Senior Third-Party Cyber Risk Analyst

1 month ago


London, Greater London, United Kingdom Pearson Full time

Role: Senior Third-Party Cyber Risk Analyst

Company: Pearson

Location: UK 80 Strand

About Pearson:

Our purpose: At Pearson we 'add life to a lifetime of learning' so everyone can realise the life they imagine. We do this by creating vibrant and enriching learning experiences designed for real-life impact. Pearson was founded in 1844 and has been built on our ability to grow with and adapt to a constantly evolving market. Our 20,000+ employees are dedicated to creating high-quality, digital-first, accessible and sustainable resources for lifelong learning.

About Pearson's Chief Information Security Office

Pearson's Chief Information Security Office (CISO) is responsible for establishing and maintaining the enterprise vision, strategy, and program for protecting the confidentiality, integrity and availability of information assets and technologies from threats and vulnerabilities. We are composed of 4 key pillars: Security Operations, Security Engineering and Architecture, Posture Management, and Governance, Risk and Compliance.

About the Job:

You will be a key member of CISO's Governance, Risk and Compliance pillar, and will be required to form strong partnerships with all CISO pillars and key stakeholders across Pearson Digital and Technology and the Business Divisions. You will contribute to the innovation and transformation of Pearson's Security Risk and Compliance programme, with a focus on third-party vendor and supply chain risk ; developing and implementing a robust risk management programme, conducting rigorous due diligence on third party practices and continuous monitoring.

You will be responsible for, but not limited to, the following:

  • Responsible for conducting timely security assessments of third-party suppliers, recording results accurately and initiating appropriate assurance responses.
  • Support the production of high quality, informative and accurate reports in respect of third-party assurance assessments.
  • Provide advice and guidance to stakeholders on Information/Cyber Security Minimum Requirements for assessments with vendors.
  • Collaborate with procurement, legal, and other stakeholders to ensure vendor contracts and agreements include appropriate security and compliance requirements.
  • Participate in and contribute to collection of KRI's, Management Information reporting on 3rd party cyber risks and assessments.
  • Assist and support management with internal reporting, including steering committees and updates for senior management.
  • Develop metrics and measurements to demonstrate adherence to security frameworks.
  • Support internal stakeholders with Third Party related information security projects.
  • Support wider cyber risk function on third party/vendor related risk assessments.
  • Help the global team with the development and enhancement of the programme, progressing currently identified and future improvements to make the function more effective and efficient.
  • Provide support to management and engage with the wider information Security.
  • Develop subject matter expertise on third party security requirements that impact Pearson.
  • Stay up to date with the latest cyber threats, attack vectors, and industry best practices for third party risk management.

Key Skills & Experience:

  • Experience within the Cyber Security field, with a focus on Governance, Risk, Compliance and Assurance.
  • Relevant professional cyber security qualifications (e.g., CISSP, CISM, CRISC, CCSP, ISO 27001 LA/LI).
  • Demonstrable expertise working with common information security management frameworks, such as ISO/IEC 27001/2, NIST 800-53, NIST CSF, CIS Top 20, CIS benchmarks.
  • Demonstrate experience in translating data privacy legal regulatory requirements into information security language such as GDPR, CCPA, HIPPA, etc.
  • Excellent verbal and written communication skills, with experience communicating with a wide range of audiences including technologists, executives, and business stakeholders.
  • Demonstrable experience within the design, implementation, and management of systems and/or assurance frameworks.
  • Highly analytical and a critical thinker, with strong problem-solving skills.
  • High degree of initiative, dependability and thought leadership.

Desirable Skills & Experience:

  • Master's degree in information security or a related subject, such as Information Technology.
  • Experience in internal conducting internal audits against recognized standards and frameworks (ISO 27001, ISO 22301, etc.).
  • Experience working in a similar sized organization or in a consulting practice.
  • Knowledge of relevant legal and regulatory requirements, specifically US, UK, and EU.
  • Experience governing Payment Card Industry Data Security Standards (PCI DSS) compliance within eCommerce is a bonus.

Pearson's Benefits:

  • 25 Days annual leave (increasing by 1 day with every year of continuous service up to 30 days); annual leave trading, +/- 5 days.
  • Annual Bonus
  • Private Pension plan scheme where we pay in double what you contribute, up to 16% depending on your age.
  • Life, private medical and dental care insurance options, plus free eye tests
  • Stock/share purchase options
  • Maternity, paternity, and family care leave as well as flexible working policies.
  • An employee wellbeing assistance programme
  • Cycle to work program, volunteering days, gym membership concessions in selected office locations, along with retail and leisure discounts.
  • We actively encourage our staff to participate in at least 40 hours of training a year and offer relevant AWS (Amazon Web Service) training and certification as part of this role.

Flexible working: Pearson is committed to hybrid working practices and has adopted flexible remote and virtual working. Where possible our employees can choose to manage their attendance to the office more flexibly. We work a 37.5-hour week, with all our team free to flex their day around our core hours, which are Monday to Friday, 10 to 4 GMT/BST. School runs, etc can be accommodated.

Diversity: At Pearson we value the power of an inclusive culture and a strong sense of belonging. We promote a culture where differences are embraced as strengths and opportunities are equal and accessible.

How to apply: Thank you for your interest in applying for a role at Pearson. Please submit an updated CV and cover letter (optional) in English. If you have any additional questions or require further information, please do not hesitate to reach out to us.

We look forward to receiving your application - Pearson Recruitment

What to expect from Pearson

Did you know Pearson is one of the 10 most innovative education companies of 2022?

At Pearson, we add life to a lifetime of learning so everyone can realize the life they imagine. We do this by creating vibrant and enriching learning experiences designed for real-life impact. We are on a journey to be 100 percent digital to meet the changing needs of the global population by developing a new strategy with ambitious targets. To deliver on our strategic vision, we have five business divisions that are the foundation for the long-term growth of the company: Assessment & Qualifications, Virtual Learning, English Language Learning, Workforce Skills and Higher Education. Alongside these, we have our corporate divisions: Digital & Technology, Finance, Global Corporate Marketing & Communications, Human Resources, Legal, Strategy and Direct to Consumer. Learn more at We are Pearson.

We value the power of an inclusive culture and also a strong sense of belonging. We promote a culture where differences are embraced, opportunities are accessible, consideration and respect are the norm and all individuals are supported in reaching their full potential. Through our talent, we believe that diversity, equity and inclusion make us a more innovative and vibrant place to work. People are at the center, and we are committed to building a workplace where talent can learn, grow and thrive.

Pearson is an Affirmative Action and Equal Opportunity Employer and a member of E-Verify. We want a team that represents a variety of backgrounds, perspectives and skills. The more inclusive we are, the better our work will be. All employment decisions are based on qualifications, merit and business need. All qualified applicants will receive consideration for employment without regard to race, ethnicity, color, religion, sex, sexual orientation, gender identity, gender expression, age, national origin, protected veteran status, disability status or any other group protected by law. We strive for a workforce that reflects the diversity of our communities.

To learn more about Pearson's commitment to a diverse and inclusive workforce, navigate to: Diversity, Equity & Inclusion at Pearson.

If you are an individual with a disability and are unable or limited in your ability to use or access our career site as a result of your disability, you may request reasonable accommodations by emailing

Note that the information you provide will stay confidential and will be stored securely. It will not be seen by those involved in making decisions as part of the recruitment process.

Job: TECHNOLOGY

Organization: Corporate Strategy & Technology

Schedule: FULL_TIME

Workplace Type:

Req ID: 16483




  • London, Greater London, United Kingdom Pearson Full time

    Position: Senior Cyber Risk Management Analyst Company: Pearson About Pearson: At Pearson, our mission is to 'add life to a lifetime of learning,' enabling individuals to achieve their envisioned futures. We create dynamic and impactful learning experiences tailored for real-world application. Established in 1844, Pearson has continually evolved to meet the...


  • London, Greater London, United Kingdom Pearson Full time

    Position: Senior Cyber Risk Management Analyst Company: Pearson About Pearson: At Pearson, our mission is to 'add life to a lifetime of learning', enabling individuals to achieve their aspirations. We focus on creating engaging and impactful educational experiences. Established in 1844, Pearson has evolved alongside the educational landscape, employing over...


  • London, Greater London, United Kingdom Pearson Full time

    Position: Senior Cyber Risk Management Analyst Company: Pearson Overview of Pearson: At Pearson, our mission is to 'add life to a lifetime of learning,' enabling individuals to achieve their envisioned futures. We accomplish this by crafting engaging and impactful educational experiences. Established in 1844, Pearson has evolved alongside the changing market...


  • London, Greater London, United Kingdom Cornwallis Elt Ltd Full time

    Job OverviewPosition: Third Party Risk Analyst - Financial Services, TPRM, Policies, Regulation, Vendor Management Cornwallis Elt Ltd is seeking a skilled Third Party Risk Analyst to enhance our operations within the financial services sector. In this role, you will collaborate closely with the Head of Procurement & Outsourcing, contributing to a newly...


  • London, Greater London, United Kingdom Cornwallis Elt Ltd Full time

    Position OverviewThird Party Risk Analyst - Financial Sector, TPRM, Policies, Compliance, Vendor Oversight - Permanent Role Cornwallis Elt Ltd is seeking a dedicated Third Party Risk Analyst to enhance our operations within the financial services sector. In this role, you will collaborate closely with the Head of Procurement & Outsourcing, contributing to...


  • London, Greater London, United Kingdom Cornwallis Elt Ltd Full time

    Position OverviewThird Party Risk Analyst - Financial Sector, TPRM, Policies, Regulations, Vendor Oversight - Permanent Position - Competitive Salary Package Cornwallis Elt Ltd is seeking a dedicated Third Party Risk Analyst to enhance our operations within the financial services domain. In this role, you will assist the Head of Procurement & Outsourcing in...


  • London, Greater London, United Kingdom Cornwallis Elt Ltd Full time

    Position OverviewThird Party Risk Analyst - Financial Services, TPRM, Policies, Regulation, Vendor Management - Permanent Role Cornwallis Elt Ltd is seeking a skilled Third Party Risk Analyst to contribute to our operations in the financial services sector. In this role, you will collaborate closely with the Head of Procurement & Outsourcing to develop and...


  • London, Greater London, United Kingdom Cornwallis Elt Ltd Full time

    Position OverviewThird Party Risk Analyst - Financial Sector, TPRM, Policies, Compliance, Vendor Oversight - Permanent Position - Competitive Salary Cornwallis Elt Ltd is seeking a skilled Third Party Risk Analyst to enhance our team. This role is pivotal in supporting the Head of Procurement & Outsourcing within a newly formed department. Your primary...


  • London, Greater London, United Kingdom Cornwallis Elt Ltd Full time

    Position OverviewThird Party Risk Analyst - Financial Sector, TPRM, Policies, Compliance, Vendor Oversight - Permanent Role Cornwallis Elt Ltd is seeking a dedicated Third Party Risk Analyst to enhance our operational capabilities within the financial services sector. In this role, you will collaborate closely with the Head of Procurement & Outsourcing to...


  • London, Greater London, United Kingdom Pearson Full time

    Position: Senior Cyber Risk Assessment Specialist Company Overview: Pearson is dedicated to enhancing the educational journey of individuals by providing impactful learning experiences. Founded in 1844, our organization has evolved to meet the demands of a dynamic market, with over 20,000 employees committed to delivering high-quality, accessible resources...


  • London, Greater London, United Kingdom CMC Markets UK Plc Full time

    Position OverviewThird-Party Risk Management (TPRM) is an emerging discipline within CMC Markets UK Plc, and we are establishing a dedicated team within our Procurement department to thoroughly assess and address the risks associated with our vendors.As a Third Party Risk Analyst, you will play a pivotal role in this strategic initiative. Your...


  • London, Greater London, United Kingdom Cognita Asia Holdings Pte Ltd Full time

    Cyber Security Senior Analyst (Incident Response)About Cognita Cognita is a prominent global entity in the field of independent education. Established in 2004, we have evolved into a thriving network of over 100 educational institutions across 16 countries, including regions in Europe, North America, Latin America, Asia, and the Middle East, catering to more...


  • London, Greater London, United Kingdom Cognita Asia Holdings Pte Ltd Full time

    Cyber Security Senior Analyst (Incident Response)About CognitaCognita is a prominent entity in the realm of independent education, established in 2004. We are a dynamic network of over 100 educational institutions across 16 countries, catering to more than 85,000 learners. While each of our schools has its unique identity, our unified mission is to foster an...


  • London, Greater London, United Kingdom Cognita Asia Holdings Pte Ltd Full time

    About CognitaCognita is a prominent global entity in the field of independent education. Established in 2004, we have expanded to a community of over 100 schools across 16 countries, including regions in Europe, North America, Latin America, Asia, and the Middle East, catering to more than 85,000 students. Each institution within our network is distinct, yet...


  • London, Greater London, United Kingdom Close Brothers Group Full time

    OVERALL SUMMARYAt Close Brothers we look to recruit individuals from all different backgrounds and encourage you to apply even if you don't tick every box. We celebrate diversity, promote inclusivity and are open to discuss flexible work options to help you balance your work and home life.In this role, you will be responsible for leading the groupwide second...


  • London, Greater London, United Kingdom Cognita Asia Holdings Pte Ltd Full time

    Cyber Security Senior Analyst (Incident Response)About Cognita Cognita is a prominent figure in the realm of independent education, with a diverse network of over 100 schools across 16 countries, catering to more than 85,000 students. Our mission is to foster an environment where individuals can thrive amidst the rapid changes of the modern world.We are...


  • London, Greater London, United Kingdom Cognita Asia Holdings Pte Ltd Full time

    Cyber Security Senior Analyst (Incident Response)Position Overview:In the role of Cyber Security Senior Analyst, you will focus on the proactive oversight and enhancement of our technical security architecture. Your experience in managing cyber incidents on a global scale will be crucial for ensuring prompt and effective mitigation of threats. Proficiency in...


  • London, Greater London, United Kingdom Cognita Asia Holdings Pte Ltd Full time

    About CognitaCognita is a prominent figure in the realm of independent education. Established in 2004, we have evolved into a network of over 100 schools across 16 countries, including regions in Europe, North America, Latin America, Asia, and the Middle East, catering to more than 85,000 students. While each of our institutions boasts its own unique...


  • London, Greater London, United Kingdom Pearson Full time

    Position: Senior Cyber Risk Assessment Specialist Company: Pearson About Pearson: At Pearson, our mission is to 'add life to a lifetime of learning', enabling individuals to achieve their aspirations. We are dedicated to crafting engaging and impactful educational experiences that resonate in real-world scenarios. Established in 1844, Pearson has continually...


  • London, Greater London, United Kingdom Cognita Schools Full time

    About Cognita SchoolsCognita Schools is a prominent entity in the realm of independent education. With a foundation established in 2004, we have expanded into a vibrant network of over 100 educational institutions across 16 countries, including regions in Europe, North America, Latin America, Asia, and the Middle East, catering to more than 85,000...