AI Security Architect

Polo

Cheltenham

Hybrid

GBP 75,000 - 85,000

Full time

6 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Polo, acting on behalf of Marco Group, is seeking an AI Security Architect to own the security posture of AI tooling across the group from Cheltenham. You will define risk assessment, governance, and secure development practices for AI-enabled platforms and vendor integrations, reporting to the Group Head of Information Security.

Key focus areas include configuring Claude and Copilot security, data governance, and managing AI-related risk across internal tools and third-party products, in line

Qualifications

  • Experience in information security architecture.
  • Knowledge of LLM/generative AI architectures.
  • Familiarity with DORA, UK GDPR, ISO 27001, NIST CSF.
  • Experience running risk assessments and translating findings into controls.
  • Strong stakeholder management and communication.

Responsibilities

  • Platform Security – Claude & Copilot: Own security configuration and hardening across full capability set.
  • AI Risk Assessment & Controls: Design and run an AI risk framework covering data classification and model access.
  • Secure AI-Assisted Development: Embed security guardrails in AI coding tools and CI/CD.
  • Third-Party & Vendor AI Governance: Assess AI features in third-party products and conduct vendor due diligence.
  • Governance, Reporting & Stakeholder Engagement: Report AI risk posture to Group Head of Information Security and governance committees.

Skills

Security architecture
Cloud security
Vendor risk
AI security
Regulatory knowledge
Stakeholder mgmt
Threat modelling
AI governance

Job description

Department: Digital

Employment Type: Permanent

Location: Cheltenham

Compensation: £75,000 - £85,000 / year

Description

PoloWorks are currently recruiting this role on behalf of our parent company Marco Group.

We are looking for an AI Security Architect to own the security posture of AI tooling across the Marco Group, covering approved platforms such as Microsoft Copilot and Anthropic Claude in their full capability set, AI capabilities embedded within existing business systems, AI-assisted software development, and third-party or vendor AI usage. This is a newly created, architecture-level role that will define how the Group adopts AI safely, at pace, and in line with regulatory expectations.

Working closely with the Group Head of Information Security, the AI Security Architect will design and maintain the security controls, risk assessment framework and governance model for AI tooling, and will act as the Group's technical authority on generative AI risk – including data leakage, prompt injection, agentic/tool-use risk and model access control. The role will also support engineering teams in embedding secure practices where AI-assisted development tools are used, and will contribute AI-specific risk assessment to vendor and third-party due diligence. This role will report into the Group Head of Information Security.

Key Responsibilities
Platform Security – Claude & Copilot

Own the security configuration and ongoing hardening of Claude and Microsoft Copilot across their full capability set, including connectors, agentic/tool-use features, data access scopes and browser or desktop extensions

Define and maintain acceptable-use policies, permission boundaries and data-loss-prevention controls specific to generative AI tooling

Monitor vendor feature releases and proactively assess new capabilities, such as new connectors or agent modes, for risk before they reach general use

AI Risk Assessment & Controls

Design and run a standing AI risk assessment framework covering data classification, model access, third-party data flows and output integrity, applied consistently to every new AI use case

Maintain a central AI tooling register of approved, restricted and prohibited tools, with documented risk ratings and compensating controls

Translate assessment findings into technical and procedural controls, including access management, logging and monitoring, and prompt and data governance

Secure AI-Assisted Development

Partner with engineering and development teams to embed security guardrails where AI coding tools are used, including code review standards, secrets handling and dependency and IP risk

Define secure-by-design patterns for building internal AI-powered tools or integrations

Third-Party & Vendor AI Governance

Assess AI capabilities embedded in third-party and vendor products, both existing suppliers adding AI features and new AI vendors, as part of vendor due diligence

Contribute AI-specific clauses to vendor contracts and DPAs, covering data use, model training exclusions and sub-processor disclosure

Maintain oversight of shadow AI usage risk across the business

Governance, Reporting & Stakeholder Engagement

Report AI risk posture and control effectiveness to the Group Head of Information Security and relevant governance committees

Support regulatory alignment as it relates to AI tool usage, including DORA, UK GDPR and sector-specific AI guidance

Act as the internal technical authority and first point of contact for AI security queries across the business

Skills, Knowledge and Expertise

Strong background in information security architecture, ideally with exposure to cloud/SaaS security and vendor risk

Working knowledge of LLM and generative AI architectures, data flows and associated threat models, including prompt injection, data leakage, model access control and agentic tool-use risk

Familiarity with regulatory frameworks relevant to the sector, including DORA, UK GDPR, ISO 27001 and NIST CSF

Experience running structured risk assessments and translating them into actionable controls

Strong stakeholder management, with the confidence to engage both technical teams and senior leadership

Desirable: experience working within the Lloyd's or London Market (insurer, managing agency, broker or managed service provider), including familiarity with Lloyd's Minimum Standards, Principle 12 and Operational Resilience (OpRes) requirements

Knowledge & Qualifications

Security architecture principles and design patterns across cloud and SaaS environments

Large language model and generative AI architectures, including agentic and tool-use / connector risk

AI governance concepts and frameworks, such as ISO/IEC 42001 and the NIST AI Risk Management Framework

DORA, ISO 27001, NIST CSF and UK/EU GDPR requirements

Vendor and third-party risk assessment methodology

Secure software development practices, particularly where AI-assisted coding tools are in use

One or more of the following (or working towards):

  • CISSP, CISM, CRISC, SABSA, TOGAF (security architecture stream) or equivalent
  • ISO 27001 LA/LI or equivalent
  • ISO/IEC 42001 Lead Auditor or Lead Implementer (AI Management Systems), or equivalent
Desirable – AI governance / assurance accreditations:
  • ISACA Certified in Artificial Intelligence (Certified AI Audit / AAIA), or AI Fundamentals certificate
  • NIST AI Risk Management Framework (AI RMF) practitioner training
  • CertNexus Certified Artificial Intelligence Practitioner (CAIP), or equivalent AI security/ethics credential
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

AI Security Architect
AI Security Architect

Polo • City Of London

On-site
GBP 75,000 - 85,000
AI Security Architect
AI Security Architect

PoloWorks • Greater London

On-site
GBP 75,000 - 85,000
Security GRC & AI Analyst
Security GRC & AI Analyst

PoloWorks • Cheltenham

On-site
GBP 45,000 - 55,000
AI Security Architect
AI Security Architect

poloworks • Cheltenham

On-site
GBP 100,000 - 160,000
AI Security Architect
AI Security Architect

Additional Resources Ltd. • Greater London

Hybrid
GBP 129,000 - 203,000
Principal Consultant - AI Security & Governance
Principal Consultant - AI Security & Governance

Fruition Group • Greater London

Hybrid
GBP 110,000 - 170,000
AI Governance SME
AI Governance SME

10Pearls • Greater London

On-site
GBP 90,000 - 130,000
Principal AI Security Software Engineer
Principal AI Security Software Engineer

Source Technology Limited • Greater London

On-site
GBP 189,000 - 208,000
Senior GenAI & AI Trust Architect
Senior GenAI & AI Trust Architect

SPG Resourcing • Greater London

Hybrid
GBP 90,000 - 140,000
AI Governance Engineering Lead
AI Governance Engineering Lead

Janus Henderson Group • Greater London

Hybrid
GBP 90,000 - 140,000
Hybrid working
Health and wellbeing benefits
Volunteer time
+3