Group Cyber Security Assurance Principal

ENGINEERINGUK

Greater London

Hybrid

GBP 62,000 - 82,000

Full time

34 hours ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Civil Service Pension
25 days annual leave
Flexible working
Hybrid working

Job summary

Department for Transport (DfT) is seeking a Group Cyber Security Assurance Principal to strengthen cyber resilience across the department. You will provide expert assurance, oversight and guidance to ensure security controls are effective and risks are managed, influencing decisions at the highest level.

You will lead assurance activities across a complex landscape, oversee GCAP delivery, and champion Secure by Design across the group, aligning with government security requirements and

Qualifications

  • Experience of implementing cyber security policies, standards, and assurance frameworks in a large, complex organisation to improve compliance.
  • Strong knowledge of security threats, risk management, and mitigation strategies.
  • Experience of incident response and crisis management.
  • Knowledge of protective security, ISO 27001/2, NCSC's Cyber Assessment Framework and GovS007: Security.
  • Professional qualifications or willingness to work towards industry-recognised qualifications in information risk and ISO 27001.

Responsibilities

  • Overseeing the delivery of the GCAP across the group.
  • Developing and implementing the cyber security assurance framework across the group.
  • Leading cyber security related risk assessments and other expert risk management activities, and enhance cyber security governance arrangements.
  • Leading the assurance of secure by design principles across the DfT Group.
  • Reviewing and reporting on the Groups compliance with NCSCs Cyber Assessment Framework and monitor the progress of action plans to improve compliance.
  • Contributing to incident management policies, incident response plans, and tests.

Skills

Cyber security policies
Risk management
Incident response
Security governance
ISO 27001 knowledge

Job description

You will need to login before you can apply for a job.

Group Cyber Security Assurance Principal

View more categories View less categories Sector Technology Contract Type Permanent Hours Full Time

Location

London

About the job

Job summary

Are you passionate about strengthening cyber resilience across multiple organisations?

Can you provide expert assurance that helps organisations understand, manage and reduce cyber risk?

Do you have the expertise and drive to influence security strategy and embed assurance activities across the DfT Group?

If so, wed love to hear from you!

This is an exciting time to join the Digital, Information and Security Directorate within the Department for Transport as we restructure our directorate to ensure we are ready for future challenges, building a more sustainable,skilledand in-house capability.

Assess risk. Strengthen resilience. Drive assurance.

Use your cyber security expertise to influence decision-making, strengthen assurance and help protect critical services, systems and information across the Department for Transport Group.

Joining our department comes with many benefits, including:

  • Employer pension contribution of 28.97% of your salary. Read more about Civil Service Pensionshere
  • 25 days annual leave, increasing by 1 day each year of service (up to a maximum of 30 days annual leave), plus 8 bank holidays aprivilege day for the Kings birthday
  • Flexible working options where we encourage a great work-life balance.

Read more in the Benefits section below!

Find out more about whatit'slike working at Department for Transport Central - Department for Transport Careers.

Job description

As a Group Cyber Security Assurance Principal, you'll play a leading role in strengthening cyber resilience across the Department for Transport Group. You'll provide expert assurance, oversight and guidance to help ensure security controls are effective, risks are managed appropriately and government security requirements are consistently applied.

Working within the Assurance, Compliance and Controls function, you'll lead cyber security assurance activities across a complex organisational landscape. You'll oversee the delivery of the Government Cyber Action Plan (GCAP), monitor compliance with the NCSC Cyber Assessment Framework and champion the application of Secure by Design principles across the DfT Group.

You'll work closely with senior stakeholders to assess cyber risks, develop assurance frameworks and provide expert advice on security governance, compliance and risk management. You'll also support the implementation of targeted improvement plans, communicate emerging threats and help drive continuous improvement in cyber security maturity across the organisation.

This is an exciting opportunity for a cyber security professional who enjoys influencing strategic decisions, leading assurance activities and helping to protect critical government services and information.

Your responsibilities will include, butarentlimited to:

  • Overseeing the delivery of the GCAP across the group.
  • Developing and implementing the cyber security assurance framework across the group.
  • Leading cyber security related risk assessments and other expert risk management activities, and enhance cyber security governance arrangements.
  • Leading the assurance of secure by design principles across the DfT Group.
  • Reviewing and reporting on the Groups compliance with NCSCs Cyber Assessment Framework and monitor the progress of action plans to improve compliance.
  • Contributing to incident management policies, incident response plans, and tests.

For further information on the role, please read the role profile. Please note that the role profile is for information purposes only - whilst all elements are relevant to the role, they may not all be assessed during the recruitment process. This job advert will detail exactly what will be assessed during the recruitment process.

