At a Glance
- Tasks: Lead cyber security assurance activities and strengthen resilience across the Department for Transport.
- Company: Join the innovative Digital, Information and Security Directorate at the Department for Transport.
- Benefits: Enjoy a competitive salary, generous pension contributions, and flexible working options.
- Other info: Access excellent career development opportunities and a diverse, inclusive workplace.
- Why this job: Make a real impact on national security while developing your career in a dynamic environment.
- Qualifications: Experience in cyber security policies and risk management is essential.
The predicted salary is between 58500 - 71500 £ per year.
Are you passionate about strengthening cyber resilience across multiple organisations? Can you provide expert assurance that helps organisations understand, manage and reduce cyber risk? Do you have the expertise and drive to influence security strategy and embed assurance activities across the DfT Group? If so, we'd love to hear from you!
This is an exciting time to join the Digital, Information and Security Directorate within the Department for Transport as we restructure our directorate to ensure we are ready for future challenges, building a more sustainable, skilled and in-house capability.
Assess risk. Strengthen resilience. Drive assurance. Use your cyber security expertise to influence decision-making, strengthen assurance and help protect critical services, systems and information across the Department for Transport Group.
Joining our department comes with many benefits, including:
- Employer pension contribution of 28.97% of your salary.
- 25 days annual leave, increasing by 1 day each year of service (up to a maximum of 30 days annual leave), plus 8 bank holidays and a privilege day for the King's birthday.
- Flexible working options where we encourage a great work-life balance.
As a Group Cyber Security Assurance Principal, you'll play a leading role in strengthening cyber resilience across the Department for Transport Group. You'll provide expert assurance, oversight and guidance to help ensure security controls are effective, risks are managed appropriately and government security requirements are consistently applied.
Your responsibilities will include, but aren't limited to:
- Overseeing the delivery of the Government Cyber Action Plan (GCAP) across the group.
- Developing and implementing the cyber security assurance framework across the group.
- Leading cyber security related risk assessments and other expert risk management activities, and enhance cyber security governance arrangements.
- Leading the assurance of secure by design principles across the DfT Group.
- Reviewing and reporting on the Groups compliance with NCSC's Cyber Assessment Framework and monitor the progress of action plans to improve compliance.
- Contributing to incident management policies, incident response plans, and tests.
To be successful in this role you will need to have the following experience:
- Experience of implementing cyber security policies, standards, and assurance frameworks in a large, complex organisation to improve compliance.
- Strong knowledge of security threats, risk management, and mitigation strategies.
- Experience of incident response and crisis management.
- Knowledge of protective security, ISO 27001/2, NCSC's Cyber Assessment Framework and Government Functional Standard GovS007: Security.
- Experience delivering quality service in high-pressure environments.
- Professional qualifications or willingness to work towards industry-recognised qualifications in information risk and ISO 27001 (e.g. Management of Risk Practitioner, Certified ISO 27001 Practitioner and/or CISSP).
The role is part of the Government Security Profession Career Framework and utilises an enhanced Capability Based Pay Framework which provides access to a Digital and Data allowance. The base pay is 62,034. In addition to this the role includes a Digital and Data allowance of up to 20,396.
Full time roles consist of 37 hours per week. Whilst we welcome applications from those looking to work with us on a part time basis, there is a business requirement for the successful candidate to be able to work at least 32 hours per week. Occasional travel to other offices will be required, which may involve overnight stays. This role is suitable for hybrid working, which is a non-contractual arrangement where a combination of workplace and home-based working can be accommodated subject to business requirements.
Successful candidates must undergo a basic (or equivalent) criminal record check. Successful candidates must meet the security requirements before they can be appointed. The level of security needed is developed vetting.
This job is broadly open to UK nationals, nationals of the Republic of Ireland, nationals of Commonwealth countries who have the right to work in the UK, and nationals of the EU, Switzerland, Norway, Iceland or Liechtenstein and family members of those nationalities with settled or pre-settled status under the European Union Settlement Scheme (EUSS).
The Civil Service embraces diversity and promotes equal opportunities. As such, we run a Disability Confident Scheme (DCS) for candidates with disabilities who meet the minimum selection criteria.
