- Salary
- £45k – £55k/yr
- Location
- Cheltenham
- Department
- Security
- Source
- Pinpoint
Description
Security GRC & AI Analyst
Department: Information Technology
Employment Type: Permanent
Location: Cheltenham
Compensation: £45,000 - £55,000 / year
Description
As we continue to grow, we are looking for a Security GRC & AI Analyst to play a key role in strengthening our information security framework whilst supporting the safe and responsible adoption of AI technologies across the Group.
This is a fantastic opportunity for a security professional who enjoys working across governance, risk, compliance, operational security and emerging technology, helping to shape how AI is governed within a modern insurance business.
Key Responsibilities
- Governance, Risk and Compliance (GRC)
- ISO 27001 certification and continuous improvement
- Operational Resilience (OpRes) and DORA compliance
- Microsoft Defender and Purview administration
- AI governance, risk management and responsible AI adoption
- Support the maintenance and continuous improvement of information security policies, procedures and standards
- Assist with ISO 27001 certification activities, including control reviews, evidence collection and audit preparation
- Support DORA compliance activities, ICT risk management and remediation tracking
- Contribute to Lloyd's Operational Resilience (OpRes) requirements, including scenario testing and self-assessments
- Monitor compliance against recognised frameworks including ISO 27001, NIST CSF and Lloyd's requirements
- Identify, assess and track security and AI-related risks through to resolution
- Produce KRI/KPI reporting for governance forums and stakeholders
- Support third-party and supplier security assessments
- Support governance and oversight of AI tools used across Marco and PoloWorks, including Microsoft Copilot, Anthropic Claude and other AI-enabled platforms
- Maintain AI acceptable use standards, approval processes and usage records
- Conduct AI risk assessments for new use cases and integrations
- Monitor AI deployments for compliance with data protection, confidentiality and regulatory requirements
- Keep up to date with evolving AI governance frameworks and regulatory developments
- Support the creation of AI training, guidance and awareness materials
- Administer and maintain Microsoft Defender security controls and alerting
- Configure and support Microsoft Purview capabilities including DLP, sensitivity labels and insider risk controls
- Investigate security alerts and support incident response activities
- Participate in incident reviews, testing exercises and security improvement initiatives
- Provide practical security advice and guidance across the business
- Help deliver the Group's security awareness and phishing simulation programme
- Create engaging training content on security and responsible AI use
- Monitor and report on training participation and awareness metrics
Skills, Knowledge and Expertise
- Experience in Information Security, ideally within a GRC, compliance or risk-focused role
- Practical knowledge of Microsoft Defender and Microsoft Purview
- Experience of security risk assessments, governance frameworks and security controls
- Understanding of ISO 27001 and security audit requirements
- Familiarity with AI governance, AI risk assessment or responsible AI adoption
- Knowledge of data protection and privacy requirements
- Strong analytical and problem-solving skills
- Excellent communication and stakeholder management skills
- A genuine interest in emerging technologies and AI
- Experience within the Lloyd's, London Market or wider insurance sector
- Knowledge of Lloyd's Minimum Standards, Principle 12 and Operational Resilience requirements
- Experience supporting DORA compliance programmes
- Knowledge of information classification and cryptography
- CISMP
- ISC2 CC
- ISO 27001 Lead Auditor or Lead Implementer
- CISM
- CISSP
- CRISC
- SANS certifications or equivalent
- SC-200
- SC-300
- SC-400