Skip to main contentA logo with &quat;the muse&quat; in dark blue text.

Enterprise Offensive Security Validation Specialist, Global Security Organization

7 days ago New York, NY

Responsibilities

SecOps Validation Team (STOV) is responsible for the tools and technologies that support the TikTok infrastructure. STOV oversees technical validation, security operations, and drives engineering enhancements, including the deployment, configuration, and maintenance of security technologies across various domains.
This role will define enterprise security technical controls and implement validation mechanisms within TikTok environments to ensure effectiveness and compliance. It will also include offensive security activities to assess the strength of existing response measures. By working with cross-functional teams, the role will establish a measurable and repeatable process to enhance the security posture of the organization continuously.

Responsibilities:
- Define measurable technical security controls for the enterprise security environment based on common global frameworks. The enterprise security environment includes employee laptops, email technologies, and common office building computing resources such as conference room tech, local servers, and IoT devices.
- Conduct offensive security assessments to simulate real-world attack scenarios and validate the effectiveness of detection and response controls.
- Design and implement technical validations to technical security controls in the enterprise security environment using existing infrastructure and utilities, or supplementing with additional technologies as required.
- Work with cross-functional teams to identify control gaps and assist those teams with plans for remediation.

Qualifications

Minimum Qualifications:
- Strong expertise in enterprise laptop technologies (Mac and Windows), with an ability to balance security and user experience.

Want more jobs like this?

Get jobs in New York, NY delivered to your inbox every week.

Job alert subscription

- Solid understanding of email security concepts in a corporate environment.
- Experience in simulating advanced threat actor behavior in live, production-like environments.
- Familiarity with at least one programming or scripting language (e.g., Python, Java, Go, Bash, C/C++), with strong debugging skills.
- Deep understanding of attacker Tactics, Techniques, and Procedures (TTPs) aligned with the MITRE ATT&CK framework.
- Experience with Breach-and-Attack Simulation (BAS) frameworks and tools in large-scale environments.
- Strong knowledge of EDR evasion techniques and post-exploitation methodologies.

Preferred Qualifications:
- Hands-on experience with security automation and testing tools (e.g., Selenium, Ansible, Jenkins, Chef, Puppet).
- Familiarity with purple teaming, detection validation processes, and collaboration with blue teams.
- Knowledge of policy-as-code or continuous security control validation platforms.
- Broad familiarity across a wide range of security domains beyond enterprise security, including email security, application security, and other critical areas of the security stack.
- Experience working in large-scale global enterprises or fast-paced technology-driven environments.
- Background in product development or engineering of enterprise security tools (e.g., DLP, EDR, security logging platforms).
- Master's degree in a relevant technical field or security certifications (e.g., OSCP, CRTO, CISSP, CEH, CCSP).

Job Information

[For Pay Transparency] Compensation Description (annually)

The base salary range for this position in the selected city is $147200 - $269800 annually.

Compensation may vary outside of this range depending on a number of factors, including a candidate's qualifications, skills, competencies and experience, and location. Base pay is one part of the Total Package that is provided to compensate and recognize employees for their work, and this role may be eligible for additional discretionary bonuses/incentives, and restricted stock units.

Benefits may vary depending on the nature of employment and the country work location. Employees have day one access to medical, dental, and vision insurance, a 401(k) savings plan with company match, paid parental leave, short-term and long-term disability coverage, life insurance, wellbeing benefits, among others. Employees also receive 10 paid holidays per year, 10 paid sick days per year and 17 days of Paid Personal Time (prorated upon hire with increasing accruals by tenure).

The Company reserves the right to modify or change these benefits programs at any time, with or without notice.

For Los Angeles County (unincorporated) Candidates:

Qualified applicants with arrest or conviction records will be considered for employment in accordance with all federal, state, and local laws including the Los Angeles County Fair Chance Ordinance for Employers and the California Fair Chance Act. Our company believes that criminal history may have a direct, adverse and negative relationship on the following job duties, potentially resulting in the withdrawal of the conditional offer of employment:

1. Interacting and occasionally having unsupervised contact with internal/external clients and/or colleagues;

2. Appropriately handling and managing confidential information including proprietary and trade secret information and access to information technology systems; and

3. Exercising sound judgment.

Client-provided location(s): New York, NY
Job ID: TikTok-7534745830792710408
Employment Type: OTHER
Posted: 2025-08-06T04:44:59

Perks and Benefits

  • Health and Wellness

    • Health Insurance
    • Dental Insurance
    • Vision Insurance
    • HSA
    • Life Insurance
    • Fitness Subsidies
    • Short-Term Disability
    • Long-Term Disability
    • On-Site Gym
    • Mental Health Benefits
    • Virtual Fitness Classes
  • Parental Benefits

    • Fertility Benefits
    • Adoption Assistance Program
    • Family Support Resources
  • Work Flexibility

    • Flexible Work Hours
    • Hybrid Work Opportunities
  • Office Life and Perks

    • Casual Dress
    • Snacks
    • Pet-friendly Office
    • Happy Hours
    • Some Meals Provided
    • Company Outings
    • On-Site Cafeteria
    • Holiday Events
  • Vacation and Time Off

    • Paid Vacation
    • Paid Holidays
    • Personal/Sick Days
    • Leave of Absence
  • Financial and Retirement

    • 401(K) With Company Matching
    • Performance Bonus
    • Company Equity
  • Professional Development

    • Promote From Within
    • Access to Online Courses
    • Leadership Training Program
    • Associate or Rotational Training Program
    • Mentor Program
  • Diversity and Inclusion

    • Diversity, Equity, and Inclusion Program
    • Employee Resource Groups (ERG)

Company Videos

Hear directly from employees about what it is like to work at TikTok.