{"id":1956767,"url":"https://alion.io/job/pearson-advanced-specialist-security-engineer","title":"Advanced Specialist, Security Engineer","company":{"id":34029,"name":"Pearson","domain":"pearson.com","url":"https://alion.io/company/pearson","size_band":"1001-5000","is_staffing_agency":false,"employer_type":"direct","is_intermediary":false,"listed_via":null,"ats_vendor":"Oracle","truth_index":{"grade":"B","score":80,"open_postings":15,"ghost_share":0,"stale_share":0.8,"repost_share":0,"time_to_fill_p50_days":38,"computed_at":"2026-10-07T05:47:15Z"}},"role":"Security","role_family":"Security","seniority":null,"employment_type":null,"work_mode":"on_site","remote_scope":null,"remote_scope_basis":null,"remote_working_hours":null,"hiring_geo_confidence":"structured","locations":["London, United Kingdom"],"countries":["GB"],"hiring_countries":[],"hiring_countries_total":0,"salary":null,"salary_estimate":{"min_usd":62000,"max_usd":137000,"period":"year","method":"role_country_seniority_unknown","sample_n":108},"experience_years_min":null,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"IAM","optional":true}],"status":"live","first_seen_at":"2026-10-06T12:25:41Z","employer_posted_date":"2026-10-06","last_verified_at":"2026-10-08T01:02:45Z","board_verified":true,"closed_at":null,"days_open":1,"trust":{"level":"ok","repost_count":null,"flags":[],"days_open":1},"description":"Job Title: Advanced Specialist, Security Engineer\nAbout the Role:\nThe BU Security Engineering Lead is a security-skilled technology professional who\nreports to the BU/function's Designated Risk Owner (DRO), with a dotted-line\nalignment to central Security to maintain consistency with enterprise security strategy,\nstandards and priorities. The role is accountable for improving the BU/function's\nsecurity outcomes and achieving agreed security objectives and metrics, working\nclosely with GRC, Security Architecture and other central Security capabilities.\nThe role combines security expertise, technical leadership, engineering thinking, data-\ndriven problem solving and strong business understanding. The Security Engineering\nLead is part of the BU technology organisation, identifying security weaknesses,\nunderstanding their root causes and delivering practical solutions that measurably\nreduce security risk.\nThe role is accountable for improving the BU/function's security outcomes and\nachieving agreed security objectives and metrics.\nWhat You’ll Do\nOwn improvement in BU security outcomes\nTake accountability for achieving agreed security objectives, targets and metrics\nfor the BU/function.\nEstablish a clear understanding of the BU's current security performance, key\nexposures and areas of greatest risk.\nUse security data, trends and analysis to identify priorities and opportunities for\nimprovement.\nDevelop and execute plans to improve security performance and reduce\nmeasurable risk.\nDCL2 - Internal Use Only\nTrack progress against agreed objectives and intervene where performance is\nnot improving.\nIdentify systemic issues and drive sustainable improvements rather than\nrepeatedly addressing individual findings.\nDrive remediation of security risk\nWork directly with technology teams to improve performance against key security\noutcomes, including areas such as:\nVulnerability and patch management\nEnd-of-life/end-of-support technology\nPrivileged access management and reviews\nSecurity control implementation\nSecurity configuration and hardening\nSecurity remediation backlogs\nRecurring security findings\nOther BU-specific security priorities\nThe role is expected to understand why a metric is poor and determine what needs to\nchange to improve it.\nThis may include process changes, technology changes, automation, data\nimprovements, changes to ownership or escalation to senior leadership.\nApply engineering thinking to security problems\nUse engineering principles to solve security problems at scale.\nIdentify opportunities to automate repetitive security activities and controls.\nUse available security and technology data to identify patterns, root causes and\nopportunities for intervention.\nWork with engineering and technology teams to design practical solutions.\nChallenge approaches that rely primarily on manual activity, repeated chasing or\ntemporary remediation.\nHelp establish measurable, sustainable controls rather than one-off compliance\nexercises.\nEmbed security into technology delivery\nAct as the BU's security subject matter expert within technology teams.\nParticipate in relevant technology planning, architecture and delivery activity.\nIdentify security requirements early in the technology lifecycle.\nDCL2 - Internal Use Only\nHelp teams interpret and apply Security policies, standards and control\nrequirements.\nIdentify when specialist Security Architecture or other central expertise is\nrequired and bring it into the work at the appropriate point.\nPromote secure-by-design engineering practices.\nUse data to drive decisions\nEstablish reliable views of BU security performance.\nAnalyse security data to identify trends, root causes and priority areas.\nChallenge inaccurate, incomplete or misleading security data.\nTranslate security data into actionable priorities for technology leadership.\nMeasure whether interventions have actually improved the security outcome.\nProvide transparent reporting to the DRO and relevant governance forums.