Back to search

Principal Security Policy Lead

Civil Service

Job Description

Job summary

Are you ready to shape the future of security policy at the Department for Transport?

Can you turn complex security and information governance requirements into clear, effective policies?

Would you like to influence how security and information risk are managed across government?

If so, wed love to hear from you!

This is an exciting time to join the Digital, Information and Security Directorate within the Department for Transport as we restructure our directorate to ensure we are ready for future challenges, building a more sustainable, skilled and in-house capability.

Shape policy. Manage risk. Strengthen compliance.

Lead the development of protective security and information governance policies and standards that protect the Department for Transport, influence decision-making, and help create a secure, resilient and compliant organisation.

Joining our department comes with many benefits, including:

  • Employer pension contribution of 28.97% of your salary. Read more about Civil Service Pensions here
  • 25 days annual leave, increasing by 1 day each year of service (up to a maximum of 30 days annual leave), plus 8 bank holidays a privilege day for the Kings birthday
  • Flexible working options where we encourage a great work-life balance.

Read more in the Benefits section below!

Find out more about what it's like working at Department for Transport Central - Department for Transport Careers.

Job description

Join the Department for Transport's Digital, Information and Security Directorate and play a key role in shaping the policies that underpin security, information governance and compliance across the department. As a Principal Security Policy Lead, you will help ensure that we have a comprehensive control framework aligned with organisational priorities while enabling the delivery of effective public services.

Working within the Assurance, Compliance and Controls function, you'll lead the development, implementation and review of policies, standards and guidance. You'll work closely with stakeholders across the DfT Group to share resources, identify policy gaps, drive consistency, and ensure compliance with both government requirements and industry best practice.

You'll use evidence, data and risk insight to inform decision-making, translating complex requirements into clear and practical policies that can be understood by technical and non-technical audiences alike. You'll also influence senior stakeholders, champion continuous improvement and help strengthen the department's overall security posture.

This is an excellent opportunity for someone with excellent written skills who enjoys strategic thinking, stakeholder engagement and delivering meaningful change in a complex environment.

Your responsibilities will include, but arent limited to:

  • Defining the overarching control framework needed by the department aligned to established frameworks/standards, regulatory requirements and industry best practice.
  • Conducting a gap analysis to identify gaps in our suite of policy documentation and developing a plan to address these with input from the relevant stakeholders and SMEs.
  • Making the current suite of policy documents easily accessible via the intranet site and raising awareness of them amongst the relevant audience.
  • Consulting with representatives from across the DfT Group to share materials and align resources to ensure consistency of approach and drive efficiencies, where appropriate.
  • Leading the establishment of an appropriate protective security organisational posture to ensure an effective risk-based approach to security across the estate, considering political, economic, social, technological, legal and environmental considerations.

For further information on the role, please read the role profile. Please note that the role profile is for information purposes only - whilst all elements are relevant to the role, they may not all be assessed during the recruitment process. This job advert will detail exactly what will be assessed during the recruitment process.

Person specification

To be successful in this role you will need to have the following experience:

  • Experience of policy development and implementation
  • Knowledge of legal and regulatory compliance
  • Hold professional certifications (Data Protection Foundation Certificate, ISO27001, or equivalent), or willing to work towards
  • Knowledge of security threats, risk management, and mitigation strategies
  • Excellent written skills, communicating a technical matter to a non-technical audience
  • Experience of working in a protective security environment
  • Experience delivering quality service in high-pressure environments
  • Drive continuous improvement and encourage the sharing of best practice
  • Developing and maintaining stakeholder engagement for the delivery of a discrete piece of work
  • Working in a protective security and/or regulatory compliance environment

Additional information

https://view.officeapps.live.com/op/view.aspx?src=https%3A%2F%2Fcdn-files.smartsurvey.io%2F241142_Government_Digital_and_Data_CapabilityBased_Pay_Framework_Principles.docx&wdOrigin=BROWSELINKWorking hours, office attendance and travel requirements

Full time roles consist of 37 hours per week.

Whilst we welcome applications from those looking to work with us on a part time basis, there is a business requirement for the successful candidate to be able to work at least 32 hours per week.

Occasional travel to other offices will be required, which may involve overnight stays. 

This role is suitable for hybrid working, which is a non-contractual arrangement where a combination of workplace and home-based working can be accommodated subject to business requirements.

The expectation at present is a minimum of 60% of your working time a month will be spent at either your designated workplace (one of the locations cited in the advert) or, when required for business reasons, in another office/work location/visiting stakeholders. Your designated workplace will be your contractual place of work. There may be occasions where you are required to attend above the minimum expectation.

If you have a question about hybrid working, part time/job share hours, flexible working, travelling for work, or require a reasonable adjustment, please contact the Vacancy Holder during the recruitment process to avoid possible disappointment later in the process should your working arrangements not be compatible with the requirements of the role (see below for contact details).

Visa Sponsorship

DfTc does not offer Visa Sponsorship for this role.

Yodel are hiring now

Working at Yodel, they promise to support you, develop you and give you all the tools you need to do a great job. They have a range of opportunities across the UK now - why not see if Yodel have the perfect role for you?

See Yodel jobs

Good luck with your application