HC

Advanced Specialist, Security Engineer

Hiring from
United Kingdom
Work type
Hybrid
Posted
Is this job info correct?
Show job description

Job Title: Advanced Specialist, Security Engineer

About the Role:


The BU Security Engineering Lead is a security-skilled technology professional who

reports to the BU/function's Designated Risk Owner (DRO), with a dotted-line

alignment to central Security to maintain consistency with enterprise security strategy,

standards and priorities. The role is accountable for improving the BU/function's

security outcomes and achieving agreed security objectives and metrics, working

closely with GRC, Security Architecture and other central Security capabilities.

The role combines security expertise, technical leadership, engineering thinking, data-

driven problem solving and strong business understanding. The Security Engineering

Lead is part of the BU technology organisation, identifying security weaknesses,

understanding their root causes and delivering practical solutions that measurably

reduce security risk.

The role is accountable for improving the BU/function's security outcomes and

achieving agreed security objectives and metrics.

What You’ll Do

Own improvement in BU security outcomes

• Take accountability for achieving agreed security objectives, targets and metrics

for the BU/function.

• Establish a clear understanding of the BU's current security performance, key

exposures and areas of greatest risk.

• Use security data, trends and analysis to identify priorities and opportunities for

improvement.

• Develop and execute plans to improve security performance and reduce

measurable risk.

DCL2 - Internal Use Only• Track progress against agreed objectives and intervene where performance is

not improving.

• Identify systemic issues and drive sustainable improvements rather than

repeatedly addressing individual findings.

Drive remediation of security risk

Work directly with technology teams to improve performance against key security

outcomes, including areas such as:

• Vulnerability and patch management

• End-of-life/end-of-support technology

• Privileged access management and reviews

• Security control implementation

• Security configuration and hardening

• Security remediation backlogs

• Recurring security findings

• Other BU-specific security priorities

The role is expected to understand why a metric is poor and determine what needs to

change to improve it.

This may include process changes, technology changes, automation, data

improvements, changes to ownership or escalation to senior leadership.

Apply engineering thinking to security problems

• Use engineering principles to solve security problems at scale.

• Identify opportunities to automate repetitive security activities and controls.

• Use available security and technology data to identify patterns, root causes and

opportunities for intervention.

• Work with engineering and technology teams to design practical solutions.

• Challenge approaches that rely primarily on manual activity, repeated chasing or

temporary remediation.

• Help establish measurable, sustainable controls rather than one-off compliance

exercises.

Embed security into technology delivery

• Act as the BU's security subject matter expert within technology teams.

• Participate in relevant technology planning, architecture and delivery activity.

• Identify security requirements early in the technology lifecycle.

DCL2 - Internal Use Only• Help teams interpret and apply Security policies, standards and control

requirements.

• Identify when specialist Security Architecture or other central expertise is

required and bring it into the work at the appropriate point.

• Promote secure-by-design engineering practices.

Use data to drive decisions

• Establish reliable views of BU security performance.

• Analyse security data to identify trends, root causes and priority areas.

• Challenge inaccurate, incomplete or misleading security data.

• Translate security data into actionable priorities for technology leadership.

• Measure whether interventions have actually improved the security outcome.

• Provide transparent reporting to the DRO and relevant governance forums.

The role should be evidence-led rather than activity-led: success is demonstrated

through improved security outcomes, not the volume of meetings, communications or

assessments completed.

Risk management and escalation

• Provide the DRO with a clear view of current security exposure and material

changes in risk.

• Identify risks requiring escalation, remediation investment or formal risk

acceptance.

• Support the DRO in understanding the potential business and technology impact

of security risks.

• Ensure material security issues are escalated promptly and accurately.

• Work with GRC to ensure risks, controls and remediation activity are

appropriately recorded and evidenced.

The Security Engineering Lead does not replace the DRO's accountability for risk; they

provide the expertise, insight and delivery focus required to improve the risk position.

Build security capability within the BU

• Develop security awareness and capability within technology teams.

• Coach engineers and technology leaders on practical application of security

requirements.

• Encourage technology teams to take increasing ownership of security within

their services.

• Share successful engineering approaches and lessons learned across the wider

Security community.

DCL2 - Internal Use Only• Contribute to a culture in which security is treated as part of good technology

engineering rather than a separate compliance activity.

Key Relationships

BU / Function DRO

The role reports to and works closely with the DRO.

The DRO remains accountable for the BU/function's risk. The Security Engineering Lead

is accountable for achieving agreed security outcomes and providing the DRO with the

expertise, insight and delivery focus required to improve those outcomes.

