Principal Cyber Security Risk Manager
Driver and Vehicle Standards Agency
- Department
- Driver and Vehicle Standards Agency
- Location
- Birmingham, Leeds, Bristol, Swansea, Nottingham, Newcastle, Oldham
- Openings
- 2 posts
- Grade
- Grade 7
- Salary
- £57,515
- Closing
- 14 days left
- Profession
- DDaT
- Contract
- Permanent
- Security clearance
- SC
- Working pattern
- Flexible working, Full-time, Job share, Part-time
Job summary
The DVSA are continuing to strengthen security capability across the business. This role will form a part of a growing Cyber function continuing to embed and maintain an assurance and response function protecting our Services and customer data.
Our work also supports the DVSA Data Strategy which has recently been refreshed. This sets the direction for making the Agency an evidence based and data driven organisation whilst maintaining an appropriate level of security of our services and data.
You will work with the wider Security function as well as supporting Service Owners and multi-disciplinary teams to ensure that security is built into the service development lifecycle and strategic planning. You will be responsible for providing the consolidated risk picture for the Products within that Service and recommending risk acceptance aligning with defined risk appetites. You will lead a small service group team of security professionals to support the assurance as well as engage as necessary with the Enterprise Architecture processes via the Security Architecture function to influence pattern adoption.
Joining our department comes with many benefits, including:
- Employer pension contribution of 28.97% of your salary. Read more about Civil Service Pensions here
- 25 days annual leave, increasing by 1 day each year of service (up to a maximum of 30 days annual leave), plus 8 bank holidays a privilege day for the King’s birthday.
- Flexible working options where we encourage a great work-life balance.
Read more in the Benefits section below!
Find out more about what it's like working at Driver and Vehicle Standards Agency - Department for Transport Careers
What they’re looking for
- Required experience:
- A Chartered Cyber Professional or be willing to work towards becoming Chartered.
- Demonstrate experience in cloud security across at least one platform of AWS or Azure and be willing to undertake formal training and certifications in this area.
- As a Principal Cyber Risk Manager you are inquisitive and enjoy understanding the context of the full service and product suite you are supporting. You work in a matrix team with roles such as developers, User experience and service design, business analysis to bring a rounded approach to a Service.
- You are good at making evidenced based recommendations to both Service Owners and Senior Security Leadership roles around the level of security risk being managed within each Product.
- You are part of a wider Security profession and support the development of that profession as part of a leadership role in the organisation and are able to bring strategic influence to your local Services and Products.
- Additional Information
- Working hours, office attendance and travel requirements
- Full time roles consist of 37 hours per week.
- Whilst we welcome applications from those looking to work with us on a part time basis, there is a business requirement for the successful candidate to be able to work at least 30 hours per week.
- Occasional travel to other offices will be required, which may involve overnight stays.
- This role is suitable for hybrid working, which is a non-contractual arrangement where a combination of workplace and home-based working can be accommodated subject to business requirements.
- The expectation at present is a minimum of 60% of your working time a month will be spent at either your designated workplace (one of the locations cited in the advert) or, when required for business reasons, in another office/work location. There may be occasions where you are required to attend above the minimum expectation.
- If you have a question about hybrid working, part time/job share hours, flexible working, travelling for work, or require a reasonable adjustment, please contact the Vacancy Holder during the recruitment process to avoid possible disappointment later in the process should your working arrangements not be compatible with the requirements of the role (see below for contact details).
- Please note that we do not hold a UK Visa & Immigration (UKVI) Skilled Worker Licence sponsor and are unable to sponsor any individuals for Skilled Worker Sponsorship. Candidates must ensure they have the appropriate rights to work in the UK before application.
- Government Digital and Data Allowance
- The role is part of the Government Digital and Data (or Government Security Profession Career Framework) profession and utilises an enhanced Capability–Based Pay Framework which provides access to a Digital and Data allowance.
- The base pay is £57,515. In addition to this the role includes a Digital and Data allowance of up to £24,915.
- The value of allowance awarded will be based on an assessment of your skills and experience as demonstrated through the selection process. Here are more details on the pay framework.
Behaviours you’ll be assessed on
This advert says the panel will score you against these behaviours at Grade 7 level. Each one links to worked examples.
