Security GRC & AI Analyst

PoloWorks

Cheltenham, England, UKfulltimeInsuranceposted
Unlock apply linkApply links and the original listing are a Pro feature: £4.99/mo or £25 once.
Department: Information Technology Location: Cheltenham Compensation: £45,000 - £55,000 / year Description PoloWorks are currently recruiting this role on behalf of our parent company Marco Group. As we continue to grow, we are looking for a Security GRC \& AI Analyst to play a key role in strengthening our information security framework whilst supporting the safe and responsible adoption of AI technologies across the Group. This is a fantastic opportunity for a security professional who enjoys working across governance, risk, compliance, operational security and emerging technology, helping to shape how AI is governed within a modern insurance business. Key Responsibilities Reporting to the Information Security Management function, you will support the ongoing development of the Group's Information Security programme, with a focus on: * Governance, Risk and Compliance (GRC) * ISO 27001 certification and continuous improvement * Operational Resilience (OpRes) and DORA compliance * Microsoft Defender and Purview administration * AI governance, risk management and responsible AI adoption Working closely with Risk \& Compliance teams, Technology, business leaders and third-party suppliers, you will help ensure Marco Group maintains strong security controls, manages risk effectively and adopts AI technologies in a secure and compliant manner. Governance, Risk \& Compliance * Support the maintenance and continuous improvement of information security policies, procedures and standards * Assist with ISO 27001 certification activities, including control reviews, evidence collection and audit preparation * Support DORA compliance activities, ICT risk management and remediation tracking * Contribute to Lloyd's Operational Resilience (OpRes) requirements, including scenario testing and self-assessments * Monitor compliance against recognised frameworks including ISO 27001, NIST CSF and Lloyd's requirements * Identify, assess and track security and AI-related risks through to resolution * Produce KRI/KPI reporting for governance forums and stakeholders * Support third-party and supplier security assessments AI Governance \& Responsible AI * Support governance and oversight of AI tools used across Marco and PoloWorks, including Microsoft Copilot, Anthropic Claude and other AI-enabled platforms * Maintain AI acceptable use standards, approval processes and usage records * Conduct AI risk assessments for new use cases and integrations * Monitor AI deployments for compliance with data protection, confidentiality and regulatory requirements * Keep up to date with evolving AI governance frameworks and regulatory developments * Support the creation of AI training, guidance and awareness materials Security Operations * Administer and maintain Microsoft Defender security controls and alerting * Configure and support Microsoft Purview capabilities including DLP, sensitivity labels and insider risk controls * Investigate security alerts and support incident response activities * Participate in incident reviews, testing exercises and security improvement initiatives * Provide practical security advice and guidance across the business Security Awareness * Help deliver the Group's security awareness and phishing simulation programme * Create engaging training content on security and responsible AI use * Monitor and report on training participation and awareness metrics Essential Experience Skills, Knowledge and Expertise * Experience in Information Security, ideally within a GRC, compliance or risk-focused role * Practical knowledge of Microsoft Defender and Microsoft Purview * Experience of security risk assessments, governance frameworks and security controls * Understanding of ISO 27001 and security audit requirements * Familiarity with AI governance, AI risk assessment or responsible AI adoption * Knowledge of data protection and privacy requirements * Strong analytical and problem-solving skills * Excellent communication and stakeholder management skills * A genuine interest in emerging technologies and AI Desirable Experience * Experience within the Lloyd's, London Market or wider insurance sector * Knowledge of Lloyd's Minimum Standards, Principle 12 and Operational Resilience requirements * Experience supporting DORA compliance programmes * Knowledge of information classification and cryptography We're interested in candidates who hold, or are working towards, one or more of the following: * CISMP * ISC2 CC * ISO 27001 Lead Auditor or Lead Implementer * CISM * CISSP * CRISC * SANS certifications or equivalent Microsoft Certifications Such As * SC-200 * SC-300 * SC-400