Group Cyber Security Assurance Principal employer: ENGINEERINGUK
Superdrug is an exceptional employer that prioritises its team members and customers, fostering a vibrant work culture where fun and hard work go hand in hand. Located in the bustling Deepdale Shopping Centre, employees enjoy flexible hours, competitive pay, and generous benefits including up to 28 days of holiday and a substantial discount for friends and family. With a strong focus on personal development and excellent training opportunities, Superdrug empowers its staff to thrive in their roles while delivering outstanding service to customers.
StudySmarter Expert Advice🤫
We think this is how you could land Group Cyber Security Assurance Principal
✨Get Involved in the Cybersecurity Community
Diving into the cybersecurity community is key for landing that full-time gig. Join forums like Reddit's r/cybersecurity or attend local meetups to connect with industry veterans and other job seekers. Networking is everything in this field—don’t just be a passive lurker!
✨Show Off Your Skills with Capture the Flag Competitions
Participate in Capture the Flag (CTF) competitions; these are not just a fun way to boost your skills but also a chance to showcase your talent to potential employers. Many companies, including ENGINEERINGUK, love seeing candidates who actively engage in these challenges.
✨Tailor Your Online Presence
Make sure your LinkedIn and any professional profiles reflect your cybersecurity expertise. Share your projects, whether they’re personal or from a previous role, to catch the eye of hiring managers. This is how they’ll find your passion and commitment to the field!
✨Apply Directly Through ENGINEERINGUK
Don’t forget to head straight to our website and check out any openings for cybersecurity roles at ENGINEERINGUK. Applying directly can sometimes give you an edge, especially if you can mention that you've been following our work or engaging in the community.
We think you need these skills to ace Group Cyber Security Assurance Principal
Some tips for your application 🫡
Show off your technical skills:In cybersecurity, it's crucial to highlight your technical prowess. Make sure your CV showcases specific skills like network security, penetration testing, or threat analysis. If you have relevant certifications (like CEH or CISSP), pop those on the front page to grab attention!
Tailor your portfolio for the role:Even for a full-time role, a portfolio can set you apart. If you've worked on any cybersecurity projects—be it CTF challenges, security assessments, or research papers—include these in your application. This demonstrates not just your skills, but also your hands-on experience!
Use real-world examples:When writing your cover letter, don’t just stick to your qualifications. Share real-world examples of how you’ve tackled security issues or vulnerabilities. This gives the hiring team at ENGINEERINGUK insight into your practical problem-solving abilities and makes your application memorable.
Demonstrate your passion for cybersecurity:Cybersecurity is an ever-evolving field, so show us that you’re always learning! Mention any recent courses, webinars, or industry events you’ve attended. This not only exhibits your enthusiasm but also signals to ENGINEERINGUK that you’re committed to staying ahead in the game.
How to prepare for a job interview at ENGINEERINGUK
✨Sharpen Your Technical Skills
For a role in cybersecurity, it’s essential to be up-to-date with the latest tools and techniques. Brush up on your knowledge of firewalls, intrusion detection systems, and vulnerability assessment tools. Be ready to discuss specific scenarios where you’ve applied these skills, as hands-on experience can really set us apart in interviews.
✨Prepare for Scenario-Based Questions
Expect the interviewers at ENGINEERINGUK to throw in some hypothetical situations to see how you’d handle them. Think about common security breaches or incidents and be prepared to explain how you would respond. This not only shows your problem-solving skills but also your understanding of real-world cybersecurity challenges.
✨Highlight Your Certifications
Certifications like CompTIA Security+, CISSP, or CEH can give you a significant edge in a full-time role in cybersecurity. Make sure to mention these during your interview and be prepared to discuss what you learned through those certifications and how they relate to the position at ENGINEERINGUK.
✨Show Your Passion for Cybersecurity
Since you’re going for a full-time gig, showing genuine enthusiasm for the field can make all the difference. Share any personal projects, blogs, or communities you’re part of that relate to cybersecurity. This not only showcases your passion but also your commitment to staying engaged in this ever-evolving field.