{"schemaVersion":"jobsearcher.job.v1","id":"20c04c00a8cd4fbf39a2d868","url":"https://jobsearcher.com/jobs/20c04c00a8cd4fbf39a2d868","canonicalUrl":"https://jobsearcher.com/jobs/20c04c00a8cd4fbf39a2d868","title":"Manager, Security Operations","description":"Job Description Role: Manager, Security Operations\n\nLocation: United States (Hybrid - Durham, NC)\n\nDepartment: Cybersecurity - Security Operations\n\nReports to: Senior Director, Security Operations\n\nRole Overview\nThe Manager, Security Operations is responsible for the operational delivery, governance, and assurance of cybersecurity services provided to government, public sector, and highly regulated Pearson customers . This role acts as the primary Security Operations point of accountability for these clients, ensuring that Pearson meets contractual, regulatory, and assurance obligations while maintaining a strong security posture.\n\nThe role combines SOC leadership, stakeholder management, regulatory alignment, and incident oversight , working closely with internal SOC teams, GRC, Legal, Product, and Customer teams, as well as external auditors and government stakeholders.\n\nKey Responsibilities\nGovernment & Public Sector Client Management\n\nAct as the primary Security Operations contact for government and regulated customers, supporting security assurance discussions, audits, and contractual obligations.\n\nOwn the operational security relationship with public sector clients, including response to security questionnaires, evidence requests, and assurance reviews.\n\nEnsure SOC services align with government security expectations , contractual SLAs, and regulatory requirements (e.g. FedRAMP-adjacent controls, ISO, SOC, regional equivalents where applicable).\n\nSecurity Operations Oversight\n\nProvide operational leadership across SOC functions supporting government and regulated environments, including:\n\nMonitoring and detection\n\nIncident response coordination\n\nAccess governance and periodic reviews\n\nVulnerability and risk tracking\n\nEnsure consistent, auditable execution of SOC processes aligned to approved runbooks and playbooks.\n\nOversee escalation handling for security events impacting regulated customers, ensuring timely, accurate, and compliant communications.\n\nIncident Response & Regulatory Support\n\nLead or coordinate incident response activities involving government or regulated customers, including:\n\nTriage and containment oversight\n\nExecutive and customer communications\n\nPost-incident reporting and lessons learned\n\nPartner with Legal, GRC, and Communications teams to support regulatory notifications and customer disclosures where required.\n\nAssurance, Reporting & Evidence Management\n\nOwn delivery of security reporting and evidence for government clients, including:\n\nAccess reviews\n\nIncident summaries\n\nControl effectiveness metrics\n\nEnsure SOC data used for external reporting is accurate, validated, and defensible .\n\nSupport internal and external audits relevant to government and regulated customers.\n\nStakeholder & Cross-Functional Leadership\n\nAct as a trusted advisor to:\n\nGovernment customer stakeholders\n\nInternal Product and Engineering teams\n\nGRC, Legal, and Privacy partners\n\nTranslate complex SOC operations into clear, non-technical risk and assurance narratives for customers and leadership.\n\nContinuous Improvement & Risk Reduction\n\nIdentify systemic risks or control gaps affecting regulated environments and drive remediation through SOC and engineering teams.\n\nContribute to the evolution of SOC processes, tooling, and reporting to better support government and regulated use cases.\n\nMentor SOC team members on regulatory awareness, evidence quality, and customer-facing security operations.\n\nSkills & Experience\nRequired\n\nProven experience in Security Operations or Incident Response leadership roles.\n\nStrong understanding of security controls, monitoring, and incident management in regulated environments.\n\nDemonstrated experience supporting government or highly regulated customers .\n\nExcellent stakeholder management and written communication skills, particularly for audit and customer-facing contexts.\n\nAbility to translate technical security issues into clear risk-based explanations for non-technical audiences.\n\nDesirable\n\nExperience supporting audits or frameworks such as ISO 27001, SOC 2, FedRAMP-aligned environments, or similar .\n\nFamiliarity with SOC tooling (SIEM, EDR, SOAR) and access governance processes.\n\nPrior experience working with Legal, Privacy, or Compliance teams during security incidents.\n\nWhat Success Looks Like\n\nGovernment and regulated customers have high confidence in Pearson's Security Operations capability.