Pearson
Specialist, Application Security
About This Role
About Pearson
Pearson VUE is a global leader in secure, computer-based testing and assessment services. Founded in 1994 and acquired by Pearson in 2000, the company specializes in delivering high-stakes professional certification and licensure exams across various industries. With nearly 20,000 test centers in over 180 countries, Pearson VUE also offers online remote proctoring through its OnVUE platform. As a subsidiary of Pearson plc, Pearson VUE provides a comprehensive range of testing services, including exam lifecycle management, candidate registration, and secure exam delivery. The company supports sectors such as information technology, healthcare, finance, and government, offering customized testing solutions that meet industry standards. Pearson VUE is dedicated to enhancing the candidate experience through continuous innovation in testing technology and preparation resources. Its mission focuses on empowering individuals through professional credentials, contributing to workforce development and public safety globally.
Security at Pearson
Compiled from public job postings, careers pages, and company materials. Data may not reflect current state — verify during interviews.
Security Philosophy
- Pearson's Application Security mission is to lead the design, implementation, and continuous improvement of its global Application Security program, committed to the security and availability of its online learning applications.
- Their approach emphasizes embedding security into every stage of CI/CD pipelines and publishing 'paved road' toolchains, reference architectures, and code libraries to enable developers.
- The risk philosophy includes defining OKRs and SLAs for vulnerability remediation, with the Application Security team responsible for the security of Pearson learning management applications.
- Stated goals include building and enhancing automation pipelines for real-time vulnerability detection and remediation, and providing security training to developers via various formats.
Security Team
Pearson's AppSec team reports to the VP, Head of Engineering – PSG. The team structure involves managing local application security teams and aligning them with the broader global Application Security organization. Key public-facing leaders are not publicly available. The team size estimate is also not publicly available, based on a LinkedIn search. As of, there are at least 2 active AppSec-focused job postings: 'Application Security -Technical Lead' and 'Director of Engineering – Security & Compliance Engineering'. Common skill/tool patterns from job postings include driving adoption and integration of SAST, DAST, SCA, IaC security, container scanning, RASP, and secret scanning tools, along with hands-on experience integrating controls into developer workflows (policy-as-code, pipelines, pre-commit/pre-merge checks).
Key Initiatives
- Pearson has a Security Champions Program, with evidence found that they 'Lead the Developer Security Champion program'.
- Their 'Shift Left' practices involve embedding security into every stage of CI/CD pipelines and driving 'shift-left' security through reusable CI/CD templates.
- The vulnerability management process includes intake via static code vulnerability scanning tools like Veracode and dynamic web application security vulnerability scanning tools such as IBM AppScan and WhiteHat.
- For triage/remediation, they 'Define OKRs and SLAs for vulnerability remediation'.
- Secure SDLC artifacts include architecting and institutionalizing secure SDLC practices and providing security training to Pearson's developer community.
- No recent initiatives (last 6 months) were publicly available.
Preparing for an AppSec interview?
Get the weekly briefing 2,000+ security pros trust.
Interested in this role?
Apply on LinkedIn