×
Register Here to Apply for Jobs or Post Jobs. X
More jobs:

Lead Specialist, Internal Audit, Controls, Compliance and Risk

Job in Bismarck, Burleigh County, North Dakota, 58502, USA
Listing for: Pearson
Full Time position
Listed on 2026-08-12
Job specializations:
  • IT/Tech
    Cybersecurity
Salary/Wage Range or Industry Benchmark: 90000 - 150000 USD Yearly USD 90000.00 150000.00 YEAR
Job Description & How to Apply Below

Pearson Virtual Schools operates audited platforms that serve schools, teachers, and students, in which audit readiness and a defensible control environment are not optional. This role is the dedicated owner of audit response and governance, risk, and compliance (GRC) for our platforms.

As Staff, Governance, Risk & Compliance, you own the response across the internal audit lifecycle, SOC 2 (Types 1 and
2), the risk register, and the business continuity and disaster recovery (BC/DR) program. You set evidence and attestation standards across service owners, translate findings into tracked remediation, and partner with internal audit, cybersecurity, privacy, risk, and legal.

This is a senior individual contributor role. It sits independently of the operational security team; it assures that the team operates the controls, and you independently verify and attest to them. You also have a dotted-line relationship to the Lead, Service Operations & Cyber Risk for day-to-day coordination.

Key Responsibilities Internal Audit & SOC 2 Leadership
  • Lead the response across the audit lifecycle, including planning, fieldwork coordination, and reviewing draft observations, root causes, and risks.
  • Challenge observation and management action plan ownership, wording, and feasibility, and draft and submit audit-closure proposals with stakeholder alignment.
  • Own SOC 2 (Type 1 and Type
    2) coordination, including planning and bringing additional platforms into scope. Review evidence and send weak submissions back for rework.
  • Work with partner teams to ensure resources are assigned and aligned, and continually work with them on gaps and help them close them.
Controls, Evidence & Remediation
  • Set standards for evidence, attestation, and documentation across services.
  • Translate findings into structured remediation plans with owners, due dates, and evidence requirements, tracked to closure.
  • Maintain the audit-action tracker and hold action owners accountable, challenging weak ownership and unrealistic timelines.
  • Coordinate audit actions owned by other teams across the organization and keep them visible to closure.
  • Govern the configuration management database (CMDB, the inventory of services and their dependencies) for audit scope, keeping ownership and classification accurate. Solution Architecture operates and maintains it.
Risk & Resilience Governance
  • Own the risk register, including quality, owners, clear write-ups, closure, and escalation of risks beyond tolerance.
  • Turn access-review and vulnerability gaps into formal risks or audit actions where appropriate.
  • Govern the business continuity and disaster recovery program, including impact analyses, coverage and gaps, vendor continuity, annual reviews, and tabletop exercises, and executive attestation.
Cross-Functional Influence & Reporting
  • Partner with internal audit, cybersecurity, privacy, risk, and legal to close findings and prevent repeat observations.
  • Prepare audit and GRC status updates for monthly operations reviews, covering open actions, overdue items, blockers, and risks.
  • Advise service owners and coach peers on governance expectations, acting as an objective assurance partner.
What You Will Bring
  • 5 or more years in internal audit, controls, compliance, or risk (IT audit or GRC strongly preferred)
  • Hands-on coordination of SOC 2 (or SOX) programs, including evidence and attestation management
  • Demonstrated ownership of a risk register and the risk-management lifecycle
  • Experience governing or supporting business continuity and disaster recovery (impact analyses, plans, tabletops, attestation)
  • A professional qualification is expected or strongly preferred (CISA, CIA, CRISC, ACA/ACCA, or CISSP)
  • Proven ability to challenge peers and leaders and to represent the organization to external auditors
  • Experience in EdTech, SaaS, regulated, or highly distributed environments is a plus; familiarity with NIST CSF or ISO 22301 is a plus
  • Bachelor's degree in a relevant field; advanced degree a plus
Key Behaviors & Attributes

Independent & Objective: You bring professional skepticism and integrity, and you hold the line on audit-readiness.

Business-Enabling: You approach assurance as a means of enabling the business, not policing it, while staying objective.

Influence Without Authority: You push peers and leaders to own and close actions, challenging weak ownership and unrealistic timelines.

Continuous Improvement: You bring proven GRC frameworks and improve governance without slowing delivery.

Collaborative: You partner across security, engineering, privacy, legal, and internal audit to build a consistent control environment.

Key Relationships

Direct Reports: None. This is a senior individual contributor role.

Peers: The security operations lead, incident and service operations leads, manager of data governance, internal audit leads, and cybersecurity leads

Cross-functional: Internal audit, cybersecurity, privacy, risk, legal, engineering, product, and service owners

External: External auditors and vendors

Pearson is an equal…

To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary