
Location
City of Westminster
Hours
Full Time - 37 hours per week (minimum 32 hours per week considered)
Salary
£62,034 plus a Digital and Data allowance of up to £20,396, dependent on skills and experience
About the Role
Join the Department for Transport's Digital, Information and Security Directorate and play a key role in strengthening cyber security across the organisation. As a Cyber Security Assurance Principal, you will help ensure that appropriate cyber security controls are in place and security risks are correctly identified, assessed and managed, enabling the department to deliver secure and resilient digital services.
You will ensure adherence to the department’s cyber security policies, standards and assurance frameworks. You'll evaluate risks, review security arrangements and provide evidence-based recommendations that support informed decision-making and continuous improvement.
You'll build strong relationships with technical and non-technical stakeholders, influencing positive security outcomes and helping to embed a risk-based approach to cyber security. Through assurance activities, monitoring and reporting, you'll support the department in maintaining compliance, improving resilience and protecting critical services and information.
This is an excellent opportunity for a cyber security professional who enjoys balancing technical knowledge with stakeholder engagement to drive compliance and make a tangible impact across a complex organisation.
Your responsibilities will include, but aren’t limited to:
- Leading the assurance of ‘secure by design’ principles into application development, integrating security tools, standards, and processes into product life cycles.
- Leading engagement with senior internal and external stakeholders to present assurance findings to inform risk-based decisions.
- Overseeing the procurement, development and implementation of a programme of penetration tests, red team exercises and/or vulnerability assessments of IT assets.
- Providing expert security advice on cyber security related risks, informed by current threat information, and pragmatic advice on mitigation.
- Setting the cyber security requirements for the Department’s suppliers and overseeing the assurance activities needed to ensure suppliers meet the required standards throughout the lifetime of the contract.
This role supports hybrid working with an expectation of spending a minimum of 60% of working time at the designated workplace or other business locations as required. Occasional travel, including overnight stays, may be necessary.
Experience
- Strong knowledge of security threats, risk management, and mitigation strategies.
- Experience of incident response and crisis management.
- Experience of implementing supply chain assurance mechanisms to improve cyber security and resilience.
- Experience of protective security, specifically ISO 27001/2, the NCSC’s Cyber Assessment Framework and/or Government Functional Standard GovS 007: Security.
About you
Proactive and influential cyber security professional with the ability to engage and build strong relationships across technical and non-technical stakeholders. You are motivated to drive security compliance and assurance in complex environments and have a pragmatic approach to risk management.
You are willing to work towards industry recognised professional certifications in information risk, penetration and ethical hacking, and ISO 27001 (e.g. Management of Risk Practitioner, Certified ISO 27001 Practitioner, CISSP).
Qualifications
While specific qualifications are not mandatory, willingness to pursue relevant professional certifications is expected to support your development and success in the role.



