At a Glance
- Tasks: Strengthen information security and support AI adoption across the Group.
- Company: Join Marco Group, a leader in innovative insurance solutions.
- Benefits: Competitive salary, career growth, and a dynamic work environment.
- Other info: Exciting opportunity to work with emerging technologies and make a real impact.
- Why this job: Shape the future of AI governance in a modern insurance business.
- Qualifications: Experience in Information Security with a focus on GRC and compliance.
The predicted salary is between 45000 - 55000 £ per year.
Security GRC & AI Analyst
Department
Information Technology
Employment Type
Permanent
Location
Cheltenham
Compensation
Description
Polo Works are currently recruiting this role on behalf of our parent company Marco Group.
As we continue to grow, we are looking for a Security GRC & AI Analyst to play a key role in strengthening our information security framework whilst supporting the safe and responsible adoption of AI technologies across the Group.
This is a fantastic opportunity for a security professional who enjoys working across governance, risk, compliance, operational security and emerging technology, helping to shape how AI is governed within a modern insurance business.
Key Responsibilities
Reporting to the Information Security Management function, you will support the ongoing development of the Group's Information Security programme, with a focus on:
- Governance, Risk and Compliance (GRC)
- ISO 27001 certification and continuous improvement
- Operational Resilience (Op Res) and DORA compliance
- Microsoft Defender and Purview administration
- AI governance, risk management and responsible AI adoption
Working closely with Risk & Compliance teams, Technology, business leaders and third-party suppliers, you will help ensure Marco Group maintains strong security controls, manages risk effectively and adopts AI technologies in a secure and compliant manner.
- Support the maintenance and continuous improvement of information security policies, procedures and standards
- Assist with ISO 27001 certification activities, including control reviews, evidence collection and audit preparation
- Support DORA compliance activities, ICT risk management and remediation tracking Support DORA compliance activities, ICT risk management and remediation tracking
- Contribute to Lloyd's Operational Resilience (Op Res) requirements, including scenario testing and self-assessments
- Monitor compliance against recognised frameworks including ISO 27001, NIST CSF and Lloyd's requirements
- Identify, assess and track security and AI-related risks through to resolution
- Produce KRI/KPI reporting for governance forums and stakeholders
- Support third-party and supplier security assessments
- Support governance and oversight of AI tools used across Marco and Polo Works, including Microsoft Copilot, Anthropic Claude and other AI-enabled platforms
- Maintain AI acceptable use standards, approval processes and usage records
- Conduct AI risk assessments for new use cases and integrations
- Monitor AI deployments for compliance with data protection, confidentiality and regulatory requirements
- Keep up to date with evolving AI governance frameworks and regulatory developments
- Support the creation of AI training, guidance and awareness materials
- Administer and maintain Microsoft Defender security controls and alerting
- Configure and support Microsoft Purview capabilities including DLP, sensitivity labels and insider risk controls
- Investigate security alerts and support incident response activities
- Participate in incident reviews, testing exercises and security improvement initiatives
- Provide practical security advice and guidance across the business
- Help deliver the Group's security awareness and phishing simulation programme
- Create engaging training content on security and responsible AI use
- Monitor and report on training participation and awareness metrics
Skills, Knowledge and Expertise
- Experience in Information Security, ideally within a GRC, compliance or risk-focused role
- Practical knowledge of Microsoft Defender and Microsoft Purview
- Experience of security risk assessments, governance frameworks and security controls
- Understanding of ISO 27001 and security audit requirements
- Familiarity with AI governance, AI risk assessment or responsible AI adoption
- Knowledge of data protection and privacy requirements
- Strong analytical and problem-solving skills
- Excellent communication and stakeholder management skills
- A genuine interest in emerging technologies and AI
- Experience within the Lloyd's, London Market or wider insurance sector
- Knowledge of Lloyd's Minimum Standards, Principle 12 and Operational Resilience requirements
- Experience supporting DORA compliance programmes
- Knowledge of information classification and cryptography
We're interested in candidates who hold, or are working towards, one or more of the following:
- CISMP
- ISC2 CC
- ISO 27001 Lead Auditor or Lead Implementer
- CISM
- CISSP
- CRISC
- SANS certifications or equivalent
Microsoft certifications such as
#J-18808-Ljbffr
Security GRC & AI Analyst in Cheltenham employer: Polo
As a Syndicate Underwriting Manager in London, you will join a dynamic team that prioritises employee growth and well-being. Our company offers a competitive salary, flexible hybrid working arrangements, and a comprehensive benefits package including private health insurance and generous annual leave. With a strong focus on collaboration and professional development, we foster a supportive work culture that encourages innovation and community involvement.
