Job Title: Advanced Specialist, Security Engineer
About the Role:
The BU Security Engineering Lead is a security-skilled technology professional who
reports to the BU/function's Designated Risk Owner (DRO), with a dotted-line
alignment to central Security to maintain consistency with enterprise security strategy,
standards and priorities. The role is accountable for improving the BU/function's
security outcomes and achieving agreed security objectives and metrics, working
closely with GRC, Security Architecture and other central Security capabilities.
The role combines security expertise, technical leadership, engineering thinking, data-
driven problem solving and strong business understanding. The Security Engineering
Lead is part of the BU technology organisation, identifying security weaknesses,
understanding their root causes and delivering practical solutions that measurably
reduce security risk.
The role is accountable for improving the BU/function's security outcomes and
achieving agreed security objectives and metrics.
What You'll Do
- Own improvement in BU security outcomes
- Take accountability for achieving agreed security objectives, targets and metrics for the BU/function.
- Establish a clear understanding of the BU's current security performance, key exposures and areas of greatest risk.
- Use security data, trends and analysis to identify priorities and opportunities for improvement.
- Develop and execute plans to improve security performance and reduce measurable risk.
- Identify systemic issues and drive sustainable improvements rather than repeatedly addressing individual findings.
- Drive remediation of security risk
- Vulnerability and patch management
- End-of-life/end-of-support technology
- Privileged access management and reviews
- Security control implementation
- Security configuration and hardening
- Security remediation backlogs
- Recurring security findings
- Other BU-specific security priorities
- The role is expected to understand why a metric is poor and determine what needs to change to improve it.
- This may include process changes, technology changes, automation, data improvements, changes to ownership or escalation to senior leadership.
- Apply engineering thinking to security problems Use engineering principles to solve security problems at scale. Identify opportunities to automate repetitive security activities and controls. Use available security and technology data to identify patterns, root causes and opportunities for intervention. Work with engineering and technology teams to design practical solutions. Challenge approaches that rely primarily on manual activity, repeated chasing or temporary remediation. Help establish measurable, sustainable controls rather than one-off compliance exercises.
- Embed security into technology delivery Act as the BU's security subject matter expert within technology teams. Participate in relevant technology planning, architecture and delivery activity. Identify security requirements early in the technology lifecycle. Help teams interpret and apply Security policies, standards and control requirements. Identify when specialist Security Architecture or other central expertise is required and bring it into the work at the appropriate point. Promote secure‑by‑design engineering practices.
- Use data to drive decisions Establish reliable views of BU security performance. Analyse security data to identify trends, root causes and priority areas. Challenge inaccurate, incomplete or misleading security data. Translate security data into actionable priorities for technology leadership. Measure whether interventions have actually improved the security outcome. Provide transparent reporting to the DRO and relevant governance forums. The role should be evidence‑led rather than activity‑led: success is demonstrated through improved security outcomes, not the volume of meetings, communications or assessments completed.
- Risk management and escalation Provide the DRO with a clear view of current security exposure and material changes in risk. Identify risks requiring escalation, remediation investment or formal risk acceptance. Support the DRO in understanding the potential business and technology impact of security risks. Ensure material security issues are escalated promptly and accurately. Work with GRC to ensure risks, controls and remediation activity are appropriately recorded and evidenced. The Security Engineering Lead does not replace the DRO's accountability for risk; they provide the expertise, insight and delivery focus required to improve the risk position.
- Build security capability within the BU Develop security awareness and capability within technology teams. Coach engineers and technology leaders on practical application of security requirements. Encourage technology teams to take increasing ownership of security within their services. Share successful engineering approaches and lessons learned across the wider Security community. Contribute to a culture in which security is treated as part of good technology engineering rather than a separate compliance activity.
Key Relationships
BU / Function DRO
The role reports to and works closely with the DRO.
The DRO remains accountable for the BU/function's risk. The Security Engineering Lead is accountable for achieving agreed security outcomes and providing the DRO with the expertise, insight and delivery focus required to improve those outcomes.
Technology Leadership and Engineering Teams
The role operates as part of the BU technology organisation and works directly with engineering, infrastructure, application, identity and other technology teams to deliver improved security outcomes.
GRC
Works with GRC to:
- understand applicable policies, standards and control requirements;
- provide evidence of security performance and remediation;
- identify and elevate material risks;
- support independent governance and assurance; and
- maintain consistency of security expectations across the organisation.
GRC provides the independent governance and challenge function; the Security Engineering Lead is focused on improving the BU's actual security outcomes.
Security Architecture
Works with Security Architecture where specialist expertise, design authority or complex security decisions are required.