\nThe role should be evidence-led rather than activity-led: success is demonstrated\nthrough improved security outcomes, not the volume of meetings, communications or\nassessments completed.\nRisk management and escalation\nProvide the DRO with a clear view of current security exposure and material\nchanges in risk.\nIdentify risks requiring escalation, remediation investment or formal risk\nacceptance.\nSupport the DRO in understanding the potential business and technology impact\nof security risks.\nEnsure material security issues are escalated promptly and accurately.\nWork with GRC to ensure risks, controls and remediation activity are\nappropriately recorded and evidenced.\nThe Security Engineering Lead does not replace the DRO's accountability for risk; they\nprovide the expertise, insight and delivery focus required to improve the risk position.\nBuild security capability within the BU\nDevelop security awareness and capability within technology teams.\nCoach engineers and technology leaders on practical application of security\nrequirements.\nEncourage technology teams to take increasing ownership of security within\ntheir services.\nShare successful engineering approaches and lessons learned across the wider\nSecurity community.\nDCL2 - Internal Use Only\nContribute to a culture in which security is treated as part of good technology\nengineering rather than a separate compliance activity.\nKey Relationships\nBU / Function DRO\nThe role reports to and works closely with the DRO.\nThe DRO remains accountable for the BU/function's risk. The Security Engineering Lead\nis accountable for achieving agreed security outcomes and providing the DRO with the\nexpertise, insight and delivery focus required to improve those outcomes.\nTechnology Leadership and Engineering Teams\nThe role operates as part of the BU technology organisation and works directly with\nengineering, infrastructure, application, identity and other technology teams to deliver\nimproved security outcomes.\nGRC\nWorks with GRC to:\nunderstand applicable policies, standards and control requirements;\nprovide evidence of security performance and remediation;\nidentify and escalate material risks;\nsupport independent governance and assurance; and\nmaintain consistency of security expectations across the organisation.\nGRC provides the independent governance and challenge function; the Security\nEngineering Lead is focused on improving the BU's actual security outcomes.\nSecurity Architecture\nWorks with Security Architecture where specialist expertise, design authority or\ncomplex security decisions are required.\nDCL2 - Internal Use OnlyWider Security Function\nParticipates in the Security community, sharing knowledge, patterns, data and\nsuccessful solutions while retaining primary accountability for the BU's agreed\noutcomes.\nWhat You Bring\nEssential\nSignificant experience in technology, engineering, cyber security or a closely\nrelated discipline.\nStrong understanding of practical cyber security controls and technology risk.\nDemonstrable experience working directly with technology and engineering\nteams.\nAbility to understand security standards and translate them into practical\ntechnical outcomes.\nStrong analytical and data-driven problem-solving skills.\nExperience improving measurable operational or technology outcomes.\nAbility to understand complex technical environments and identify root causes\nof security problems.\nStrong stakeholder management and influencing skills.\nAbility to challenge constructively and escalate when required.\nComfortable working with ambiguity and determining practical solutions rather\nthan simply identifying problems.\nDesirable\nEngineering, software development, infrastructure or architecture background.\nExperience with vulnerability/patch management, IAM/PAM, cloud security or\nsecurity operations.\nExperience automating security processes or controls.\nExperience working within regulated or highly controlled environments.\nRelevant professional security qualifications or equivalent practical experience.\nBehaviours\nThe successful candidate will:\nDCL2 - Internal Use OnlyThink like an engineer.\nThey look for root causes, scalable solutions and ways to make security better through\ntechnology and process.\nAct like part of the business.\nThey understand commercial and operational priorities and find ways to improve\nsecurity without treating the BU as an external customer.\nOwn outcomes.\nThey don't stop at identifying a problem. They stay focused on getting the outcome\nchanged.\nUse evidence.\nThey rely on accurate data and are prepared to challenge assumptions, including when\nthe data is uncomfortable.\nBe pragmatic.\nThey understand that perfect security is not the objective; materially reducing risk and\nimproving resilience is.\nKnow when to collaborate.\nThey don't try to be the expert in everything. They bring in GRC, Architecture or other\nspecialists when appropriate.\nBuild capability, not dependency.\nThey leave the technology organisation stronger and more capable of managing\nsecurity itself.