AI Security Architect
Listed on 2026-09-20
-
IT/Tech
AI Engineer (Applied/Software), Information Security & Data Protection, Cybersecurity
AI Security Architect
Department: Digital
Employment Type: Permanent
Location: Cheltenham
Compensation: £75,000 - £85,000 / year
DescriptionPolo Works are currently recruiting this role on behalf of our parent company Marco Group.
We are looking for an AI Security Architect to own the security posture of AI tooling across the Marco Group, covering approved platforms such as Microsoft Copilot and Anthropic Claude in their full capability set, AI capabilities embedded within existing business systems, AI-assisted software development, and third-party or vendor AI usage. This is a newly created, architecture-level role that will define how the Group adopts AI safely, at pace, and in line with regulatory expectations.
Working closely with the Group Head of Information Security, the AI Security Architect will design and maintain the security controls, risk assessment framework and governance model for AI tooling, and will act as the Group's technical authority on generative AI risk – including data leakage, prompt injection, agentic/tool-use risk and model access control. The role will also support engineering teams in embedding secure practices where AI-assisted development tools are used, and will contribute AI-specific risk assessment to vendor and third-party due diligence.
This role will report into the Group Head of Information Security.
Platform Security – Claude & Copilot
Own the security configuration and ongoing hardening of Claude and Microsoft Copilot across their full capability set, including connectors, agentic/tool-use features, data access scopes and browser or desktop extensions
Define and maintain acceptable-use policies, permission boundaries and data-loss-prevention controls specific to generative AI tooling
Monitor vendor feature releases and proactively assess new capabilities, such as new connectors or agent modes, for risk before they reach general use
AI Risk Assessment & ControlsDesign and run a standing AI risk assessment framework covering data classification, model access, third-party data flows and output integrity, applied consistently to every new AI use case
Maintain a central AI tooling register of approved, restricted and prohibited tools, with documented risk ratings and compensating controls
Translate assessment findings into technical and procedural controls, including access management, logging and monitoring, and prompt and data governance
Secure AI-Assisted DevelopmentPartner with engineering and development teams to embed security guardrails where AI coding tools are used, including code review standards, secrets handling and dependency and IP risk
Define secure-by-design patterns for building internal AI-powered tools or integrations
Third-Party & Vendor AI GovernanceAssess AI capabilities embedded in third-party and vendor products, both existing suppliers adding AI features and new AI vendors, as part of vendor due diligence
Contribute AI-specific clauses to vendor contracts and DPAs, covering data use, model training exclusions and sub-processor disclosure
Maintain oversight of shadow AI usage risk across the business
Governance, Reporting & Stakeholder EngagementReport AI risk posture and control effectiveness to the Group Head of Information Security and relevant governance committees
Support regulatory alignment as it relates to AI tool usage, including DORA, UK GDPR and sector-specific AI guidance
Act as the internal technical authority and first point of contact for AI security queries across the business
Skills, Knowledge and ExpertiseStrong background in information security architecture, ideally with exposure to cloud/SaaS security and vendor risk
Working knowledge of LLM and generative AI architectures, data flows and associated…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).