Janus Henderson Investors
AI Governance Engineering Lead

How your CV stacks up
Upload your CV to see how well it fits this job role
?%
Why work for us?
A career at Janus Henderson is more than a job, it’s about investing in a brighter future together.
Our Mission at Janus Henderson is to help clients define and achieve superior financial outcomes through differentiated insights, disciplined investments, and world-class service. We will do this by protecting and growing our core business, amplifying our strengths and diversifying where we have the right.
Our Values are key to driving our success, and are at the heart of everything we do:
- Clients Come First - Always
- Execution Supersedes Intention
- Together We Win
- Diversity Improves Results
- Truth Builds Trust
If our mission, values, and purpose align with your own, we would love to hear from you!
Your opportunity
This is an engineering role. Janus Henderson is undertaking a firm-wide AI transformation to become the most technologically sophisticated asset manager in the industry, and it has to move quickly inside boundaries that actually hold. Your job is to make those boundaries part of the platform — governance as code and by design, so that engineers and users inherit the right behaviour automatically instead of passing through a review queue at the end.
You will sit within AI Technology and report to the Head of AI Technology. You will not be the firm’s expert on AI regulation, and you do not need to be: Risk has a dedicated AI governance specialist who owns regulatory interpretation, policy, and standards, and Infosec owns security policy and security-control approval. You will work with both, day to day. What we need from you is the engineering half of that partnership — the person who can take what a risk, legal, privacy, or audit specialist tells them they need, work out what it means in a system, and build it.
The controls you build land on our two central platforms: Nexus, our agentic workspace, where employees and citizen developers build and run AI applications, agents, and shared skills; and Accio, our centralised MCP server, which consumes other MCP servers and presents enterprise datasets through one governed interface. In practice that means identity and permissions for agents and tools, policy-as-code and deployment gates, evaluation hooks in the release path, and the telemetry and evidence that show any of it is working — across the model gateway, agent orchestration, and the applications built on top.
The skill that decides whether this role succeeds is translation. You will sit with people whose domains are nothing like yours, understand what they are actually asking for rather than the words they used, and turn it into a technical design they recognise as their requirement. You should be able to hit the ground running on identity, cloud, and controls, and be comfortable that the AI part of the problem is changing faster than anyone’s standards for it.
What success looks like
- Controls exist as working platform capability rather than documents. Engineers satisfy them through standard paths, without informal interpretation or repeated meetings.
- Risk, Infosec, and Internal Audit recognise their requirements in what you built, and can test control operation from evidence the platform generates rather than assembled after the event.
- Every production AI workload has a named owner, risk classification, evaluation record, approved access, operating telemetry, and retrievable release evidence.
- Low-risk model and software updates move through a repeatable, time-bound path while higher-risk deployments get the scrutiny they require, and when a control fails the lesson lands in a platform default rather than a report.
Reasons to use Rodeo
I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?
Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.
Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.
Start with a chat, not a search bar
Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.
Graduate Consultant — 2026 Scheme
Why you're a good match
StrongYour economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.
See breakdownIt searches the market for you
Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.
Why you're a good match
You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.
Experience fit
Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.
Only hits
No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.
Your responsibilities
Build governance into the platform
- Turn the policies, standards, and risk decisions that Risk and Infosec own into reusable controls, policy-as-code, deployment gates, and secure defaults.
- Create self-service governance patterns and templates so approved teams can build safely without repeated manual approvals, and embed control checks and evidence capture into repositories, CI/CD pipelines, infrastructure-as-code, and deployment workflows.
- Establish cost, usage, data-access, and model-access boundaries that are enforced by default through the model gateway and platform services.
- Define a proportionate lifecycle for experiments, pilots, production AI products, model changes, and autonomous agents, and set the release requirements that go with each tier.
Engineer identity, access, and permissions
- Design and implement identity, authentication, authorisation, and permission patterns for agents, models, tools, connectors, and service accounts, working with enterprise IAM and AI Security.
- Implement least privilege and entitlement models that hold when a request crosses several systems, including through Accio to downstream MCP servers.
- Build the approval and human-in-the-loop patterns that high-stakes actions require, while keeping low-risk activity self-service.
- Implement an auditable framework for agents and end-user-developed applications, covering named ownership, permissions, approved data, testing, change history, and retirement.