\nMeasures of Success\nSuccess will be measured primarily through improved security outcomes, for\nexample:\nImprovement against agreed vulnerability and patching targets\nReduction in EOL/EOS exposure\nImprovement in privileged access review performance\nReduction in security remediation backlog and ageing\nReduction in recurring security findings\nImprovement in security control effectiveness\nIncreased adoption of secure-by-design practices\nIncreased automation of security controls and processes\nDCL2 - Internal Use Only\nImproved quality and reliability of security data\nTimely and appropriate escalation of material security risks\nDemonstrable reduction in the BU's overall security exposure\nThe role is not measured primarily by the amount of security activity performed. The\nmeasure is whether the BU becomes measurably more secure.\nWhat Makes This Role Different\nThis role is intentionally designed as an embedded security engineering capability\nrather than a traditional advisory BISO role.\nThe individual is part of the BU, understands its technology environment, works directly\nwith its engineers and leaders, and is accountable for improving agreed security\noutcomes.\nUnlike traditional advisory security roles, the Security Engineering Lead is expected to\ninfluence, coordinate and drive remediation activity through the BU technology\norganisation until agreed outcomes are achieved.\nThe role therefore sits at the intersection of:\nSecurity expertise + Technology engineering + Data + Business accountability\nIts success is demonstrated by what changes in the BU - not simply by what the\nSecurity function reports about it.\nWhy Pearson?\nThis role represents a significant shift in how security is delivered across Pearson.\nRather than operating as a central advisory function, the Security Engineering Lead is embedded\nwithin the business and accountable for driving measurable improvements in security outcomes\nwhere risk is created and managed.\nThe role provides the opportunity to work directly with technology leaders, engineers and\nbusiness stakeholders to solve real security problems, improve resilience and reduce risk at scale.\nSuccess is measured through better security outcomes, stronger technology practices and a\ndemonstrably more secure business.\nDCL2 - Internal Use OnlyAs Pearson continues to strengthen its security capabilities, this role offers the opportunity to\ninfluence technology decisions, improve security performance across critical services, and help\nestablish a model in which security is treated as an integral part of good technology engineering\nrather than a separate compliance activity.\nDCL2 - Internal Use Only","description_format":"text","description_chars":11653,"description_truncated":false,"requirements":{"experience_years_min":null,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":null,"security_clearance":false,"languages":[]},"benefits":[],"hiring_locations":[],"hiring_excludes":[],"relocation_offered":false,"industries":["EdTech Platforms","Publishing","E-learning"],"lifecycle":[{"event":"open","at":"2026-10-06T13:20:05Z"}],"visa":[],"liveness":{"score":63,"band":"ok","label":"Likely open","p_open":1,"p_active":0.632,"p_room":1,"age_days":0,"expected_fill_days":38,"reasons":["conf:0","stale_co","velocity","win:early","comp:brand"],"computed_at":"2026-10-07T05:47:15Z"},"pay":null,"html_url":"https://alion.io/job/pearson-advanced-specialist-security-engineer","json_url":"https://alion.io/job/pearson-advanced-specialist-security-engineer.json","meta":{"generated_at":"2026-10-08T01:37:23Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","about":"Alion is a live layer of people, companies and AI agents: who they are, whether they are real and active right now, what they do and how to work with them, readable by people and by agents and paid per call.","catalog":"https://alion.io/catalog.json","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":2822,"day_limit":5000,"remaining_today":2178,"minute_limit":60,"resets_at":"2026-10-09T00:00:00Z"}},"offers":[{"id":"company.slices","title":"One company in depth, by slice","status":"live","price":{"credits":0.02,"usd":0.002,"plus_per_slice":{"credits":0.05,"usd":0.005}},"unit":"per company, plus each slice with data","note":"the employer in depth","call":{"mcp_tool":"get_company","arguments":{"id":34029},"rest":"https://alion.io/mcp/rest/get_company?id=34029"},"human":"https://alion.io/catalog?offer=company.slices&for=job%2Fpearson-advanced-specialist-security-engineer"},{"id":"market.stats","title":"A market slice: pay, demand and time to fill","status":"live","price":{"credits":1,"usd":0.1},"unit":"per slice","note":"pay, demand and time to fill for this role and place","call":{"mcp_tool":"market_stats"},"human":"https://alion.io/catalog?offer=market.stats&for=job%2Fpearson-advanced-specialist-security-engineer"},{"id":"job.search","title":"Open jobs by role, technology, place, pay and visa","status":"live","price":{"credits":0.02,"usd":0.002},"unit":"per posting in a list","note":"similar open postings","call":{"mcp_tool":"search_jobs"},"human":"https://alion.io/catalog?offer=job.search&for=job%2Fpearson-advanced-specialist-security-engineer"},{"id":"company.verify","title":"Is this company real and active right now","status":"pilot","price":null,"unit":"per company","request":{"url":"https://alion.io/catalog/request","method":"POST","body":"{\"offer\": \"company.verify\", \"for\": \"job/pearson-advanced-specialist-security-engineer\", \"note\": \"what you need it for\"}"},"human":"https://alion.io/catalog?offer=company.verify&for=job%2Fpearson-advanced-specialist-security-engineer"}]}