Full-Time

Business Solution Consultant

Deadline 7/13/27
PowerSchool Group

PowerSchool Group

1,001-5,000 employees

AI-driven cloud-based K-12 education software platform

Compensation Overview

$63.9k - $119.2k/yr

United States

In Person

Travel is extensive at 60–75%, with weekly customer visits common.

Bachelor's

Category
Consulting (1)
Required Skills
ERP
Data Visualization
CRM
Salesforce
SAML
REST APIs
Data Analysis

Get referred to PowerSchool Group

See people who can refer or advise you

Requirements
  • Working knowledge of one K–12 technical domain, such as Student Information Systems and analytics, learning and engagement, or ERP and talent, and relevant K–12 buyer personas.
  • Understanding of K–12 district operations, funding models, and stakeholder priorities.
  • Ability to co-lead customer demos and workshops and configure common demo scenarios live.
  • Familiarity with integrations and data flows, including APIs, rostering, SFTP, authentication, and basic security controls, with the ability to flag risks.
  • Ability to explain technical topics clearly to non-technical audiences in writing and verbally.
  • Comfort using Salesforce or a similar CRM for notes, artifacts, and basic MEDDPICC capture.
  • Strong organization and time management across multiple live pursuits.
  • At least 4 years of experience in solution consulting, sales engineering, implementation, or a related K–12 SaaS role.
  • A bachelor's degree or equivalent experience.
Responsibilities
  • Build deep expertise in a defined product group and associated buyer personas, act as the primary subject matter expert for active sales opportunities, and represent the appropriate product domain in multi-product pursuits.
  • Partner with Sales Development Representatives and Account Executives in early discovery to qualify opportunities and assess systems, data flows, integration points, and non-functional requirements such as security, scalability, and accessibility.
  • Translate functional requirements into actionable solution designs and configuration options, lead product proofs of concept, and validate solution fit.
  • Document Metrics and Decision Criteria insights aligned with MEDDPICC in the customer relationship management system and pursuit documentation.
  • Provide accurate and comprehensive responses to requests for proposals and requests for information that address functional buyers' needs.
  • Serve as the stock-keeping unit configuration subject matter expert to validate quotes against the proposed solution and customer technical landscape.
  • Design and deliver persona-specific demos, workshops, and proofs of concept aligned with product capabilities, buyer outcomes, and Decision Criteria.
  • Maintain demo environments with current data, reusable scripts, scenario assets, and runbooks that support Sales progression.
  • Prepare detailed post-sale handoff materials for seamless transitions to Services and Customer Success.
  • Provide structured feedback to Product and Enablement teams on gaps, objections, and content needs based on real-world sales cycles.
  • Travel extensively, 60–75%, with weekly customer visits common, including onsite demos and executive workshops.
Desired Qualifications
  • Experience delivering persona-based demos for K–12 buyers such as Superintendent staff, CIO, Curriculum, Finance, HR, and Procurement.
  • Experience contributing to RFPs, RFIs, or security questionnaires in the public sector.
  • Familiarity with EdTech standards and identity models such as Ed-Fi, OneRoster, LTI, SAML, and OIDC.
  • Ability to build simple prototypes or data visualizations to show outcomes and return on investment.
  • Ability to reuse demo assets, runbooks, or checklists that improved team demo quality and consistency.

PowerSchool provides cloud-based K-12 education software that helps schools, districts, and ministries manage instructional planning, data management, attendance, grades, and communication in one platform. Its product combines multiple school operations into a single suite and uses AI to support personalized learning and data-driven decision making. The platform is subscription-based with services, designed to scale across regions (North America, India, Asia Pacific) and to comply with state regulations, enabling long-term partnerships and ongoing upselling opportunities. PowerSchool differentiates itself by offering an integrated, scalable solution that covers both administrative tasks and instructional tools, aiming to improve student success and streamline digital modernization in education.

Company Size

1,001-5,000

Company Stage

Acquired

Total Funding

$742.5M

Headquarters

Folsom, California

Founded

1997

Get referred to PowerSchool Group

See people who can refer or advise you

Simplify Jobs

Simplify's Take

What believers are saying

  • Bain Capital agreed August 6, 2026 to buy PowerSchool for $5.6 billion.
  • Customer trust persists: districts keep migrating, as Belmont Public Schools did July 30, 2026.
  • PowerSchool Mobile updated July 31, 2026, signaling active product maintenance across the installed base.

What critics are saying

  • Texas Attorney General sued PowerSchool on September 3, 2025 over 880,000 exposed Texans.
  • The December 2024 breach spawned a $17.25 million settlement and dozens of lawsuits.
  • A second major breach would trigger mass district defections and existential renewal collapse.

What makes PowerSchool Group unique

  • PowerSchool SIS centralizes grades, attendance, communications, and APIs across districts.
  • PowerBuddy for Engagement, launched April 2025, gives families K-12 answers inside MyPowerHub.
  • Belmont Public Schools switched July 30, 2026, citing simpler UI and faster access.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Health Insurance

Dental Insurance

Vision Insurance

Life Insurance

Disability Insurance

Health Savings Account/Flexible Spending Account

Unlimited Paid Time Off

401(k) Retirement Plan

Generous Parental Leave

Wellness Program

Tuition Reimbursement

Pet Insurance

Identity Theft Protection

Student Loan Assistance

Prepaid Legal coverage

Growth & Insights and Company News

Headcount

6 month growth

0%

1 year growth

1%

2 year growth

0%
EdTech Magazine
Aug 4th, 2026
Protecting student data through smarter vendor risk management.

Protecting student data through smarter vendor risk management. Thousands of Software as a Service tools create risks districts cannot manage equally. A rightsized program starts with visibility and focuses resources where exposure is greatest. Nathan Eddy works as an independent filmmaker and journalist based in Berlin, specializing in architecture, business technology and healthcare IT. He is a graduate of Northwestern University's Medill School of Journalism. Recent breaches involving Canvas and PowerSchool, resulting in the theft of millions of individuals' private information, have intensified attention on third-party technology risk in K-12 education environments. The incidents underscore that a district can protect its own environment and still be exposed through a vendor - a risk difficult to contain when the average district relies on thousands of ed tech tools, many delivered through Software as a Service (SaaS). While small IT teams cannot investigate every provider with the resources of an enterprise security organization, they can build a defensible program by establishing visibility, ranking risks and setting minimum requirements. What the Canvas breach reveals about K-12 vendor risk. Large education platforms concentrate risk because one compromise can affect many customers at once. Matt Leger, research lead for IDC Public Sector's worldwide education and education technology digital strategies, says districts increasingly depend on outside providers to keep daily operations and instruction running. "Schools have become very dependent on third parties to do what they need to do for teaching and learning to happen every day," he says. Moving systems to the cloud may strengthen an individual district's security, but it can also create shared dependencies outside the district's direct control. Vendor reviews should therefore consider not only data protection but also hosting arrangements, redundancy, recovery capabilities and the operational consequences if a widely used provider becomes unavailable. Building a SaaS inventory for your district. Building a SaaS inventory is a strong first step toward better understanding a district's vendor risk profile. Districts should begin with known systems, such as student information, learning management, finance, communications and identity platforms. They should then add classroom tools, browser applications, administrative software and services purchased outside of central IT. The inventory should record the owner, purpose, data handled, users, integrations, hosting environment, authentication method and renewal date for every tool. Mapping connections matters because a compromised application may provide a path into another system. "Without investing in a full cloud access security broker platform, I think the most common and effective way is through the use of unified threat management firewalls to identify which platforms are being accessed," says Chester Wisniewski, director and global field CISO at Sophos. How to tier ed tech vendors by risk level. Districts should not devote equal scrutiny to every application but rather evaluate what type of information is being shared with vendors and then use that to determine which ones to scrutinize most, based on impact. High-risk vendors include those handling regulated or highly sensitive information, supporting mission-critical operations or integrating broadly with other systems. This tier typically includes student information systems, learning management platforms, identity providers and any tool with single sign-on access or broad application programming interface connections. A compromise in any of these can propagate across multiple systems. Tools that collect health, financial or behavioral data on students also belong here, regardless of their operational role. Medium-risk tools may access limited student records or support important but replaceable functions. A tool moves from medium to high risk when its access scope expands, either through broader system integrations, additional data collection at renewal or connections to other platforms. Low-risk products should receive basic review if they use little or no identifiable information. Reference tools, general productivity applications and anonymous content platforms typically fall here, though districts should verify that assumption rather than take it on faith. "Districts should also determine what student data each tool genuinely needs and restrict access accordingly," says Mary Schlegelmilch, business development manager for education at Cisco. That principle applies at the tiering stage; if a tool is requesting more data than its function requires, that itself is a signal worth flagging. Vendors who exhibit high levels of transparency typically have a stronger security culture as well as more mature practices." Chester Wisniewski Director and Global Field CISO, Sophos Contract language that protects districts before a breach. Security expectations should appear in the request for proposals and remain enforceable in the final agreement. Addressing security requirements at the RFP stage gives districts leverage before a vendor is selected, making it harder for a preferred vendor to negotiate those provisions away after the fact. Once contracts are on the table, they should define authorized access, breach notification deadlines, service levels, backup and recovery obligations, data deletion, audit evidence and each party's incident response responsibilities. For example: * Breach notification windows should be explicit and should require the vendor to notify the district even when the full scope of an incident is not yet known. * Subprocessor disclosure clauses are worth including, as many SaaS vendors rely on their own third parties to deliver the service, and those relationships extend the district's exposure. Leger says that, within contracts, districts need to embed requests pertaining to resilient design, which can include zero-trust controls, stronger identity management, reauthentication between sensitive functions and plans for maintaining service during a vendor outage. Right-to-audit provisions support this, giving districts or their representatives the ability to request evidence of security controls rather than relying solely on vendor-provided assurances. Vendor monitoring without enterprise tools. Monitoring can begin with inexpensive, repeatable checks. "The easiest thing is to contact [the vendor] and discover which security and privacy certifications they have achieved and inquire as to which frameworks they use for managing risk," Wisniewski says. Districts can subscribe to vendor security notices, review public incident disclosures and require annual updates from high-risk providers. "Vendors who exhibit high levels of transparency typically have a stronger security culture as well as more mature practices," he adds. He advises districts to document those reviews so they can show how monitoring decisions were made. Shadow IT: finding unapproved apps that store student data. Firewalls, endpoint security and device management systems can reveal cloud and locally installed applications. Districts can compare those discoveries with the approved catalog and investigate exceptions. Leger cautions that technology alone will not expose every tool, particularly when employees and students use personal devices or cellular connections. Schools need a nonpunitive process for educators to disclose what they use. Training should explain why unreviewed tools create risk while recognizing that teachers usually adopt them to solve real instructional problems. An accessible review process gives staff a safer alternative to bypassing central IT. Building a vendor incident response plan for K-12. An incident plan should identify the district owner for each vendor, escalation contacts, legal and communications roles, procedures for revoking access and steps for continuing critical services. Risk tiers should drive how detailed those playbooks are. High-risk vendors warrant named contacts, documented revocation steps and tested runbooks, while medium-risk vendors can be covered more lightly. Exercises should test what happens when a provider is unavailable or a compromise spreads through an integration. Two scenarios worth running explicitly: * A critical vendor going down during a high-stakes window, such as state testing or enrollment * A breach propagating from one integrated tool into another Even a short tabletop discussion with IT, administration and legal stakeholders can surface gaps that a written plan misses. K-12 districts also face a communication obligation that enterprise organizations do not. When a vendor breach involves student data, parent and community notification may be required - and the plan should designate who owns that process, what triggers it and how messaging will be coordinated with legal counsel. The inventory and risk tiers determine which vendors require the most detailed playbooks. Plans should be reviewed whenever services, data flows or contract terms change. "Knowing what your service-level agreement is with those vendors, whom to contact and what steps you can take, from both a continuity and containment perspective, is a bare minimum," Wisniewski says.

