Security GRC & AI Analyst

PoloWorks

Cheltenham

On-site

GBP 45,000 - 55,000

Full time

14 days+
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

PoloWorks is seeking a Security GRC & AI Analyst to strengthen information security across the Marco Group, with responsibility for governance, risk management and AI governance. The role focuses on ISO 27001, DORA, OpRes and security controls, in a cross-functional environment spanning Risk, Compliance, Technology and third-party suppliers.

You will help deliver AI governance, risk assessments and responsible AI adoption, while maintaining strong policies and incident response readiness within

Qualifications

  • Experience in information security in a governance, risk, or compliance role.
  • Practical knowledge of Microsoft Defender and Microsoft Purview.
  • Experience with security risk assessments and governance frameworks.
  • Understanding of ISO 27001 and security audit requirements.
  • Familiarity with AI governance and responsible AI adoption.
  • Knowledge of data protection and privacy requirements.
  • Strong analytical and problem-solving skills.
  • Excellent communication and stakeholder management abilities.
  • Interest in emerging technologies and AI.

Responsibilities

  • Governance, Risk and Compliance activities including policy maintenance and audits.
  • ISO 27001 certification activities and control reviews.
  • Support DORA compliance and ICT risk management.
  • Monitor and improve Lloyd's Operational Resilience requirements.
  • Administer Microsoft Defender and Purview security controls.
  • Oversee AI governance, risk management and responsible AI adoption.
  • Collaborate with Risk, Compliance, Technology and suppliers.
  • Produce KRI/KPI reporting for governance forums.
  • Support third-party supplier security assessments.
  • Security awareness and training content creation.

Skills

GRC
ISO 27001
Microsoft Defender
Microsoft Purview
AI governance
Risk assessment
Data protection
Stakeholder management
Incident response
Security controls

Job description

Department: Information Technology

Location: Cheltenham

Compensation: £45,000 - £55,000 / year

Description

PoloWorks are currently recruiting this role on behalf of our parent company Marco Group.

As we continue to grow, we are looking for a Security GRC & AI Analyst to play a key role in strengthening our information security framework whilst supporting the safe and responsible adoption of AI technologies across the Group.

This is a fantastic opportunity for a security professional who enjoys working across governance, risk, compliance, operational security and emerging technology, helping to shape how AI is governed within a modern insurance business.

Key Responsibilities
  • Governance, Risk and Compliance (GRC)
  • ISO 27001 certification and continuous improvement
  • Operational Resilience (OpRes) and DORA compliance
  • Microsoft Defender and Purview administration
  • AI governance, risk management and responsible AI adoption

Working closely with Risk & Compliance teams, Technology, business leaders and third-party suppliers, you will help ensure Marco Group maintains strong security controls, manages risk effectively and adopts AI technologies in a secure and compliant manner.

Governance, Risk & Compliance
  • Support the maintenance and continuous improvement of information security policies, procedures and standards
  • Assist with ISO 27001 certification activities, including control reviews, evidence collection and audit preparation
  • Support DORA compliance activities, ICT risk management and remediation tracking
  • Contribute to Lloyd's Operational Resilience (OpRes) requirements, including scenario testing and self-assessments
  • Monitor compliance against recognised frameworks including ISO 27001, NIST CSF and Lloyd's requirements
  • Identify, assess and track security and AI-related risks through to resolution
  • Produce KRI/KPI reporting for governance forums and stakeholders
  • Support third-party and supplier security assessments
AI Governance & Responsible AI
  • Support governance and oversight of AI tools used across Marco and PoloWorks, including Microsoft Copilot, Anthropic Claude and other AI-enabled platforms
  • Maintain AI acceptable use standards, approval processes and usage records
  • Conduct AI risk assessments for new use cases and integrations
  • Monitor AI deployments for compliance with data protection, confidentiality and regulatory requirements
  • Keep up to date with evolving AI governance frameworks and regulatory developments
  • Support the creation of AI training, guidance and awareness materials
Security Operations
  • Administer and maintain Microsoft Defender security controls and alerting
  • Configure and support Microsoft Purview capabilities including DLP, sensitivity labels and insider risk controls
  • Investigate security alerts and support incident response activities
  • Participate in incident reviews, testing exercises and security improvement initiatives
  • Provide practical security advice and guidance across the business
Security Awareness
  • Help deliver the Group's security awareness and phishing simulation programme
  • Create engaging training content on security and responsible AI use
  • Monitor and report on training participation and awareness metrics
Essential Experience
Skills, Knowledge and Expertise
  • Experience in Information Security, ideally within a GRC, compliance or risk-focused role
  • Practical knowledge of Microsoft Defender and Microsoft Purview
  • Experience of security risk assessments, governance frameworks and security controls
  • Understanding of ISO 27001 and security audit requirements
  • Familiarity with AI governance, AI risk assessment or responsible AI adoption
  • Knowledge of data protection and privacy requirements
  • Strong analytical and problem-solving skills
  • Excellent communication and stakeholder management skills
  • A genuine interest in emerging technologies and AI
Desirable Experience
  • Experience within the Lloyd's, London Market or wider insurance sector
  • Knowledge of Lloyd's Minimum Standards, Principle 12 and Operational Resilience requirements
  • Experience supporting DORA compliance programmes
  • Knowledge of information classification and cryptography

We're interested in candidates who hold, or are working towards, one or more of the following:

  • CISMP
  • ISC2 CC
  • ISO 27001 Lead Auditor or Lead Implementer
  • CISM
  • CISSP
  • CRISC
  • SANS certifications or equivalent
Microsoft Certifications Such As
  • SC-200
  • SC-300
  • SC-400
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security GRC & AI Analyst
Security GRC & AI Analyst

Polo • Cheltenham

On-site
GBP 45,000 - 55,000
AI Governance & Security Analyst
AI Governance & Security Analyst

Polo • Cheltenham

On-site
GBP 45,000 - 55,000
GRC & AI Security Analyst
GRC & AI Security Analyst

PoloWorks • Cheltenham

On-site
GBP 45,000 - 55,000
GRC Senior Analyst
GRC Senior Analyst

Recruitment • Greater London

On-site
GBP 75,000 - 110,000
Information Security – (Data & AI team)
Information Security – (Data & AI team)

Lorien • Greater London

Hybrid
Cybersecurity Consultant
Cybersecurity Consultant

Experis UK • Greater London

Hybrid
GBP 111,000 - 166,000
Security Engineer - AI and Emerging Technologies
Security Engineer - AI and Emerging Technologies

Harrington Starr • Greater London

Hybrid
GBP 85,000 - 110,000
Hybrid work environment
Exposure to senior stakeholders
Career development opportunities
+1
GRC Analyst
GRC Analyst

IMT Resourcing Solutions • Cheltenham

On-site
GBP 42,000 - 58,000
Senior Information Security Governance Analyst
Senior Information Security Governance Analyst

Blue Legal • Portsmouth

On-site
GBP 60,000 - 90,000
Cyber Security Analyst
Cyber Security Analyst

Novia Financial plc • Bath

On-site
GBP 55,000 - 75,000