Person specification

To be successful in this role you will need to have the following experience:

  • Experienceofimplementingcyber securitypolicies,standards,andassurance frameworksin a large, complex organisation to improve compliance
  • Strongknowledgeofsecuritythreats,riskmanagement,andmitigationstrategies.
  • Experienceofincidentresponseandcrisismanagement.
  • Knowledgeofprotectivesecurity,ISO27001/2,NCSCsCyberAssessment Framework and Government Functional StandardGovS007: Security
  • Experiencedeliveringqualityserviceinhigh-pressureenvironments.
  • Professional qualifications or willingness to work towards industry-recognised qualifications in information risk and ISO 27001 (e.g. Management of Risk Practitioner, Certified ISO 27001 Practitioner and/or CISSP).

Additional information

The role is part of the Government Security Profession Career Framework and utilises an enhanced CapabilityBased Pay Framework which provides access to a Digital and Data allowance.

The base pay is 62,034. In addition to this the role includes a Digital and Data allowance of up to 20,396.

The value of allowance awarded will be based on an assessment of your skills and experience as demonstrated through the selection process. Here are more details on the pay framework.

Working hours, officeattendanceand travel requirements

Full timeroles consist of 37 hours per week.

Whilst we welcome applications from those looking to work with us on a part time basis, there is a business requirement for the successful candidate to be able to work at least 32 hours per week.

Occasionaltravel to other offices will berequired, which may involve overnight stays.

This role is suitable for hybrid working, which is a non-contractual arrangement where a combination of workplace and home-based working can be accommodated subject to business requirements.

The expectation at present is a minimum of 60% of your working time a month will be spent at either your designated workplace (one of the locations cited in the advert) or, when required for business reasons, in another office/work location/visiting stakeholders. Your designated workplace will be your contractual place of work. There may be occasions where youare required toattend above the minimum expectation.

If you haveaquestionabout hybrid working,part time/job share hours,flexible working,travellingfor work,or requireareasonable adjustment,please contact the Vacancy Holderduring the recruitment processto avoid possible disappointment later in the process should yourworking arrangements not be compatible with the requirements of the role(see below for contact details).

Visa Sponsorship

DfTc does not offer Visa Sponsorship for this role.

Behaviours

We'll assess you against these behaviours during the selection process:

  • Communicating and Influencing
  • Delivering at Pace
  • Leadership
  • Seeing the Big Picture

Technical skills

We'll assess you against these technical skills during the selection process:

  • Government Security Framework - Applied Security Capability
  • Government Security Framework - Threat Understanding

Benefits

Alongside your salary of 62,034, Department for Transport contributes 17,971 towards you being a member of the Civil Service Defined Benefit Pension scheme. Find out what benefits a Civil Service Pension provides (opens in a new window).

Being part of our brilliant Civil Service means you will have access to a wide range of fantastic benefits:

  • Employer pension contribution of 28.97% of your salary. Read more about Civil Service Pensionshere
  • 25 days annual leave, increasing by 1 day each year of service (up to a maximum of 30 days annual leave).
  • 8 Bank Holidays plus an additional Privilege Day to mark the Kings birthday.
  • Access to the staff discount portal.
  • Excellent career development opportunities and the potential to undertake professional qualifications relevant to your role paid for by the department, such as CIPD, Prince2, apprenticeships, etc.
  • Joining a diverse and inclusive workforce with a range of staff communities to support all our colleagues.
  • 24-hour Employee Assistance Programme providing free confidential help and advice for staff.
  • Flexible working options where we encourage a great work-life balance.

Find out more aboutthe benefits of working at DfT and its agencies.

Things you need to know

Artificial intelligence

Artificial intelligence can be a useful tool to support your application, however, all examples and statements provided must be truthful, factually accurate and taken directly from your own experience. Where plagiarism has been identified (presenting the ideas and experiences of others, or generated by artificial intelligence, as your own) applications may be withdrawn and internal candidates may be subject to disciplinary action. Please see our candidate guidance (opens in a new window) for more information on appropriate and inappropriate use.

Selection process details

This vacancy is using Success Profiles (opens in a new window), and will assess your Behaviours, Experience and Technical skills.

The selection process for this role will be:

Stage 1: Sift of CV and personal statement

Stage 2: Interview

You must be successful at each stage to progress to the next stage.

Stage 1: Sift

At sift, you will be assessed against the following Success Profile elements:

Experience you will be asked to provide a CV (unlimited wordcount) and personal statement (1000-word count). Please provide evidence of your Experience of the following:

  • Experienceofimplementingcyber securitypolicies,standards,andassurance frameworksin a large, complex organisation to improve compliance.
  • Strongknowledgeofsecuritythreats,riskmanagement,andmitigationstrategies.
  • Experienceofincidentresponseandcrisismanagement.
  • Knowledge of protective security, ISO 27001/2, NCSCs Cyber Assessment Framework and Government Functional Standard GovS 007: Security.

