflows and enrich incident data.
  • Define and report KPIs, KRIs, dashboards, and reporting demonstrating risk reduction, control effectiveness, and operational improvement.
  • Mentor security engineers on AI security and build enough AI literacy across Infosec so the team is not dependent on a single point of knowledge.

What you bring

  • Strong cybersecurity experience across security engineering, application security, product security, cloud security, or security architecture, with a hands-on engineering background and a track record of protections reaching production.
  • Hands-on experience securing GenAI, LLMs, machine learning, agentic AI, and AI-enabled solutions across their lifecycle.
  • Proven ability to lead threat modeling, architecture reviews, and risk assessments for complex technology platforms and services.
  • Strong understanding of AI-specific threats and risk assessment approaches, including prompt injection, model manipulation, excessive agency, and frameworks such as STRIDE, PASTA, MITRE ATT&CK, MITRE ATLAS, and equivalent industry practices.
  • Experience defining and evolving AI security standards, guardrails, governance controls, and secure-by-design patterns aligned with enterprise requirements and risk appetite.
  • Experience securing AI agents and integrations including MCP, permissions, non-human identities, autonomous workflows, and AI platform integrations.
  • Cloud security depth, ideally Azure, including IAM, service principals and workload identity, secrets management, RBAC, network controls, and logging, plus experience securing application delivery with secure SDLC and CI/CD controls such as code and dependency scanning.
  • Practical experience with AI/LLM systems (prompt engineering, retrieval-augmented generation, function calling, agent-based tools) and the ability to build and deploy automation using code, APIs, scripting, orchestration platforms, or low-code technologies (for example Python, workflow engines, or SOAR), integrating security logs, AI models, and platform components into cohesive pipelines.
  • Metrics-driven mindset with experience defining KPIs, KRIs, dashboards, and reporting.
  • Strong stakeholder engagement and influencing skills, including translating technical risk into business impact, providing pragmatic controls, and maintaining an independent security position under delivery pressure.

Tools and technologies

  • STRIDE, PASTA, MITRE ATT&CK, MITRE ATLAS
  • CI/CD, Azure, RBAC, DLP, MCP
  • LLM, GenAI, machine learning
  • Python, SOAR, retrieval-augmented generation, function calling
  • NIST AI RMF, OWASP Top 10 for LLM applications, ISO/IEC 42001, EU AI Act

Benefits and support

  • Hybrid working and reasonable accommodations
  • Generous Holiday policies
  • Excellent Health and Wellbeing benefits including corporate membership to Wellhub
  • Paid volunteer time
  • Support for professional development including development courses and tuition/qualification reimbursement
  • Maternal/paternal leave benefits and family services
  • Unique employee events and programs including a 14er challenge
  • Complimentary beverages, snacks and all employee Happy Hours
  • Annual Bonus Opportunity
  • Competitive compensation, pension/retirement plans, and various health, wellbeing and lifestyle benefits

Additional details

  • Division: Office of the CISO
  • Supervisory responsibilities: No (individual-contributor role). Security design authority for AI systems and mentors security engineers, but does not line-manage.
  • Potential for growth: Mentoring, leadership development programs, regular training, career development services, and continuing education courses.

Note on application window: This position will be open through [add date]. Colorado law requires an estimated closing date for job postings. If you see this date has passed, you are still encouraged to apply.

Similar Jobs