Identity Security Engineer
Janus Henderson Investors Denver, Colorado, United States · $90K–$100K/yr
Financial Services · 1,001-5,000 employees
About the role
Design, implement, and operate Privileged Access Management (PAM) controls to secure identities, service accounts, and AI agents. Support identity threat detection, investigate security events, and develop automation to reduce operational risk.
What they look for
Requirements
Requires strong expertise in PAM principles and experience with enterprise platforms like CyberArk or Britive across cloud and on-premise environments. Candidates should be proficient in identity governance, Active Directory/Entra ID, and developing security metrics.
Benefits
Full description
Why work for us?
A career at Janus Henderson is more than a job, it’s about investing in a brighter future together.
Our Mission at Janus Henderson is to help clients define and achieve superior financial outcomes through differentiated insights, disciplined investments, and world-class service. We will do this by protecting and growing our core business, amplifying our strengths and diversifying where we have the right.
Our Values are key to driving our success, and are at the heart of everything we do:
Clients Come First - Always | Execution Supersedes Intention | Together We Win | Diversity Improves Results | Truth Builds Trust
If our mission, values, and purpose align with your own, we would love to hear from you!
Your opportunity
The Identity Security Engineer is a hands-on security engineering role focused on securing privileged access and identities across JHI. The role is primarily responsible for designing, implementing, and operating Privileged Access Management (PAM) controls, ensuring privileged users, service accounts, machine identities, APIs, and emerging AI agents are securely managed throughout their lifecycle. In addition, the engineer will support identity threat detection and response capabilities, investigate identity-related security events, maintain data access governance tooling, and develop security metrics and automation that strengthen JHI's overall identity security posture and reduce operational risk.
What to expect when you join our firm
- Hybrid working and reasonable accommodations
- Generous Holiday policies
- Excellent Health and Wellbeing benefits including corporate membership to Wellhub
- Paid volunteer time to step away from your desk and into the community
- Support to grow through professional development courses, tuition/qualification reimbursement and more
- Maternal/paternal leave benefits and family services
- Unique employee events and programs including a 14er challenge
- Complimentary beverages, snacks and all employee Happy Hours
Must have skills
- Strong understanding of Privileged Access Management (PAM) principles, including least privilege, just-in-time access, ephemeral access, privileged session management, secrets management, and credential vaulting.
- Ability to investigate, triage, and resolve PAM and identity-related incidents, requests, and operational issues while driving root-cause remediation.
- Experience administering and engineering enterprise PAM platforms such as Britive, CyberArk, Delinea, or equivalent.
- Experience designing, implementing, and operating privileged access controls across on-premise and cloud environments.
- Experience onboarding and governing privileged users, service accounts, machine identities, APIs, workload identities, and other non-human identities throughout their lifecycle.
- Experience securing and managing privileged access for automation platforms, cloud workloads, DevOps tooling, and emerging AI/agentic systems.
- Experience configuring and maintaining identity security and data access governance platforms, including Active Directory/Entra ID auditing, permissions analysis, access monitoring, and security reporting.
- Strong understanding of Identity Access Governance (IAG) concepts and integrations between PAM, IAG, and ITSM platforms, such as SailPoint Identity Security Cloud (ISC) and ServiceNow, with experience supporting identity lifecycle management, provisioning workflows, and troubleshooting workflow issues.
- Experience working with Active Directory, Entra ID, federation, authentication, access control, and modern identity security architectures.
- Experience developing security metrics, KPIs, dashboards, and reporting that measure control effectiveness, operational performance, adoption, and risk reduction in an automated manner.
Nice to have skills
- Experience with Identity Threat Detection & Response (ITDR) and identity-centric threat monitoring.
- Experience with User and Entity Behaviour Analytics (UEBA) platforms.
- Experience creating, tuning, or maintaining identity-focused detections, analytics, and use cases within a SIEM platform.
- Understanding of identity-focused attack techniques including account compromise, privilege escalation, credential theft, lateral movement, and insider threats.
- PowerShell and/or Python scripting experience for automation and operational efficiency.
- Experience integrating identity platforms with SIEM, SOAR, and security operations tooling.
- Experience monitoring and securing non-human identities, machine identities, and AI agents.
- Knowledge of AI agent security, non-human identity governance, MCP security, delegated permissions, workload identities, and AI-related identity threats.
Supervisory responsibilities
- No
Potential for growth
- Mentoring
- Leadership development programs
- Regular training
- Career development services
- Continuing education courses
Compensation information
The base salary range for this position is $90,000 to $100,000. This range is estimated for this role. Actual pay may be different. This position will be open through October 2026.
Colorado law requires an estimated closing date for job postings. Please don't be discouraged from applying if you see this date has passed.
At Janus Henderson Investors we’re committed to an inclusive and supportive environment. We believe diversity improves results and we welcome applications from candidates from all backgrounds. Don’t worry if you don’t think you tick every box, we still want to hear from you! We understand everyone has different commitments and while we can’t accommodate every flexible working request, we’re happy to be asked about work flexibility and our hybrid working environment. If you need any reasonable accommodations during our recruitment process, please get in touch and let us know at recruiter@janushenderson.com
#LI-LN2
Annual Bonus Opportunity: Position may be eligible to receive an annual discretionary bonus award from the profit pool. The profit pool is funded based on Company profits. Individual bonuses are determined based on Company, department, team and individual performance.
Benefits: Janus Henderson is committed to offering a comprehensive total rewards package to eligible employees that includes; competitive compensation, pension/retirement plans, and various health, wellbeing and lifestyle benefits. To learn more about our offerings please visit the Why Join Us section on the career page here.
Janus Henderson Investors is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability or veteran status. All applications are subject to background checks.
Janus Henderson (including its subsidiaries) will not maintain existing or sponsor new industry registrations or licenses where not supported by an employee’s job functions (as determined by Janus Henderson at its sole discretion).
You should be willing to adhere to the provisions of our Investment Advisory Code of Ethics related to personal securities activities and other disclosure and certification requirements, including past political contributions and political activities. Applicants’ past political contributions or activity may impact applicants’ eligibility for this position.
You will be expected to understand the regulatory obligations of the firm, and abide by the regulated entity requirements and JHI policies applicable for your role.
Similar roles
-
Cloud Security Engineer
Gifthealth Inc Columbus, Ohio, United States · $115K–$150K/yr
-
Senior Cybersecurity Engineer (Identity and Access Management)
Open Dealer Exchange Southfield, Michigan, United States
-
Cybersecurity Engineer
Open Dealer Exchange Southfield, Michigan, United States
-
Senior Information Security Engineer
Zscaler United States · $134K–$168K/yr
-
Cybersecurity Analyst
Smiths Group Pune, Maharashtra, India
-
Staff Product Security Engineer
Affirm Canada · CA$181K–CA$241K/yr