Belmont Public Schools
Jul 30th, 2026
Say goodbye to PlusPortals: Belmont Public Schools is moving to PowerSchool.

Say goodbye to PlusPortals: Belmont Public Schools is moving to PowerSchool. Belmont Public Schools July 30, 2026 Beginning August 1, Belmont Public Schools will transition from PlusPortals to PowerSchool, its new student information system. Like PlusPortals, PowerSchool provides students, families, teachers, and administrators with access to important student information, including grades, attendance, class schedules, and more - all in one integrated platform. Belmont Public Schools selected PowerSchool because it offers a simpler, faster user interface, making it easier to access information while supporting improved communication between schools and families. District staff completed initial training this spring, with refresher training scheduled before the start of the school year. Additional information, including parent login instructions and a secure process for families to claim access to their students' accounts, will be shared in the coming weeks.

Stingray Group
May 13th, 2026
Government responsible for ensuring companies live up to privacy protection measures: privacy commissioner.

Government responsible for ensuring companies live up to privacy protection measures: privacy commissioner. May 13, 2026 | 10:43 AM The province's privacy commissioner says the onus is on government to ensure that companies they deal with live up to their contractual obligations in privacy protection. Kerry Hatfield yesterday released her report on the cyber attack involving PowerSchool, and the actions of the public bodies responsible for safeguarding personal information. The PowerSchool cyber attack, which involved jurisdictions across North America, was the province's second largest privacy breach, affecting some 285,000 Newfoundlanders and Labradorians. Hatfield says it's not enough to leave it to the company to ensure that the appropriate privacy procedures are in place and that personal information is protected, it's up to the public bodies involved to ensure that a company is living up to its obligations. "I have kids in school myself, and we're reliant on the department to ensure these security measures are in place. But I think one of the key findings I want people to be aware of is that it's not just what's in the contract, is that the follow-up has to happen. There has to be really strict, systematic monitoring to verify that these big tech companies are actually not just saying they're going to do something in a contract, but they're actually doing it." The provincial government meanwhile says it is taking "proactive steps" to safeguard against future privacy breaches and "ensure stronger cyber protection" for users of PowerSchool. They include enhancing cybersecurity training for all departmental staff, reviewing all data held within PowerSchool, updating a retention and deletion schedule for personal information store in PowerSchool and reviewing and implementing additional security controls.

Cybersol
Apr 30th, 2026
PowerSchool data breach: what happened and what families should do | Security.org.

PowerSchool data breach: what happened and what families should do | Security.org. Source originally from "PowerSchool data breach: what happened and what families should do | Security.org" by Security.org - view original. Educational vendor breach exposes systemic governance failure in K-12 supply chain risk management. Why this matters at the governance level. The PowerSchool data breach of December 2024 - affecting 62 million students and 9.5 million teachers across North America - is not primarily a technology failure. It is a governance failure. School districts, operating under constrained budgets and competing operational priorities, deployed a mission-critical vendor without contractual security baselines, audit rights, or subcontractor visibility. When PowerSchool's own third-party dependencies were compromised, districts had no contractual mechanism to enforce remediation, demand transparency, or recover damages. This incident exposes a structural weakness in how public institutions manage vendor risk: procurement focuses on cost and functionality; security governance is treated as optional. The attack vector reveals absent contractual controls. The breach mechanics are instructive. An attacker obtained credentials from a PowerSchool subcontractor, then accessed PowerSource - PowerSchool's customer support portal - without multi-factor authentication. This portal granted administrative access to student information systems across thousands of school districts. The attacker then systematically exfiltrated databases from December 19-28, 2024, before PowerSchool detected the intrusion on December 28 when the extortion demand arrived. From a vendor risk governance perspective, this sequence reveals three critical failures. First, PowerSchool did not enforce MFA on administrative tools - a control standard for over a decade. Second, PowerSchool maintained "always on" remote maintenance access without adequate logging or detection mechanisms. Third, school districts had no contractual right to audit PowerSchool's security posture, subcontractor vetting practices, or access control architecture. Most educational procurement agreements lack provisions requiring vendors to implement specific security baselines or to disclose