Skip to main contentA logo with &quat;the muse&quat; in dark blue text.

DevOps Engineer, Assurance and Infrastructure Services - USDS

Yesterday Seattle, WA

Responsibilities

Our team owns the developer platform and release toolchain that powers TikTok's US infrastructure. We focus on CI/CD pipelines, artifact repository management, and cloud deployment workflows, partnering closely with engineering teams and assurance partners (USDS/USTS, auditors) to make build, test, and release fast, secure, and compliant by design.

You will design, build, and operate the critical tooling that developers use every day: CI/CD pipelines, artifact repositories, and deployment workflows across multiple environments. You will work with engineers across teams to understand their development lifecycle, reduce friction in shipping code, and implement robust security and assurance guardrails that keep our production environments stable, auditable, and compliant.

Responsibilities
- Own and Evolve CI/CD Pipelines: Design, build, and maintain CI/CD pipelines for backend and platform services, improving reliability, speed, and developer experience while embedding security and compliance checks.
- Secure Supply Chain Management: Implement and manage software supply chain security controls, including SBOM generation and validation, artifact signing and attestation (e.g., SLSA), and provenance tracking to ensure the integrity of the build and release process.
- Automate Policy-as-Code Gates: Integrate and enforce automated security and compliance gates within CI/CD pipelines, such as secrets scanning, dependency risk analysis, license compliance checks, and vulnerability scanning, with fail-safe promotion rules.
- Ensure Auditability and Evidence Collection: Design and operate systems for comprehensive auditability, including immutable change logs, deployment records, and traceable rollbacks. Support internal and external assurance requests by providing clear, auditable evidence.
- Manage Cloud IAM and Secrets: Design and enforce least-privilege access controls in OCI/cloud environments. Implement best practices for role design, key/secrets hygiene, and periodic access reviews to minimize security risks.
- Enhance System Resilience and Disaster Recovery: Align release tooling with Risk, Disaster Recovery (DR), and Business Continuity Planning (BCP) requirements. Implement and periodically test backup and restore procedures for critical repositories and pipelines.
- Develop and Maintain Incident Playbooks: Create, document, and rehearse incident response playbooks for build/deploy failures and security events. Lead postmortems and drive corrective actions to prevent recurrence.
- Design and Maintain Deployment Workflows: Standardize deployment workflows (e.g., blue/green, canary, automated rollout/rollback) in a major cloud environment (OCI preferred).

Want more jobs like this?

Get jobs in Seattle, WA delivered to your inbox every week.

Job alert subscription

- Manage Artifact Repositories: Administer artifact repositories (e.g., Artifactory) including layout, permissions, retention policies, and housekeeping to ensure build reproducibility and integrity.

Qualifications

Minimum Qualifications
- Bachelor's degree in Computer Science, a related technical field, or equivalent practical experience.
- Solid software engineering skills with one or more programming languages (e.g., Python, Go, Java).
- Hands-on experience building and maintaining CI/CD pipelines using systems like GitLab CI, Jenkins, or similar.
- Experience with at least one major cloud provider (OCI, AWS, GCP), with a strong understanding of IAM concepts.
- Practical experience with artifact repositories (e.g., JFrog Artifactory, Nexus) for container images and language packages.
- Experience integrating security scanning tools (e.g., for dependencies, vulnerabilities, secrets) into CI/CD pipelines.
- Good communication skills and the ability to work closely with developers and partner teams.

Preferred Qualifications
- Experience working within compliance-heavy environments and supporting audits (e.g., SOC2, ISO 27001, PCI).
- Expertise in designing and implementing software supply chain security measures, such as code signing, SBOM tools (e.g., Syft, Grype), and artifact attestation frameworks (e.g., SLSA).
- Deep experience with OCI, including advanced IAM, and automating infrastructure and deployments.
- Experience in platform or developer productivity teams, building internal tools and templates for other engineers.
- Familiarity with containerization (Docker, Kubernetes) and its security ecosystem.
- A demonstrated track record of writing clear technical documentation for security processes and runbooks.

Job Information

[For Pay Transparency] Compensation Description (annually)

The base salary range for this position in the selected city is $100320 - $246240 annually.

Compensation may vary outside of this range depending on a number of factors, including a candidate's qualifications, skills, competencies and experience, and location. Base pay is one part of the Total Package that is provided to compensate and recognize employees for their work, and this role may be eligible for additional discretionary bonuses/incentives, and restricted stock units.

Benefits may vary depending on the nature of employment and the country work location. Employees have day one access to medical, dental, and vision insurance, a 401(k) savings plan with company match, paid parental leave, short-term and long-term disability coverage, life insurance, wellbeing benefits, among others. Employees also receive 10 paid holidays per year, 10 paid sick days per year and 17 days of Paid Personal Time (prorated upon hire with increasing accruals by tenure).

The Company reserves the right to modify or change these benefits programs at any time, with or without notice.

For Los Angeles County (unincorporated) Candidates:

Qualified applicants with arrest or conviction records will be considered for employment in accordance with all federal, state, and local laws including the Los Angeles County Fair Chance Ordinance for Employers and the California Fair Chance Act. Our company believes that criminal history may have a direct, adverse and negative relationship on the following job duties, potentially resulting in the withdrawal of the conditional offer of employment:

1. Interacting and occasionally having unsupervised contact with internal/external clients and/or colleagues;

2. Appropriately handling and managing confidential information including proprietary and trade secret information and access to information technology systems; and

3. Exercising sound judgment.

Client-provided location(s): Seattle, WA
Job ID: TikTok-7618443308958255365
Employment Type: OTHER
Posted: 2026-03-19T19:41:06

Perks and Benefits

  • Health and Wellness

    • Health Insurance
    • Dental Insurance
    • Vision Insurance
    • HSA
    • Life Insurance
    • Fitness Subsidies
    • Short-Term Disability
    • Long-Term Disability
    • On-Site Gym
    • Mental Health Benefits
    • Virtual Fitness Classes
  • Parental Benefits

    • Fertility Benefits
    • Adoption Assistance Program
    • Family Support Resources
  • Work Flexibility

    • Flexible Work Hours
    • Hybrid Work Opportunities
  • Office Life and Perks

    • Casual Dress
    • Snacks
    • Pet-friendly Office
    • Happy Hours
    • Some Meals Provided
    • Company Outings
    • On-Site Cafeteria
    • Holiday Events
  • Vacation and Time Off

    • Paid Vacation
    • Paid Holidays
    • Personal/Sick Days
    • Leave of Absence
  • Financial and Retirement

    • 401(K) With Company Matching
    • Performance Bonus
    • Company Equity
  • Professional Development

    • Promote From Within
    • Access to Online Courses
    • Leadership Training Program
    • Associate or Rotational Training Program
    • Mentor Program
  • Diversity and Inclusion

    • Diversity, Equity, and Inclusion Program
    • Employee Resource Groups (ERG)

Company Videos

Hear directly from employees about what it is like to work at TikTok.