AI Governance Engineering Lead
Why work for us?
A career at Janus Henderson is more than a job, it’s about investing in a brighter future together.
Our Mission at Janus Henderson is to help clients define and achieve superior financial outcomes through differentiated insights, disciplined investments, and world-class service. We will do this by protecting and growing our core business, amplifying our strengths and diversifying where we have the right.
Our Values are key to driving our success, and are at the heart of everything we do:
Clients Come First - Always | Execution Supersedes Intention | Together We Win | Diversity Improves Results | Truth Builds Trust
If our mission, values, and purpose align with your own, we would love to hear from you!
Your opportunity
This is an engineering role. Janus Henderson is undertaking a firm-wide AI transformation to become the most technologically sophisticated asset manager in the industry, and it has to move quickly inside boundaries that actually hold. Your job is to make those boundaries part of the platform — governance as code and by design, so that engineers and users inherit the right behaviour automatically instead of passing through a review queue at the end.
You will sit within AI Technology and report to the Head of AI Technology. You will not be the firm’s expert on AI regulation, and you do not need to be: Risk has a dedicated AI governance specialist who owns regulatory interpretation, policy, and standards, and Infosec owns security policy and security-control approval. You will work with both, day to day. What we need from you is the engineering half of that partnership — the person who can take what a risk, legal, privacy, or audit specialist tells them they need, work out what it means in a system, and build it.
The controls you build land on our two central platforms: Nexus, our agentic workspace, where employees and citizen developers build and run AI applications, agents, and shared skills; and Accio, our centralised MCP server, which consumes other MCP servers and presents enterprise datasets through one governed interface. In practice that means identity and permissions for agents and tools, policy-as-code and deployment gates, evaluation hooks in the release path, and the telemetry and evidence that show any of it is working — across the model gateway, agent orchestration, and the applications built on top.
The skill that decides whether this role succeeds is translation. You will sit with people whose domains are nothing like yours, understand what they are actually asking for rather than the words they used, and turn it into a technical design they recognise as their requirement. You should be able to hit the ground running on identity, cloud, and controls, and be comfortable that the AI part of the problem is changing faster than anyone’s standards for it.
What success looks like
- Controls exist as working platform capability rather than documents. Engineers satisfy them through standard paths, without informal interpretation or repeated meetings.
- Risk, Infosec, and Internal Audit recognise their requirements in what you built, and can test control operation from evidence the platform generates rather than assembled after the event.
- Every production AI workload has a named owner, risk classification, evaluation record, approved access, operating telemetry, and retrievable release evidence.
- Low-risk model and software updates move through a repeatable, time-bound path while higher-risk deployments get the scrutiny they require, and when a control fails the lesson lands in a platform default rather than a report.
Your responsibilities
Build governance into the platform
- Turn the policies, standards, and risk decisions that Risk and Infosec own into reusable controls, policy-as-code, deployment gates, and secure defaults.
- Create self-service governance patterns and templates so approved teams can build safely without repeated manual approvals, and embed control checks and evidence capture into repositories, CI/CD pipelines, infrastructure-as-code, and deployment workflows.
- Establish cost, usage, data-access, and model-access boundaries that are enforced by default through the model gateway and platform services.
- Define a proportionate lifecycle for experiments, pilots, production AI products, model changes, and autonomous agents, and set the release requirements that go with each tier.
Engineer identity, access, and permissions
- Design and implement identity, authentication, authorisation, and permission patterns for agents, models, tools, connectors, and service accounts, working with enterprise IAM and AI Security.
- Implement least privilege and entitlement models that hold when a request crosses several systems, including through Accio to downstream MCP servers.
- Build the approval and human-in-the-loop patterns that high-stakes actions require, while keeping low-risk activity self-service.
- Implement an auditable framework for agents and end-user-developed applications, covering named ownership, permissions, approved data, testing, change history, and retirement.
Build the evidence, telemetry, and evaluation layer
- Define and build the event and evidence model needed to reconstruct prompts, model responses, tool calls, agent decisions, approvals, data access, and cost.
- Work with AI Engineering and AI Platforms to make telemetry consistent across the model gateway, agent orchestration, applications, and external providers.
- Build evaluation and regression hooks into the release path, with acceptance thresholds for models, prompts, agents, and platform changes, automated wherever practical.
- Design monitoring for control failures, model drift, anomalous use, permission breaches, and high-risk actions, with clear escalation and remediation paths.
- Build the dashboards and evidence packs that service owners, Risk, Infosec, and Internal Audit use directly, so assurance does not depend on you being in the room.
Translate across domains, and work across the firm
- Work with Risk’s AI governance specialist, Infosec, Legal, Compliance, Privacy, Records Management, and TPRM to understand what each needs, and convert it into technical requirements engineers can implement.
