Skip to main contentA logo with &quat;the muse&quat; in dark blue text.

AI Governance and Compliance Specialist - Global Security Organization

2 months ago San Jose, CA

Responsibilities

The mission of TikTok's Global Security Organization is to build and earn trust by reducing risk and securing our businesses and products. Also known as "GSO", this team is the foundation of our efforts to keep TikTok safe, secure, and operating at scale for over 1 billion people around the world. We work to ensure that the TikTok platform is safe and secure, that our users' experience and their data remains safe from external or internal threats, and that we comply with global regulations wherever TikTok operates.

Trust is one of TikTok's biggest initiatives, and security is integral to our success. In whatever ways users interact with us - whether they're watching videos on their For You page, interacting with a Live video, or buying products on TikTok Shop - GSO protects their data and privacy, so they can have a secure and trustworthy experience.

The GSO provides industry-leading security and privacy services to company, guided by four principles: trust and transparency, business enablement, risk-informed decision-making, and proactive risk reduction. We strive to build sustainable, world-class security capabilities.

TikTok is seeking an AI Governance and Compliance Specialist to drive the technical assurance and compliance operations of our content recommendation and AI systems, ensuring they operate transparantly, fairly, and in compliance with evolving regulatory frameworks such as the AI Governance Act, DSA, GDPR, ISO, OSA, etc. This role sits at the intersection of engineering, policy, and governance - translating regulatory obligations into concrete compliance frameworks, algorithmic controls, risk assessments, and providing expert input into regulatory engagement.

Want more jobs like this?

Get Data and Analytics jobs in San Jose, CA delivered to your inbox every week.

Job alert subscription


Responsibilities
Regulatory Readiness & Operational Controls
- Regulatory Mapping: Interpret global AI and platform safety laws (e.g., EU DSA, EU AI Act, US state laws like CA SB 1047 / Colorado AI Act) and translate requirements into actionable technical guardrails for recommendation and Algorithmic systems.
- Recommender Compliance: Execute compliance strategy for Recommender specific mandates, including options for non-profiling recommendation feeds, ad/content parameter disclosures, and systemic risk mitigation for content curation.
- Model Risk Tiering & Auditability: Evaluate recommendation architectures, input data, and optimization objectives to assign appropriate regulatory risk classifications. Build automated tracking systems that log model lineage, training parameters, and evaluation results to ensure end-to-end traceability for compliance audits.

Technical Assurance and Model Auditing
- Systemic Risk Mitigation Pipelines: Design operational guardrails to prevent feed algorithms from amplifying illegal content, severe disinformation, hate speech, or content linked to mental health harms and minor safety
- Algorithmic Bias & Fairness Testing: Conduct quantitative pre-release and post-release audits evaluating candidate generation (retrieval) and ranking stages for popularity bias, demographic disparity, and filter-bubble formation.
- ML-SDLC Governance Gates: Ensure compliance sign-off gates into the Machine Learning Software Development Lifecycle (ML-SDLC), ensuring no high-risk recommendation model ships to production without documented clearance.
- Third-Party Audit Package Preparation: Assemble end-to-end evidence packages, data samples, and code/architecture explanations for external statutory auditors and regulatory bodies.

Audit Readiness & External Engagement
- Regulatory Liaison: Act as the primary technical point of contact during independent third-party audits, regulatory inquiries, or statutory compliance filings.
- Auditing Rigor: Exceptional attention to detail in constructing audit trails, technical documentation, and regulatory evidence packages.
- Engineering & Legal Bridge: Serve as the translator between Machine Learning Engineers/Data Scientists and Legal/Policy teams to align model architecture choices with legal defensibility.
- Global Process Enablement: Establish standardized playbooks and repeatable compliance protocols for recommendation engine risk assessments, ensuring consistent regulatory adherence across diverse geographic markets and product verticals.

Qualifications

Minimum Qualifications:
- Proven track record in successfully developing, implementing, and managing comprehensive compliance programs at scale with experience engaging directly with regulators, external auditors, or supervisory bodies on algorithmic or AI compliance matters.
- Deep understanding of recommendation systems, ranking algorithms, recommendation architectures, and content distribution pipelines at scale.
- Proficiency in Python, SQL, and data analysis; experience with ML frameworks (e.g., PyTorch, TensorFlow) and experimentation platforms.
- Exceptional analytical, critical thinking, and problem-solving skills, coupled with the ability to translate complex legal and technical concepts into clear, actionable advice for diverse technical and non-technical audiences.
- Demonstrated ability to work independently, effectively manage multiple competing priorities, and thrive in a fast-paced, dynamic, and often ambiguous environment.

