Cyber Security Assurance Principal
Department for Transport · London, London
Cyber Security Assurance Principal at Department for Transport, based in London, London, paying £62,034 - £82,430 per annum. This is a permanent role.
- Salary
- £62,034 - £82,430 per annum
- Location
- London, London
- Contract
- Permanent
- Posted
- 1 day ago
- Closes
- 7 Sep 2026
- Sector
- Security Officer
About 41% above the going rate for security officer
Reference ca7cf7dac18bc7d969c0103e24a1fec4b5c451e0
About the role
Job summary
Are you passionate about strengthening cyber security through effective assurance and risk management?
Can you provide expert advice that helps organisations identify, assess and manage cyber risk?
Do you have the influence and expertise to drive security compliance and assurance across complex environments?
If so, we’d love to hear from you!
This is an exciting time to join the Digital, Information and Security Directorate within the Department for Transport as we restructure our directorate to ensure we are ready for future challenges, building a more sustainable, skilled and in-house capability.
Assess risk. Strengthen resilience. Build confidence.
Use your cyber security expertise to provide assurance, influence decision-making, and help protect critical services, systems and information across the Department for Transport.
Joining our department comes with many benefits, including:
- Employer pension contribution of 28.97% of your salary. Read more about Civil Service Pensions here
- 25 days annual leave, increasing by 1 day each year of service (up to a maximum of 30 days annual leave), plus 8 bank holidays a privilege day for the King’s birthday
- Flexible working options where we encourage a great work-life balance.
Read more in the Benefits section below!
Find out more about what it's like working at Department for Transport Central - Department for Transport Careers.
Job description
Join the Department for Transport's Digital, Information and Security Directorate and play a key role in strengthening cyber security across the organisation. As a Cyber Security Assurance Principal, you will help ensure that appropriate cyber security controls are in place and security risks are correctly identified, assessed and managed, enabling the department to deliver secure and resilient digital services.
You will ensure adherence to the department’s cyber security policies, standards and assurance frameworks. You'll evaluate risks, review security arrangements and provide evidence-based recommendations that support informed decision-making and continuous improvement.
You'll build strong relationships with technical and non-technical stakeholders, influencing positive security outcomes and helping to embed a risk-based approach to cyber security. Through assurance activities, monitoring and reporting, you'll support the department in maintaining compliance, improving resilience and protecting critical services and information.
This is an excellent opportunity for a cyber security professional who enjoys balancing technical knowledge with stakeholder engagement to drive compliance and make a tangible impact across a complex organisation.
Your responsibilities will include, but aren’t limited to:
- Leading the assurance of ‘secure by design’ principles into application development, integrating security tools, standards, and processes into product life cycles.
- Leading engagement with senior internal and external stakeholders to present assurance findings to inform risk-based decisions
- Overseeing the procurement, development and implementation of a programme of penetration tests, red team exercises and/or vulnerability assessments of IT assets.
- Providing expert security advice on cyber security related risks, informed by current threat information, and pragmatic advice on mitigation.
- Set the cyber security requirements for the Department’s suppliers and oversee the assurance activities needed to ensure suppliers meet the required standards throughout the lifetime of the contract.
For further information on the role, please read the role profile. Please note that the role profile is for information purposes only - whilst all elements are relevant to the role, they may not all be assessed during the recruitment process. This job advert will detail exactly what will be assessed during the recruitment process.
Person specification
To be successful in this role you will need to have the following experience:
- Strong knowledge of security threats, risk management, and mitigation strategies.
- Experience of incident response and crisis management.
- Experience of implementing supply chain assurance mechanisms to improve cyber security and resilience
- Experience of protective security, specifically ISO 27001/2, the NCSC’s Cyber Assessment Framework and/or Government Functional Standard GovS 007: Security.
- Willingness to work towards industry recognised professional certifications in information risk, penetration and ethical hacking and ISO 27001 (e.g. Management of Risk Practitioner, Certified ISO 27001 Practitioner, CISSP).
Additional Information
The role is part of the and utilises an enhanced Capability–Based Pay Framework which provides access to a Digital and Data allowance.
The base pay is £62,034. In addition to this the role includes a Digital and Data allowance of up to £20,396.
The value of allowance awarded will be based on an assessment of your skills and experience as demonstrated through the selection process. Here are more details on the pay framework.
Working hours, office attendance and travel requirements
Full time roles consist of 37 hours per week.
Whilst we welcome applications from those looking to work with us on a part time basis, there is a business requirement for the successful candidate to be able to work at least 32 hours per week.
Occasional travel to other offices will be required, which may involve overnight stays.
This role is suitable for hybrid working, which is a non-contractual arrangement where a combination of workplace and home-based working can be accommodated subject to business requirements.
The expectation at present is a minimum of 60% of your working time a month will be spent at either your designated workplace (one of the locations cited in the advert) or, when required for business reasons, in another office/work location/visiting stakeholders. Your designated workplace will be your contractual place of work. There may be occasions where you are required to attend above the minimum expectation.
If you have a question about hybrid working, part time/job share hours, flexible working, travelling for work, or require a reasonable adjustment, please contact the Vacancy Holder during the recruitment process to avoid possible disappointment later in the process should your working arrangements not be compatible with the requirements of the role (see below for contact details).
Visa Sponsorship
DfTc does not offer Visa Sponsorship for this role.
Behaviours
We'll assess you against these behaviours during the selection process:
- Communicating and Influencing
- Delivering at Pace
- Leadership
- Managing a Quality Service
Technical skills
We'll assess you against these technical skills during the selection process:
Reference: ca7cf7dac18bc7d969c0103e24a1fec4b5c451e0 · Posted 1 day ago · Closes 7 Sep 2026 · Listed via Department for Transport
Apply for this job
This role is listed via Department for Transport. Applications are handled on the employer's site.
Apply on employer siteOpens the employer's website in a new tab.
Safe applying: a genuine employer will never ask you to pay for a DBS check, training or equipment, or move you onto WhatsApp before you are hired. If this listing does, report it and do not pay anything.