Build the evidence, telemetry, and evaluation layer
- Define and build the event and evidence model needed to reconstruct prompts, model responses, tool calls, agent decisions, approvals, data access, and cost.
- Work with AI Engineering and AI Platforms to make telemetry consistent across the model gateway, agent orchestration, applications, and external providers.
- Build evaluation and regression hooks into the release path, with acceptance thresholds for models, prompts, agents, and platform changes, automated wherever practical.
- Design monitoring for control failures, model drift, anomalous use, permission breaches, and high-risk actions, with clear escalation and remediation paths.
- Build the dashboards and evidence packs that service owners, Risk, Infosec, and Internal Audit use directly, so assurance does not depend on you being in the room.
Translate across domains, and work across the firm
- Work with Risk’s AI governance specialist, Infosec, Legal, Compliance, Privacy, Records Management, and TPRM to understand what each needs, and convert it into technical requirements engineers can implement.
- Write standards and control requirements that are specific enough to build from, and explain back to non-engineers how the platform behaves and why.
- Advise AI Architecture, AI Engineering, AI Platforms, and Forward Deployed Engineering on control design, and help teams classify use cases and understand which controls apply before they build.
- Support risk-based onboarding of new foundation models, AI software, and connectors with AI Platforms and AI Security without restarting the process for every low-risk update, and work alongside Percepta so controls and operating knowledge transfer into our ownership.
What to expect when you join our firm
- Hybrid working and reasonable accommodations
- Generous Holiday policies
- Excellent Health and Wellbeing benefits including corporate membership to Wellhub
- Paid volunteer time to step away from your desk and into the community
- Support to grow through professional development courses, tuition/qualification reimbursement and more
- Maternal/paternal leave benefits and family services
- All employee events including networking opportunities and social activities
- Lunch allowance for use within our subsidized onsite canteen


Get help with your application
Your very own career expert that helps elevate your application to the next level.
Must have skills
- At least six years in software, platform, or security engineering, with a track record of building and operating things that reached production. This is an engineering role — a policy, audit, or compliance background is not what we are looking for.
- Strong Python and SQL, and hands-on ability with APIs, infrastructure as code, and CI/CD. You will build the controls, not specify them for somebody else to build.
- Real depth in identity and access: authentication, authorisation, RBAC, service principals and workload identity, secrets management, entitlement models, and least privilege.
- A practical understanding of what a technical control is and how to implement one — preventive and detective controls, secure defaults, deployment gates, and the evidence a control has to produce.
- Hands-on experience with a major cloud, ideally Azure, including logging, monitoring, and data-protection primitives.
- The ability to work with stakeholders whose domain is not yours — risk, legal, privacy, compliance, audit, security — understand what they actually need rather than the words they used, and turn it into a technical design they recognise as their requirement.
- Practical knowledge of generative AI and agentic systems: foundation models, prompts, retrieval, tools, connectors, model gateways, and autonomous workflows.
- Judgement to distinguish a control objective from a preferred implementation and apply proportionate controls based on actual risk, and clear communication — you can write a technical standard an engineer can implement, and explain to a non-engineer why the platform does what it does.
Nice to have skills
- Policy-as-code tooling such as Open Policy Agent or Rego, and automated evidence or compliance-as-code pipelines.
- Entra ID, Microsoft Purview, DLP policy design, or data classification across a Microsoft 365 estate.
- Experience securing or governing agents, tool execution, MCP servers, or other machine-to-machine interfaces.
- Experience building internal developer platforms, golden-path patterns, or self-service guardrails used by other engineering teams.
- Snowflake, Microsoft Fabric / OneLake, and governed enterprise data access patterns.
- Exposure to a regulated environment, or to Internal Audit and independent control testing. Useful context, but we will build the regulatory knowledge around you.
Supervisory responsibilities
No. This is a senior individual-contributor role with authority over the design and implementation of governance controls. The role may lead cross-functional work and coach engineers, but does not line-manage.
Potential for growth
- Mentoring
- Leadership development programs
- Regular training
- Career development services
- Continuing education courses
At Janus Henderson Investors we’re committed to an inclusive and supportive environment. We believe diversity improves results and we welcome applications from candidates from all backgrounds. Don’t worry if you don’t think you tick every box, we still want to hear from you!
“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”
Jessica, London