\n\nSecurity incidents involving regulated clients are managed professionally, consistently, and compliantly .\n\nAudit and assurance requests are handled efficiently with high-quality evidence .\n\nSOC processes supporting regulated environments are repeatable, documented, and defensible .\n\nApplications will be accepted through 5/26/2026. This window may be extended depending on business needs.\n\nCompensation for this position is influenced by a wide array of factors including but not limited to skill set, level of experience, and specific location. As required by the California, Colorado, Hawaii, Illinois, Maryland, Minnesota, New Jersey, New York State, New York City, Vermont, Washington State, and Washington DC laws, the pay range for this position is between $130,000 and $140,000.\n\nThis position is eligible to participate in an annual incentive program, and information on benefits offered is here.\n\nEqual Opportunity Employer Statement\nPearson is an Equal Opportunity Employer and a member of E-Verify. Employment decisions are based on qualifications, merit and business need. Qualified applicants will receive consideration for employment without regard to race, ethnicity, color, religion, sex, sexual orientation, gender identity, gender expression, age, national origin, protected veteran status, disability status or any other group protected by law. We actively seek qualified candidates who are protected veterans and individuals with disabilities as defined under VEVRAA and Section 503 of the Rehabilitation Act.\n\nIf you are an individual with a disability and are unable or limited in your ability to use or access our career site as a result of your disability, you may request reasonable accommodations by emailing TalentExperienceGlobalTeam@.\n\n#J-18808-Ljbffr","company":"Broughton Group","rawCompany":"broughton group","city":"East Boston","state":"MA","isRemote":false,"isActive":false,"createdAt":"2026-06-20T03:28:33.425Z","occupations":[{"code":"11-3013.01","title":"Security Managers","slug":"security-managers"},{"code":"13-1199.07","title":"Security Management Specialists","slug":"security-management-specialists"},{"code":"15-1212.00","title":"Information Security Analysts","slug":"information-security-analysts"}],"industries":[{"code":"541512","title":"Computer Systems Design Services","slug":"computer-systems-design-services"},{"code":"541690","title":"Other Scientific and Technical Consulting Services","slug":"other-scientific-and-technical-consulting-services"},{"code":"561621","title":"Security Systems Services (except Locksmiths)","slug":"security-systems-services-except-locksmiths"}],"jobPosting":{"@context":"https://schema.org","@type":"JobPosting","title":"Manager, Security Operations","description":"Job Description Role: Manager, Security Operations\n\nLocation: United States (Hybrid - Durham, NC)\n\nDepartment: Cybersecurity - Security Operations\n\nReports to: Senior Director, Security Operations\n\nRole Overview\nThe Manager, Security Operations is responsible for the operational delivery, governance, and assurance of cybersecurity services provided to government, public sector, and highly regulated Pearson customers . This role acts as the primary Security Operations point of accountability for these clients, ensuring that Pearson meets contractual, regulatory, and assurance obligations while maintaining a strong security posture.\n\nThe role combines SOC leadership, stakeholder management, regulatory alignment, and incident oversight , working closely with internal SOC teams, GRC, Legal, Product, and Customer teams, as well as external auditors and government stakeholders.\n\nKey Responsibilities\nGovernment & Public Sector Client Management\n\nAct as the primary Security Operations contact for government and regulated customers, supporting security assurance discussions, audits, and contractual obligations.\n\nOwn the operational security relationship with public sector clients, including response to security questionnaires, evidence requests, and assurance reviews.\n\nEnsure SOC services align with government security expectations , contractual SLAs, and regulatory requirements (e.g. FedRAMP-adjacent controls, ISO, SOC, regional equivalents where applicable).\n\nSecurity Operations Oversight\n\nProvide operational leadership across SOC functions supporting government and regulated environments, including:\n\nMonitoring and detection\n\nIncident response coordination\n\nAccess governance and periodic reviews\n\nVulnerability and risk tracking\n\nEnsure consistent, auditable execution of SOC processes aligned to approved runbooks and playbooks.\n\nOversee escalation handling for security events impacting regulated customers, ensuring timely, accurate, and compliant communications.