
Location
City of Westminster
Hours
Full Time - 37 hours per week. Part time considered with a minimum of 32 hours per week. Hybrid working available with an expectation of at least 60% of working time spent at the designated workplace or other business locations as required.
Salary
£62,034 per annum plus a Digital and Data allowance of up to £20,396, dependent on skills and experience.
About the Role
Join the Department for Transport's Digital, Information and Security Directorate at an exciting time of transformation. As a Group Cyber Security Assurance Principal, you will lead efforts to strengthen cyber resilience across the DfT Group by providing expert assurance, oversight, and guidance. You will oversee the delivery of the Government Cyber Action Plan (GCAP), monitor compliance with the NCSC Cyber Assessment Framework, and champion Secure by Design principles. Working closely with senior stakeholders, you will assess cyber risks, develop assurance frameworks, and advise on security governance, compliance, and risk management. Your role will be critical in protecting vital government services, systems, and information, driving continuous improvement in cyber security maturity across the organisation. This position offers the opportunity to influence strategic decisions and lead assurance activities within a complex organisational landscape.
Experience
- Implementing cyber security policies, standards, and assurance frameworks in large, complex organisations to improve compliance.
- Strong knowledge of security threats, risk management, and mitigation strategies.
- Experience in incident response and crisis management.
- Knowledge of protective security, ISO 27001/2, NCSC’s Cyber Assessment Framework, and Government Functional Standard GovS 007: Security.
- Delivering quality service in high-pressure environments.
About you
Professional, proactive, and able to influence senior stakeholders. You are passionate about cyber security and resilient systems, with the ability to lead assurance activities and embed security principles across diverse teams. You thrive in complex environments and are committed to continuous improvement and strategic impact.
Qualifications
Professional qualifications or willingness to work towards industry-recognised certifications in information risk and ISO 27001 (e.g. Management of Risk Practitioner, Certified ISO 27001 Practitioner, CISSP) are required or highly desirable.