Wider Security Function
Participates in the Security community, sharing knowledge, patterns, data and successful solutions while retaining primary accountability for the BU's agreed outcomes.
What You Bring
Essential
- Significant experience in technology, engineering, cyber security or a closely related discipline.
- Strong understanding of practical cyber security controls and technology risk.
- Demonstrable experience working directly with technology and engineering teams.
- Ability to understand security standards and translate them into practical technical outcomes.
- Strong analytical and data‑driven problem‑solving skills.
- Experience improving measurable operational or technology outcomes.
- Ability to understand complex technical environments and identify root causes of security problems.
- Strong stakeholder management and influencing skills.
- Ability to challenge constructively and climb when required.
- Comfortable working with ambiguity and determining practical solutions rather than simply identifying problems.
Desirable
- Engineering, software development, infrastructure or architecture background.
- Experience with vulnerability/patch management, IAM/PAM, cloud security or security operations.
- Experience automating security processes or controls.
- Experience working within regulated or highly controlled environments.
- Relevant professional security qualifications or equivalent practical experience.
Behaviours
- Think like an engineer. They look for root causes, scalable solutions and ways to make security better through technology and process.
- Act like part of the business. They understand commercial and operational priorities and find ways to improve security without treating the BU as an external customer.
- Own outcomes. They don't stop at identifying a problem. They stay focused on getting the outcome changed.
- Use evidence. They rely on accurate data and are prepared to challenge assumptions, including when the data is uncomfortable.
- Be pragmatic. They understand that perfect security is not the objective; materially reducing risk and improving resilience is.
- Know when to collaborate. They don't try to be the expert in everything. They bring in GRC, Architecture or other specialists when appropriate.
- Build capability, not dependency. They leave the technology organisation stronger and more capable of managing security itself.
Measures of Success
- Improvement against agreed vulnerability and patching targets
- Reduction in EOL/EOS exposure
- Improvement in privileged access review performance
- Reduction in security remediation backlog and ageing
- Reduction in recurring security findings
- Improvement in security control effectiveness
- Increased adoption of secure‑by‑design practices
- Increased automation of security controls and processes
- Improved quality and reliability of security data
- Timely and appropriate escalation of material security risks
- Demonstrable reduction in the BU's overall security exposure
The role is not measured primarily by the amount of security activity performed. The measure is whether the BU becomes measurably more secure.
What Makes This Role Different
This role is intentionally designed as an embedded security engineering capability rather than a traditional advisory BISO role.
The individual is part of the BU, understands its technology environment, works directly with its engineers and leaders, and is accountable for improving agreed security outcomes.
Unlike traditional advisory security roles, the Security Engineering Lead is expected to influence, coordinate and drive remediation activity through the BU technology organisation until agreed outcomes are achieved.
The role therefore sits at the intersection of:
Security expertise + Technology engineering + Data + Business accountability
Its success is demonstrated by what changes in the BU - not simply by what the Security function reports about it.
Why Pearson?
This role represents a significant shift in how security is delivered across Pearson.
Rather than operating as a central advisory function, the Security Engineering Lead is embedded within the business and accountable for driving measurable improvements in security outcomes where risk is created and managed.
The role provides the opportunity to work directly with technology leaders, engineers and business stakeholders to solve real security problems, improve resilience and reduce risk at scale.
Success is measured through better security outcomes, stronger technology practices and a demonstrably more secure business.
As Pearson continues to strengthen its security capabilities, this role offers the opportunity to influence technology decisions, improve security performance across critical services, and help establish a model in which security is treated as an integral part of good technology engineering rather than a separate compliance activity.
Who we are:
At Pearson, our purpose is simple: to help people realize the life they imagine through learning. We believe that every learning opportunity is a chance for a personal breakthrough. We are the world's lifelong learning company. For us, learning isn't just what we do. It's who we are. To learn more: We are Pearson.
Pearson is an Equal Opportunity Employer and a member of E-Verify. Employment decisions are based on qualifications, merit and business need. Qualified applicants will receive consideration for employment without regard to race, ethnicity, color, religion, sex, sexual orientation, gender identity, gender expression, age, national origin, protected veteran status, disability status or any other group protected by law. We actively seek qualified candidates who are protected veterans and individuals with disabilities as defined under VEVRAA and Section 503 of the Rehabilitation Act.
If you are an individual with a disability and are unable or limited in your ability to use or access our career site as a result of your disability, you may request reasonable accommodations by emailing TalentExperienceGlobalTeam@grp.pearson.com.
Job: Engineering
Job Family: TECHNOLOGY
Organization: OCTO
Schedule: FULL\_TIME
Workplace Type: Hybrid
Req ID: 26169