Should a large number of applications be received, an initial sift may be conducted using the lead Success Profile element:

"Experience of protective security within the public sector, specifically ISO 27001/2, the NCSCs Cyber Assessment Framework v4 and/or Government Functional Standard GovS 007: Security."

Candidates who pass the initial sift may be progressed to a full sift or progressed straight to assessment/interview.

The sift will take place week commencing from 12 October 2026.

Stage 2: Interview

At interview stage, you will be assessed against the following Success Profile elements:

  • Behaviours Communicating and Influencing, Delivering at Pace, Leadership, Seeing the Big Picture
  • Technical Applied Security Capability, Threat Understanding

The interviews will take place from 23 October.

This interview will be conducted online via Microsoft Teams. Further details will be provided to you should you be selected for interview.

We will also hold a 12-monthreserve list for this role, which may lead to potential opportunities beyond the role you applied for.

During your application, you shouldindicatewhich location(s) you wish to be considered for and, if successful, you will be placed on an individual list of candidates for each location. Candidates will be held on that list and drawn from it in merit order. Weadvise you tocarefully consider which locations you wish to be considered for. If you decline an offer for alocationyou have expressed a preference in or have expressed an interest in more than one location and accept an offer, you will be withdrawn from any lists you may be held on. We may also offer candidates a location that they have not expressed a preference for where we have the requirement to do so but this will again be done on the basis of your place in the overall merit order and, in this event, you will not be removed from the list if you decline.

Appointments for this position will be made in order of merit.Ifyouare successful in the selection processbutthere are no further available postsfor the advertised role,you may be contacted to discuss anoffer for a lower graded role (with similar experience and responsibility requirements).

Ifyou are unsuccessfulin the selection process, your application may be considered for a lower graded positionif your demonstrated skills and experience meet the requirements of the alternative position.Candidates will be considered in order of merit.

Reasonable Adjustments

As a Disability Confident Leader employer, we are committed to ensuring that the recruitment process is fair, accessible and allows all candidates to perform at their best. If a person with a visible or non-visible disability is substantially disadvantaged, we have a duty to make reasonable changes to our processes.

Complete the Assistance required section in the Additional requirements page of your application form to tell us what changes or help you might need during the recruitment process. For instance, you may need wheelchair access at an interview, or if youre deaf, a Language Service Professional.

If you need a reasonable adjustment so that you can complete your application, you should contact Government Recruitment Service via dftrecruitment.grs@cabinetoffice.gov.uk as soon as possible before the closing date to discuss your needs.

Document Accessibility

This job advert contains links to the DfT Careers website. Our website provides useful guidance and information that can support you during the application process. If you are experiencing accessibility problems with any attachments on this advert or the information on your website, please contact the email address in the 'Contact point for applicants' section.

For further information about how we hire, and for useful tips on submitting your application for this role, visit the How We Hire page of our DfT Careers website. You can find detailed information about the recruitment process and what to expect when applying for a role.

For further information on National Security Vetting please visit the Demystifying Vetting website.

Applicants who are successful at interview will be, as part of pre-employment screening, subject to a check on the Internal Fraud Database (IFD). This check will provide information about employees who have been dismissed for fraud or dishonesty offences. This check also applies to employees who resign or otherwise leave before being dismissed for fraud or dishonesty had their employment continued. Any applicants details held on the IFD will be refused employment. A candidate is not eligible to apply for a role within the Civil Service if the application is made within a 5-year period following a dismissal for carrying out internal fraud against government.

All external applicants and current employees of accredited non-departmental public bodies (NDPBs) will be required to undergo a Social Media Check. A Social Media Check is a review of your publicly available online activity, typically across platforms like LinkedIn, Facebook, X (formerly Twitter), Instagram, and others. The purpose is to identify any public posts or content that could raise concerns for employers, such as:

  • Hate speech or discriminatory behaviour
  • Threats or acts of violence
  • Illegal activity or substance misuse
  • Sexually explicit material
  • Extremist views or affiliations

Importantly, this check does not involve hacking into your accounts or accessing private messages. It only considers content you have chosen to make public. Employers use this kind of screening to help ensure their workplace remains safe, inclusive, and aligned with company values. Its not about judging your personality or lifestyle - its about checking for potential red flags that might affect the role or company culture. If you have questions or concerns about the social media check, we would be happy to explain in more detail whats being looked at and how your data is handled securely and fairly.

Feedback will only be provided if you attend an interview or assessment.

Security

Successful candidates must undergo a basic (or equivalent) criminal record check.

