Rodeo
Get started

Pearson

Advanced Specialist, Security Engineer

London
Posted about 18 hours ago
Sign up to applySee more jobs like this
Get notified of more jobs like this · No spam, ever

How your CV stacks up

1Upload CV
2Analyse CV
3Improve CV

Upload your CV to see how well it fits this job role

?%

Advanced Specialist, Security Engineer

About the Role

The BU Security Engineering Lead is a security-skilled technology professional who reports to the BU/function's Designated Risk Owner (DRO), with a dotted-line alignment to central Security to maintain consistency with enterprise security strategy, standards and priorities. The role is accountable for improving the BU/function's security outcomes and achieving agreed security objectives and metrics, working closely with GRC, Security Architecture and other central Security capabilities.

The role combines security expertise, technical leadership, engineering thinking, data-driven problem solving and strong business understanding. The Security Engineering Lead is part of the BU technology organisation, identifying security weaknesses, understanding their root causes and delivering practical solutions that measurably reduce security risk.

What You’ll Do

Own Improvement in BU Security Outcomes

  • Take accountability for achieving agreed security objectives, targets and metrics for the BU/function.
  • Establish a clear understanding of the BU's current security performance, key exposures and areas of greatest risk.
  • Use security data, trends and analysis to identify priorities and opportunities for improvement.
  • Develop and execute plans to improve security performance and reduce measurable risk.
  • Track progress against agreed objectives and intervene where performance is not improving.
  • Identify systemic issues and drive sustainable improvements rather than repeatedly addressing individual findings.

Drive Remediation of Security Risk

Work directly with technology teams to improve performance against key security outcomes, including areas such as:

  • Vulnerability and patch management
  • End-of-life/end-of-support technology
  • Privileged access management and reviews
  • Security control implementation
  • Security configuration and hardening
  • Security remediation backlogs
  • Recurring security findings
  • Other BU-specific security priorities

Apply Engineering Thinking to Security Problems

  • Use engineering principles to solve security problems at scale.
  • Identify opportunities to automate repetitive security activities and controls.
  • Use available security and technology data to identify patterns, root causes and opportunities for intervention.
  • Work with engineering and technology teams to design practical solutions.
  • Challenge approaches that rely primarily on manual activity, repeated chasing or temporary remediation.
  • Help establish measurable, sustainable controls rather than one-off compliance exercises.

Embed Security into Technology Delivery

  • Act as the BU's security subject matter expert within technology teams.
  • Participate in relevant technology planning, architecture and delivery activity.
  • Identify security requirements early in the technology lifecycle.
  • Help teams interpret and apply Security policies, standards and control requirements.
  • Identify when specialist Security Architecture or other central expertise is required and bring it into the work at the appropriate point.
  • Promote secure-by-design engineering practices.

Reasons to use Rodeo

I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?

Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.

Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.

Start with a chat, not a search bar

Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.

P

Graduate Consultant — 2026 Scheme

PwC·London, UK
£35,000/yr

Why you're a good match

Strong

Your economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.

See breakdown
Save jobNot relevant
View details

It searches the market for you

Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.

Why you're a good match

You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.

See breakdown
Strong

Experience fit

Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.

See breakdown
Strong

Only hits

No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.

Use Data to Drive Decisions

  • Establish reliable views of BU security performance.
  • Analyse security data to identify trends, root causes and priority areas.
  • Challenge inaccurate, incomplete or misleading security data.
  • Translate security data into actionable priorities for technology leadership.
  • Measure whether interventions have actually improved the security outcome.
  • Provide transparent reporting to the DRO and relevant governance forums.

Key Relationships

BU / Function DRO

The role reports to and works closely with the DRO.

The DRO remains accountable for the BU/function's risk. The Security Engineering Lead is accountable for achieving agreed security outcomes and providing the DRO with the expertise, insight and delivery focus required to improve those outcomes.

Technology Leadership and Engineering Teams

The role operates as part of the BU technology organisation and works directly with engineering, infrastructure, application, identity and other technology teams to deliver improved security outcomes.

GRC

Works with GRC to:

  • understand applicable policies, standards and control requirements;
  • provide evidence of security performance and remediation;
  • identify and escalate material risks;
  • support independent governance and assurance; and
  • maintain consistency of security expectations across the organisation.

GRC provides the independent governance and challenge function; the Security Engineering Lead is focused on improving the BU's actual security outcomes.

Security Architecture

Works with Security Architecture where specialist expertise, design authority or complex security decisions are required.

Wider Security Function

Participates in the Security community, sharing knowledge, patterns, data and successful solutions while retaining primary accountability for the BU's agreed outcomes.

What You Bring

Essential

  • Significant experience in technology, engineering, cyber security or a closely related discipline.
  • Strong understanding of practical cyber security controls and technology risk.
  • Demonstrable experience working directly with technology and engineering teams.
  • Ability to understand security standards and translate them into practical technical outcomes.
  • Strong analytical and data-driven problem-solving skills.
  • Experience improving measurable operational or technology outcomes.
  • Ability to understand complex technical environments and identify root causes of security problems.
  • Strong stakeholder management and influencing skills.
  • Ability to challenge constructively and escalate when required.
  • Comfortable working with ambiguity and determining practical solutions rather than simply identifying problems.

Desirable

  • Engineering, software development, infrastructure or architecture background.
  • Experience with vulnerability/patch management, IAM/PAM, cloud security or security operations.
  • Experience automating security processes or controls.
  • Experience working within regulated or highly controlled environments.
  • Relevant professional security qualifications or equivalent practical experience.

Get help with your application

Your very own career expert that helps elevate your application to the next level.

Get help applying for this job

Behaviours

The successful candidate will:

  • Think like an engineer.
  • Act like part of the business.
  • Own outcomes.
  • Use evidence.
  • Be pragmatic.
  • Know when to collaborate.
  • Build capability, not dependency.

Measures of Success

Success will be measured primarily through improved security outcomes, for example:

  • Improvement against agreed vulnerability and patching targets
  • Reduction in EOL/EOS exposure
  • Improvement in privileged access review performance
  • Reduction in security remediation backlog and ageing
  • Reduction in recurring security findings
  • Improvement in security control effectiveness
  • Increased adoption of secure-by-design practices
  • Increased automation of security controls and processes
  • Improved quality and reliability of security data
  • Timely and appropriate escalation of material security risks
  • Demonstrable reduction in the BU's overall security exposure

The role is not measured primarily by the amount of security activity performed. The measure is whether the BU becomes measurably more secure.

What Makes This Role Different

This role is intentionally designed as an embedded security engineering capability rather than a traditional advisory BISO role.

The individual is part of the BU, understands its technology environment, works directly with its engineers and leaders, and is accountable for improving agreed security outcomes.

Unlike traditional advisory security roles, the Security Engineering Lead is expected to influence, coordinate and drive remediation activity through the BU technology organisation until agreed outcomes are achieved.

The role therefore sits at the intersection of:

Security expertise + Technology engineering + Data + Business accountability

Its success is demonstrated by what changes in the BU — not simply by what the Security function reports about it.

Why Pearson?

This role represents a significant shift in how security is delivered across Pearson. Rather than operating as a central advisory function, the Security Engineering Lead is embedded within the business and accountable for driving measurable improvements in security outcomes where risk is created and managed.

The role provides the opportunity to work directly with technology leaders, engineers and business stakeholders to solve real security problems, improve resilience and reduce risk at scale.

Success is measured through better security outcomes, stronger technology practices and a demonstrably more secure business.

As Pearson continues to strengthen its security capabilities, this role offers the opportunity to influence technology decisions, improve security performance across critical services, and help establish a model in which security is treated as an integral part of good technology engineering rather than a separate compliance activity.

Trusted by 25,000+ job seekers

“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”

Jessica, London

Get help applying for this job

Location

London, UK

Sign up to applySee more jobs like this