AI Security Architect
Department: Digital
Employment Type: Permanent
Location: London
PoloWorks are currently recruiting this role on behalf of our parent company Marco Group.
Key Responsibilities
Platform Security – Claude & Copilot
- Own the security configuration and ongoing hardening of Claude and Microsoft Copilot across their full capability set, including connectors, agentic/tool-use features, data access scopes and browser or desktop extensions
- Define and maintain acceptable-use policies, permission boundaries and data-loss-prevention controls specific to generative AI tooling
- Monitor vendor feature releases and proactively assess new capabilities, such as new connectors or agent modes, for risk before they reach general use
AI Risk Assessment & Controls
- Design and run a standing AI risk assessment framework covering data classification, model access, third- party data flows and output integrity, applied consistently to every new AI use case
- Maintain a central AI tooling register of approved, restricted and prohibited tools, with documented risk ratings and compensating controls
- Translate assessment findings into technical and procedural controls, including access management, logging and monitoring, and prompt and data governance
Secure AI-Assisted Development
- Partner with engineering and development teams to embed security guardrails where AI coding tools are used, including code review standards, secrets handling and dependency and IP risk
- Define secure-by-design patterns for building internal AI-powered tools or integrations
Third-Party & Vendor AI Governance
- Assess AI capabilities embedded in third-party and vendor products, both existing suppliers adding AI features and new AI vendors, as part of vendor due diligence
- Contribute AI-specific clauses to vendor contracts and DPAs, covering data use, model training exclusions and sub-processor disclosure
- Maintain oversight of shadow AI usage risk across the business
Governance, Reporting & Stakeholder Engagement
- Report AI risk posture and control effectiveness to the Group Head of Information Security and relevant governance committees
- Support regulatory alignment as it relates to AI tool usage, including DORA, UK GDPR and sector‑specific AI guidance
- Act as the internal technical authority and first point of contact for AI security queries across the business
Skills, Knowledge and Expertise
- Strong background in information security architecture, ideally with exposure to cloud/SaaS security and vendor risk
- Working knowledge of LLM and generative AI architectures, data flows and associated threat models, including prompt injection, data leakage, model access control and agentic tool-use risk
- Familiarity with regulatory frameworks relevant to the sector, including DORA, UK GDPR, ISO 27001 and NIST CSF
- Experience running structured risk assessments and translating them into actionable controls
- Strong stakeholder management, with the confidence to engage both technical teams and senior leadership
- Desirable: experience working within the Lloyd's or London Market (insurer, managing agency, broker or managed service provider), including familiarity with Lloyd's Minimum Standards, Principle 12 and Operational Resilience (OpRes) requirements
Knowledge & Qualifications
- Security architecture principles and design patterns across cloud and SaaS environments
- Large language model and generative AI architectures, including agentic and tool-use / connector risk
- AI governance concepts and frameworks, such as ISO/IEC 42001 and the NIST AI Risk Management Framework
- DORA, ISO 27001, NIST CSF and UK/EU GDPR requirements
- Vendor and third-party risk assessment methodology
- Secure software development practices, particularly where AI-assisted coding tools are in use
Security Certifications
- CISSP, CISM, CRISC, SABSA, TOGAF (security architecture stream) or equivalent
- ISO 27001 LA/LI or equivalent
- ISO/IEC 42001 Lead Auditor or Lead Implementer (AI Management Systems), or equivalent
Desirable – AI governance / assurance accreditations:
- ISACA Certified in Artificial Intelligence (Certified AI Audit / AAIA), or AI Fundamentals certificate
- NIST AI Risk Management Framework (AI RMF) practitioner training
- CertNexus Certified Artificial Intelligence Practitioner (CAIP), or equivalent AI security/ethics credential