AI Governance Engineering Lead
Listed on 2026-09-22
-
Software Development
AI Engineer (Applied/Software), DevOps
You will sit within AI Technology and report to the Head of AI Technology. You will not be the firm's expert on AI regulation, and you do not need to be:
Risk has a dedicated AI governance specialist who owns regulatory interpretation, policy, and standards, and Infosec owns security policy and security-control approval. You will work with both, day to day. What we need from you is the engineering half of that partnership - the person who can take what a risk, legal, privacy, or audit specialist tells them they need, work out what it means in a system, and build it.
The controls you build land on our two central platforms:
Nexus, our agentic workspace, where employees and citizen developers build and run AI applications, agents, and shared skills; and Accio, our centralised MCP server, which consumes other MCP servers and presents enterprise datasets through one governed interface. In practice that means identity and permissions for agents and tools, policy-as-code and deployment gates, evaluation hooks in the release path, and the telemetry and evidence that show any of it is working - across the model gateway, agent orchestration, and the applications built on top.
The skill that decides whether this role succeeds is translation. You will sit with people whose domains are nothing like yours, understand what they are actually asking for rather than the words they used, and turn it into a technical design they recognise as their requirement. You should be able to hit the ground running on identity, cloud, and controls, and be comfortable that the AI part of the problem is changing faster than anyone's standards for it.
success looks like
- Controls exist as working platform capability rather than documents. Engineers satisfy them through standard paths, without informal interpretation or repeated meetings.
- Risk, Infosec, and Internal Audit recognise their requirements in what you built, and can test control operation from evidence the platform generates rather than assembled after the event.
- Every production AI workload has a named owner, risk classification, evaluation record, approved access, operating telemetry, and retrievable release evidence.
- Low-risk model and software updates move through a repeatable, time-bound path while higher-risk deployments get the scrutiny they require, and when a control fails the lesson lands in a platform default rather than a report.
- Turn the policies, standards, and risk decisions that Risk and Infosec own into reusable controls, policy-as-code, deployment gates, and secure defaults.
- Create self-service governance patterns and templates so approved teams can build safely without repeated manual approvals, and embed control checks and evidence capture into repositories, CI/CD pipelines, infrastructure-as-code, and deployment workflows.
- Establish cost, usage, data-access, and model-access boundaries that are enforced by default through the model gateway and platform services.
- Define a proportionate lifecycle for experiments, pilots, production AI products, model changes, and autonomous agents, and set the release requirements that go with each tier.
- Design and implement identity, authentication, authorisation, and permission patterns for agents, models, tools, connectors, and service accounts, working with enterprise IAM and AI Security.
- Implement least privilege and entitlement models that hold when a request crosses several systems, including through Accio to downstream MCP servers.
- Build the approval and human-in-the-loop patterns that high-stakes actions require, while keeping low-risk activity self-service.
- Implement an auditable framework for agents and…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).