Demo

Lead Specialist, Internal Audit, Controls, Compliance and Risk

Pearson
Montgomery, AL Full Time
POSTED ON 8/7/2026
AVAILABLE BEFORE 9/4/2026

Role Overview



Pearson Virtual Schools operates audited platforms that serve schools, teachers, and students, in which audit readiness and a defensible control environment are not optional. This role is the dedicated owner of audit response and governance, risk, and compliance (GRC) for our platforms.



As Staff, Governance, Risk & Compliance, you own the response across the internal audit lifecycle, SOC 2 (Types 1 and 2), the risk register, and the business continuity and disaster recovery (BC/DR) program. You set evidence and attestation standards across service owners, translate findings into tracked remediation, and partner with internal audit, cybersecurity, privacy, risk, and legal.



This is a senior individual contributor role. It sits independently of the operational security team; it assures that the team operates the controls, and you independently verify and attest to them. You also have a dotted-line relationship to the Lead, Service Operations & Cyber Risk for day-to-day coordination.



Key Responsibilities



Internal Audit & SOC 2 Leadership



  • Lead the response across the audit lifecycle, including planning, fieldwork coordination, and reviewing draft observations, root causes, and risks.


  • Challenge observation and management action plan ownership, wording, and feasibility, and draft and submit audit-closure proposals with stakeholder alignment.


  • Own SOC 2 (Type 1 and Type 2) coordination, including planning and bringing additional platforms into scope. Review evidence and send weak submissions back for rework.


  • Work with partner teams to ensure resources are assigned and aligned, and continually work with them on gaps and help them close them.


Controls, Evidence & Remediation



  • Set standards for evidence, attestation, and documentation across services.


  • Translate findings into structured remediation plans with owners, due dates, and evidence requirements, tracked to closure.


  • Maintain the audit-action tracker and hold action owners accountable, challenging weak ownership and unrealistic timelines.


  • Coordinate audit actions owned by other teams across the organization and keep them visible to closure.


  • Govern the configuration management database (CMDB, the inventory of services and their dependencies) for audit scope, keeping ownership and classification accurate. Solution Architecture operates and maintains it.


Risk & Resilience Governance



  • Own the risk register, including quality, owners, clear write-ups, closure, and escalation of risks beyond tolerance.


  • Turn access-review and vulnerability gaps into formal risks or audit actions where appropriate.


  • Govern the business continuity and disaster recovery program, including impact analyses, coverage and gaps, vendor continuity, annual reviews, and tabletop exercises, and executive attestation.


Cross-Functional Influence & Reporting



  • Partner with internal audit, cybersecurity, privacy, risk, and legal to close findings and prevent repeat observations.


  • Prepare audit and GRC status updates for monthly operations reviews, covering open actions, overdue items, blockers, and risks.


  • Advise service owners and coach peers on governance expectations, acting as an objective assurance partner.


What You Will Bring



  • 5 or more years in internal audit, controls, compliance, or risk (IT audit or GRC strongly preferred)


  • Hands-on coordination of SOC 2 (or SOX) programs, including evidence and attestation management


  • Demonstrated ownership of a risk register and the risk-management lifecycle


  • Experience governing or supporting business continuity and disaster recovery (impact analyses, plans, tabletops, attestation)


  • A professional qualification is expected or strongly preferred (CISA, CIA, CRISC, ACA/ACCA, or CISSP)


  • Proven ability to challenge peers and leaders and to represent the organization to external auditors


  • Experience in EdTech, SaaS, regulated, or highly distributed environments is a plus; familiarity with NIST CSF or ISO 22301 is a plus


  • Bachelor's degree in a relevant field; advanced degree a plus


Key Behaviors & Attributes



Independent & Objective: You bring professional skepticism and integrity, and you hold the line on audit-readiness.



Business-Enabling: You approach assurance as a means of enabling the business, not policing it, while staying objective.



Influence Without Authority: You push peers and leaders to own and close actions, challenging weak ownership and unrealistic timelines.



Continuous Improvement: You bring proven GRC frameworks and improve governance without slowing delivery.



