How to apply:
Our selection process ensures a comprehensive assessment of each applicant's skills, and potential fit within our organisation.
The selection process for this role will be:
Stage 1: Sift of CV and personal statement
Stage 2: Interview
You must be successful at each stage to progress to the next stage.
Stage 1: Sift
At sift, you will be assessed against the following Success Profile elements:
Experience you will be asked to provide a CV (unlimited wordcount) and personal statement (1250-word count). Please provide evidence of your Experience of the following:
-
Extensive experience in working on information security programmes in an organisation, ideally in an area that has low tolerance for service disruption or incidents, preferably with experience of working in mission critical environments.
-
Experience of leading security cultural change within a complex organisation
-
Experience of developing and implementing a pragmatic approach to assessing the security, privacy and resilience risks, including engaging stakeholders to create shared understanding of the risks.
-
Experience of providing effective advice on compliance issues,
Should a large number of applications be received, an initial sift may be conducted using the lead Success Profile element, Extensive experience in working on information security programmes in an organisation, ideally in an area that has low tolerance for service disruption or incidents, preferably with experience of working in mission critical environments. Candidates who pass the initial sift may be progressed to a full sift or progressed straight to assessment/interview.
Please note: the sift will be completed on a rolling basis whilst the campaign is still live, so you may receive your sift scores before the advert closing date.
The sift will take place week commencing 08/06/2026
Stage2: Interview
At interview stage, you will be assessed against the following Success Profile elements:
Behaviours -
-
Leadership
-
Making Effective Decisions
-
Communicating and Influencing
-
Seeing the Big Picture
Technical -
Cyber Security Governance & Risk Management - Principal
-
Information Risk Assessment and Risk Management Expert
-
Applied Security Capability Practitioner
-
Protective Security Expert
-
Threat Understanding Practitioner
Cyber Security Audit & Assurance - Principal
-
Risk Understanding and Mitigation Practitioner
-
Legal and Regulatory Environment and Compliance Practitioner
You will also be required to create and deliver a presentation to assess the Behaviour: Communicating and Influencing and Technical: Information Risk Assessment and Risk Management Expert, and Technical: Risk Understanding and Mitigation Practitioner. Guidance will be provided if you are invited to interview.
The interviews will take place week commencing 22/06/2026.
This interview will be conducted in person at our Southampton office (Spring Place, 105 Commercial Road, Southampton, SO15 1EG). Further details will be provided to you should you be selected for interview.
You can find out more about our hiring process, how to apply, and application and interview guidance on our careers site .
Please note that we will try to meet the dates set out in the advert. There may be occasions when these dates will change.
Further information on the selection process
We will also hold a 12 month reserve list for this role, which may lead to potential opportunities beyond the role you applied for. You can read more about our reserve lists here.
Appointments for this position will be made in order of merit. If you are successful in the selection process but there are no further available posts for the advertised role, you may be contacted to discuss an offer for a lower graded role (with similar experience and responsibility requirements).
If you are unsuccessful in the selection process, your application may be considered for a lower graded position if your demonstrated skills and experience meet the requirements of the alternative position. Candidates will be considered in order of merit.
Further Information
For more information about how we hire, and for useful tips on submitting your application for this role, visit the How We Hire page of our DfT Careers website. You can find detailed information about the recruitment process and what to expect when applying for a role.
If your application is successful but you have been dismissed from the Civil Service, your application could be removed at the pre-employment checking stage depending on the nature of the dismissal.
Pre-employment Checking
Applicants who are successful at interview will be, as part of pre-employment screening, subject to a check on the Internal Fraud Database (IFD). This check will provide information about employees who have been dismissed for fraud or dishonesty offences. This check also applies to employees who resign or otherwise leave before being dismissed for fraud or dishonesty had their employment continued. Any applicants details held on the IFD will be refused employment.
A candidate is not eligible to apply for a role within the Civil Service if the application is made within a 5-year period following a dismissal for carrying out internal fraud against government.
All External applicants and current employees of accredited non-departmental public bodies (NDPBs) will be required to undergo a Social Media Check. A Social Media Check is a review of your publicly available online activity, typically across platforms like LinkedIn, Facebook, X (formerly Twitter), Instagram, and others. The purpose is to identify any public posts or content that could raise concerns for employers, such as:
Hate speech or discriminatory behaviour
Threats or acts of violence
Illegal activity or substance misuse
Sexually explicit material
Extremist views or affiliations
Importantly, this check does not involve hacking into your accounts or accessing private messages. It only considers content you have chosen to make public.
Employers use this kind of screening to help ensure their workplace remains safe, inclusive, and aligned with company values. Its not about judging your personality or lifestyleits about checking for potential red flags that might affect the role or company culture.
If you have questions or concerns about the social media check, we would be happy to explain in more detail whats being looked at and how your data is handled securely and fairly.
Feedback will only be provided if you attend an interview or assessment.