Security GRC & AI Analyst

Posted 8 Days Ago
Be an Early Applicant
Cheltenham, Gloucestershire, England, GBR
Hybrid
45K-55K Annually
Entry level
Insurance • Professional Services
The Role
Supports information security governance, risk, compliance, ISO 27001, DORA, and operational resilience activities. The role conducts security and AI risk assessments, manages controls and audit evidence, supports third-party assessments, administers Microsoft Defender and Purview, investigates alerts, contributes to incident response, and helps govern responsible AI adoption. It also delivers security awareness and phishing simulation activities while producing risk, compliance, and training metrics for stakeholders.
Summary Generated by Built In
PoloWorks are currently recruiting this role on behalf of our parent company Marco Group.
As we continue to grow, we are looking for a Security GRC & AI Analyst to play a key role in strengthening our information security framework whilst supporting the safe and responsible adoption of AI technologies across the Group.

This is a fantastic opportunity for a security professional who enjoys working across governance, risk, compliance, operational security and emerging technology, helping to shape how AI is governed within a modern insurance business.


Key Responsibilities
Reporting to the Information Security Management function, you will support the ongoing development of the Group's Information Security programme, with a focus on:
  • Governance, Risk and Compliance (GRC)
  • ISO 27001 certification and continuous improvement
  • Operational Resilience (OpRes) and DORA compliance
  • Microsoft Defender and Purview administration
  • AI governance, risk management and responsible AI adoption
Working closely with Risk & Compliance teams, Technology, business leaders and third-party suppliers, you will help ensure Marco Group maintains strong security controls, manages risk effectively and adopts AI technologies in a secure and compliant manner.
Governance, Risk & Compliance
  • Support the maintenance and continuous improvement of information security policies, procedures and standards
  • Assist with ISO 27001 certification activities, including control reviews, evidence collection and audit preparation
  • Support DORA compliance activities, ICT risk management and remediation tracking
  • Contribute to Lloyd's Operational Resilience (OpRes) requirements, including scenario testing and self-assessments
  • Monitor compliance against recognised frameworks including ISO 27001, NIST CSF and Lloyd's requirements
  • Identify, assess and track security and AI-related risks through to resolution
  • Produce KRI/KPI reporting for governance forums and stakeholders
  • Support third-party and supplier security assessments
AI Governance & Responsible AI
  • Support governance and oversight of AI tools used across Marco and PoloWorks, including Microsoft Copilot, Anthropic Claude and other AI-enabled platforms
  • Maintain AI acceptable use standards, approval processes and usage records
  • Conduct AI risk assessments for new use cases and integrations
  • Monitor AI deployments for compliance with data protection, confidentiality and regulatory requirements
  • Keep up to date with evolving AI governance frameworks and regulatory developments
  • Support the creation of AI training, guidance and awareness materials
Security Operations
  • Administer and maintain Microsoft Defender security controls and alerting
  • Configure and support Microsoft Purview capabilities including DLP, sensitivity labels and insider risk controls
  • Investigate security alerts and support incident response activities
  • Participate in incident reviews, testing exercises and security improvement initiatives
  • Provide practical security advice and guidance across the business
Security Awareness
  • Help deliver the Group's security awareness and phishing simulation programme
  • Create engaging training content on security and responsible AI use
  • Monitor and report on training participation and awareness metrics


Skills, Knowledge and Expertise
Essential Experience
  • Experience in Information Security, ideally within a GRC, compliance or risk-focused role
  • Practical knowledge of Microsoft Defender and Microsoft Purview
  • Experience of security risk assessments, governance frameworks and security controls
  • Understanding of ISO 27001 and security audit requirements
  • Familiarity with AI governance, AI risk assessment or responsible AI adoption
  • Knowledge of data protection and privacy requirements
  • Strong analytical and problem-solving skills
  • Excellent communication and stakeholder management skills
  • A genuine interest in emerging technologies and AI
Desirable Experience
  • Experience within the Lloyd's, London Market or wider insurance sector
  • Knowledge of Lloyd's Minimum Standards, Principle 12 and Operational Resilience requirements
  • Experience supporting DORA compliance programmes
  • Knowledge of information classification and cryptography
We're interested in candidates who hold, or are working towards, one or more of the following:
  • CISMP
  • ISC2 CC
  • ISO 27001 Lead Auditor or Lead Implementer
  • CISM
  • CISSP
  • CRISC
  • SANS certifications or equivalent
Microsoft certifications such as:
  • SC-200
  • SC-300
  • SC-400