\n\nIncident Response & Regulatory Support\n\nLead or coordinate incident response activities involving government or regulated customers, including:\n\nTriage and containment oversight\n\nExecutive and customer communications\n\nPost-incident reporting and lessons learned\n\nPartner with Legal, GRC, and Communications teams to support regulatory notifications and customer disclosures where required.\n\nAssurance, Reporting & Evidence Management\n\nOwn delivery of security reporting and evidence for government clients, including:\n\nAccess reviews\n\nIncident summaries\n\nControl effectiveness metrics\n\nEnsure SOC data used for external reporting is accurate, validated, and defensible .\n\nSupport internal and external audits relevant to government and regulated customers.\n\nStakeholder & Cross-Functional Leadership\n\nAct as a trusted advisor to:\n\nGovernment customer stakeholders\n\nInternal Product and Engineering teams\n\nGRC, Legal, and Privacy partners\n\nTranslate complex SOC operations into clear, non-technical risk and assurance narratives for customers and leadership.\n\nContinuous Improvement & Risk Reduction\n\nIdentify systemic risks or control gaps affecting regulated environments and drive remediation through SOC and engineering teams.\n\nContribute to the evolution of SOC processes, tooling, and reporting to better support government and regulated use cases.\n\nMentor SOC team members on regulatory awareness, evidence quality, and customer-facing security operations.\n\nSkills & Experience\nRequired\n\nProven experience in Security Operations or Incident Response leadership roles.\n\nStrong understanding of security controls, monitoring, and incident management in regulated environments.\n\nDemonstrated experience supporting government or highly regulated customers .\n\nExcellent stakeholder management and written communication skills, particularly for audit and customer-facing contexts.\n\nAbility to translate technical security issues into clear risk-based explanations for non-technical audiences.\n\nDesirable\n\nExperience supporting audits or frameworks such as ISO 27001, SOC 2, FedRAMP-aligned environments, or similar .\n\nFamiliarity with SOC tooling (SIEM, EDR, SOAR) and access governance processes.\n\nPrior experience working with Legal, Privacy, or Compliance teams during security incidents.\n\nWhat Success Looks Like\n\nGovernment and regulated customers have high confidence in Pearson's Security Operations capability.\n\nSecurity incidents involving regulated clients are managed professionally, consistently, and compliantly .\n\nAudit and assurance requests are handled efficiently with high-quality evidence .\n\nSOC processes supporting regulated environments are repeatable, documented, and defensible .\n\nApplications will be accepted through 5/26/2026. This window may be extended depending on business needs.\n\nCompensation for this position is influenced by a wide array of factors including but not limited to skill set, level of experience, and specific location. As required by the California, Colorado, Hawaii, Illinois, Maryland, Minnesota, New Jersey, New York State, New York City, Vermont, Washington State, and Washington DC laws, the pay range for this position is between $130,000 and $140,000.\n\nThis position is eligible to participate in an annual incentive program, and information on benefits offered is here.\n\nEqual Opportunity Employer Statement\nPearson is an Equal Opportunity Employer and a member of E-Verify. Employment decisions are based on qualifications, merit and business need. Qualified applicants will receive consideration for employment without regard to race, ethnicity, color, religion, sex, sexual orientation, gender identity, gender expression, age, national origin, protected veteran status, disability status or any other group protected by law. We actively seek qualified candidates who are protected veterans and individuals with disabilities as defined under VEVRAA and Section 503 of the Rehabilitation Act.\n\nIf you are an individual with a disability and are unable or limited in your ability to use or access our career site as a result of your disability, you may request reasonable accommodations by emailing TalentExperienceGlobalTeam@.\n\n#J-18808-Ljbffr","datePosted":"2026-06-20T03:28:33.425Z","dateModified":"2026-06-20T03:28:33.425Z","hiringOrganization":{"@type":"Organization","name":"Broughton Group","sameAs":"https://jobsearcher.com"},"jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"East Boston","addressRegion":"MA","addressCountry":"US"}},"identifier":{"@type":"PropertyValue","name":"JobSearcher","value":"20c04c00a8cd4fbf39a2d868"},"url":"https://jobsearcher.com/jobs/20c04c00a8cd4fbf39a2d868"}}