Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.
Department for Transport (DfT) is seeking a Group Cyber Security Assurance Principal to strengthen cyber resilience across the department. You will provide expert assurance, oversight and guidance to ensure security controls are effective and risks are managed, influencing decisions at the highest level.
You will lead assurance activities across a complex landscape, oversee GCAP delivery, and champion Secure by Design across the group, aligning with government security requirements and
You will need to login before you can apply for a job.
View more categories View less categories Sector Technology Contract Type Permanent Hours Full Time
Location
London
About the job
Job summary
Are you passionate about strengthening cyber resilience across multiple organisations?
Can you provide expert assurance that helps organisations understand, manage and reduce cyber risk?
Do you have the expertise and drive to influence security strategy and embed assurance activities across the DfT Group?
If so, wed love to hear from you!
This is an exciting time to join the Digital, Information and Security Directorate within the Department for Transport as we restructure our directorate to ensure we are ready for future challenges, building a more sustainable,skilledand in-house capability.
Assess risk. Strengthen resilience. Drive assurance.
Use your cyber security expertise to influence decision-making, strengthen assurance and help protect critical services, systems and information across the Department for Transport Group.
Joining our department comes with many benefits, including:
Read more in the Benefits section below!
Find out more about whatit'slike working at Department for Transport Central - Department for Transport Careers.
Job description
As a Group Cyber Security Assurance Principal, you'll play a leading role in strengthening cyber resilience across the Department for Transport Group. You'll provide expert assurance, oversight and guidance to help ensure security controls are effective, risks are managed appropriately and government security requirements are consistently applied.
Working within the Assurance, Compliance and Controls function, you'll lead cyber security assurance activities across a complex organisational landscape. You'll oversee the delivery of the Government Cyber Action Plan (GCAP), monitor compliance with the NCSC Cyber Assessment Framework and champion the application of Secure by Design principles across the DfT Group.
You'll work closely with senior stakeholders to assess cyber risks, develop assurance frameworks and provide expert advice on security governance, compliance and risk management. You'll also support the implementation of targeted improvement plans, communicate emerging threats and help drive continuous improvement in cyber security maturity across the organisation.
This is an exciting opportunity for a cyber security professional who enjoys influencing strategic decisions, leading assurance activities and helping to protect critical government services and information.
Your responsibilities will include, butarentlimited to:
For further information on the role, please read the role profile. Please note that the role profile is for information purposes only - whilst all elements are relevant to the role, they may not all be assessed during the recruitment process. This job advert will detail exactly what will be assessed during the recruitment process.
Person specification
To be successful in this role you will need to have the following experience:
Additional information
The role is part of the Government Security Profession Career Framework and utilises an enhanced CapabilityBased Pay Framework which provides access to a Digital and Data allowance.
The base pay is 62,034. In addition to this the role includes a Digital and Data allowance of up to 20,396.
The value of allowance awarded will be based on an assessment of your skills and experience as demonstrated through the selection process. Here are more details on the pay framework.
Working hours, officeattendanceand travel requirements
Full timeroles consist of 37 hours per week.
Whilst we welcome applications from those looking to work with us on a part time basis, there is a business requirement for the successful candidate to be able to work at least 32 hours per week.
Occasionaltravel to other offices will berequired, which may involve overnight stays.
This role is suitable for hybrid working, which is a non-contractual arrangement where a combination of workplace and home-based working can be accommodated subject to business requirements.
The expectation at present is a minimum of 60% of your working time a month will be spent at either your designated workplace (one of the locations cited in the advert) or, when required for business reasons, in another office/work location/visiting stakeholders. Your designated workplace will be your contractual place of work. There may be occasions where youare required toattend above the minimum expectation.
If you haveaquestionabout hybrid working,part time/job share hours,flexible working,travellingfor work,or requireareasonable adjustment,please contact the Vacancy Holderduring the recruitment processto avoid possible disappointment later in the process should yourworking arrangements not be compatible with the requirements of the role(see below for contact details).
Visa Sponsorship
DfTc does not offer Visa Sponsorship for this role.
Behaviours
We'll assess you against these behaviours during the selection process:
Technical skills
We'll assess you against these technical skills during the selection process:
Benefits
Alongside your salary of 62,034, Department for Transport contributes 17,971 towards you being a member of the Civil Service Defined Benefit Pension scheme. Find out what benefits a Civil Service Pension provides (opens in a new window).
Being part of our brilliant Civil Service means you will have access to a wide range of fantastic benefits:
Find out more aboutthe benefits of working at DfT and its agencies.
Things you need to know
Artificial intelligence
Artificial intelligence can be a useful tool to support your application, however, all examples and statements provided must be truthful, factually accurate and taken directly from your own experience. Where plagiarism has been identified (presenting the ideas and experiences of others, or generated by artificial intelligence, as your own) applications may be withdrawn and internal candidates may be subject to disciplinary action. Please see our candidate guidance (opens in a new window) for more information on appropriate and inappropriate use.
Selection process details
This vacancy is using Success Profiles (opens in a new window), and will assess your Behaviours, Experience and Technical skills.
The selection process for this role will be:
Stage 1: Sift of CV and personal statement
Stage 2: Interview
You must be successful at each stage to progress to the next stage.
Stage 1: Sift
At sift, you will be assessed against the following Success Profile elements:
Experience you will be asked to provide a CV (unlimited wordcount) and personal statement (1000-word count). Please provide evidence of your Experience of the following:
Should a large number of applications be received, an initial sift may be conducted using the lead Success Profile element:
"Experience of protective security within the public sector, specifically ISO 27001/2, the NCSCs Cyber Assessment Framework v4 and/or Government Functional Standard GovS 007: Security."