third-party dependencies. Districts negotiated with PowerSchool but exercised zero visibility into the vendor's own supply chain. Regulatory and liability exposure compounds the governance gap. Educational records fall under the Family Educational Rights and Privacy Act (FERPA), which imposes obligations on educational institutions to protect student data. However, FERPA does not explicitly require institutions to conduct vendor due diligence or to include security mandates in contracts. This creates a regulatory blind spot: regulators investigating the breach will examine whether districts met their FERPA obligations, but the contractual mechanisms to enforce vendor compliance were absent. The Texas Attorney General's lawsuit against PowerSchool alleges negligence and failure to implement basic security features - including MFA and encryption - despite marketing claims of "highest security standards." This creates secondary liability exposure for school districts themselves. Regulators and plaintiffs' counsel will examine whether districts conducted independent security assessments before deployment, whether procurement processes included security baseline verification, and whether contracts mandated audit rights. Districts that cannot demonstrate contractual security obligations or evidence of vendor vetting face regulatory scrutiny and potential liability for negligent vendor selection. The exposure of bus stop information and transportation routes adds a physical safety dimension that regulators will scrutinize. This is not merely identity theft risk; it is child safety risk. Procurement and governance frameworks must reflect this elevated threat profile. The ransom payment and ongoing extortion reveal contractual gaps. PowerSchool paid approximately $2.85 million in Bitcoin to the attacker. The payment did not resolve the incident. By May 2025, attackers were sending ransom demands directly to individual school districts, threatening to release the same stolen data. This second wave of extortion demonstrates a critical governance failure: PowerSchool had no contractual obligation to coordinate breach response with downstream customers, to provide timely scope reporting, or to cover costs associated with extortion attempts. School districts absorbed operational costs, notification expenses, credit monitoring services, and reputational damage - none of which were contractually recoverable from the vendor. Most educational vendor agreements lack provisions requiring vendors to fund breach response, coordinate notification timelines, or indemnify customers for downstream extortion. The incident should trigger comprehensive contract review: vendor agreements must include explicit breach notification obligations, cost-sharing provisions, and indemnification clauses. Cybersol's governance perspective: structural weaknesses in educational procurement. Educational institutions prioritize cost and functionality during vendor selection but systematically deprioritize security baseline verification and contractual enforcement. School districts often lack in-house technical expertise to evaluate vendor security claims independently. Procurement processes do not mandate pre-deployment security assessments. Contracts do not include audit rights, subcontractor disclosure requirements, or security baseline mandates. Vendor risk monitoring is episodic rather than continuous. The PowerSchool incident should catalyze systemic change in educational procurement governance. Districts must establish vendor security baseline requirements as non-negotiable procurement criteria. Contracts must include explicit security obligations (MFA, encryption, access controls, logging), audit rights, subcontractor disclosure requirements, and breach notification coordination provisions. Districts should require vendors to maintain cyber insurance and to provide evidence of annual security assessments. Ongoing vendor risk monitoring should be formalized, with quarterly security posture reviews and incident response testing. Educational institutions also face a regulatory inflection point. As state-level data protection laws expand and FERPA enforcement intensifies, regulators will examine whether districts conducted adequate vendor due diligence. Procurement decisions that lack documented security assessment will be viewed as negligent governance. Districts should document vendor selection criteria, evidence of security evaluation, and contractual security obligations in procurement files. Attribution and Source. Original Author: Gene Petrino, Home Security Expert, Security.org Source URL: https://www.security.org/identity-theft/breach/powerschool/ Publication Date: Last updated March 31, 2026 Closing reflection. The PowerSchool breach is a watershed moment for educational vendor governance. The incident demonstrates that vendor risk management cannot be delegated to procurement departments operating under cost constraints. Board-level oversight, contractual security mandates, and ongoing vendor monitoring are now regulatory expectations, not optional governance enhancements. Organizations should review the original Security.org article for detailed incident timeline, victim impact data, and family remediation guidance. Governance teams should use this incident as a catalyst for comprehensive vendor risk assessments, contract review, and procurement process redesign.

