AI Security Architect in Cheltenham

AI Security Architect in Cheltenham

Cheltenham Full-Time 72000 - 88000 £ / year (est.) No working from home possible
P

At a Glance

  • Tasks: Lead AI security initiatives and ensure safe adoption of AI tools across the Marco Group.
  • Company: Join PoloWorks, part of the innovative Marco Group, focused on cutting-edge AI security.
  • Benefits: Competitive salary, flexible working options, and opportunities for professional growth.
  • Other info: Collaborate with top professionals and make a real impact in the tech industry.
  • Why this job: Be at the forefront of AI security and shape the future of technology in a dynamic environment.
  • Qualifications: Strong background in information security and knowledge of AI architectures required.

The predicted salary is between 72000 - 88000 £ per year.

PoloWorks are currently recruiting this role on behalf of our parent company Marco Group. We are looking for an AI Security Architect to own the security posture of AI tooling across the Marco Group, covering approved platforms such as Microsoft Copilot and Anthropic Claude in their full capability set, AI capabilities embedded within existing business systems, AI-assisted software development, and third-party or vendor AI usage. This is a newly created, architecture-level role that will define how the Group adopts AI safely, at pace, and in line with regulatory expectations.

Working closely with the Group Head of Information Security, the AI Security Architect will design and maintain the security controls, risk assessment framework and governance model for AI tooling, and will act as the Group's technical authority on generative AI risk – including data leakage, prompt injection, agentic/tool-use risk and model access control. The role will also support engineering teams in embedding secure practices where AI-assisted development tools are used, and will contribute AI-specific risk assessment to vendor and third-party due diligence. This role will report into the Group Head of Information Security.

Key Responsibilities

  • Platform Security – Claude & Copilot
    • Own the security configuration and ongoing hardening of Claude and Microsoft Copilot across their full capability set, including connectors, agentic/tool-use features, data access scopes and browser or desktop extensions.
    • Define and maintain acceptable-use policies, permission boundaries and data-loss-prevention controls specific to generative AI tooling.
    • Monitor vendor feature releases and proactively assess new capabilities, such as new connectors or agent modes, for risk before they reach general use.
  • AI Risk Assessment & Controls
    • Design and run a standing AI risk assessment framework covering data classification, model access, third-party data flows and output integrity, applied consistently to every new AI use case.
    • Maintain a central AI tooling register of approved, restricted and prohibited tools, with documented risk ratings and compensating controls.
    • Translate assessment findings into technical and procedural controls, including access management, logging and monitoring, and prompt and data governance.
  • Secure AI-Assisted Development
    • Partner with engineering and development teams to embed security guardrails where AI coding tools are used, including code review standards, secrets handling and dependency and IP risk.
    • Define secure-by-design patterns for building internal AI-powered tools or integrations.
  • Third-Party & Vendor AI Governance
    • Assess AI capabilities embedded in third-party and vendor products, both existing suppliers adding AI features and new AI vendors, as part of vendor due diligence.
    • Contribute AI-specific clauses to vendor contracts and DPAs, covering data use, model training exclusions and sub-processor disclosure.
    • Maintain oversight of shadow AI usage risk across the business.
  • Governance, Reporting & Stakeholder Engagement
    • Report AI risk posture and control effectiveness to the Group Head of Information Security and relevant governance committees.
    • Support regulatory alignment as it relates to AI tool usage, including DORA, UK GDPR and sector-specific AI guidance.
    • Act as the internal technical authority and first point of contact for AI security queries across the business.

Skills, Knowledge and Expertise

  • Strong background in information security architecture, ideally with exposure to cloud/SaaS security and vendor risk.
  • Working knowledge of LLM and generative AI architectures, data flows and associated threat models, including prompt injection, data leakage, model access control and agentic tool-use risk.
  • Familiarity with regulatory frameworks relevant to the sector, including DORA, UK GDPR, ISO 27001 and NIST CSF.
  • Experience running structured risk assessments and translating them into actionable controls.
  • Strong stakeholder management, with the confidence to engage both technical teams and senior leadership.
  • Desirable: experience working within the Lloyd's or London Market (insurer, managing agency, broker or managed service provider), including familiarity with Lloyd's Minimum Standards, Principle 12 and Operational Resilience (OpRes) requirements.