Preferred Qualifications
- Bachelor's degree in Computer Science, Data Science, Information Policy, Law & Technology, or a related quantitative/policy discipline.
- 4+ years of professional experience in AI/ML governance, tech compliance, algorithmic auditing, or responsible AI engineering.
- Solid understanding and practical experience in Global regulations (e.g., DSA, OSA, GDPR, AI Governance Act), including practical experience in their application.
- Strong foundational understanding of leading cybersecurity frameworks (e.g., NIST, ISO 27001) and robust control environments.
- Audit and risk experience conducting algorithmic impact assessments (AIAs), data protection impact assessments (DPIAs), or systemic risk evaluations.
- Familiarity with the unique challenges and opportunities related to algorithmic governance, fairness, and transparency in large-scale online platforms.
- Industry experience in technology or social media.
- Relevant professional certifications such as AIGP, CISA, CISM, CRISC, CISSP, or CIPP/E.

Job Information

[For Pay Transparency] Compensation Description (annually)

The base salary range for this position in the selected city is $111600 - $162000 annually.

Compensation may vary outside of this range depending on a number of factors, including a candidate's qualifications, skills, competencies and experience, and location. Base pay is one part of the Total Package that is provided to compensate and recognize employees for their work, and this role may be eligible for additional discretionary bonuses/incentives, and restricted stock units.

Benefits may vary depending on the nature of employment and the country work location. Employees have day one access to medical, dental, and vision insurance, a 401(k) savings plan with company match, paid parental leave, short-term and long-term disability coverage, life insurance, wellbeing benefits, among others. Employees also receive 10 paid holidays per year, 10 paid sick days per year and 17 days of Paid Personal Time (prorated upon hire with increasing accruals by tenure).

The Company reserves the right to modify or change these benefits programs at any time, with or without notice.

For Los Angeles County (unincorporated) Candidates:

Qualified applicants with arrest or conviction records will be considered for employment in accordance with all federal, state, and local laws including the Los Angeles County Fair Chance Ordinance for Employers and the California Fair Chance Act. Our company believes that criminal history may have a direct, adverse and negative relationship on the following job duties, potentially resulting in the withdrawal of the conditional offer of employment:

1. Interacting and occasionally having unsupervised contact with internal/external clients and/or colleagues;

2. Appropriately handling and managing confidential information including proprietary and trade secret information and access to information technology systems; and

3. Exercising sound judgment.

Client-provided location(s): San Jose, CA
Job ID: TikTok-7641220240684468533
Employment Type: OTHER
Posted: 2026-05-19T20:38:55

Perks and Benefits

  • Health and Wellness

    • Health Insurance
    • Dental Insurance
    • Vision Insurance
    • HSA
    • Life Insurance
    • Fitness Subsidies
    • Short-Term Disability
    • Long-Term Disability
    • On-Site Gym
    • Mental Health Benefits
    • Virtual Fitness Classes
  • Parental Benefits

    • Fertility Benefits
    • Adoption Assistance Program
    • Family Support Resources
  • Work Flexibility

    • Flexible Work Hours
    • Hybrid Work Opportunities
  • Office Life and Perks

    • Casual Dress
    • Snacks
    • Pet-friendly Office
    • Happy Hours
    • Some Meals Provided
    • Company Outings
    • On-Site Cafeteria
    • Holiday Events
  • Vacation and Time Off

    • Paid Vacation
    • Paid Holidays
    • Personal/Sick Days
    • Leave of Absence
  • Financial and Retirement

    • 401(K) With Company Matching
    • Performance Bonus
    • Company Equity
  • Professional Development

    • Promote From Within
    • Access to Online Courses
    • Leadership Training Program
    • Associate or Rotational Training Program
    • Mentor Program
  • Diversity and Inclusion

    • Diversity, Equity, and Inclusion Program
    • Employee Resource Groups (ERG)

Company Videos

Hear directly from employees about what it is like to work at TikTok.