Responsibilities
TikTok is the leading destination for short-form mobile video. Our mission is to inspire creativity and bring joy. TikTok has global offices including Los Angeles, New York, London, Paris, Berlin, Dubai, Singapore, Jakarta, Seoul and Tokyo.
Why Join Us
Creation is the core of TikTok's purpose. Our platform is built to help imaginations thrive. This is doubly true of the teams that make TikTok possible.
Together, we inspire creativity and bring joy - a mission we all believe in and aim towards achieving every day.
To us, every challenge, no matter how difficult, is an opportunity; to learn, to innovate, and to grow as one team. Status quo? Never. Courage? Always.
At TikTok, we create together and grow together. That's how we drive impact - for ourselves, our company, and the communities we serve.
Join us.
The Global Security Organization provides industry-leading cyber-security and business protection services to TikTok globally. Our organization employs four principles that guide our strategic and tactical operations. Firstly, we Champion Transparency & Trust by leading the charge in organizational transparency, prioritizing customer trust, and placing user needs first. Secondly, we aim to maintain Best in Class Global Security by proactively identifying and reducing risks while enabling innovative product development. We constantly work towards a sustainable world-class security capability. Thirdly, we strive to be a Business Catalyst & Enabler by embodying the DNA of technical innovation and ensuring our Global Security operations are fast and agile. Finally, we Drive Empowered & Risk-Informed Decision Making by providing our leaders with the necessary information to make agile decisions based on risk. In order to enhance collaboration and cross-functional partnerships, our organization follows a hybrid work schedule that requires employees to work in the office for 2 to 3 days a week, as directed by their manager. We regularly review our hybrid work model, and the specific requirements may change at any time.
As a direct report to the Global Third Party Security Management (TPSM) Lead, you will join a dynamic team that is responsible for reducing the security risk related to ByteDance's use of third parties. In support of that responsibility, you will have the unique opportunity to both conduct third party security assessments and monitor third party security risk for the company.
We are working on a hybird schedule, with an expected 2-3 days a week in office, as designated by your manager. We are continuously reviewing our hybrid-working model and requirements are subject to change at any time.
Responsibilities
- Conduct security assessments of Bytedance's third parties. This includes:
- The planning of third party security assessments, namely, coordinating internal and external stakeholders, evaluating security and developing a security assessment plan
- The execution of third party security assessments, namely, the review of security documentation and the performance of technical assessment procedures
- The reporting of security assessments, namely, reporting results, developing findings and recommended remediation plans
- Support third party monitoring and offboarding operations. This includes:
- Working with industry leading security tools to dynamically measure third party risks and report to various stakeholders
- Conducting data validation and cleanliness activities to ensure accurate reporting and integration with other teams and tools
- Partnering with cross-functional teams to further security leading practices in the offboarding of third parties
- Conducting data clean-up and lineage exercises between GRC tooling and related systems
- Advocate GSO capabilities to business stakeholders by demonstrating value and fostering awareness
- Assist in developing innovative solutions to help evaluate complex business, technology, and risk issues in a fast paced environment
Qualifications
-Bachelor's degree in risk or equivalent privacy, security, compliance, project management, or like discipline from an accredited college or university or measurable knowledge/experience from proven industry, military, defense, or government operations.
- 1+ years of governance risk and compliance (GRC) or related security experience
- Experience managing projects to completion and demonstrating successful outcomes
- Experience balancing security leading practice with business objectives
- A highly motivated individual, with strong communication and relationship-building skills, and demonstrate a record of ongoing accomplishment and commitment to excellence
- Accustomed to working in a highly dynamic, startup-like environment. Adaptable to changing or emerging priorities
- Experience working hands-on with cross-functional teams including legal, procurement, information security, business continuity, privacy, and IT engineering
- Knowledge of controls frameworks and industry standard frameworks (FAIR, COBIT, NIST CSF, SOC, ISO, etc.)
- Industry relevant certification (CISA, Security+, Etc.)
TikTok is committed to creating an inclusive space where employees are valued for their skills, experiences, and unique perspectives. Our platform connects people from across the globe and so does our workplace. At TikTok, our mission is to inspire creativity and bring joy. To achieve that goal, we are committed to celebrating our diverse voices and to creating an environment that reflects the many communities we reach. We are passionate about this and hope you are too.
TikTok is committed to providing reasonable accommodations in our recruitment processes for candidates with disabilities, pregnancy, sincerely held religious beliefs or other reasons protected by applicable laws. If you need assistance or a reasonable accommodation, please reach out to us at [email protected]
#LI-Hybrid