At a Glance
- Tasks: Strengthen information security and support AI technology adoption across the Group.
- Company: Join Marco Group, a leader in modern insurance with a focus on innovation.
- Benefits: Competitive salary, professional development, and a dynamic work environment.
- Other info: Great opportunity for career growth in a supportive team.
- Why this job: Shape the future of AI governance in a rapidly evolving industry.
- Qualifications: Experience in Information Security, GRC, and a passion for emerging technologies.
The predicted salary is between 48661 - 59475 Β£ per year.
PoloWorks are currently recruiting this role on behalf of our parent company Marco Group. As we continue to grow, we are looking for a Security GRC & AI Analyst to play a key role in strengthening our information security framework whilst supporting the safe and responsible adoption of AI technologies across the Group. This is a fantastic opportunity for a security professional who enjoys working across governance, risk, compliance, operational security and emerging technology, helping to shape how AI is governed within a modern insurance business.
Key Responsibilities
- Reporting to the Information Security Management function, you will support the ongoing development of the Group's Information Security programme, with a focus on:
- Governance, Risk and Compliance (GRC)
- ISO 27001 certification and continuous improvement
- Operational Resilience (OpRes) and DORA compliance
- Microsoft Defender and Purview administration
- AI governance, risk management and responsible AI adoption
- Working closely with Risk & Compliance teams, Technology, business leaders and third-party suppliers, you will help ensure Marco Group maintains strong security controls, manages risk effectively and adopts AI technologies in a secure and compliant manner.
Governance, Risk & Compliance
- Support the maintenance and continuous improvement of information security policies, procedures and standards
- Assist with ISO 27001 certification activities, including control reviews, evidence collection and audit preparation
- Support DORA compliance activities, ICT risk management and remediation tracking
- Contribute to Lloyd's Operational Resilience (OpRes) requirements, including scenario testing and self-assessments
- Monitor compliance against recognised frameworks including ISO 27001, NIST CSF and Lloyd's requirements
- Identify, assess and track security and AI-related risks through to resolution
- Produce KRI/KPI reporting for governance forums and stakeholders
- Support third-party and supplier security assessments
AI Governance & Responsible AI
- Support governance and oversight of AI tools used across Marco and PoloWorks, including Microsoft Copilot, Anthropic Claude and other AI-enabled platforms
- Maintain AI acceptable use standards, approval processes and usage records
- Conduct AI risk assessments for new use cases and integrations
- Monitor AI deployments for compliance with data protection, confidentiality and regulatory requirements
- Keep up to date with evolving AI governance frameworks and regulatory developments
- Support the creation of AI training, guidance and awareness materials
Security Operations
- Administer and maintain Microsoft Defender security controls and alerting
- Configure and support Microsoft Purview capabilities including DLP, sensitivity labels and insider risk controls
- Investigate security alerts and support incident response activities
- Participate in incident reviews, testing exercises and security improvement initiatives
- Provide practical security advice and guidance across the business
Security Awareness
- Help deliver the Group's security awareness and phishing simulation programme
- Create engaging training content on security and responsible AI use
- Monitor and report on training participation and awareness metrics
Skills, Knowledge and Expertise
Essential Experience
- Experience in Information Security, ideally within a GRC, compliance or risk-focused role
- Practical knowledge of Microsoft Defender and Microsoft Purview
- Experience of security risk assessments, governance frameworks and security controls
- Understanding of ISO 27001 and security audit requirements
- Familiarity with AI governance, AI risk assessment or responsible AI adoption
- Knowledge of data protection and privacy requirements
- Strong analytical and problem-solving skills
- Excellent communication and stakeholder management skills
- A genuine interest in emerging technologies and AI
Desirable Experience
- Experience within the Lloyd's, London Market or wider insurance sector
- Knowledge of Lloyd's Minimum Standards, Principle 12 and Operational Resilience requirements
- Experience supporting DORA compliance programmes
- Knowledge of information classification and cryptography
We're interested in candidates who hold, or are working towards, one or more of the following:
- CISMP
- ISC2 CC
- ISO 27001 Lead Auditor or Lead Implementer
- CISM
- CISSP
- CRISC
- SANS certifications or equivalent
- Microsoft certifications such as: SC-200, SC-300, SC-400
Security GRC & AI Analyst in Cheltenham employer: PoloWorks
As a Syndicate Underwriting Manager in London, you will join a dynamic team that values collaboration and innovation within the Lloyd's market. The company offers a competitive salary alongside an impressive benefits package, including flexible hybrid working, private health insurance, and generous leave options, fostering a supportive work culture that prioritises employee well-being and growth. With opportunities for professional development and engagement in community initiatives, this role is perfect for those seeking meaningful and rewarding employment in a thriving environment.