AppSec Jobs
← Back to all jobs

Pearson

Specialist, Application Security

Bengaluru East, Karnataka, IndiaPosted 6 days agoWebsite
Apply on LinkedIn →

About This Role

The job posting indicates that this Specialist, Application Security position has expired. The markdown content provided contains only a notice of expiration and links to other related job openings at Pearson, without detailed job description content.

About Pearson

Pearson VUE is a global leader in secure, computer-based testing and assessment services. Founded in 1994 and acquired by Pearson in 2000, the company specializes in delivering high-stakes professional certification and licensure exams across various industries. With nearly 20,000 test centers in over 180 countries, Pearson VUE also offers online remote proctoring through its OnVUE platform. As a subsidiary of Pearson plc, Pearson VUE provides a comprehensive range of testing services, including exam lifecycle management, candidate registration, and secure exam delivery. The company supports sectors such as information technology, healthcare, finance, and government, offering customized testing solutions that meet industry standards. Pearson VUE is dedicated to enhancing the candidate experience through continuous innovation in testing technology and preparation resources. Its mission focuses on empowering individuals through professional credentials, contributing to workforce development and public safety globally.

Industry

information technology & services

Employees

2,600

46 engineers

Revenue

$700M

Website

Visit →

Security at Pearson

Compiled from public job postings, careers pages, and company materials. Data may not reflect current state — verify during interviews.

3 Intel Signals

Security Philosophy

  • Pearson's Application Security mission is to lead the design, implementation, and continuous improvement of its global Application Security program, committed to the security and availability of its online learning applications.
  • Their approach emphasizes embedding security into every stage of CI/CD pipelines and publishing 'paved road' toolchains, reference architectures, and code libraries to enable developers.
  • The risk philosophy includes defining OKRs and SLAs for vulnerability remediation, with the Application Security team responsible for the security of Pearson learning management applications.
  • Stated goals include building and enhancing automation pipelines for real-time vulnerability detection and remediation, and providing security training to developers via various formats.

Security Team

Pearson's AppSec team reports to the VP, Head of Engineering – PSG. The team structure involves managing local application security teams and aligning them with the broader global Application Security organization. Key public-facing leaders are not publicly available. The team size estimate is also not publicly available, based on a LinkedIn search. As of, there are at least 2 active AppSec-focused job postings: 'Application Security -Technical Lead' and 'Director of Engineering – Security & Compliance Engineering'. Common skill/tool patterns from job postings include driving adoption and integration of SAST, DAST, SCA, IaC security, container scanning, RASP, and secret scanning tools, along with hands-on experience integrating controls into developer workflows (policy-as-code, pipelines, pre-commit/pre-merge checks).

Key Initiatives

  • Pearson has a Security Champions Program, with evidence found that they 'Lead the Developer Security Champion program'.
  • Their 'Shift Left' practices involve embedding security into every stage of CI/CD pipelines and driving 'shift-left' security through reusable CI/CD templates.
  • The vulnerability management process includes intake via static code vulnerability scanning tools like Veracode and dynamic web application security vulnerability scanning tools such as IBM AppScan and WhiteHat.
  • For triage/remediation, they 'Define OKRs and SLAs for vulnerability remediation'.
  • Secure SDLC artifacts include architecting and institutionalizing secure SDLC practices and providing security training to Pearson's developer community.
  • No recent initiatives (last 6 months) were publicly available.

Preparing for an AppSec interview?

Get the weekly briefing 2,000+ security pros trust.

Interested in this role?

Apply on LinkedIn