Hiring.Camp

Security GRC & AI Analyst

PoloWorks

·

Today

Salary
£45k – £55k/yr
Location
Cheltenham
Department
Security
Source
Pinpoint

Description

Security GRC & AI Analyst

Department: Information Technology

Employment Type: Permanent

Location: Cheltenham

Compensation: £45,000 - £55,000 / year



Description

PoloWorks are currently recruiting this role on behalf of our parent company Marco Group.

As we continue to grow, we are looking for a Security GRC & AI Analyst to play a key role in strengthening our information security framework whilst supporting the safe and responsible adoption of AI technologies across the Group.

This is a fantastic opportunity for a security professional who enjoys working across governance, risk, compliance, operational security and emerging technology, helping to shape how AI is governed within a modern insurance business.





Key Responsibilities

Reporting to the Information Security Management function, you will support the ongoing development of the Group's Information Security programme, with a focus on:
  • Governance, Risk and Compliance (GRC)
  • ISO 27001 certification and continuous improvement
  • Operational Resilience (OpRes) and DORA compliance
  • Microsoft Defender and Purview administration
  • AI governance, risk management and responsible AI adoption
Working closely with Risk & Compliance teams, Technology, business leaders and third-party suppliers, you will help ensure Marco Group maintains strong security controls, manages risk effectively and adopts AI technologies in a secure and compliant manner.
  • Support the maintenance and continuous improvement of information security policies, procedures and standards
  • Assist with ISO 27001 certification activities, including control reviews, evidence collection and audit preparation
  • Support DORA compliance activities, ICT risk management and remediation tracking
  • Contribute to Lloyd's Operational Resilience (OpRes) requirements, including scenario testing and self-assessments
  • Monitor compliance against recognised frameworks including ISO 27001, NIST CSF and Lloyd's requirements
  • Identify, assess and track security and AI-related risks through to resolution
  • Produce KRI/KPI reporting for governance forums and stakeholders
  • Support third-party and supplier security assessments
  • Support governance and oversight of AI tools used across Marco and PoloWorks, including Microsoft Copilot, Anthropic Claude and other AI-enabled platforms
  • Maintain AI acceptable use standards, approval processes and usage records
  • Conduct AI risk assessments for new use cases and integrations
  • Monitor AI deployments for compliance with data protection, confidentiality and regulatory requirements
  • Keep up to date with evolving AI governance frameworks and regulatory developments
  • Support the creation of AI training, guidance and awareness materials
  • Administer and maintain Microsoft Defender security controls and alerting
  • Configure and support Microsoft Purview capabilities including DLP, sensitivity labels and insider risk controls
  • Investigate security alerts and support incident response activities
  • Participate in incident reviews, testing exercises and security improvement initiatives
  • Provide practical security advice and guidance across the business
  • Help deliver the Group's security awareness and phishing simulation programme
  • Create engaging training content on security and responsible AI use
  • Monitor and report on training participation and awareness metrics




Skills, Knowledge and Expertise

  • Experience in Information Security, ideally within a GRC, compliance or risk-focused role
  • Practical knowledge of Microsoft Defender and Microsoft Purview
  • Experience of security risk assessments, governance frameworks and security controls
  • Understanding of ISO 27001 and security audit requirements
  • Familiarity with AI governance, AI risk assessment or responsible AI adoption
  • Knowledge of data protection and privacy requirements
  • Strong analytical and problem-solving skills
  • Excellent communication and stakeholder management skills
  • A genuine interest in emerging technologies and AI
  • Experience within the Lloyd's, London Market or wider insurance sector
  • Knowledge of Lloyd's Minimum Standards, Principle 12 and Operational Resilience requirements
  • Experience supporting DORA compliance programmes
  • Knowledge of information classification and cryptography
We're interested in candidates who hold, or are working towards, one or more of the following:
  • CISMP
  • ISC2 CC
  • ISO 27001 Lead Auditor or Lead Implementer
  • CISM
  • CISSP
  • CRISC
  • SANS certifications or equivalent
Microsoft certifications such as:
  • SC-200
  • SC-300
  • SC-400




Skills

Risk ManagementComplianceISO 27001CISSP

Similar Jobs

30

GRC Security Analyst

General Curanahealth · Remote, US · Remote

Yesterday

Principal Security GRC Analyst

Rescale · Remote (United States) · Remote

2 days ago

GRC Security Analyst

Purestorage · Bangalore, India

6 days ago

Lead, Information Security GRC Automation

Pru · Wash, 213 Washington St., Newark, NJ, United States of America · Remote, Hybrid, Onsite

6 days ago

Mid SAP GRC Security Analyst

Encora · Peru

1 week ago

CIT Information Security & GRC, Lead

Talentmanagementsolution · Markham, Ontario - CAN, Canada

1 week ago

Senior Engineer, Information Security GRC

Ice · Atlanta, GA, US

1 week ago

Senior Information Security GRC Specialist

Reconomy · Bucharest

1 week ago

SAP Security/GRC Expert - Access Control (Contract SME)

M&S Consulting · (Multiple States) · Remote

3 weeks ago

Technical Program Manager, Security & GRC - 11745

Coupa · Bogota, Colombia · Remote

3 weeks ago

Security GRC Analyst

Protective · Work From Home · Remote

4 weeks ago

Sr.Technical Program Manager, Security & GRC - 11740

Coupa · Pune, India · Onsite

4 weeks ago

Head of Security GRC

DriveWealth · AMER-US-Remote; Austin, Texas, United States; Dallas, Texas, United States; Denver, Colorado, United States; Miami, Florida, United States; San Francisco, California, United States; Seattle, Washington, United States · Remote

4 weeks ago

IN_Associate | SAP GRC Security | SAP | Advisory | Kolkata

Pwc · Kolkata DN 57, India

4 weeks ago

SAP Security & GRC Engineer

Kbi · ASIA > IND > India > Remote - KBI · Remote

1 month ago

Corporate Security GRC Leader

Airbus · Bangalore (Airbus), India

1 month ago

GRC Security Engineer

Ddome · France - Remote · Remote

1 month ago

Security GRC Analyst

Salesforce · California - San Francisco, United States of America · Onsite

1 month ago

Senior Security GRC Lead

Gong.io · Austin | Chicago | New York City | Salt Lake City | San Francisco +1 · onsite

1 month ago

GRC Security Consultant

Accenture · Monterrey, Torres Moradas 2, Mexico · Remote

2 months ago

Senior Lead, SAP Security, GRC & Compliance- - PVH Corp.

PVH as one of the · Bridgewater, NJ Office, United States of America

2 months ago

GRC SECURITY ANALYST

Clearcapital · Reno, NV +1 · Remote

2 months ago

Security GRC Manager

Humaans · London · Onsite

2 months ago

Security GRC Manager: Customer Trust Enablement

Sierra · San Francisco, CA · Onsite

2 months ago

SAP Security / GRC - Roles, Authorizations, Compliance

"Data-Core System, Inc." · Harrisburg, Pennsylvania

2 months ago

GRC Security Analyst II

Aquaamerica · PA Bryn Mawr, United States of America

2 months ago

Information Security GRC Manager

Signetjewelers · Support Center - Akron, OH, United States of America · Remote, Hybrid

2 months ago

SAP Security/GRC administrator

DXC Technology · HU104 - Budapest,Hungary,(HU104) · Hybrid

2 months ago

Business Relationship Officer - Security & GRC Lead

Ivlglobaliod · IND-Mumbai, India

3 months ago

Security GRC Officer

Paystack · Nigeria, Kenya, South Africa +3

3 months ago