Successful candidates must meet the security requirements before they can be appointed. The level of security needed is developed vetting (opens in a new window).

See our vetting charter (opens in a new window).

People working with government assets must complete baseline personnel security standard (opens in new window) checks.

Nationality requirements

This job is broadly open to the following groups:

  • UK nationals
  • nationals of the Republic of Ireland
  • nationals of Commonwealth countries who have the right to work in the UK
  • nationals of the EU, Switzerland, Norway, Iceland or Liechtenstein and family members of those nationalities with settled or pre-settled status under the European Union Settlement Scheme (EUSS) (opens in a new window)
  • nationals of the EU, Switzerland, Norway, Iceland or Liechtenstein and family members of those nationalities who have made a valid application for settled or pre-settled status under the European Union Settlement Scheme (EUSS)
  • individuals with limited leave to remain or indefinite leave to remain who were eligible to apply for EUSS on or before 31 December 2020
  • Turkish nationals, and certain family members of Turkish nationals, who have accrued the right to work in the Civil Service

Further information on nationality requirements (opens in a new window)

Working for the Civil Service

The Civil Service Code (opens in a new window) sets out the standards of behaviour expected of civil servants.

We recruit by merit on the basis of fair and open competition, as outlined in the Civil Service Commission's recruitment principles (opens in a new window).

The Civil Service embraces diversity and promotes equal opportunities. As such, we run a Disability Confident Scheme (DCS) for candidates with disabilities who meet the minimum selection criteria.

The Civil Service also offers a Redeployment Interview Scheme to civil servants who are at risk of redundancy, and who meet the minimum requirements for the advertised vacancy.

Diversity and Inclusion

The Civil Service is committed to attract, retain and invest in talent wherever it is found. To learn more please see the Civil Service People Plan (opens in a new window) and the Civil Service Diversity and Inclusion Strategy (opens in a new window).

Company

Learn more about this company

Visit this company’s hub to learn about their values, culture, and latest jobs.

Visit this company’s hub to learn about their values, culture, and latest jobs.

Create a job alert and receive personalised job recommendations straight to your inbox.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Principal Compliance Manager
Principal Compliance Manager

ENGINEERINGUK • Birmingham, Hastings, Leeds, Swansea

Hybrid
GBP 52,000 - 63,000
Civil Service Pension 28.97%
25 days leave + 8 bank holidays
Hybrid working
Cyber Security Assurance Principal
Cyber Security Assurance Principal

Department for Transport (DfT), United Kingdom • Greater London

Hybrid
GBP 62,000 - 82,000
Civil Service Pension 28.97%
25 days annual leave
8 Bank Holidays + Privilege Day
+3
Cyber Security Assurance Principal
Cyber Security Assurance Principal

Department for Transport • Greater London

Hybrid
GBP 62,000 - 82,000
Civil Service pension 28.97%
25 days annual leave
8 bank holidays + King’s Birthday Priv
+4
Regulatory Analyst
Regulatory Analyst

ENGINEERINGUK • Southampton

Hybrid
GBP 40,000 - 49,000
Civil Service Pension (28.97% employer
25 days annual leave
Flexible working options
Cyber Security Engineer - Cyber & Autonomous Systems Team
Cyber Security Engineer - Cyber & Autonomous Systems Team

AI Security Institute (AISI) • Greater London

Hybrid
GBP 65,000 - 145,000
Hybrid working
Learning & development stipend
25 days annual leave
+2
Product Manager (Closing date 23rd March 2025)
Product Manager (Closing date 23rd March 2025)

慨正橡扯 • Bristol

Hybrid
GBP 56,000
Flexible hybrid working
Civil Service Pension
25 days annual leave
+5
Senior IT Service Manager (Catalogue) - Department for Transport - SEO
Senior IT Service Manager (Catalogue) - Department for Transport - SEO

Manchester Digital • Manchester

Hybrid
GBP 65,000 - 80,000
Employer pension 28.97% of salary
25 days annual leave + 8 bank holidays
Flexible working options
Senior Cyber Responder
Senior Cyber Responder

FCDO • Milton Keynes

On-site
GBP 39,000 - 47,000
Learning and development tailored to你的
Flexible working options
Diversity and inclusion
+4
Digital Data and Technology Apprentice
Digital Data and Technology Apprentice

Llywodraeth Cymru / Welsh Government • Cardiff, Merthyr Tydfil, Aberystwyth, Llandudno

Hybrid
GBP 27,000 - 29,000
IT Service Manager
IT Service Manager

Department for Work and Pensions • Stafford

Hybrid
GBP 39,000 - 46,000
Civil Service Pension
Flexible working
Generous annual leave
+1