Candidates who pass the initial sift may be progressed to a full sift or progressed straight to assessment/interview.
The sift will take place week commencing from 12 October 2026.
Stage 2: Interview
At interview stage, you will be assessed against the following Success Profile elements:
The interviews will take place from 23 October.
This interview will be conducted online via Microsoft Teams. Further details will be provided to you should you be selected for interview.
We will also hold a 12-monthreserve list for this role, which may lead to potential opportunities beyond the role you applied for.
During your application, you shouldindicatewhich location(s) you wish to be considered for and, if successful, you will be placed on an individual list of candidates for each location. Candidates will be held on that list and drawn from it in merit order. Weadvise you tocarefully consider which locations you wish to be considered for. If you decline an offer for alocationyou have expressed a preference in or have expressed an interest in more than one location and accept an offer, you will be withdrawn from any lists you may be held on. We may also offer candidates a location that they have not expressed a preference for where we have the requirement to do so but this will again be done on the basis of your place in the overall merit order and, in this event, you will not be removed from the list if you decline.
Appointments for this position will be made in order of merit.Ifyouare successful in the selection processbutthere are no further available postsfor the advertised role,you may be contacted to discuss anoffer for a lower graded role (with similar experience and responsibility requirements).
Ifyou are unsuccessfulin the selection process, your application may be considered for a lower graded positionif your demonstrated skills and experience meet the requirements of the alternative position.Candidates will be considered in order of merit.
Reasonable Adjustments
As a Disability Confident Leader employer, we are committed to ensuring that the recruitment process is fair, accessible and allows all candidates to perform at their best. If a person with a visible or non-visible disability is substantially disadvantaged, we have a duty to make reasonable changes to our processes.
Complete the Assistance required section in the Additional requirements page of your application form to tell us what changes or help you might need during the recruitment process. For instance, you may need wheelchair access at an interview, or if youre deaf, a Language Service Professional.
If you need a reasonable adjustment so that you can complete your application, you should contact Government Recruitment Service via dftrecruitment.grs@cabinetoffice.gov.uk as soon as possible before the closing date to discuss your needs.
Document Accessibility
This job advert contains links to the DfT Careers website. Our website provides useful guidance and information that can support you during the application process. If you are experiencing accessibility problems with any attachments on this advert or the information on your website, please contact the email address in the 'Contact point for applicants' section.
For further information about how we hire, and for useful tips on submitting your application for this role, visit the How We Hire page of our DfT Careers website. You can find detailed information about the recruitment process and what to expect when applying for a role.
For further information on National Security Vetting please visit the Demystifying Vetting website.
Applicants who are successful at interview will be, as part of pre-employment screening, subject to a check on the Internal Fraud Database (IFD). This check will provide information about employees who have been dismissed for fraud or dishonesty offences. This check also applies to employees who resign or otherwise leave before being dismissed for fraud or dishonesty had their employment continued. Any applicants details held on the IFD will be refused employment. A candidate is not eligible to apply for a role within the Civil Service if the application is made within a 5-year period following a dismissal for carrying out internal fraud against government.
All external applicants and current employees of accredited non-departmental public bodies (NDPBs) will be required to undergo a Social Media Check. A Social Media Check is a review of your publicly available online activity, typically across platforms like LinkedIn, Facebook, X (formerly Twitter), Instagram, and others. The purpose is to identify any public posts or content that could raise concerns for employers, such as:
Importantly, this check does not involve hacking into your accounts or accessing private messages. It only considers content you have chosen to make public. Employers use this kind of screening to help ensure their workplace remains safe, inclusive, and aligned with company values. Its not about judging your personality or lifestyle - its about checking for potential red flags that might affect the role or company culture. If you have questions or concerns about the social media check, we would be happy to explain in more detail whats being looked at and how your data is handled securely and fairly.
Feedback will only be provided if you attend an interview or assessment.
Security
Successful candidates must undergo a basic (or equivalent) criminal record check.
Successful candidates must meet the security requirements before they can be appointed. The level of security needed is developed vetting (opens in a new window).
See our vetting charter (opens in a new window).
People working with government assets must complete baseline personnel security standard (opens in new window) checks.
Nationality requirements
This job is broadly open to the following groups:
Further information on nationality requirements (opens in a new window)
Working for the Civil Service
The Civil Service Code (opens in a new window) sets out the standards of behaviour expected of civil servants.
We recruit by merit on the basis of fair and open competition, as outlined in the Civil Service Commission's recruitment principles (opens in a new window).
The Civil Service embraces diversity and promotes equal opportunities. As such, we run a Disability Confident Scheme (DCS) for candidates with disabilities who meet the minimum selection criteria.
The Civil Service also offers a Redeployment Interview Scheme to civil servants who are at risk of redundancy, and who meet the minimum requirements for the advertised vacancy.
Diversity and Inclusion
The Civil Service is committed to attract, retain and invest in talent wherever it is found. To learn more please see the Civil Service People Plan (opens in a new window) and the Civil Service Diversity and Inclusion Strategy (opens in a new window).
Learn more about this company
Visit this company’s hub to learn about their values, culture, and latest jobs.
Visit this company’s hub to learn about their values, culture, and latest jobs.
Create a job alert and receive personalised job recommendations straight to your inbox.