Back to search

Group Cyber Security Assurance Principal

Civil Service

Job Description

Job summary

Are you passionate about strengthening cyber resilience across multiple organisations?

Can you provide expert assurance that helps organisations understand, manage and reduce cyber risk?

Do you have the expertise and drive to influence security strategy and embed assurance activities across the DfT Group?

If so, wed love to hear from you!

This is an exciting time to join the Digital, Information and Security Directorate within the Department for Transport as we restructure our directorate to ensure we are ready for future challenges, building a more sustainable, skilled and in-house capability.

Assess risk. Strengthen resilience. Drive assurance.

Use your cyber security expertise to influence decision-making, strengthen assurance and help protect critical services, systems and information across the Department for Transport Group.

Joining our department comes with many benefits, including:

  • Employer pension contribution of 28.97% of your salary. Read more about Civil Service Pensions here
  • 25 days annual leave, increasing by 1 day each year of service (up to a maximum of 30 days annual leave), plus 8 bank holidays a privilege day for the Kings birthday
  • Flexible working options where we encourage a great work-life balance.

Read more in the Benefits section below!

Find out more about what it's like working at Department for Transport Central - Department for Transport Careers.

Job description

As a Group Cyber Security Assurance Principal, you'll play a leading role in strengthening cyber resilience across the Department for Transport Group. You'll provide expert assurance, oversight and guidance to help ensure security controls are effective, risks are managed appropriately and government security requirements are consistently applied.

Working within the Assurance, Compliance and Controls function, you'll lead cyber security assurance activities across a complex organisational landscape. You'll oversee the delivery of the Government Cyber Action Plan (GCAP), monitor compliance with the NCSC Cyber Assessment Framework and champion the application of Secure by Design principles across the DfT Group.

You'll work closely with senior stakeholders to assess cyber risks, develop assurance frameworks and provide expert advice on security governance, compliance and risk management. You'll also support the implementation of targeted improvement plans, communicate emerging threats and help drive continuous improvement in cyber security maturity across the organisation.

This is an exciting opportunity for a cyber security professional who enjoys influencing strategic decisions, leading assurance activities and helping to protect critical government services and information.

Your responsibilities will include, but arent limited to:

  • Overseeing the delivery of the GCAP across the group.
  • Developing and implementing the cyber security assurance framework across the group.
  • Leading cyber security related risk assessments and other expert risk management activities, and enhance cyber security governance arrangements.
  • Leading the assurance of secure by design principles across the DfT Group.
  • Reviewing and reporting on the Groups compliance with NCSCs Cyber Assessment Framework and monitor the progress of action plans to improve compliance.
  • Contributing to incident management policies, incident response plans, and tests.

For further information on the role, please read the role profile. Please note that the role profile is for information purposes only - whilst all elements are relevant to the role, they may not all be assessed during the recruitment process. This job advert will detail exactly what will be assessed during the recruitment process.

Person specification

To be successful in this role you will need to have the following experience:

  • Experience of implementing cyber security policies, standards, and assurance frameworks in a large, complex organisation to improve compliance
  • Strong knowledge of security threats, risk management, and mitigation strategies.
  • Experience of incident response and crisis management.
  • Knowledge of protective security, ISO 27001/2, NCSCs Cyber Assessment Framework and Government Functional Standard GovS 007: Security
  • Experience delivering quality service in high-pressure environments.
  • Professional qualifications or willingness to work towards industry-recognised qualifications in information risk and ISO 27001 (e.g. Management of Risk Practitioner, Certified ISO 27001 Practitioner and/or CISSP).

Additional information

The role is part of the Government Security Profession Career Framework and utilises an enhanced CapabilityBased Pay Framework which provides access to a Digital and Data allowance.

The base pay is 62,034. In addition to this the role includes a Digital and Data allowance of up to 20,396.

The value of allowance awarded will be based on an assessment of your skills and experience as demonstrated through the selection process. Here are more details on the pay framework.

Working hours, office attendance and travel requirements

Full time roles consist of 37 hours per week.

Whilst we welcome applications from those looking to work with us on a part time basis, there is a business requirement for the successful candidate to be able to work at least 32 hours per week.

Occasional travel to other offices will be required, which may involve overnight stays. 

This role is suitable for hybrid working, which is a non-contractual arrangement where a combination of workplace and home-based working can be accommodated subject to business requirements.

The expectation at present is a minimum of 60% of your working time a month will be spent at either your designated workplace (one of the locations cited in the advert) or, when required for business reasons, in another office/work location/visiting stakeholders. Your designated workplace will be your contractual place of work. There may be occasions where you are required to attend above the minimum expectation.

If you have a question about hybrid working, part time/job share hours, flexible working, travelling for work, or require a reasonable adjustment, please contact the Vacancy Holder during the recruitment process to avoid possible disappointment later in the process should your working arrangements not be compatible with the requirements of the role (see below for contact details).

Visa Sponsorship

DfTc does not offer Visa Sponsorship for this role.

Yodel are hiring now

Working at Yodel, they promise to support you, develop you and give you all the tools you need to do a great job. They have a range of opportunities across the UK now - why not see if Yodel have the perfect role for you?

See Yodel jobs

Good luck with your application