Software Engineer, Insider Risk - Global Security Organization
TikTok
- Location
- San Jose, California, United States of America
- Employment
- Full Time
- Work model
- On-Site
- Level
- Mid
- H-1B history
- 148 approvals (FY2023)
About this role
The mission of TikTok's Global Security Organization is to build and earn trust by reducing risk and securing our businesses and products. Also known as "GSO", this team is the foundation of our efforts to keep TikTok safe, secure, and operating at scale for over 1 billion people around the world. We work to ensure that the TikTok platform is safe and secure, that our users' experience and their data remains safe from external or internal threats, and that we comply with global regulations wherever TikTok operates.
Trust is one of TikTok's biggest initiatives, and security is integral to our success. In whatever ways users interact with us — whether they're watching videos on their For You page, interacting with a Live video, or buying products on TikTok Shop — GSO protects their data and privacy, so they can have a secure and trustworthy experience.
The GSO provides industry-leading security and privacy services guided by four principles: trust and transparency, business enablement, risk-informed decision-making, and proactive risk reduction. We strive to build sustainable, world-class security capabilities.
This is a Software Engineer role within Global Security's Insider Risk team. In this role, you are responsible for executing on the overall strategy for insider risk, from detection and triage to containment and remediation of Insider Risk incidents. There are two major deliverables for the team, automation development and detection engineering. Automation development focuses on ideating and creating tooling solutions and automated workflows to support investigation analysts and remediate crucial Insider Risk issues. Detection engineering focuses on the creation and maintenance of proactive logic to proactively identify inside risks with high fidelity and at scale to prevent harm to users and to the company. This role will work cross functionally with various business organizations to detect, mitigate, and remediate instances of Insider Risk through: - Review critical services involved in Insider risk security incidents and work with RD teams to scope technical remediations and security posture improvements (e.g. re-architecting a manual operations workflow to remove the viewability of an API secret token) - Help stakeholders identify relevant strategies for mitigating insider threats for users and the business. - Maintain and support compliant data flows and automation access to allow for interoperability across various business regions. - Directly contribute to technical projects via committing code, root cause analyses, code reviews, and architecture design. - Work with cross functional teams globally to ensure alignment, collect feedback on automations, and deploy solutions to get cross functional adoption.