
Group Cyber Security Assurance Principal
Group Cyber Security Assurance Principal at Department for Transport in London
About the role
Job summary
Are you passionate about strengthening cyber resilience across multiple organisations?
Can you provide expert assurance that helps organisations understand, manage and reduce cyber risk?
Do you have the expertise and drive to influence security strategy and embed assurance activities across the DfT Group?
If so, we’d love to hear from you!
This is an exciting time to join the Digital, Information and Security Directorate within the Department for Transport as we restructure our directorate to ensure we are ready for future challenges, building a more sustainable, skilled and in-house capability.
Assess risk. Strengthen resilience. Drive assurance.
Use your cyber security expertise to influence decision-making, strengthen assurance and help protect critical services, systems and information across the Department for Transport Group.
Joining our department comes with many benefits, including:
- Employer pension contribution of 28.97% of your salary. Read more about Civil Service Pensions here
- 25 days annual leave, increasing by 1 day each year of service (up to a maximum of 30 days annual leave), plus 8 bank holidays a privilege day for the King’s birthday
- Flexible working options where we encourage a great work-life balance.
Read more in the Benefits section below!
Find out more about what it's like working at Department for Transport Central - Department for Transport Careers .
Job description
As a Group Cyber Security Assurance Principal, you'll play a leading role in strengthening cyber resilience across the Department for Transport Group. You'll provide expert assurance, oversight and guidance to help ensure security controls are effective, risks are managed appropriately and government security requirements are consistently applied.
Working within the Assurance, Compliance and Controls function, you'll lead cyber security assurance activities across a complex organisational landscape. You'll oversee the delivery of the Government Cyber Action Plan (GCAP), monitor compliance with the NCSC Cyber Assessment Framework and champion the application of Secure by Design principles across the DfT Group.
You'll work closely with senior stakeholders to assess cyber risks, develop assurance frameworks and provide expert advice on security governance, compliance and risk management. You'll also support the implementation of targeted improvement plans, communicate emerging threats and help drive continuous improvement in cyber security maturity across the organisation.
This is an exciting opportunity for a cyber security professional who enjoys influencing strategic decisions, leading assurance activities and helping to protect critical government services and information.
Your responsibilities will include, but aren’t limited to:
- Overseeing the delivery of the GCAP across the group.
- Developing and implementing the cyber security assurance framework across the group.
- Leading cyber security related risk assessments and other expert risk management activities, and enhance cyber security governance arrangements.
- Leading the assurance of ‘secure by design’ principles across the DfT Group.
- Reviewing and reporting on the Group’s compliance with NCSC’s Cyber Assessment Framework and monitor the progress of action plans to improve compliance.
- Contributing to incident management policies, incident response plans, and tests.
For further information on the role, please read the role profile. Please note that the role profile is for information purposes only - whilst all elements are relevant to the role, they may not all be assessed during the recruitment process. This job advert will detail exactly what will be assessed during the recruitment process.
Person specification
To be successful in this role you will need to have the following experience:
- Experience of implementing cyber security policies, standards, and assurance frameworks in a large, complex organisation to improve compliance
- Strong knowledge of security threats, risk management, and mitigation strategies.
- Experience of incident response and crisis management.
- Knowledge of protective security, ISO 27001/2, NCSC’s Cyber Assessment Framework and Government Functional Standard GovS 007: Security
- Experience delivering quality service in high-pressure environments.
- Professional qualifications or willingness to work towards industry-recognised qualifications in information risk and ISO 27001 (e.g. Management of Risk Practitioner, Certified ISO 27001 Practitioner and/or CISSP).
Additional information
The role is part of the Government Security Profession Career Framework and utilises an enhanced Capability–Based Pay Framework which provides access to a Digital and Data allowance.
The base pay is £62,034. In addition to this the role includes a Digital and Data allowance of up to £20,396.
The value of allowance awarded will be based on an assessment of your skills and experience as demonstrated through the selection process. Here are more details on the pay framework.
Working hours, office attendance and travel requirements
Full time roles consist of 37 hours per week.
Whilst we welcome applications from those looking to work with us on a part time basis, there is a business requirement for the successful candidate to be able to work at least 32 hours per week.
Occasional travel to other offices will be required, which may involve overnight stays.
This role is suitable for hybrid working, which is a non-contractual arrangement where a combination of workplace and home-based working can be accommodated subject to business requirements.
The expectation at present is a minimum of 60% of your working time a month will be spent at either your designated workplace (one of the locations cited in the advert) or, when required for business reasons, in another office/work location/visiting stakeholders. Your designated workplace will be your contractual place of work. There may be occasions where you are required to attend above the minimum expectation.
If you have a question about hybrid working, part time/job share hours, flexible working, travelling for work, or require a reasonable adjustment, please contact the Vacancy Holder during the recruitment process to avoid possible disappointment later in the process should your working arrangements not be compatible with the requirements of the role (see below for contact details).
Visa Sponsorship
DfTc does not offer Visa Sponsorship for this role.
Behaviours
We'll assess you against these behaviours during the selection process:
- Communicating and Influencing
- Delivering at Pace
- Leadership
- Seeing the Big Picture
Technical skills
We'll assess you against these technical skills during the selection process:
- Government Security Framework - Applied Security Capability
- Government Security Framework - Threat Understanding
Benefits
Alongside your salary of £62,034, Department for Transport contributes
£17,971 towards you being a member of the Civil Service Defined Benefit Pension scheme.
Find out what benefits a Civil Service Pension provides (opens in a new window).
Being part of our brilliant Civil Service means you will have access to a wide range of fantastic benefits:
- Employer pension contribution of 28.97% of your salary. Read more about Civil Service Pensions here
- 25 days annual leave, increasing by 1 day each year of service (up to a maximum of 30 days annual leave).
- 8 Bank Holidays plus an additional Privilege Day to mark the King’s birthday.
- Access to the staff discount portal.
- Excellent career development opportunities and the potential to undertake professional qualifications relevant to your role paid for by the department, such as CIPD, Prince2, apprenticeships, etc.
- Joining a diverse and inclusive workforce with a range of staff communities to support all our colleagues.
- 24-hour Employee Assistance Programme providing free confidential help and advice for staff.
- Flexible working options where we encourage a great work-life balance.
Find out more about the benefits of working at DfT and its agencies .
Things you need to know
Artificial intelligence
Artificial intelligence can be a useful tool to support your application, however, all examples and statements provided must be truthful, factually accurate and taken directly from your own experience. Where plagiarism has been identified (presenting the ideas and experiences of others, or generated by artificial intelligence, as your own) applications may be withdrawn and internal candidates may be subject to disciplinary action. Please see our candidate guidance (opens in a new window) for more information on appropriate and inappropriate use.
Selection process details
This vacancy is using Success Profiles (opens in a new window) , and will assess your Behaviours, Experience and Technical skills.
The selection process for this role will be:
Stage 1: Sift of CV and personal statement
Stage 2: Interview
You must be successful at each stage to progress to the next stage.
Stage 1: Sift
At sift, you will be assessed against the following Success Profile elements:
Experience – you will be asked to provide a CV (unlimited wordcount) and personal statement (1000-word count). Please provide evidence of your Experience of the following:
- Experience ofimplementing cyber security policies, standards, and assurance frameworks in a large, complex organisation to improve compliance.
- Strong knowledge of security threats, risk management, and mitigation strategies.
- Experience of incident response and crisis management.
- Knowledge of protective security, ISO 27001/2, NCSC’s Cyber Assessment Framework and Government Functional Standard GovS 007: Security.
Should a large number of applications be received, an initial sift may be conducted using the lead Success Profile element:
" Experience of protective security within the public sector, specifically ISO 27001/2, the NCSC’s Cyber Assessment Framework v4 and/or Government Functional Standard GovS 007: Security."
Candidates who pass the initial sift may be progressed to a full sift or progressed straight to assessment/interview.
The sift will take place week commencing from 12 October 2026.
Stage 2: Interview
At interview stage, you will be assessed against the following Success Profile elements:
- Behaviours – Communicating and Influencing, Delivering at Pace, Leadership, Seeing the Big Picture
- Technical – Applied Security Capability, Threat Understanding
The interviews will take place from 23 October.
This interview will be conducted online via Microsoft Teams. Further details will be provided to you should you be selected for interview.
You can find out more about our hiring process, how to apply, and application and interview guidance on our careers site.
Please note that we will try to meet the dates set out in the advert. There may be occasions when these dates will change.
Further information on the selection process
We will also hold a 12-month reserve list for this role, which may lead to potential opportunities beyond the role you applied for.
During your application, you should indicate which location(s) you wish to be considered for and, if successful, you will be placed on an individual list of candidates for each location. Candidates will be held on that list and drawn from it in merit order. We advise you to carefully consider which locations you wish to be considered for. If you decline an offer for a location you have expressed a preference in or have expressed an interest in more than one location and accept an offer, you will be withdrawn from any lists you may be held on. We may also offer candidates a location that they have not expressed a preference for where we have the requirement to do so but this will again be done on the basis of your place in the ove