Director of Engineering Security & Compliance Engineering (Washington) Job at Pearson, Washington DC

UXp3RFVUT3hIelZjMVEyaS9oS0wydlUxeFE9PQ==
  • Pearson
  • Washington DC

Job Description

Director of Engineering Security & Compliance Engineering

Reports to: VP, Head of Engineering PSG

About Pearson Software Group (PSG)

Pearson Software Group (PSG) powers Pearsons Higher Education and PPG product lines, delivering worldclass learning platforms at scale (e.g., MyLab, Mastering, Pearson+, Exam Prep). PSG supports 5,000+ colleagues and millions of learners globally.

Role Overview

The Director of Security & Compliance Engineering (S&C) is a handson technical leader who embeds security into the SDLC, partnering with engineering to drive securebydesign architecture, DevSecOps automation, and developer enablement. The role leads the PSGSC program to reduce risk, harden platforms, and streamline audits through engineeringfirst practices and evidence from delivery systems.

Key Responsibilities

  • Architect and institutionalize secure SDLC practices (threat modeling, secure coding, dependency hygiene, automated testing, release gating).
  • Own DevSecOps integration across CI/CD (SAST/DAST/IAST, secrets scanning, SBOM, container/image hardening, IaC policy checks).
  • Drive shiftleft security through reusable CI/CD templates, policyascode, and golden paths.
  • Partner with platform/SRE to enforce WAF, API AuthN/AuthZ, mTLS, and runtime protections via guardrailsnot gates.
  • Publish paved road toolchains, reference architectures, and code libraries with secure defaults.
  • Stand up sandboxed environments (e.g., GitPod) and securebydefault scaffolds to accelerate teams.
  • Deliver targeted training for engineers (OWASP, secrets, auth, threat modeling) tied to real code and pipelines.
  • Lead SOC2 Type2, HECVAT, and institutional reviews using automated evidence from pipelines and platforms.
  • Define OKRs and SLAs for vulnerability remediation, secrets rotation, agent coverage, and audit readiness; publish executive dashboards.
  • Align compliance asks with product/engineering roadmaps; triage by business risk and customer impact.
  • Own vulnerability management (Qualys/Snyk/OSS posture), secrets lifecycle and key rotation, and perimeter/API security.
  • Continuously monitor control health; ensure clear ownership, escalation paths, and exception processes.
  • Improve MTTD/MTTR by integrating detections with engineering telemetry and runbooks.
  • Optimize run costs for security tooling and tests; ensure renewals/SOWs are timely and valuebased.
  • Report posture, compliance status, and maturity trends; drive continuous improvement and transparency.
  • Champion a blameless, learning culture that balances speed and safety.

Qualifications

  • 10+ years in software engineering or DevSecOps; 5+ years leading secure SDLC at scale (cloudfirst; AWS preferred).
  • Expertise in CI/CD automation, SAST/DAST/IAST, SBOM/OSS governance, secrets management, and API/perimeter security.
  • Handson experience integrating controls into developer workflows (policyascode, pipelines, precommit/premerge checks).
  • Proven delivery of SOC2 Type2/HECVAT using automated, systemofrecord evidence.
  • Executive communication; OKR setting; budget ownership; ability to influence product/engineering/security.

Preferred

  • Certifications: CISSP, CISM, CCSP, AWS, or relevant DevSecOps credentials.
  • Experience in EdTech or regulated SaaS; institutionfacing security reviews.
  • Track record of automating compliance (evidence collection, control verification, reporting).

Compensation & Application

Compensation at Pearson is influenced by a wide array of factors including but not limited to skill set, level of experience, and specific location. The minimum fulltime salary range is $170,000$195,000. This position is eligible to participate in an annual incentive program.

Applications will be accepted through until 31 Devember 2025 . This window may be extended depending on business needs.

Equal Employment Opportunity

Pearson is an Equal Opportunity Employer and a member of EVerify. Employment decisions are based on qualifications, merit and business need. Qualified applicants will receive consideration for employment without regard to race, ethnicity, color, religion, sex, sexual orientation, gender identity, gender expression, age, national origin, protected veteran status, disability status or any other group protected by law. We actively seek qualified candidates who are protected veterans and individuals with disabilities as defined under VEVRAA and Section503 of the Rehabilitation Act.

If you are an individual with a disability and are unable or limited in your ability to use or access our career site as a result of your disability, you may request reasonable accommodations by emailing TalentExperienceGlobalTeam@grp.pearson.com.

#J-18808-Ljbffr

Job Tags

Full time,

Similar Jobs

1KOMMA5 Bremen

Chief of Staff CRO Office (m/w/d) (Germany) Job at 1KOMMA5 Bremen

 ...Permanent employee, Full-time Berlin, Hamburg, Mnchen Wir suchen Dich zur Verstrkung unseres CRO (Chief Revenue Officer) Teams vorzugsweise in Berlin, alternativ Hamburg oder Mnchen. 1KOMMA5 schafft Deutschlands grten One-Stop-Shop fr den Verkauf, die Installation und... 

Kamehameha Schools

High School Educational Assistant, Kauluhala Summer Academy Job at Kamehameha Schools

 ...Job Posting Title High School Educational Assistant, Kauluhala Summer Academy Employee Type Temporary Seasonal (Fixed Term) (Seasonal) Recruiting Start Date 12-17-2025 Job Exempt? No Recruiting End Date Open Until Filled Aloha mai! Mahalo for your interest... 

Arcadia Home Care and Staffing - an Addus family company

Personal Care Aide Job at Arcadia Home Care and Staffing - an Addus family company

 ...Currently looking to hire aides for all shifts; daytime, evening, and overnights. Also hiring weekend aides. Arcadia Home Care & Staffing is hiring...  ...entry-level position provides consistent, flexible full-time/part-time hours to accommodate your personal needs, while... 

Minnesota Department of Health

Stroke System Evaluation Specialist - Research Scientist 3 Job at Minnesota Department of Health

 ...Job Details Working Title: Stroke System Evaluation Specialist Job Class: Research Scientist 3 Agency: Health Department...  ...check and reference check. Under the U.S. Citizen and Immigration Services regulations, the successful candidate must be able... 

Overland Park Regional Medical Center

Registered Nurse Cardiovascular Prep and Recovery Job at Overland Park Regional Medical Center

 ...Submit your application for Registered Nurse Cardiovascular Prep and Recovery position and spend more time at the bedside with the patient....  ..., or work to deliver clinical excellence behind the scenes in data science, case management or transfer centers. Unlock your potential...