Lead, Information Security

Lead, Information Security

Full-Time 69750 - 85250 £ / year (est.) Home office (partial)
Pearson

At a Glance

  • Tasks: Lead the development of Pearson's Operational Resilience capability and ensure critical services remain operational.
  • Company: Join Pearson, a global leader in lifelong learning and innovation.
  • Benefits: Hybrid work model, competitive salary, and opportunities for professional growth.
  • Other info: Be part of a dynamic team driving change in a complex global environment.
  • Why this job: Shape the future of resilience at Pearson and make a real impact.
  • Qualifications: Experience in operational resilience, crisis management, and strong leadership skills required.

The predicted salary is between 69750 - 85250 £ per year.

Build resilience into the way Pearson operates. Define what must keep running. Give leaders confidence in disruption.

Pearson is seeking a Principle, Information Security - Operational Resilience to establish and lead its central Operational Resilience capability. This is a highly visible enterprise role responsible for defining the framework, governance, and operating rhythm needed to sustain Pearson's most critical services through major disruption. The role will lead the development of the Minimum Viable Company approach, set standards for planning and exercising, coordinate activity across business and technology teams, and provide executives with credible, evidence-based assurance on resilience readiness.

The ideal candidate will be an experienced resilience, continuity, or risk leader who can bring structure to an evolving environment, navigate complexity with confidence, and influence across a large matrixed organisation. This role requires someone who can translate resilience concepts into practical operating requirements, align business, technology, cyber, supplier, and crisis stakeholders, and establish a capability that is credible to senior leadership and practical for operational teams.

Pearson Leadership Dimensions

As a senior leader at Pearson, you will be expected to embody and role model our leadership dimensions. You will align the resilience capability to Pearson's purpose and strategy, simplify complexity into clear operational priorities, build a collaborative and high-performing culture, and deliver measurable results. This role requires visible leadership, sound judgement in ambiguity, and the ability to bring people together across business, technology, risk, and security around a shared understanding of what matters most in disruption.

What You'll Do

  • Strategic leadership and transformation
    • Define and own the long-term vision, strategy, and implementation roadmap for Operational Resilience at Pearson, moving the organisation from fragmented planning to a credible enterprise capability with clear standards, effective governance, and demonstrable readiness.
    • Translate resilience concepts into a practical operating model for a complex global business, creating clarity on critical services, minimum acceptable service levels, prioritisation, tolerances, and recovery sequencing.
    • Act as a senior subject matter leader for operational resilience and continuity, bringing thought leadership, external awareness, and disciplined execution to how Pearson matures its capability.
    • Lead a shift in how Pearson approaches resilience by moving the focus from document collection alone to service-level understanding, tested recovery capability, decision-useful data, and practical executive assurance.
  • Framework, governance, and Minimum Viable Company
    • Own and maintain Pearson's enterprise operational resilience framework, associated standards, policy requirements, templates, governance forums, and reporting mechanisms needed to run the capability effectively and consistently.
    • Lead the development and ongoing refinement of Pearson's Minimum Viable Company approach, ensuring the organisation can articulate the minimum operating state required to continue safely, legally, and sustainably through severe disruption.
    • Define and oversee the methodology for identifying critical services, important processes, recovery priorities, and service tolerances, including the relationship between business requirements, technology recovery, supplier dependencies, and crisis decision-making.
    • Ensure resilience requirements are governed in a proportionate, practical, and auditable way, with clear accountability for plan ownership, review cycles, evidence retention, remediation tracking, and executive escalation.
  • Planning, exercising, and assurance
    • Oversee the creation, refresh, quality, and maintenance of continuity and resilience plans across the enterprise, ensuring they are aligned to service priorities and usable in practice rather than static documentation.
    • Design and lead a structured annual exercise and testing programme, including tabletop simulations, targeted service-level recovery tests, cross-functional scenario walkthroughs, and lessons-learned reviews.
    • Translate testing into measurable assurance by tracking outcomes, remediation actions, residual risks, and evidence that recovery assumptions have been validated for leadership and audit purposes.
    • Provide regular executive reporting on resilience maturity, plan coverage, testing progress, critical dependency risks, unresolved issues, and overall readiness, ensuring leaders receive decision-useful insight rather than disconnected metrics.
  • Cross-functional leadership and operating model
    • Work across business divisions, enterprise risk, technology, cyber, supplier management, internal audit, and crisis management to build a coherent end-to-end approach to resilience that clarifies ownership and reduces fragmentation.
    • Act as the central point of leadership for divisional continuity leads and plan owners, creating a sustainable operating rhythm of governance forums, reviews, escalation paths, management information, and follow-up actions.
    • Ensure the Operational Resilience capability complements and strengthens adjacent disciplines such as IT disaster recovery, cyber incident response, crisis management, enterprise risk, and third-party resilience, with clear boundaries that avoid duplication.
    • Influence senior stakeholders across a matrixed global organisation, balancing pragmatism with rigour while driving accountability for resilience activity that often sits outside direct reporting lines.
  • People and organisation
    • Establish and lead a small but high-impact central Operational Resilience team, setting direction, priorities, ways of working, and performance expectations for a function intended to grow in credibility and maturity over time.
    • Build a culture of practical resilience, collaboration, and accountability by coaching team members and business stakeholders to focus on usable plans, evidence-based readiness, and continuous improvement rather than compliance alone.
    • Support workforce planning, role design, onboarding, development, and capability building for the resilience function, creating clear expectations for specialist, analyst, and divisional continuity lead roles.
    • Create an operating rhythm that supports both UK and US time zones, enabling the central team to work effectively with distributed stakeholders across Pearson's global environment.

