Principal Governance and Risk Manager
Department for Transport · Birmingham, England
Principal Governance and Risk Manager at Department for Transport, based in Birmingham, England, paying £57,515 - £82,430 per annum. This is a permanent role.
- Salary
- £57,515 - £82,430 per annum
- Location
- Birmingham, England
- Contract
- Permanent
- Posted
- 1 day ago
- Closes
- 13 Oct 2026
- Sector
- Security
About 19% above the going rate for security
Reference 987a61eb2e9bfd05d855deb82625b3d7b0caaa35
About the role
Job summary
Are you passionate about helping organisations understand, manage and reduce risk?
Can you influence senior decision-making through expert risk analysis?
Do you have the expertise to lead governance and risk management activities in complex environments?
If so, we’d love to hear from you!
This is an exciting time to join the Digital, Information and Security Directorate within the Department for Transport as we restructure our directorate to ensure we are ready for future challenges, building a more sustainable, skilled and in-house capability.
Reduce risk. Strengthen governance. Enable confident decisions.
Lead risk management activities that help the Department for Transport understand emerging threats, improve resilience, and make risk-based decisions that keep our critical services and information secure.
Joining our department comes with many benefits, including:
- Employer pension contribution of 28.97% of your salary. Read more about Civil Service Pensions here
- 25 days annual leave, increasing by 1 day each year of service (up to a maximum of 30 days annual leave), plus 8 bank holidays a privilege day for the King’s birthday
- Flexible working options where we encourage a great work-life balance.
Read more in the Benefits section below!
Find out more about what it's like working at Department for Transport Central - Department for Transport Careers.
Job description
Join the Department for Transport's Digital, Information and Security Directorate and play a leading role in shaping how risks are managed across the Directorate and wider group. As a Principal Governance & Risk Manager, you will help strengthen risk management arrangements that support informed decision-making and organisational resilience.
Working within the Assurance, Compliance and Controls function, you'll develop and implement a risk management framework across Digital, Information and Security, ensuring risks are identified, assessed, monitored and reported effectively. You'll work closely with risk owners, senior stakeholders and assurance teams to provide expert advice on risk management strategies, drive continuous improvement and embed best practice across the organisation.
You'll analyse complex risks, oversee governance processes and provide clear, evidence-based reporting that supports strategic decision-making. Alongside this, you'll champion risk management and develop capability across teams, building strong relationships with stakeholders across the wider DfT Group.
This is an excellent opportunity for an experienced risk professional who enjoys influencing change, solving complex problems and helping organisations navigate uncertainty with confidence.
Your responsibilities will include, but aren’t limited to:
- Developing and implementing the risk management framework within the Directorate in line with existing corporate governance arrangements.
- Leading and undertaking risk management activities while applying the fundamental principles of risk management to a range of complex scenarios
- Promoting risk management and the development of applicable skills, providing leadership to risk managers and sharing best practice.
- Leading risk assessments and providing expert advice on risk management strategies.
- Developing risk reporting mechanisms to support governance arrangements within the Directorate and across the group.
For further information on the role, please read the role profile. Please note that the role profile is for information purposes only - whilst all elements are relevant to the role, they may not all be assessed during the recruitment process. This job advert will detail exactly what will be assessed during the recruitment process.
Person specification
To be successful in this role you will need to have the following experience:
- Essential Sift Criteria - Industry-recognised qualification in risk management is essential (e.g. Management of Risk Practitioner or similar).
- Experience of working within the field of protective security and/or information governance.
- Experience of having implemented a risk management framework within a large, complex organisation.
- Knowledge of relevant standards and assurance frameworks such as ISO 27001, NCSC’s Cyber Assessment Framework and Government Security Functional Standard GovS007.
- Experience of developing effective relationships and influencing a wide range of stakeholders to reduce risk.
Additional information
The role is part of the Government Security Profession Career Framework and utilises an enhanced Capability–Based Pay Framework which provides access to a Digital and Data allowance.
The base pay is £57,515. In addition to this the role includes a Digital and Data allowance of up to £24,915.
The value of allowance awarded will be based on an assessment of your skills and experience as demonstrated through the selection process. Here are more details on the pay framework.
Working hours, office attendance and travel requirements
Full time roles consist of 37 hours per week.
Whilst we welcome applications from those looking to work with us on a part time basis, there is a business requirement for the successful candidate to be able to work at least 32 hours per week.
Occasional travel to other offices will be required, which may involve overnight stays.
This role is suitable for hybrid working, which is a non-contractual arrangement where a combination of workplace and home-based working can be accommodated subject to business requirements.
The expectation at present is a minimum of 60% of your working time a month will be spent at either your designated workplace (one of the locations cited in the advert) or, when required for business reasons, in another office/work location/visiting stakeholders. Your designated workplace will be your contractual place of work. There may be occasions where you are required to attend above the minimum expectation.
If you have a question about hybrid working, part time/job share hours, flexible working, travelling for work, or require a reasonable adjustment, please contact the Vacancy Holder during the recruitment process to avoid possible disappointment later in the process should your working arrangements not be compatible with the requirements of the role (see below for contact details).
Visa Sponsorship
DfTc does not offer Visa Sponsorship for this role.
Behaviours
We'll assess you against these behaviours during the selection process:
- Communicating and Influencing
- Making Effective Decisions
- Leadership
- Managing a Quality Service
Technical skills
We'll assess you against these technical skills during the selection process:
Reference: 987a61eb2e9bfd05d855deb82625b3d7b0caaa35 · Posted 1 day ago · Closes 13 Oct 2026 · Listed via Department for Transport
Apply for this job
This role is listed via Department for Transport. Applications are handled on the employer's site.
Apply on employer siteOpens the employer's website in a new tab.
Safe applying: a genuine employer will never ask you to pay for a DBS check, training or equipment, or move you onto WhatsApp before you are hired. If this listing does, report it and do not pay anything.