Job description
Your responsibilities will include, but aren’t limited to:
- Lead and undertake risk management activities against the hardest or most novel scenarios, while applying the fundamental principles of risk management to a range of complex scenarios, and lead regulatory or legislative compliance activities.
- Guide and direct specialist activities of others, actively promoting development in the applicable skills, providing leadership to other risk managers, and sharing best practice widely across government, the public sector, and industry.
- Lead the analysis and derivation of complex security needs.
- Lead Cyber Security related risk assessments and other expert risk management activities, including providing guidance on establishing the organisation’s Cyber Securityrelated governance arrangements.
- Provide guidance to ensure ongoing confidence that fundamental organisational security needs have been met, including integrating a range of assurance approaches and techniques to give continued confidence to the risk, service or system owner.
- Shape leadership decision-making through:
- effective reporting and communication regarding the effectiveness of security processes across an organisation
- providing recommendations to highly complex problems
- acting as an SME for complex cyber risk management concerns, issues and problems
Great line management is important to us as an organisation, and we will equip and support line managers to develop the skills set out in the Civil Service Line Management Standards.
For further information on the role, please read the attached role profile. Please note that the role profile is for information purposes only - whilst all elements are relevant to the role, they may not all be assessed during the recruitment process. This job advert will detail exactly what will be assessed during the recruitment process.
Nationality requirements
This job is broadly open to the following groups:
- UK nationals
- nationals of the Republic of Ireland
- nationals of Commonwealth countries who have the right to work in the UK
- nationals of the EU, Switzerland, Norway, Iceland or Liechtenstein and family members of those nationalities with settled or pre-settled status under the European Union Settlement Scheme (EUSS) (opens in a new window)
- nationals of the EU, Switzerland, Norway, Iceland or Liechtenstein and family members of those nationalities who have made a valid application for settled or pre-settled status under the European Union Settlement Scheme (EUSS)
- individuals with limited leave to remain or indefinite leave to remain who were eligible to apply for EUSS on or before 31 December 2020
- Turkish nationals, and certain family members of Turkish nationals, who have accrued the right to work in the Civil Service
Further information on nationality requirements (opens in a new window)
Selection process
This vacancy is using Success Profiles (opens in a new window), and will assess your Behaviours, Experience and Technical skills.
How to apply:
Our selection process ensures a comprehensive assessment of each applicant's qualifications, skills, and potential fit within our organisation.
The selection process for this role will be:
Stage 1: Sift of CV and personal statement
Stage 2: Interview and assessment
You must be successful at each stage to progress to the next stage.
Stage 1: Sift
At sift, you will be assessed against the following Success Profile elements:
Experience:
You will be asked to provide a CV (unlimited wordcount) and a personal statement (1000-words max). Please provide detailed evidence against each of the following within your personal statement:
- Experience of when you have gathered and derived meaningful security requirements to support an identified need.
- Experience of when you have delivered a comprehensive risk assessment for a complicated scenario using appropriate methodologies.
The sift will take place week commencing 28/09/2026.
Stage 2: Interview
At interview stage, you will be assessed against the following Success Profile elements:
Behaviours –
- Seeing the Big Picture
- Communicating and Influencing
Technical –
- Information Risk Assessment and Risk Management – Expert level
- Threat Understanding – Practitioner level
- Protective Security – Expert level
- Applied Security Capability – Practitioner level
You will also be required to complete an Assessment to assess the following Success Profile elements:
Technical skills
- Applied Security Capability – Practitioner level
- Security architecture – Expert level
Guidance will be provided if you are invited to interview.
The interviews will take place week commencing 19/10/2026
This interview will be conducted online via Microsoft Teams. Further details will be provided to you should you be selected for interview.
You can find out more about our hiring process, how to apply, and application and interview guidance on our careers site (opens in a new window).
Please note that we will try to meet the dates set out in the advert. There may be occasions when these dates will change.
Further information on the selection process
We will also hold a 12 reserve list for this role, which may lead to potential opportunities beyond the role you applied for. You can read more about our reserve lists here.
Reasonable Adjustments
As a Disability Confident Leader employer, we are committed to ensuring that the recruitment process is fair, accessible and allows all candidates to perform at their best. If a person with a visible or non-visible disability is substantially disadvantaged, we have a duty to make reasonable changes to our processes.