Collaborative: You partner across security, engineering, privacy, legal, and internal audit to build a consistent control environment.



Key Relationships



Direct Reports: None. This is a senior individual contributor role.



Peers: The security operations lead, incident and service operations leads, manager of data governance, internal audit leads, and cybersecurity leads



Cross-functional: Internal audit, cybersecurity, privacy, risk, legal, engineering, product, and service owners



External: External auditors and vendors



Pearson is an equal opportunity employer. We celebrate diversity and are committed to creating an inclusive environment for all employees. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or veteran status.



Who we are:



At Pearson, our purpose is simple: to help people realize the life they imagine through learning. We believe that every learning opportunity is a chance for a personal breakthrough. We are the world's lifelong learning company. For us, learning isn't just what we do. It's who we are. To learn more: We are Pearson.



Pearson is an Equal Opportunity Employer and a member of E-Verify. Employment decisions are based on qualifications, merit and business need. Qualified applicants will receive consideration for employment without regard to race, ethnicity, color, religion, sex, sexual orientation, gender identity, gender expression, age, national origin, protected veteran status, disability status or any other group protected by law. We actively seek qualified candidates who are protected veterans and individuals with disabilities as defined under VEVRAA and Section 503 of the Rehabilitation Act.



If you are an individual with a disability and are unable or limited in your ability to use or access our career site as a result of your disability, you may request reasonable accommodations by emailing TalentExperienceGlobalTeam@grp.pearson.com.



Job: Finance



Job Family: ENTERPRISE



Organization: Virtual Learning



Schedule: FULL_TIME



Workplace Type: Remote



Req ID: 25219



#location

Salary.com Estimation for Lead Specialist, Internal Audit, Controls, Compliance and Risk in Montgomery, AL
$78,287 to $94,505
If your compensation planning software is too rigid to deploy winning incentive strategies, it’s time to find an adaptable solution. Compensation Planning
Enhance your organization's compensation strategy with salary data sets that HR and team managers can use to pay your staff right. Surveys & Data Sets

What is the career path for a Lead Specialist, Internal Audit, Controls, Compliance and Risk?

Sign up to receive alerts about other jobs on the Lead Specialist, Internal Audit, Controls, Compliance and Risk career path by checking the boxes next to the positions that interest you.
Income Estimation: 
$94,633 - $115,926
Income Estimation: 
$116,408 - $144,065
Income Estimation: 
$74,781 - $93,224
Income Estimation: 
$94,633 - $115,926
Employees: Get a Salary Increase
View Core, Job Family, and Industry Job Skills and Competency Data for more than 15,000 Job Titles Skills Library

Job openings at Pearson

  • Pearson Bismarck, ND
  • Under the direction of the Supervisor, Training and Quality, the Quality & Training Coordinator is responsible for Operations training and documentation, c... more
  • Just Posted

  • Pearson Montpelier, VT
  • About the Team Our charter is simple to state and ambitious to deliver: build what Pearson does next. We are a small, newly formed team within Pearson's En... more
  • Just Posted

  • Pearson Montpelier, VT
  • At Pearson, we’re committed to a world that’s always learning and to our talented team who makes it all possible. Role summary The Advanced Specialist, Imp... more
  • Just Posted

  • Pearson Providence, RI
  • About the Team Our charter is simple to state and ambitious to deliver: build what Pearson does next. We are a small, newly formed team within Pearson's En... more
  • Just Posted


Not the job you're looking for? Here are some other Lead Specialist, Internal Audit, Controls, Compliance and Risk jobs in the Montgomery, AL area that may be a better fit.

  • Sanders Lead Company Troy, AL
  • Job Summary: The Safety Specialist is responsible for promoting and maintaining a safe, healthy, and environmentally compliant workplace. This position sup... more
  • 19 Days Ago

  • Old Republic Commercial Risk Montgomery, AL
  • As a member of our Claims team, you will proactively manage medical only and limited lost time claims in order to minimize losses, manage permanent total c... more
  • 5 Days Ago

AI Assistant is available now!

Feel free to start your new journey!