What You Bring

  • Significant experience leading operational resilience, business continuity, disaster recovery, crisis management, or a closely related enterprise resilience function in a complex global organisation.
  • Demonstrated ability to build frameworks, governance models, and cross-functional programmes that depend on influence rather than direct control, particularly in matrixed environments with multiple stakeholder groups.
  • Deep experience with business impact analysis, critical service identification, dependency mapping, service tolerances, scenario testing, continuity planning, and resilience or recovery assurance.
  • Strong understanding of the relationship between business continuity, IT disaster recovery, cyber resilience, supplier resilience, enterprise risk, audit, and crisis management, with the judgement to define clear boundaries between them.
  • Experience building or maturing capabilities, introducing standards, and creating sustainable governance, reporting, and assurance mechanisms that stand up to executive and audit scrutiny.
  • Strong analytical and reporting capability, with experience translating resilience data, interdependencies, and complex risks into clear executive insight and action-oriented management information.
  • Excellent stakeholder management, communication, and influencing skills, with the ability to work credibly with senior leaders, operational teams, and control functions across a large matrixed organisation.
  • Experience leading teams, developing specialist capability, and building a culture of accountability, clarity, and practical delivery in a new or evolving enterprise function.
  • Comfort working with ambiguity and complexity, with the resilience and judgement needed to make balanced, risk-aware decisions in areas where standards are still developing.
  • Relevant qualifications in business continuity, resilience, risk, or security would be advantageous, for example CBCI, CBCP, DRI, ISO 22301-related training, or equivalent practical experience.

Why Pearson?

This is an opportunity to build a genuinely important enterprise capability at a pivotal stage in Pearson's resilience maturity. As Pearson becomes more dependent on digital services, shared platforms, suppliers, coordinated recovery, and credible assurance, the need for a clear and effective operational resilience capability is increasing. The organisation is still early in its maturity journey, which makes this role both challenging and unusually high impact.

This role offers the chance to shape how Pearson defines what must keep running, how it prioritises during disruption, and how it gives leaders confidence that critical services can be sustained and recovered in a controlled way. It is a rare opportunity to create lasting structure, influence enterprise decision-making, and establish a capability with visibility across leadership, risk, technology, security, and the wider business.

Who we are:

At Pearson, our purpose is simple: to help people realize the life they imagine through learning. We believe that every learning opportunity is a chance for a personal breakthrough. We are the world's lifelong learning company. For us, learning isn't just what we do. It's who we are. To learn more: We are Pearson.

Pearson is an Equal Opportunity Employer and a member of E-Verify. Employment decisions are based on qualifications, merit and business need. Qualified applicants will receive consideration for employment without regard to race, ethnicity, color, religion, sex, sexual orientation, gender identity, gender expression, age, national origin, protected veteran status, disability status or any other group protected by law. We actively seek qualified candidates who are protected veterans and individuals with disabilities as defined under VEVRAA and Section 503 of the Rehabilitation Act.