Knowledge & Qualifications

  • Security architecture principles and design patterns across cloud and SaaS environments.
  • Large language model and generative AI architectures, including agentic and tool-use / connector risk.
  • AI governance concepts and frameworks, such as ISO/IEC 42001 and the NIST AI Risk Management Framework.
  • DORA, ISO 27001, NIST CSF and UK/EU GDPR requirements.
  • Vendor and third-party risk assessment methodology.
  • Secure software development practices, particularly where AI-assisted coding tools are in use.
  • One or more of the following (or working towards): CISSP, CISM, CRISC, SABSA, TOGAF (security architecture stream) or equivalent; ISO 27001 LA/LI or equivalent; ISO/IEC 42001 Lead Auditor or Lead Implementer (AI Management Systems), or equivalent.
  • Desirable – AI governance / assurance accreditations: ISACA Certified in Artificial Intelligence (Certified AI Audit / AAIA), or AI Fundamentals certificate; NIST AI Risk Management Framework (AI RMF) practitioner training; CertNexus Certified Artificial Intelligence Practitioner (CAIP), or equivalent AI security/ethics credential.

AI Security Architect in Cheltenham employer: PoloWorks

At Marco Group, we pride ourselves on being an exceptional employer, offering a dynamic work environment that fosters collaboration and innovation. As a Test Manager, you will have the opportunity to lead critical testing initiatives within the regulated financial services sector, while benefiting from our commitment to employee growth through continuous learning and development programmes. Our London-based office not only provides a vibrant city atmosphere but also encourages a culture of inclusivity and support, making it an ideal place for professionals seeking meaningful and rewarding careers.

P

Contact Details:

PoloWorks Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land AI Security Architect in Cheltenham

Get Involved in the Cybersecurity Community

Diving into the cybersecurity community is key for landing that full-time gig. Join forums like Reddit's r/cybersecurity or attend local meetups to connect with industry veterans and other job seekers. Networking is everything in this field—don’t just be a passive lurker!

Show Off Your Skills with Capture the Flag Competitions

Participate in Capture the Flag (CTF) competitions; these are not just a fun way to boost your skills but also a chance to showcase your talent to potential employers. Many companies, including PoloWorks, love seeing candidates who actively engage in these challenges.

Tailor Your Online Presence

Make sure your LinkedIn and any professional profiles reflect your cybersecurity expertise. Share your projects, whether they’re personal or from a previous role, to catch the eye of hiring managers. This is how they’ll find your passion and commitment to the field!

Apply Directly Through PoloWorks

Don’t forget to head straight to our website and check out any openings for cybersecurity roles at PoloWorks. Applying directly can sometimes give you an edge, especially if you can mention that you've been following our work or engaging in the community.

We think you need these skills to ace AI Security Architect in Cheltenham

Information Security Architecture
Cloud/SaaS Security
Vendor Risk Assessment
Large Language Model (LLM) Knowledge
Generative AI Architectures
Data Flows and Threat Models
Prompt Injection Awareness

Some tips for your application 🫡

Show off your technical skills:In cybersecurity, it's crucial to highlight your technical prowess. Make sure your CV showcases specific skills like network security, penetration testing, or threat analysis. If you have relevant certifications (like CEH or CISSP), pop those on the front page to grab attention!

Tailor your portfolio for the role:Even for a full-time role, a portfolio can set you apart. If you've worked on any cybersecurity projects—be it CTF challenges, security assessments, or research papers—include these in your application. This demonstrates not just your skills, but also your hands-on experience!

Use real-world examples:When writing your cover letter, don’t just stick to your qualifications. Share real-world examples of how you’ve tackled security issues or vulnerabilities. This gives the hiring team at PoloWorks insight into your practical problem-solving abilities and makes your application memorable.

Demonstrate your passion for cybersecurity:Cybersecurity is an ever-evolving field, so show us that you’re always learning! Mention any recent courses, webinars, or industry events you’ve attended. This not only exhibits your enthusiasm but also signals to PoloWorks that you’re committed to staying ahead in the game.

How to prepare for a job interview at PoloWorks

Sharpen Your Technical Skills

For a role in cybersecurity, it’s essential to be up-to-date with the latest tools and techniques. Brush up on your knowledge of firewalls, intrusion detection systems, and vulnerability assessment tools. Be ready to discuss specific scenarios where you’ve applied these skills, as hands-on experience can really set us apart in interviews.

Prepare for Scenario-Based Questions

Expect the interviewers at PoloWorks to throw in some hypothetical situations to see how you’d handle them. Think about common security breaches or incidents and be prepared to explain how you would respond. This not only shows your problem-solving skills but also your understanding of real-world cybersecurity challenges.

Highlight Your Certifications

Certifications like CompTIA Security+, CISSP, or CEH can give you a significant edge in a full-time role in cybersecurity. Make sure to mention these during your interview and be prepared to discuss what you learned through those certifications and how they relate to the position at PoloWorks.

Show Your Passion for Cybersecurity

Since you’re going for a full-time gig, showing genuine enthusiasm for the field can make all the difference. Share any personal projects, blogs, or communities you’re part of that relate to cybersecurity. This not only showcases your passion but also your commitment to staying engaged in this ever-evolving field.