> Markdown version of [/jobs/ext/2972690-ai-security-architect](https://www.wearedevelopers.com/jobs/ext/2972690-ai-security-architect). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # AI Security Architect - **Company:** PoloWorks - **Location:** Bishops Cleeve, UK - **Salary:** £75,000.0 - £85,000.0 - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Business Systems, Software as a Service, Cloud Computing, Cloud Computing Security, Code Review, Cyber Security, Data Governance, Information Leak Prevention, Data Security, Software Design Patterns, Identity and Access Management, Sherwood Applied Business Security Architecture, Software Engineering, Data Streaming, Data Logging, Application Enhancement Tool, Cloud Platform System, Data Classification, Microsoft Power Automate, Large Language Models, Control Structures, Togaf - **Published:** September 18, 2026 - **Apply:** https://www.adzuna.co.uk/jobs/details/5889035529 ## About the Role Strong background in information security architecture, ideally with exposure to cloud/SaaS security and vendor risk Working knowledge of LLM and generative AI architectures, data flows and associated threat models, including prompt injection, data leakage, model access control and agentic tool-use risk Familiarity with regulatory frameworks relevant to the sector, including DORA, UK GDPR, ISO 27001 and NIST CSF Experience running structured risk assessments and translating them into actionable controls Strong stakeholder management, with the confidence to engage both technical teams and senior leadership Desirable: experience working within the Lloyd's or London Market (insurer, managing agency, broker or managed service provider), including familiarity with Lloyd's Minimum Standards, Principle 12 and Operational Resilience (OpRes) requirements Knowledge & Qualifications Security architecture principles and design patterns across cloud and SaaS environments Large language model and generative AI architectures, including agentic and tool-use / connector risk AI governance concepts and frameworks, such as ISO/IEC 42001 and the NIST AI Risk Management Framework DORA, ISO 27001, NIST CSF and UK/EU GDPR requirements Vendor and third-party risk assessment methodology Secure software development practices, particularly where AI-assisted coding tools are in use One or more of the following (or working towards): * CISSP, CISM, CRISC, SABSA, TOGAF (security architecture stream) or equivalent * ISO 27001 LA/LI or equivalent * ISO/IEC 42001 Lead Auditor or Lead Implementer (AI Management Systems), or equivalent Desirable - AI governance / assurance accreditations: * ISACA Certified in Artificial Intelligence (Certified AI Audit / AAIA), or AI Fundamentals certificate * NIST AI Risk Management Framework (AI RMF) practitioner training * CertNexus Certified Artificial Intelligence Practitioner (CAIP), or equivalent AI security/ethics credential ## Description We are looking for an AI Security Architect to own the security posture of AI tooling across the Marco Group, covering approved platforms such as Microsoft Copilot and Anthropic Claude in their full capability set, AI capabilities embedded within existing business systems, AI-assisted software development, and third-party or vendor AI usage. This is a newly created, architecture-level role that will define how the Group adopts AI safely, at pace, and in line with regulatory expectations. Working closely with the Group Head of Information Security, the AI Security Architect will design and maintain the security controls, risk assessment framework and governance model for AI tooling, and will act as the Group's technical authority on generative AI risk - including data leakage, prompt injection, agentic/tool-use risk and model access control. The role will also support engineering teams in embedding secure practices where AI-assisted development tools are used, and will contribute AI-specific risk assessment to vendor and third-party due diligence. This role will report into the Group Head of Information Security. Platform Security - Claude & Copilot Own the security configuration and ongoing hardening of Claude and Microsoft Copilot across their full capability set, including connectors, agentic/tool-use features, data access scopes and browser or desktop extensions Define and maintain acceptable-use policies, permission boundaries and data-loss-prevention controls specific to generative AI tooling Monitor vendor feature releases and proactively assess new capabilities, such as new connectors or agent modes, for risk before they reach general use AI Risk Assessment & Controls Design and run a standing AI risk assessment framework covering data classification, model access, third-party data flows and output integrity, applied consistently to every new AI use case Maintain a central AI tooling register of approved, restricted and prohibited tools, with documented risk ratings and compensating controls Translate assessment findings into technical and procedural controls, including access management, logging and monitoring, and prompt and data governance Secure AI-Assisted Development Partner with engineering and development teams to embed security guardrails where AI coding tools are used, including code review standards, secrets handling and dependency and IP risk Define secure-by-design patterns for building internal AI-powered tools or integrations Third-Party & Vendor AI Governance Assess AI capabilities embedded in third-party and vendor products, both existing suppliers adding AI features and new AI vendors, as part of vendor due diligence Contribute AI-specific clauses to vendor contracts and DPAs, covering data use, model training exclusions and sub-processor disclosure Maintain oversight of shadow AI usage risk across the business Governance, Reporting & Stakeholder Engagement Report AI risk posture and control effectiveness to the Group Head of Information Security and relevant governance committees Support regulatory alignment as it relates to AI tool usage, including DORA, UK GDPR and sector-specific AI guidance Act as the internal technical authority and first point of contact for AI security queries across the business ## Related Videos - [Building Sovereign AI: Lessons from Deploying Secure RAG Systems using Confidential Computing](https://www.wearedevelopers.com/videos/100108-building-sovereign-ai-lessons-from-deploying-secure-rag-systems-using-confidential-computing) - [Crypto-secure Data Management with In-Database Blockchain](https://www.wearedevelopers.com/videos/632-crypto-secure-data-management-with-in-database-blockchain) - [Are Code Reviews Worth It? Insights from 16 Years of Review Data](https://www.wearedevelopers.com/videos/1135-are-code-reviews-worth-it-insights-from-16-years-of-review-data) - [Introduction to Responsible AI: Balancing Value and Risk](https://www.wearedevelopers.com/videos/1972-introduction-to-responsible-ai-balancing-value-and-risk) - [Build Delightful Mobile Experiences with Kotlin, Realm, and Atlas Device Sync](https://www.wearedevelopers.com/videos/694-build-delightful-mobile-experiences-with-kotlin-realm-and-atlas-device-sync) - [Build a CI/CD pipeline to automate code reviews and ensure code quality](https://www.wearedevelopers.com/videos/349-build-a-ci-cd-pipeline-to-automate-code-reviews-and-ensure-code-quality) ## Related Articles - [Trustworthy AI Starts at Deployment: 5 Checks Before You Ship](https://www.wearedevelopers.com/magazine/753-trustworthy-ai-starts-at-deployment-5-checks-before-you-ship) - [Got AI ideas but no money? Here are 10 free ways to level up your AI skills with Google Cloud](https://www.wearedevelopers.com/magazine/600-got-ai-ideas-but-no-money-here-are-10-free-ways-to-level-up-your-ai-skills-with-google-cloud) - [Navigating the AI Shift](https://www.wearedevelopers.com/magazine/629-navigating-the-ai-shift) - [Best US AI Conferences for CTOs in 2026: Build vs. Buy, Vendor Evaluation, and Peer Intelligence](https://www.wearedevelopers.com/magazine/736-best-us-ai-conferences-for-ctos-in-2026-build-vs-buy-vendor-evaluation-and-peer-intelligence) - [How to Become an AI Engineer](https://www.wearedevelopers.com/magazine/331-how-to-become-an-ai-engineer) - [MLOps And AI Driven Development](https://www.wearedevelopers.com/magazine/82-mlops-and-ai-driven-development)