Complete the “Assistance required” section in the “Additional requirements” page of your application form to tell us what changes or help you might need during the recruitment process. For instance, you may need wheelchair access at an interview, or if you’re deaf, a Language Service Professional.
If you need a reasonable adjustment so that you can complete your application, you should contact Government Recruitment Service via dftrecruitment.grs@cabinetoffice.gov.uk as soon as possible before the closing date to discuss your needs.
Document Accessibility
This job advert contains links to the DfT Careers website. Our website provides useful guidance and information that can support you during the application process. If you are experiencing accessibility problems with any attachments on this advert or the information on our website, please contact the email address in the 'Contact point for applicants' section.
Further Information
For more information about how we hire, and for useful tips on submitting your application for this role, visit the How We Hire page of our DfT Careers website. You can find detailed information about the recruitment process and what to expect when applying for a role.
Should we receive a large number of applications, we may invite a shortlist of the highest performing candidates to interview. This means that some applications that meet the required standard could be placed ‘on hold’ after the sift and invited to interview if the vacant position(s) remain unfilled. You will be notified if your application is being put ‘on hold’ once the sift has been completed.
Appointments for this position will be made in order of merit. If you are successful in the selection process but there are no further available posts for the advertised role, you may be contacted to discuss an offer for a lower graded role (with similar experience and responsibility requirements).
If you are unsuccessful in the selection process, your application may be considered for a lower graded position if your demonstrated skills and experience meet the requirements of the alternative position. Candidates will be considered in order of merit.
For further information on National Security Vetting please visit the Demystifying Vetting website.
AI Tools and Platforms
Artificial Intelligence can be a useful tool to support your application, however, all examples and statements provided must be truthful, factually accurate and taken directly from your own experience. Where plagiarism has been identified (presenting the ideas and experiences of others, or generated by artificial intelligence, as your own) applications may be withdrawn and internal candidates may be subject to disciplinary action. Please see our for more information on appropriate and inappropriate use.
Pre-employment Checking
If your application is successful but you have been dismissed from the Civil Service, your application could be removed at the pre-employment checking stage depending on the nature of the dismissal.
Applicants who are successful at interview will be, as part of pre-employment screening, subject to a check on the Internal Fraud Database (IFD). This check will provide information about employees who have been dismissed for fraud or dishonesty offences. This check also applies to employees who resign or otherwise leave before being dismissed for fraud or dishonesty had their employment continued. Any applicant’s details held on the IFD will be refused employment. A candidate is not eligible to apply for a role within the Civil Service if the application is made within a 5-year period following a dismissal for carrying out internal fraud against government.
All External applicants and current employees of accredited non-departmental public bodies (NDPBs) will be required to undergo a Social Media Check. A Social Media Check is a review of your publicly available online activity, typically across platforms like LinkedIn, Facebook, X (formerly Twitter), Instagram, and others. The purpose is to identify any public posts or content that could raise concerns for employers, such as:
- Hate speech or discriminatory behaviour
- Threats or acts of violence
- Illegal activity or substance misuse
- Sexually explicit material
- Extremist views or affiliations
Importantly, this check does not involve hacking into your accounts or accessing private messages. It only considers content you have chosen to make public. Employers use this kind of screening to help ensure their workplace remains safe, inclusive, and aligned with company values. It’s not about judging your personality or lifestyle—it’s about checking for potential red flags that might affect the role or company culture. If you have questions or concerns about the social media check, we would be happy to explain in more detail what’s being looked at and how your data is handled securely and fairly.
Feedback
Feedback will only be provided if you attend an interview or assessment.
Practise before you apply
Civil Service panels score every answer against the Success Profiles behaviours at Grade 7 level. Practise STAR answers and get them marked against the same framework.
3 free questions · No card needed
Similar vacancies
- Lead Solutions Architect - Apprenticeship · Driver and Vehicle Standards Agency · £57,515
- Senior Business Analyst · Active Travel England · £57,515
- Security Operations DevOps Engineer · Companies House · £62,881+
- Senior Service Designer · Department for Work and Pensions · £57,946+
- Technical Architect · Ministry of Housing, Communities and Local Government · £64,811