Security GRC & AI Analyst

PoloWorks are currently recruiting this role on behalf of our parent company Marco Group.

As we continue to grow, we are looking for a Security GRC & AI Analyst to play a key role in strengthening our information security framework whilst supporting the safe and responsible adoption of AI technologies across the Group.

This is a fantastic opportunity for a security professional who enjoys working across governance, risk, compliance, operational security and emerging technology, helping to shape how AI is governed within a modern insurance business.



Reporting to the Information Security Management function, you will support the ongoing development of the Group's Information Security programme, with a focus on:
  • Governance, Risk and Compliance (GRC)
  • ISO 27001 certification and continuous improvement
  • Operational Resilience (OpRes) and DORA compliance
  • Microsoft Defender and Purview administration
  • AI governance, risk management and responsible AI adoption
Working closely with Risk & Compliance teams, Technology, business leaders and third-party suppliers, you will help ensure Marco Group maintains strong security controls, manages risk effectively and adopts AI technologies in a secure and compliant manner.

Governance, Risk & Compliance

  • Support the maintenance and continuous improvement of information security policies, procedures and standards
  • Assist with ISO 27001 certification activities, including control reviews, evidence collection and audit preparation
  • Support DORA compliance activities, ICT risk management and remediation tracking
  • Contribute to Lloyd's Operational Resilience (OpRes) requirements, including scenario testing and self-assessments
  • Monitor compliance against recognised frameworks including ISO 27001, NIST CSF and Lloyd's requirements
  • Identify, assess and track security and AI-related risks through to resolution
  • Produce KRI/KPI reporting for governance forums and stakeholders
  • Support third-party and supplier security assessments

AI Governance & Responsible AI

  • Support governance and oversight of AI tools used across Marco and PoloWorks, including Microsoft Copilot, Anthropic Claude and other AI-enabled platforms
  • Maintain AI acceptable use standards, approval processes and usage records
  • Conduct AI risk assessments for new use cases and integrations
  • Monitor AI deployments for compliance with data protection, confidentiality and regulatory requirements
  • Keep up to date with evolving AI governance frameworks and regulatory developments
  • Support the creation of AI training, guidance and awareness materials

Security Operations

  • Administer and maintain Microsoft Defender security controls and alerting
  • Configure and support Microsoft Purview capabilities including DLP, sensitivity labels and insider risk controls
  • Investigate security alerts and support incident response activities
  • Participate in incident reviews, testing exercises and security improvement initiatives
  • Provide practical security advice and guidance across the business

Security Awareness

  • Help deliver the Group's security awareness and phishing simulation programme
  • Create engaging training content on security and responsible AI use
  • Monitor and report on training participation and awareness metrics


Essential Experience

  • Experience in Information Security, ideally within a GRC, compliance or risk-focused role
  • Practical knowledge of Microsoft Defender and Microsoft Purview
  • Experience of security risk assessments, governance frameworks and security controls
  • Understanding of ISO 27001 and security audit requirements
  • Familiarity with AI governance, AI risk assessment or responsible AI adoption
  • Knowledge of data protection and privacy requirements
  • Strong analytical and problem-solving skills
  • Excellent communication and stakeholder management skills
  • A genuine interest in emerging technologies and AI

Desirable Experience

  • Experience within the Lloyd's, London Market or wider insurance sector
  • Knowledge of Lloyd's Minimum Standards, Principle 12 and Operational Resilience requirements
  • Experience supporting DORA compliance programmes
  • Knowledge of information classification and cryptography
We're interested in candidates who hold, or are working towards, one or more of the following:
  • CISMP
  • ISC2 CC
  • ISO 27001 Lead Auditor or Lead Implementer
  • CISM
  • CISSP
  • CRISC
  • SANS certifications or equivalent
Microsoft certifications such as:
  • SC-200
  • SC-300
  • SC-400




See also

要針對這個職缺調整履歷嗎?

目前無法檢查您與這個職缺的符合程度;請先將履歷加入個人檔案,下次即可查看。

A new version of freehire is available