If you are an individual with a disability and are unable or limited in your ability to use or access our career site as a result of your disability, you may request reasonable accommodations by emailing TalentExperienceGlobalTeam@grp.pearson.com.

Lead, Information Security employer: Pearson

Pearson is an excellent employer that values flexibility and a supportive work culture, making it an ideal place for those seeking part-time opportunities in Birmingham. With a commitment to employee growth, Pearson offers training and development resources, ensuring that staff can enhance their skills while contributing to a meaningful mission of education and assessment. The friendly atmosphere and focus on compliance create a rewarding environment for Test Centre Administrators who enjoy helping candidates succeed.

Pearson

Contact Details:

Pearson Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land Lead, Information Security

Get Involved in the Cybersecurity Community

Diving into the cybersecurity community is key for landing that full-time gig. Join forums like Reddit's r/cybersecurity or attend local meetups to connect with industry veterans and other job seekers. Networking is everything in this field—don’t just be a passive lurker!

Show Off Your Skills with Capture the Flag Competitions

Participate in Capture the Flag (CTF) competitions; these are not just a fun way to boost your skills but also a chance to showcase your talent to potential employers. Many companies, including Pearson, love seeing candidates who actively engage in these challenges.

Tailor Your Online Presence

Make sure your LinkedIn and any professional profiles reflect your cybersecurity expertise. Share your projects, whether they’re personal or from a previous role, to catch the eye of hiring managers. This is how they’ll find your passion and commitment to the field!

Apply Directly Through Pearson

Don’t forget to head straight to our website and check out any openings for cybersecurity roles at Pearson. Applying directly can sometimes give you an edge, especially if you can mention that you've been following our work or engaging in the community.

We think you need these skills to ace Lead, Information Security

Operational Resilience
Business Continuity
Crisis Management
Governance Frameworks
Stakeholder Management
Analytical Skills
Communication Skills

Some tips for your application 🫡

Show off your technical skills:In cybersecurity, it's crucial to highlight your technical prowess. Make sure your CV showcases specific skills like network security, penetration testing, or threat analysis. If you have relevant certifications (like CEH or CISSP), pop those on the front page to grab attention!

Tailor your portfolio for the role:Even for a full-time role, a portfolio can set you apart. If you've worked on any cybersecurity projects—be it CTF challenges, security assessments, or research papers—include these in your application. This demonstrates not just your skills, but also your hands-on experience!

Use real-world examples:When writing your cover letter, don’t just stick to your qualifications. Share real-world examples of how you’ve tackled security issues or vulnerabilities. This gives the hiring team at Pearson insight into your practical problem-solving abilities and makes your application memorable.

Demonstrate your passion for cybersecurity:Cybersecurity is an ever-evolving field, so show us that you’re always learning! Mention any recent courses, webinars, or industry events you’ve attended. This not only exhibits your enthusiasm but also signals to Pearson that you’re committed to staying ahead in the game.

How to prepare for a job interview at Pearson

Sharpen Your Technical Skills

For a role in cybersecurity, it’s essential to be up-to-date with the latest tools and techniques. Brush up on your knowledge of firewalls, intrusion detection systems, and vulnerability assessment tools. Be ready to discuss specific scenarios where you’ve applied these skills, as hands-on experience can really set us apart in interviews.

Prepare for Scenario-Based Questions

Expect the interviewers at Pearson to throw in some hypothetical situations to see how you’d handle them. Think about common security breaches or incidents and be prepared to explain how you would respond. This not only shows your problem-solving skills but also your understanding of real-world cybersecurity challenges.

Highlight Your Certifications

Certifications like CompTIA Security+, CISSP, or CEH can give you a significant edge in a full-time role in cybersecurity. Make sure to mention these during your interview and be prepared to discuss what you learned through those certifications and how they relate to the position at Pearson.

Show Your Passion for Cybersecurity

Since you’re going for a full-time gig, showing genuine enthusiasm for the field can make all the difference. Share any personal projects, blogs, or communities you’re part of that relate to cybersecurity. This not only showcases your passion but also your commitment to staying engaged in this ever-evolving field.