StudySmarter Expert Advice🤫
We think this is how you could land Security GRC & AI Analyst in Cheltenham
✨Get Involved in the Cybersecurity Community
Diving into the cybersecurity community is key for landing that full-time gig. Join forums like Reddit's r/cybersecurity or attend local meetups to connect with industry veterans and other job seekers. Networking is everything in this field—don’t just be a passive lurker!
✨Show Off Your Skills with Capture the Flag Competitions
Participate in Capture the Flag (CTF) competitions; these are not just a fun way to boost your skills but also a chance to showcase your talent to potential employers. Many companies, including Polo, love seeing candidates who actively engage in these challenges.
✨Tailor Your Online Presence
Make sure your LinkedIn and any professional profiles reflect your cybersecurity expertise. Share your projects, whether they’re personal or from a previous role, to catch the eye of hiring managers. This is how they’ll find your passion and commitment to the field!
✨Apply Directly Through Polo
Don’t forget to head straight to our website and check out any openings for cybersecurity roles at Polo. Applying directly can sometimes give you an edge, especially if you can mention that you've been following our work or engaging in the community.
We think you need these skills to ace Security GRC & AI Analyst in Cheltenham
Some tips for your application 🫡
Show off your technical skills:In cybersecurity, it's crucial to highlight your technical prowess. Make sure your CV showcases specific skills like network security, penetration testing, or threat analysis. If you have relevant certifications (like CEH or CISSP), pop those on the front page to grab attention!
Tailor your portfolio for the role:Even for a full-time role, a portfolio can set you apart. If you've worked on any cybersecurity projects—be it CTF challenges, security assessments, or research papers—include these in your application. This demonstrates not just your skills, but also your hands-on experience!
Use real-world examples:When writing your cover letter, don’t just stick to your qualifications. Share real-world examples of how you’ve tackled security issues or vulnerabilities. This gives the hiring team at Polo insight into your practical problem-solving abilities and makes your application memorable.
Demonstrate your passion for cybersecurity:Cybersecurity is an ever-evolving field, so show us that you’re always learning! Mention any recent courses, webinars, or industry events you’ve attended. This not only exhibits your enthusiasm but also signals to Polo that you’re committed to staying ahead in the game.
How to prepare for a job interview at Polo
✨Sharpen Your Technical Skills
For a role in cybersecurity, it’s essential to be up-to-date with the latest tools and techniques. Brush up on your knowledge of firewalls, intrusion detection systems, and vulnerability assessment tools. Be ready to discuss specific scenarios where you’ve applied these skills, as hands-on experience can really set us apart in interviews.
✨Prepare for Scenario-Based Questions
Expect the interviewers at Polo to throw in some hypothetical situations to see how you’d handle them. Think about common security breaches or incidents and be prepared to explain how you would respond. This not only shows your problem-solving skills but also your understanding of real-world cybersecurity challenges.
✨Highlight Your Certifications
Certifications like CompTIA Security+, CISSP, or CEH can give you a significant edge in a full-time role in cybersecurity. Make sure to mention these during your interview and be prepared to discuss what you learned through those certifications and how they relate to the position at Polo.
✨Show Your Passion for Cybersecurity
Since you’re going for a full-time gig, showing genuine enthusiasm for the field can make all the difference. Share any personal projects, blogs, or communities you’re part of that relate to cybersecurity. This not only showcases your passion but also your commitment to staying engaged in this ever-evolving field.