About this role
Job Title: Principle, Information Security - Operational Resilience
*CF:*OCTO
*Function:*GRC, Cybersecurity
*Career Arch:*Technology / Security / Information Security
*Tier:*E35 (to start as the person does not have a team) and then M38 when they hire a team – hire for an M38
*Title:*Principle, Information Security – Operational Resilience
*Reports to:*Kate Beverly
*Location:*London, UK
Build resilience into the way Pearson operates. Define what must keep running. Give leaders confidence in disruption.
Pearson is seeking a *Principle, Information Security -**Operational Resilience*to establish and lead its central Operational Resilience capability. This is a highly visible enterprise role responsible for defining the framework, governance, and operating rhythm needed to sustain Pearson’s most critical services through major disruption. The role will lead the development of the Minimum Viable Company approach, set standards for planning and exercising, coordinate activity across business and technology teams, and provide executives with credible, evidence-based assurance on resilience readiness.
The ideal candidate will be an experienced resilience, continuity, or risk leader who can bring structure to an evolving environment, navigate complexity with confidence, and influence across a large matrixed organisation. This role requires someone who can translate resilience concepts into practical operating requirements, align business, technology, cyber, supplier, and crisis stakeholders, and establish a capability that is credible to senior leadership and practical for operational teams.
Pearson Leadership Dimensions
As a senior leader at Pearson, you will be expected to embody and role model our leadership dimensions. You will align the resilience capability to Pearson’s purpose and strategy, simplify complexity into clear operational priorities, build a collaborative and high-performing culture, and deliver measurable results. This role requires visible leadership, sound judgement in ambiguity, and the ability to bring people together across business, technology, risk, and security around a shared understanding of what matters most in disruption.
What You’ll Do
Strategic leadership and transformation
- Define and own the long-term vision, strategy, and implementation roadmap for Operational Resilience at Pearson, moving the organisation from fragmented planning to a credible enterprise capability with clear standards, effective governance, and demonstrable readiness.
- Translate resilience concepts into a practical operating model for a complex global business, creating clarity on critical services, minimum acceptable service levels, prioritisation, tolerances, and recovery sequencing.
- Act as a senior subject matter leader for operational resilience and continuity, bringing thought leadership, external awareness, and disciplined execution to how Pearson matures its capability.
- Lead a shift in how Pearson approaches resilience by moving the focus from document collection alone to service-level understanding, tested recovery capability, decision-useful data, and practical executive assurance.
Framework, governance, and Minimum Viable Company
- Own and maintain Pearson’s enterprise operational resilience framework, associated standards, policy requirements, templates, governance forums, and reporting mechanisms needed to run the capability effectively and consistently.
- Lead the development and ongoing refinement of Pearson’s Minimum Viable Company approach, ensuring the organisation can articulate the minimum operating state required to continue safely, legally, and sustainably through severe disruption.
- Define and oversee the methodology for identifying critical services, important processes, recovery priorities, and service tolerances, including the relationship between business requirements, technology recovery, supplier dependencies, and crisis decision-making.
- Ensure resilience requirements are governed in a proportionate, practical, and auditable way, with clear accountability for plan ownership, review cycles, evidence retention, remediation tracking, and executive escalation.
Planning, exercising, and assurance
- Oversee the creation, refresh, quality, and maintenance of continuity and resilience plans across the enterprise, ensuring they are aligned to service priorities and usable in practice rather than static documentation.
- Design and lead a structured annual exercise and testing programme, including tabletop simulations, targeted service-level recovery tests, cross-functional scenario walkthroughs, and lessons-learned reviews.
- Translate testing into measurable assurance by tracking outcomes, remediation actions, residual risks, and evidence that recovery assumptions have been validated for leadership and audit purposes.
- Provide regular executive reporting on resilience maturity, plan coverage, testing progress, critical dependency risks, unresolved issues, and overall readiness, ensuring leaders receive decision-useful insight rather than disconnected metrics.
Cross-functional leadership and operating model
- Work across business divisions, enterprise risk, technology, cyber, supplier management, internal audit, and crisis management to build a coherent end-to-end approach to resilience that clarifies ownership and reduces fragmentation.
- Act as the central point of leadership for divisional continuity leads and plan owners, creating a sustainable operating rhythm of governance forums, reviews, escalation paths, management information, and follow-up actions.
- Ensure the Operational Resilience capability complements and strengthens adjacent disciplines such as IT disaster recovery, cyber incident response, crisis management, enterprise risk, and third-party resilience, with clear boundaries that avoid duplication.
- Influence senior stakeholders across a matrixed global organisation, balancing pragmatism with rigour while driving accountability for resilience activity that often sits outside direct reporting lines.
People and organisation
- Establish and lead a small but high-impact central Operational Resilience team, setting direction, priorities, ways of working, and performance expectations for a function intended to grow in credibility and maturity over time.
- Build a culture of practical resilience, collaboration, and accountability by coaching team members and business stakeholders to focus on usable plans, evidence-based readiness, and continuous improvement rather than compliance alone.
- Support workforce planning, role design, onboarding, development, and capability building for the resilience function, creating clear expectations for specialist, analyst, and divisional continuity lead roles.
- Create an operating rhythm that supports both UK and US time zones, enabling the central team to work effectively with distributed stakeholders across Pearson’s global environment.
What You Bring
- Significant experience leading operational resilience, business continuity, disaster recovery, crisis management, or a closely related enterprise resilience function in a complex global organisation.
- Demonstrated ability to build frameworks, governance models, and cross-functional programmes that depend on influence rather than direct control, particularly in matrixed environments with multiple stakeholder groups.
- Deep experience with business impact analysis, critical service identification, dependency mapping, service tolerances, scenario testing, continuity planning, and resilience or recovery assurance.
- Strong understanding of the relationship between business continuity, IT disaster recovery, cyber resilience, supplier resilience, enterprise risk, audit, and crisis management, with the judgement to define clear boundaries between them.
About cyber security & digital forensics roles for ex-police
Cyber security, digital forensics and incident-response roles. DMIs, cybercrime investigators and digital forensics officers bring evidential discipline and investigative judgement that DFIR and security teams struggle to hire.
See all cyber security & digital forensics jobs in London →Why this fits a police background — match score 85/100
- Incident command & response
- Working to legislation & regulation
- Training & coaching delivery
What cyber security & digital forensics roles pay ex-police
Advertised UK ranges, editorial estimates reviewed July 2026
| Digital forensics analyst | £32,000–£45,000 |
| DFIR consultant | £45,000–£65,000 |
| Senior forensics / IR specialist | £60,000–£80,000 |
| Threat-intelligence specialist | £55,000–£80,000 |