Lead, Information Security at Pearson | England, GB | Rezi

Lead, Information Security at Pearson

Lead, Information Security

Pearson · England, GB

3 weeks ago

Lead, Information Security

Pearson · England, GB

24 days ago
Resume preview

Impress employers and recruiters.
Choose from hundreds of resume examples.

Target Resume Now

About the Role

Pearson is seeking a Principle, Information Security - Operational Resilience to establish and lead its central Operational Resilience capability. This is a highly visible enterprise role responsible for defining the framework, governance, and operating rhythm needed to sustain Pearson’s most critical services through major disruption. The role will lead the development of the Minimum Viable Company approach, set standards for planning and exercising, coordinate activity across business and technology teams, and provide executives with credible, evidence-based assurance on resilience readiness.

Responsibilities

  • Define and own the long-term vision, strategy, and implementation roadmap for Operational Resilience at Pearson.
  • Translate resilience concepts into a practical operating model for a complex global business.
  • Act as a senior subject matter leader for operational resilience and continuity.
  • Lead a shift in how Pearson approaches resilience by moving the focus from document collection alone to service-level understanding, tested recovery capability, decision-useful data, and practical executive assurance.
  • Own and maintain Pearson’s enterprise operational resilience framework, associated standards, policy requirements, templates, governance forums, and reporting mechanisms.
  • Lead the development and ongoing refinement of Pearson’s Minimum Viable Company approach.
  • Define and oversee the methodology for identifying critical services, important processes, recovery priorities, and service tolerances.
  • Ensure resilience requirements are governed in a proportionate, practical, and auditable way.
  • Oversee the creation, refresh, quality, and maintenance of continuity and resilience plans across the enterprise.
  • Design and lead a structured annual exercise and testing programme.
  • Translate testing into measurable assurance by tracking outcomes, remediation actions, residual risks, and evidence that recovery assumptions have been validated.
  • Provide regular executive reporting on resilience maturity, plan coverage, testing progress, critical dependency risks, unresolved issues, and overall readiness.
  • Work across business divisions, enterprise risk, technology, cyber, supplier management, internal audit, and crisis management to build a coherent end-to-end approach to resilience.
  • Act as the central point of leadership for divisional continuity leads and plan owners.
  • Ensure the Operational Resilience capability complements and strengthens adjacent disciplines.
  • Influence senior stakeholders across a matrixed global organisation, balancing pragmatism with rigour.
  • Establish and lead a small but high-impact central Operational Resilience team.
  • Build a culture of practical resilience, collaboration, and accountability by coaching team members and business stakeholders.
  • Support workforce planning, role design, onboarding, development, and capability building for the resilience function.
  • Create an operating rhythm that supports both UK and US time zones.

Requirements

  • Significant experience leading operational resilience, business continuity, disaster recovery, crisis management, or a closely related enterprise resilience function in a complex global organisation.
  • Demonstrated ability to build frameworks, governance models, and cross-functional programmes that depend on influence rather than direct control, particularly in matrixed environments with multiple stakeholder groups.
  • Deep experience with business impact analysis, critical service identification, dependency mapping, service tolerances, scenario testing, continuity planning, and resilience or recovery assurance.
  • Strong understanding of the relationship between business continuity, IT disaster recovery, cyber resilience, supplier resilience, enterprise risk, audit, and crisis management, with the judgement to define clear boundaries between them.
  • Experience building or maturing capabilities, introducing standards, and creating sustainable governance, reporting, and assurance mechanisms that stand up to executive and audit scrutiny.
  • Strong analytical and reporting capability, with experience translating resilience data, interdependencies, and complex risks into clear executive insight and action-oriented management information.
  • Excellent stakeholder management, communication, and influencing skills, with the ability to work credibly with senior leaders, operational teams, and control functions across a large matrixed organisation.
  • Experience leading teams, developing specialist capability, and building a culture of accountability, clarity, and practical delivery in a new or evolving enterprise function.
  • Comfort working with ambiguity and complexity, with the resilience and judgement needed to make balanced, risk-aware decisions in areas where standards are still developing.
  • Relevant qualifications in business continuity, resilience, risk, or security would be advantageous, for example CBCI, CBCP, DRI, ISO 22301-related training, or equivalent practical experience.

Skills

  • Operational Resilience
  • Business Continuity
  • Disaster Recovery
  • Crisis Management
  • Framework Development
  • Governance Models
  • Cross-functional Program Management
  • Stakeholder Influence
  • Business Impact Analysis
  • Critical Service Identification
  • Dependency Mapping
  • Service Tolerances
  • Scenario Testing
  • Continuity Planning
  • Resilience Assurance
  • IT Disaster Recovery
  • Cyber Resilience
  • Supplier Resilience
  • Enterprise Risk Management
  • Audit Coordination
  • Analytical Skills
  • Reporting
  • Executive Communication
  • Team Leadership
  • Capability Building
  • Ambiguity Navigation
  • Risk-aware Decision Making

Location

  • London, UK

Work Type

  • Full-time

Experience Level

  • Principle
  • Senior Leader

Education Level

  • Relevant qualifications in business continuity, resilience, risk, or security would be advantageous, for example CBCI, CBCP, DRI, ISO 22301-related training, or equivalent practical experience.

About the Company

  • Pearson is seeking a Principle, Information Security - Operational Resilience to establish and lead its central Operational Resilience capability.
  • This is an opportunity to build a genuinely important enterprise capability at a pivotal stage in Pearson’s resilience maturity.
  • As Pearson becomes more dependent on digital services, shared platforms, suppliers, coordinated recovery, and credible assurance, the need for a clear and effective operational resilience capability is increasing.
  • The organisation is still early in its maturity journey, which makes this role both challenging and unusually high impact.
  • This role offers the chance to shape how Pearson defines what must keep running, how it prioritises during disruption, and how it gives leaders confidence that critical services can be sustained and recovered in a controlled way.
  • It is a rare opportunity to create lasting structure, influence enterprise decision-making, and establish a capability with visibility across leadership, risk, technology, security, and the wider business.