- Write standards and control requirements that are specific enough to build from, and explain back to non-engineers how the platform behaves and why.
- Advise AI Architecture, AI Engineering, AI Platforms, and Forward Deployed Engineering on control design, and help teams classify use cases and understand which controls apply before they build.
- Support risk-based onboarding of new foundation models, AI software, and connectors with AI Platforms and AI Security without restarting the process for every low-risk update, and work alongside Percepta so controls and operating knowledge transfer into our ownership.
What to expect when you join our firm
- Hybrid working and reasonable accommodations
- Generous Holiday policies
- Private Medical Insurance
- Life Insurance Cover
- Paid volunteer time to step away from your desk and into the community
- Support to grow through professional development courses, tuition/qualification reimbursement and more
- Maternal/paternal leave benefits and family services
- Complimentary subscription to Headspace, Apple Health, Strava
- All employee events including networking opportunities and social activities
- Annual SZÉP Card allowance
Must have skills
- At least six years in software, platform, or security engineering, with a track record of building and operating things that reached production. This is an engineering role — a policy, audit, or compliance background is not what we are looking for.
- Strong Python and SQL, and hands-on ability with APIs, infrastructure as code, and CI/CD. You will build the controls, not specify them for somebody else to build.
- Real depth in identity and access: authentication, authorisation, RBAC, service principals and workload identity, secrets management, entitlement models, and least privilege.
- A practical understanding of what a technical control is and how to implement one — preventive and detective controls, secure defaults, deployment gates, and the evidence a control has to produce.
- Hands-on experience with a major cloud, ideally Azure, including logging, monitoring, and data-protection primitives.
- The ability to work with stakeholders whose domain is not yours — risk, legal, privacy, compliance, audit, security — understand what they actually need rather than the words they used, and turn it into a technical design they recognise as their requirement.
- Practical knowledge of generative AI and agentic systems: foundation models, prompts, retrieval, tools, connectors, model gateways, and autonomous workflows.
- Judgement to distinguish a control objective from a preferred implementation and apply proportionate controls based on actual risk, and clear communication — you can write a technical standard an engineer can implement, and explain to a non-engineer why the platform does what it does.
Nice to have skills
- Policy-as-code tooling such as Open Policy Agent or Rego, and automated evidence or compliance-as-code pipelines.
- Entra ID, Microsoft Purview, DLP policy design, or data classification across a Microsoft 365 estate.
- Experience securing or governing agents, tool execution, MCP servers, or other machine-to-machine interfaces.
- Experience building internal developer platforms, golden-path patterns, or self-service guardrails used by other engineering teams.
- Snowflake, Microsoft Fabric / OneLake, and governed enterprise data access patterns.
- Exposure to a regulated environment, or to Internal Audit and independent control testing. Useful context, but we will build the regulatory knowledge around you.
Supervisory responsibilities
No. This is a senior individual-contributor role with authority over the design and implementation of governance controls. The role may lead cross-functional work and coach engineers, but does not line-manage.
Potential for growth
- Mentoring
- Leadership development programs
- Regular training
- Career development services
- Continuing education courses
At Janus Henderson Investors we’re committed to an inclusive and supportive environment. We believe diversity improves results and we welcome applications from candidates from all backgrounds. Don’t worry if you don’t think you tick every box, we still want to hear from you! We understand everyone has different commitments and while we can’t accommodate every flexible working request, we’re happy to be asked about work flexibility and our hybrid working environment. If you need any reasonable accommodations during our recruitment process, please get in touch and let us know at recruiter@janushenderson.com.
Annual Bonus Opportunity: Position may be eligible to receive an annual discretionary bonus award from the profit pool. The profit pool is funded based on Company profits. Individual bonuses are determined based on Company, department, team and individual performance.
Benefits: Janus Henderson is committed to offering a comprehensive total rewards package to eligible employees that includes; competitive compensation, pension/retirement plans, and various health, wellbeing and lifestyle benefits. To learn more about our offerings please visit the Why Join Us section on the career page here.
Janus Henderson Investors is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability or veteran status. All applications are subject to background checks.
Janus Henderson (including its subsidiaries) will not maintain existing or sponsor new industry registrations or licenses where not supported by an employee’s job functions (as determined by Janus Henderson at its sole discretion).
You should be willing to adhere to the provisions of our Investment Advisory Code of Ethics related to personal securities activities and other disclosure and certification requirements, including past political contributions and political activities. Applicants’ past political contributions or activity may impact applicants’ eligibility for this position.
You will be expected to understand the regulatory obligations of the firm, and abide by the regulated entity requirements and JHI policies applicable for your role.