Job description
The Global Security Organization provides industry-leading cybersecurity and business protection services to TikTok globally.
Our organization employs four principles that guide our strategic and tactical operations.
Firstly, we Champion Transparency & Trust by leading the charge in organizational transparency, prioritizing customer trust, and placing user needs first.
Secondly, we aim to maintain Best in Class Global Security by proactively identifying and reducing risks while enabling innovative product development.
We constantly work towards a sustainable world-class security capability.
Thirdly, we strive to be a Business Catalyst & Enabler by embodying the DNA of technical innovation and ensuring our Global Security operations are fast and agile.
Finally, we Drive Empowered & Risk-Informed Decision Making by providing our leaders with the necessary information to make agile decisions based on risk.
In order to enhance collaboration and cross-functional partnerships, our organization follows a hybrid work schedule that requires employees to work in the office for 3 days a week, as directed by their manager.
We regularly review our hybrid work model, and the specific requirements may change at any time.
As part of the Threat and Incident Management team, you will support TikTok's inside threat operation.
You will utilize analytical methods to understand insider risk patterns and establish models for forecasting insider risk scenarios.
The candidate will also collaborate with stakeholders from data engineers to executives, prioritizing data sources for onboarding into risk models and gathering requirements for dashboards to provide a holistic view on operations.
Responsibilities
- Analyze and validate large and complex datasets to identify potential threats and develop detection logic to mitigate risks.
- Triage, investigate, and conduct end to end incident response processes for security incidents from various sources including SIEM, DLP, UEBA, and endpoint tools.
- Respond to security incidents in real-time and participate in root cause analysis, escalation, and incident recovery efforts.
- Coordinate with system owners, data teams, and business units to enhance detection logic, data, reduce false positives, and refine workflows.
- Create and maintain dashboards to support threat hunting, investigations, and operational reporting.
- Communicate findings, risk posture, and recommended remediation steps clearly to both technical and non-technical stakeholders.
- Partner with cross-functional teams to identify process improvements and implement scalable security solutions.
- Contribute to continuous improvement efforts in detection coverage, response readiness, and insider threat frameworks.
Minimum Qualifications:
- Bachelor's degree in Cybersecurity, Engineering, Information Systems, or a related discipline, or equivalent experience in military, government, or commercial environments.
- 5+ years of hands-on experience in cybersecurity with a focus on incident response or insider risk.
- Proficient in SQL - Previous experience working on an infosec/corpsec team on incident response and detection engineering.
- Excellent analytical, critical thinking, and problem-solving skills with a high attention to detail.
- Proficiency with security technologies such as SIEM, DLP, UEBA, and UAM tools.
- Ability to assess and prioritize risks in real-time in a dynamic environment.
- Passionate about staying ahead of emerging threats and continuously improving security posture.
Preferred Qualifications:
- Exposure to artificial intelligence (AI) and machine learning (ML) techniques to enhance threat detection and workflow automation.
- Strong understanding of threat intelligence platforms, TTPs, and threat modeling.
- Excellent verbal and written communication skills; ability to distill complex findings into actionable insights including to stakeholders where English may not be their primary language.
- Strong interpersonal skills and ability to work effectively across global, cross-functional teams.
- Demonstrated ability to manage competing priorities, operate independently, and deliver results under pressure.
Required Skill Profession
Computer Occupations