SHS Courier
Apr 16th, 2026
Naviance owner reaches $17.25 million settlement in privacy lawsuit.

Naviance owner reaches $17.25 million settlement in privacy lawsuit. April 16, 2026 PowerSchool Holdings LLC, owners of the Naviance platform, have reached a $17.25 million settlement in a class action lawsuit filed regarding student data privacy. The Plaintiff, Q.J., alleges that PowerSchool conducted "non-consensual interception of students' confidential and sensitive communications while using education technology products." Because the Court has not determined a winner in the case, a settlement was reached. Many parents have received communication from Kroll Settlement Administration LLC regarding claim eligibility. Students who have accessed Naviance at least once between Aug.18, 2021 and Jan. 23, 2026 are eligible to receive part of the settlement and are deemed part of the "Settlement Class." The allotment of money each student will receive is determined by the number of claims filed. When the final determination is made by the court regarding the settlement, Powerschool will form a "Web Governance Committee" to ensure student data is managed appropriately within the legal framework. "Additionally, while continuing to deny liability, PowerSchool agrees that for the next two years, it will not use within the Naviance Platform any software, technology and/or code offered or provided by any third party, including but not limited to (a) Heap Inc.; (b) Google LLC; (c) Microsoft Corporation; (d) Hotjar Inc.; and (d) Gainsight, Inc., unless the Web Governance Committee determines that such use is consistent with applicable law at that time," according to the settlement site. To further comply, all data of the Settlement Class that is held by corporations a-d must be deleted. Former Naviance owners Heap Inc. will also be required to delete all primary and backup data held on the Settlement Class. Claims forms may be made by July 27, 2026 via the Kroll Settlement Administration. Additionally, members of the Settlement Class and their guardians can exclude themselves from the settlement by July 13, 2026 to retain suing rights. The same date serves as the deadline to write an objection towards the settlement. A hearing will occur on Aug. 19, 2026 at 11 a.m. where people can request to speak on the settlement. All information and quotations used to develop this article, as well as additional information, can be found at powerschoolnaviancesettlement.com.