Technology Leadership and Engineering Teams

The role operates as part of the BU technology organisation and works directly with

engineering, infrastructure, application, identity and other technology teams to deliver

improved security outcomes.

GRC

Works with GRC to:

• understand applicable policies, standards and control requirements;

• provide evidence of security performance and remediation;

• identify and escalate material risks;

• support independent governance and assurance; and

• maintain consistency of security expectations across the organisation.

GRC provides the independent governance and challenge function; the Security

Engineering Lead is focused on improving the BU's actual security outcomes.

Security Architecture

Works with Security Architecture where specialist expertise, design authority or

complex security decisions are required.

DCL2 - Internal Use OnlyWider Security Function

Participates in the Security community, sharing knowledge, patterns, data and

successful solutions while retaining primary accountability for the BU's agreed

outcomes.

What You Bring

Essential

• Significant experience in technology, engineering, cyber security or a closely

related discipline.

• Strong understanding of practical cyber security controls and technology risk.

• Demonstrable experience working directly with technology and engineering

teams.

• Ability to understand security standards and translate them into practical

technical outcomes.

• Strong analytical and data-driven problem-solving skills.

• Experience improving measurable operational or technology outcomes.

• Ability to understand complex technical environments and identify root causes

of security problems.

• Strong stakeholder management and influencing skills.

• Ability to challenge constructively and escalate when required.

• Comfortable working with ambiguity and determining practical solutions rather

than simply identifying problems.

Desirable

• Engineering, software development, infrastructure or architecture background.

• Experience with vulnerability/patch management, IAM/PAM, cloud security or

security operations.

• Experience automating security processes or controls.

• Experience working within regulated or highly controlled environments.

• Relevant professional security qualifications or equivalent practical experience.

Behaviours

The successful candidate will:

DCL2 - Internal Use OnlyThink like an engineer.

They look for root causes, scalable solutions and ways to make security better through

technology and process.

Act like part of the business.

They understand commercial and operational priorities and find ways to improve

security without treating the BU as an external customer.

Own outcomes.

They don't stop at identifying a problem. They stay focused on getting the outcome

changed.

Use evidence.

They rely on accurate data and are prepared to challenge assumptions, including when

the data is uncomfortable.

Be pragmatic.

They understand that perfect security is not the objective; materially reducing risk and

improving resilience is.

Know when to collaborate.

They don't try to be the expert in everything. They bring in GRC, Architecture or other

specialists when appropriate.

Build capability, not dependency.

They leave the technology organisation stronger and more capable of managing

security itself.

Measures of Success

Success will be measured primarily through improved security outcomes, for

example:

• Improvement against agreed vulnerability and patching targets

• Reduction in EOL/EOS exposure

• Improvement in privileged access review performance

• Reduction in security remediation backlog and ageing

• Reduction in recurring security findings

• Improvement in security control effectiveness

• Increased adoption of secure-by-design practices

• Increased automation of security controls and processes

DCL2 - Internal Use Only• Improved quality and reliability of security data

• Timely and appropriate escalation of material security risks

• Demonstrable reduction in the BU's overall security exposure

The role is not measured primarily by the amount of security activity performed. The

measure is whether the BU becomes measurably more secure.

What Makes This Role Different

This role is intentionally designed as an embedded security engineering capability

rather than a traditional advisory BISO role.

The individual is part of the BU, understands its technology environment, works directly

with its engineers and leaders, and is accountable for improving agreed security

outcomes.

Unlike traditional advisory security roles, the Security Engineering Lead is expected to

influence, coordinate and drive remediation activity through the BU technology

organisation until agreed outcomes are achieved.

The role therefore sits at the intersection of:

Security expertise + Technology engineering + Data + Business accountability

Its success is demonstrated by what changes in the BU — not simply by what the

Security function reports about it.

Why Pearson?

This role represents a significant shift in how security is delivered across Pearson.

Rather than operating as a central advisory function, the Security Engineering Lead is embedded

within the business and accountable for driving measurable improvements in security outcomes

where risk is created and managed.

The role provides the opportunity to work directly with technology leaders, engineers and

business stakeholders to solve real security problems, improve resilience and reduce risk at scale.

Success is measured through better security outcomes, stronger technology practices and a

demonstrably more secure business.

DCL2 - Internal Use OnlyAs Pearson continues to strengthen its security capabilities, this role offers the opportunity to

influence technology decisions, improve security performance across critical services, and help

establish a model in which security is treated as an integral part of good technology engineering

rather than a separate compliance activity.

DCL2 - Internal Use Only

Similar jobs

Apply for this job