About
PoloWorks is the leading provider of UK-based support services to the insurance market. We have built a strong reputation as dedicated and dependable experts in our field. We pride ourselves on our ability to be flexible, responsive, and knowledgeable.As a leading service support company and turnkey managing agency, our clients choose us because our staff not only have the expertise but also a profound affinity with their business challenges. Our mission is to support, inspire, and develop the insurers of today and tomorrow.Our clients, whether digital start-ups or well-established organisations, rely on the PoloWorks team to develop and strengthen their businesses. Our clients' goals are our goals. As such we design and deliver bespoke solutions to their specific business challenges.Recognised as a Great Place to Work certified company and listed among the Best Workplaces in Financial Services & Insurance, PoloWorks is proud of its positive culture and commitment to its people. With offices in London and Cheltenham, PoloWorks has ambitious growth plans, offering exciting opportunities for anyone joining us on the next phase of our journey.It's our mission to unleash the potential in every team, and we know that teams perform best when they are diverse and every team member feels that they belong. It is the unique contributions of all PoloWorks colleagues that drive our success, and we are committed to building an inclusive culture where everyone is empowered to do meaningful work and are recognised for their efforts. To that end, we are committed to providing an environment free of discrimination for everyone.

Skills Required

  • Experience in information security, ideally in a governance, risk, compliance, or security risk role
  • Practical knowledge of Microsoft Defender
  • Practical knowledge of Microsoft Purview
  • Experience conducting security risk assessments
  • Experience with governance frameworks and security controls
  • Understanding of ISO 27001 and security audit requirements
  • Familiarity with AI governance, AI risk assessment, or responsible AI adoption
  • Knowledge of data protection and privacy requirements
  • Strong analytical and problem-solving skills
  • Excellent communication and stakeholder management skills
  • Genuine interest in emerging technologies and AI
  • Experience within the Lloyd's, London Market, or wider insurance sector
  • Knowledge of Lloyd's Minimum Standards, Principle 12, and operational resilience requirements
  • Experience supporting DORA compliance programmes
  • Knowledge of information classification and cryptography
  • CISMP, ISC2 CC, ISO 27001 Lead Auditor, ISO 27001 Lead Implementer, CISM, CISSP, CRISC, SANS certification, or equivalent
  • Microsoft SC-200, SC-300, or SC-400 certification
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: London
277 Employees

What We Do

PoloWorks provides business advisory and outsourced services to (re)insurers and brokers within the insurance lifecycle, operating in the Lloyd’s and companies markets.

Similar Jobs

UL Solutions Logo UL Solutions

Asbestos Surveyor

Automotive • Professional Services • Software • Consulting • Energy • Chemical • Renewable Energy
Hybrid
2 Locations
15000 Employees

UL Solutions Logo UL Solutions

Laboratory Operations Lead

Automotive • Professional Services • Software • Consulting • Energy • Chemical • Renewable Energy
Hybrid
Basingstoke, Basingstoke and Deane, Hampshire, England, GBR
15000 Employees

UL Solutions Logo UL Solutions

Product Owner

Automotive • Professional Services • Software • Consulting • Energy • Chemical • Renewable Energy
Hybrid
Basingstoke, Basingstoke and Deane, Hampshire, England, GBR
15000 Employees

UL Solutions Logo UL Solutions

Laboratory Technician, SAR (Specific Absorption Rate)

Automotive • Professional Services • Software • Consulting • Energy • Chemical • Renewable Energy
Hybrid
Basingstoke, Basingstoke and Deane, Hampshire, England, GBR
15000 Employees

Similar Companies Hiring

MassMutual India Thumbnail
Big Data • Fintech • Information Technology • Insurance • Financial Services
Hyderabad, Telangana
Quantum Rise Thumbnail
Software • Professional Services • Natural Language Processing • Machine Learning • Consulting • Automation • Artificial Intelligence
Chicago, Illinois
20 Employees
Granted Thumbnail
Artificial Intelligence • Healthtech • Insurance • Mobile • Financial Services
New York, New York
23 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account