Pearson

Lead Specialist, Internal Audit, Controls, Compliance and Risk

Remote, United States remote Entry Salary not listed
remote Technology & IT Curated
Sign in to apply Free account — we bring you straight back to this role.

About the role

Role Overview
Pearson Virtual Schools operates audited platforms that serve schools, teachers, and students, in which audit readiness and a defensible control environment are not optional. This role is the dedicated owner of audit response and governance, risk, and compliance (GRC) for our platforms.
As Staff, Governance, Risk & Compliance, you own the response across the internal audit lifecycle, SOC 2 (Types 1 and 2), the risk register, and the business continuity and disaster recovery (BC/DR) program. You set evidence and attestation standards across service owners, translate findings into tracked remediation, and partner with internal audit, cybersecurity, privacy, risk, and legal.
This is a senior individual contributor role. It sits independently of the operational security team; it assures that the team operates the controls, and you independently verify and attest to them. You also have a dotted-line relationship to the Lead, Service Operations & Cyber Risk for day-to-day coordination.
Key Responsibilities
Internal Audit & SOC 2 Leadership

Lead the response across the audit lifecycle, including planning, fieldwork coordination, and reviewing draft observations, root causes, and risks.

Challenge observation and management action plan ownership, wording, and feasibility, and draft and submit audit-closure proposals with stakeholder alignment.

Own SOC 2 (Type 1 and Type 2) coordination, including planning and bringing additional platforms into scope. Review evidence and send weak submissions back for rework.

Work with partner teams to ensure resources are assigned and aligned, and continually work with them on gaps and help them close them.

Controls, Evidence & Remediation

Set standards for evidence, attestation, and documentation across services.

Translate findings into structured remediation plans with owners, due dates, and evidence requirements, tracked to closure.

Maintain the audit-action tracker and hold action owners accountable, challenging weak ownership and unrealistic timelines.

Coordinate audit actions owned by other teams across the organization and keep them visible to closure.

Govern the configuration management database (CMDB, the inventory of services and their dependencies) for audit scope, keeping ownership and classification accurate. Solution Architecture operates and maintains it.

Risk & Resilience Governance

Own the risk register, including quality, owners, clear write-ups, closure, and escalation of risks beyond tolerance.

Turn access-review and vulnerability gaps into formal risks or audit actions where appropriate.

Govern the business continuity and disaster recovery program, including impact analyses, coverage and gaps, vendor continuity, annual reviews, and tabletop exercises, and executive attestation.

Cross-Functional Influence & Reporting

Partner with internal audit, cybersecurity, privacy, risk, and legal to close findings and prevent repeat observations.

Prepare audit and GRC status updates for monthly operations reviews, covering open actions, overdue items, blockers, and risks.

Advise service owners and coach peers on governance expectations, acting as an objective assurance partner.

What You Will Bring

5 or more years in internal audit, controls, compliance, or risk (IT audit or GRC strongly preferred)

Hands-on coordination of SOC 2 (or SOX) programs, including evidence and attestation management

Demonstrated ownership of a risk register and the risk-management lifecycle

Experience governing or supporting business continuity and disaster recovery (impact analyses, plans, tabletops, attestation)

A professional qualification is expected or strongly preferred (CISA, CIA, CRISC, ACA/ACCA, or CISSP)

Proven ability to challenge peers and leaders and to represent the organization to external auditors

Experience in EdTech, SaaS, regulated, or highly distributed environments is a plus; familiarity with NIST CSF or ISO 22301 is a plus

Bachelor's degree in a relevant field; advanced degree a plus

Key Behaviors & Attributes
Independent & Objective: You bring professional skepticism and integrity, and you hold the line on audit-readiness.
Business-Enabling: You approach assurance as a means of enabling the business, not policing it, while staying objective.
Influence Without Authority: You push peers and leaders to own and close actions, challenging weak ownership and unrealistic timelines.
Continuous Improvement: You bring proven GRC frameworks and improve governance without slowing delivery.
Collaborative: You partner across security, engineering, privacy, legal, and internal audit to build a consistent control environment.
Key Relationships
Direct Reports: None. This is a senior individual contributor role.
Peers: The security operations lead, incident and service operations leads, manager of data governance, internal audit leads, and cybersecurity leads
Cross-functional: Internal audit, cybersecurity, privacy, risk, legal, engineering, product, and service owners
External: External auditors and vendors
Pearson is an equal opportunity employer. We celebrate diversity and are committed to creating an inclusive environment for all employees. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or veteran status.
Originally posted on Himalayas

Interview prep

Walk in with sharper answers.

Use this as a quick practice sheet before you speak with the employer.

Role
Technology & IT Data Analysis MySQL Operations Writing remote

Likely questions

  1. Tell us about work you have done that is close to the Lead Specialist, Internal Audit, Controls, Compliance and Risk role.
  2. How would you approach your first 30 days at Pearson?
  3. Which of Data Analysis, MySQL and Operations have you used recently, and what did it help you achieve?
  4. Describe a time you solved a problem without waiting to be told exactly what to do.
  5. How do you stay organised and communicate clearly when working remotely?

Prepare before the call

  • A recent example that proves your experience with Data Analysis, MySQL and Operations.
  • One short story with a problem, your action, and the result.
  • Two examples that show the strengths listed on your CV.
  • A clear reason why this role and company interest you.
  • Your availability, preferred work style, and salary expectations.

Ask them

  • What would success look like in the first 90 days?
  • What are the main problems this hire should help solve?
  • How does the team give feedback and measure good work?
  • What does a normal working week look like for this role?
Practice line

I am interested in the Lead Specialist, Internal Audit, Controls, Compliance and Risk role because I can bring practical experience in Data Analysis, MySQL and Operations, learn the team quickly, and contribute to the outcomes Pearson needs from this hire.

Related jobs.

More roles from this company or category.