Skip to content
Job Details
Full-time

Lead Specialist, Internal Audit, Controls, Compliance and Risk

Pearson · Remote US

Tailor My Resume

Start free. No credit card.

Role Overview

Pearson Virtual Schools operates audited platforms that serve schools, teachers, and students, in which audit readiness and a defensible control environment are not optional. This role is the dedicated owner of audit response and governance, risk, and compliance (GRC) for our platforms.

As Staff, Governance, Risk & Compliance, you own the response across the internal audit lifecycle, SOC 2 (Types 1 and 2), the risk register, and the business continuity and disaster recovery (BC/DR) program. You set evidence and attestation standards across service owners, translate findings into tracked remediation, and partner with internal audit, cybersecurity, privacy, risk, and legal.

This is a senior individual contributor role. It sits independently of the operational security team; it assures that the team operates the controls, and you independently verify and attest to them. You also have a dotted-line relationship to the Lead, Service Operations & Cyber Risk for day-to-day coordination.

Internal Audit & SOC 2 Leadership

  • Lead the response across the audit lifecycle, including planning, fieldwork coordination, and reviewing draft observations, root causes, and risks.
  • Challenge observation and management action plan ownership, wording, and feasibility, and draft and submit audit-closure proposals with stakeholder alignment.
  • Own SOC 2 (Type 1 and Type 2) coordination, including planning and bringing additional platforms into scope. Review evidence and send weak submissions back for rework.
  • Work with partner teams to ensure resources are assigned and aligned, and continually work with them on gaps and help them close them.

Controls, Evidence & Remediation

  • Set standards for evidence, attestation, and documentation across services.
  • Translate findings into structured remediation plans with owners, due dates, and evidence requirements, tracked to closure.
  • Maintain the audit-action tracker and hold action owners accountable, challenging weak ownership and unrealistic timelines.
  • Coordinate audit actions owned by other teams across the organization and keep them visible to closure.
  • Govern the configuration management database (CMDB, the inventory of services and their dependencies) for audit scope, keeping ownership and classification accurate. Solution Architecture operates and maintains it.

Risk & Resilience Governance

  • Own the risk register, including quality, owners, clear write-ups, closure, and escalation of risks beyond tolerance.
  • Turn access-review and vulnerability gaps into formal risks or audit actions where appropriate.
  • Govern the business continuity and disaster recovery program, including impact analyses, coverage and gaps, vendor continuity, annual reviews, and tabletop exercises, and executive attestation.

Cross-Functional Influence & Reporting

  • Partner with internal audit, cybersecurity, privacy, risk, and legal to close findings and prevent repeat observations.
  • Prepare audit and GRC status updates for monthly operations reviews, covering open actions, overdue items, blockers, and risks.
  • Advise service owners and coach peers on governance expectations, acting as an objective assurance partner.

What You Will Bring

  • 5 or more years in internal audit, controls, compliance, or risk (IT audit or GRC strongly preferred)
  • Hands-on coordination of SOC 2 (or SOX) programs, including evidence and attestation management
  • Demonstrated ownership of a risk register and the risk-management lifecycle
  • Experience governing or supporting business continuity and disaster recovery (impact analyses, plans, tabletops, attestation)
  • A professional qualification is expected or strongly preferred (CISA, CIA, CRISC, ACA/ACCA, or CISSP)
  • Proven ability to challenge peers and leaders and to represent the organization to external auditors
  • Experience in EdTech, SaaS, regulated, or highly distributed environments is a plus; familiarity with NIST CSF or ISO 22301 is a plus
  • Bachelor's degree in a relevant field; advanced degree a plus

Key Behaviors & Attributes

Independent & Objective: You bring professional skepticism and integrity, and you hold the line on audit-readiness.

Business-Enabling: You approach assurance as a means of enabling the business, not policing it, while staying objective.

Influence Without Authority: You push peers and leaders to own and close actions, challenging weak ownership and unrealistic timelines.

Continuous Improvement: You bring proven GRC frameworks and improve governance without slowing delivery.

Collaborative: You partner across security, engineering, privacy, legal, and internal audit to build a consistent control environment.

Key Relationships

Direct Reports: None. This is a senior individual contributor role.

Peers: The security operations lead, incident and service operations leads, manager of data governance, internal audit leads, and cybersecurity leads

Cross-functional: Internal audit, cybersecurity, privacy, risk, legal, engineering, product, and service owners

External: External auditors and vendors

We celebrate diversity and are committed to creating an inclusive environment for all employees.

Posted

2 days ago

Job Type

Full-time

Location

  • Remote US