> Markdown version of [/jobs/ext/1942681-lead-information-security](https://www.wearedevelopers.com/jobs/ext/1942681-lead-information-security). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Lead, Information Security - **Company:** Pearson Whiffin Recruitment Ltd - **Location:** London, UK - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Cyber Security, Disaster Recovery - **Published:** August 6, 2026 - **Apply:** https://dejobs.org/x/x/29C69CC6B81C42169A8FE7F6C4A1F34E/job/ ## About the Role * Significant experience leading operational resilience, business continuity, disaster recovery, crisis management, or a closely related enterprise resilience function in a complex global organisation. * Demonstrated ability to build frameworks, governance models, and cross-functional programmes that depend on influence rather than direct control, particularly in matrixed environments with multiple stakeholder groups. * Deep experience with business impact analysis, critical service identification, dependency mapping, service tolerances, scenario testing, continuity planning, and resilience or recovery assurance. * Strong understanding of the relationship between business continuity, IT disaster recovery, cyber resilience, supplier resilience, enterprise risk, audit, and crisis management, with the judgement to define clear boundaries between them. * Experience building or maturing capabilities, introducing standards, and creating sustainable governance, reporting, and assurance mechanisms that stand up to executive and audit scrutiny. * Strong analytical and reporting capability, with experience translating resilience data, interdependencies, and complex risks into clear executive insight and action-oriented management information. * Excellent stakeholder management, communication, and influencing skills, with the ability to work credibly with senior leaders, operational teams, and control functions across a large matrixed organisation. * Experience leading teams, developing specialist capability, and building a culture of accountability, clarity, and practical delivery in a new or evolving enterprise function. * Comfort working with ambiguity and complexity, with the resilience and judgement needed to make balanced, risk-aware decisions in areas where standards are still developing. * Relevant qualifications in business continuity, resilience, risk, or security would be advantageous, for example CBCI, CBCP, DRI, ISO 22301-related training, or equivalent practical experience. ## Description * Define and own the long-term vision, strategy, and implementation roadmap for Operational Resilience at Pearson, moving the organisation from fragmented planning to a credible enterprise capability with clear standards, effective governance, and demonstrable readiness. * Translate resilience concepts into a practical operating model for a complex global business, creating clarity on critical services, minimum acceptable service levels, prioritisation, tolerances, and recovery sequencing. * Act as a senior subject matter leader for operational resilience and continuity, bringing thought leadership, external awareness, and disciplined execution to how Pearson matures its capability. * Lead a shift in how Pearson approaches resilience by moving the focus from document collection alone to service-level understanding, tested recovery capability, decision-useful data, and practical executive assurance. Framework, governance, and Minimum Viable Company * Own and maintain Pearson's enterprise operational resilience framework, associated standards, policy requirements, templates, governance forums, and reporting mechanisms needed to run the capability effectively and consistently. * Lead the development and ongoing refinement of Pearson's Minimum Viable Company approach, ensuring the organisation can articulate the minimum operating state required to continue safely, legally, and sustainably through severe disruption. * Define and oversee the methodology for identifying critical services, important processes, recovery priorities, and service tolerances, including the relationship between business requirements, technology recovery, supplier dependencies, and crisis decision-making. * Ensure resilience requirements are governed in a proportionate, practical, and auditable way, with clear accountability for plan ownership, review cycles, evidence retention, remediation tracking, and executive escalation. Planning, exercising, and assurance * Oversee the creation, refresh, quality, and maintenance of continuity and resilience plans across the enterprise, ensuring they are aligned to service priorities and usable in practice rather than static documentation. * Design and lead a structured annual exercise and testing programme, including tabletop simulations, targeted service-level recovery tests, cross-functional scenario walkthroughs, and lessons-learned reviews. * Translate testing into measurable assurance by tracking outcomes, remediation actions, residual risks, and evidence that recovery assumptions have been validated for leadership and audit purposes. * Provide regular executive reporting on resilience maturity, plan coverage, testing progress, critical dependency risks, unresolved issues, and overall readiness, ensuring leaders receive decision-useful insight rather than disconnected metrics. Cross-functional leadership and operating model * Work across business divisions, enterprise risk, technology, cyber, supplier management, internal audit, and crisis management to build a coherent end-to-end approach to resilience that clarifies ownership and reduces fragmentation. * Act as the central point of leadership for divisional continuity leads and plan owners, creating a sustainable operating rhythm of governance forums, reviews, escalation paths, management information, and follow-up actions. * Ensure the Operational Resilience capability complements and strengthens adjacent disciplines such as IT disaster recovery, cyber incident response, crisis management, enterprise risk, and third-party resilience, with clear boundaries that avoid duplication. * Influence senior stakeholders across a matrixed global organisation, balancing pragmatism with rigour while driving accountability for resilience activity that often sits outside direct reporting lines. People and organisation * Establish and lead a small but high-impact central Operational Resilience team, setting direction, priorities, ways of working, and performance expectations for a function intended to grow in credibility and maturity over time. * Build a culture of practical resilience, collaboration, and accountability by coaching team members and business stakeholders to focus on usable plans, evidence-based readiness, and continuous improvement rather than compliance alone. * Support workforce planning, role design, onboarding, development, and capability building for the resilience function, creating clear expectations for specialist, analyst, and divisional continuity lead roles. * Create an operating rhythm that supports both UK and US time zones, enabling the central team to work effectively with distributed stakeholders across Pearson's global environment. ## Related Videos - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Convincing Product teams to Adopt Gitops in a Large Org](https://www.wearedevelopers.com/videos/1936-convincing-product-teams-to-adopt-gitops-in-a-large-org) - [System Resilience: Surviving the Software Storm](https://www.wearedevelopers.com/videos/874-system-resilience-surviving-the-software-storm) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [Less Is More: How Lagom and Agile Can Create Harmonious Workflows](https://www.wearedevelopers.com/videos/1993-less-is-more-how-lagom-and-agile-can-create-harmonious-workflows) ## Related Articles - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Best Companies to work for in London: Top 25 Companies in 2023](https://www.wearedevelopers.com/magazine/187-best-companies-to-work-for-in-london-top-25-companies-in-2023) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [Building Security Champions](https://www.wearedevelopers.com/magazine/87-building-security-champions) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks)