

Search by job, company or skills

Job Overview:
This role aligns to industry-level title such as Business Information Security Officer (BISO), is a leadership role focused on providing security guidance to the whole of Pearson. This individual serves as the primary security leader and strategic partner for the assigned Business Unit(s), ensuring cybersecurity is integrated into divisional operations, product delivery, and customer trust.
BISOS are trusted technical leads, regularly delivering complex tasks, leading vulnerability management efforts, and ensuring security architecture is executed to high standards. They are points of contact for teams requiring in-depth guidance on responding to incidents or remediating problematic findings. While acting as technical mentors, their primary attention is on ensuring controls are applied effectively, compliance checks are accurate, and projects achieve desired outcomes with minimal risk. Typical activities involve supporting project planning, drafting incident case reports, and recommending process improvements based on identified trends. Risk at this stage centers on incomplete application of controls or misunderstanding root causes, which could delay remediation or allow issues to persist unnoticed.
This role is responsible for shaping divisional security governance, managing risk, and driving security initiatives that enable innovation while protecting Pearson's global testing and assessment platform. The BISO will directly engage with Business Unit (BU) leadership and technology teams, while also collaborating with enterprise security and business stakeholders to ensure seamless alignment.
Key Responsibilities:
Strategic Leadership & Business Partnership
Governance & Alignment
Risk Management
Security Change Leadership
Collaboration & Stakeholder Engagement
Metrics & Reporting
Education:
Experience:
Skills:
Key Attributes:
Who we are:
At Pearson, our purpose is simple: to help people realize the life they imagine through learning. We believe that every learning opportunity is a chance for a personal breakthrough. We are the world's lifelong learning company. For us, learning isn't just what we do. It's who we are. To learn more: We are Pearson.
Pearson is an Equal Opportunity Employer and a member of E-Verify. Employment decisions are based on qualifications, merit and business need. Qualified applicants will receive consideration for employment without regard to race, ethnicity, color, religion, sex, sexual orientation, gender identity, gender expression, age, national origin, protected veteran status, disability status or any other group protected by law. We actively seek qualified candidates who are protected veterans and individuals with disabilities as defined under VEVRAA and Section 503 of the Rehabilitation Act.
If you are an individual with a disability and are unable or limited in your ability to use or access our career site as a result of your disability, you may request reasonable accommodations by emailing [Confidential Information].
Job: Security
Job Family: TECHNOLOGY
Organization: Corporate Strategy & Technology
Schedule: FULL_TIME
Workplace Type: Hybrid
Req ID: 22766
Job ID: 147039157
Skills:
threat modeling , Pki, Security Testing, Vulnerability Assessments, risk assessments, DevSecOps practices, secure communications, key management, Security Architecture, cybersecurity controls, cryptographic technologies, cybersecurity frameworks, ISO IEC 27001, secure boot, security analyses, NIST 800-53, secure product development processes, certificate lifecycle management, IEC 62443, NIST Cybersecurity Framework, security risk assessment methodologies
Skills:
DevSecOps, Cloud Security, Network Security, Secure software supply chain, SOC SIEM SOAR and threat detection architectures, Cloud-native security platforms, Data Protection Encryption, Zero Trust Architecture, AI ML and GenAI security risks controls and governance requirements, Application API Security
Skills:
Application Security, Data Protection, Encryption, Cloud Security, Bid governance, Proposal planning and coordination, SIEM platforms, RFP RFI RFQ management, Bid Management, Compliance matrix preparation, Commercial coordination, Security Testing methodologies
Skills:
risk governance , Information Security, Operating Model, Business Advisory, AI Risk, Regulatory Awareness, Stakeholder Management
Skills:
Vulnerability Management, Cloud Security, Soc, Threat Hunting, Siem, Security Architecture, Threat intel, EDR, cybersecurity technology solutions, Security advisory, SOAR platform, Pen testing