Identity Access Management Governance Specialist - Global Security Organization
Responsibilities
The mission of TikTok's Global Security Organization is to build and earn trust by reducing risk and securing our businesses and products. Also known as "GSO", this team is the foundation of our efforts to keep TikTok safe, secure, and operating at scale for over 1 billion people around the world. We work to ensure that the TikTok platform is safe and secure, that our users' experience and their data remain safe from external or internal threats, and that we comply with global regulations wherever TikTok operates.
Trust is one of TikTok's biggest initiatives, and security is integral to our success. In whatever ways users interact with us - whether they're watching videos on their For You page, interacting with a Live video, or buying products on TikTok Shop - GSO protects their data and privacy, so they can have a secure and trustworthy experience.
The IAM Operation & Validation team is part of the Global Security Organization (GSO), focused on protecting the organization by ensuring that the right identities have the right access to the right resources under the right conditions. Our mission is to strengthen identity and access security through effective governance, reliable security operations, and independent control validation. We develop and evolve IAM governance frameworks and security controls, identify and assess identity and access risks, validate whether controls are designed and operating effectively, and drive remediation and continuous improvement across the organization.
Our work spans the identity and access lifecycle and increasingly extends beyond traditional human identities to service accounts, machine and workload identities, and emerging agentic identities. We partner closely with engineering, security, privacy, compliance, and business teams to address complex IAM risks and build scalable, risk-based governance and assurance capabilities.
Joining the IAM Operation & Validation team means working at the intersection of security, technology, governance, and risk. You will have the opportunity to solve complex identity security challenges in a large-scale global environment and help shape the next generation of IAM governance, validation, and security capabilities.
Responsibilities
- Define and continuously enhance enterprise IAM governance strategies and control frameworks, including least privilege, role and entitlement governance, segregation of duties (SoD), and risk-based access controls, to strengthen the organization's overall identity and access security posture.
Want more jobs like this?
Get jobs in Singapore delivered to your inbox every week.

- Establish and evolve governance policies, standards, processes, and control requirements across the identity and access lifecycle, including identity onboarding, access request and provisioning, modification, periodic review, revocation, and auditability.
- Drive IAM governance initiatives across relevant stakeholders, establishing clear control ownership and accountability, identifying governance and control gaps, and partnering with technology, security, privacy, compliance, and business teams to drive remediation and sustainable improvements.
- Leverage identity, access, and authorization data to identify excessive privileges, dormant access, toxic combinations, policy violations, and other access risks; assess their impact and drive risk-based remediation with relevant stakeholders.
- Define and operate IAM governance measurement and monitoring frameworks, including governance metrics, key risk indicators, control effectiveness measures, and compliance baselines, to provide visibility into IAM risk and drive continuous improvement.
- Support the evolution of IAM governance across human and non-human identities, including service, system, and emerging agentic identities, helping establish appropriate governance principles and controls as the organization's identity landscape evolves.
Qualifications
Minimum Qualification(s)
- Strong knowledge of Identity and Access Management (IAM) concepts and practices, including identity lifecycle management, authentication, authorization, access control, and access governance.
- Solid understanding of IAM governance principles and controls, including least privilege, role and entitlement governance, segregation of duties (SoD), access reviews, and access lifecycle controls.
- Experience developing, implementing, or assessing IAM policies, standards, governance processes, or control frameworks in complex enterprise environments.
- Strong analytical and problem-solving skills, with the ability to identify identity and access risks, assess control gaps, and drive risk-based remediation.
- Strong cross-functional collaboration and communication skills, with the ability to work with technical and non-technical stakeholders to drive governance initiatives and control improvements.
Preferred Qualification(s)
- Bachelor's degree or higher in Computer Science, Information Security, Information Systems, Engineering, or a related field, or equivalent practical experience.
- 3+ years of relevant experience in IAM, cybersecurity, security governance, technology risk, or related fields, with experience in IAM governance or access governance preferred.
- Experience independently owning IAM governance initiatives or workstreams and driving them from problem identification through remediation and closure.
- Experience designing or operating enterprise-scale IAM governance programs, such as access reviews, entitlement governance, segregation of duties (SoD), privileged access governance, or identity lifecycle governance.
- Experience with enterprise IAM/IGA platforms and technologies such as SailPoint, Saviynt, Tuebora, Okta, Microsoft Entra ID, or comparable solutions.
- Experience working with security or compliance frameworks such as NIST, ISO 27001, SOC 2, SOX, PCI DSS, or similar control environments.
- Experience with governance of non-human identities, including service accounts, machine identities, workload identities, API credentials, or emerging agentic identities.
Perks and Benefits
Health and Wellness
- Health Insurance
- Dental Insurance
- Vision Insurance
- HSA
- Life Insurance
- Fitness Subsidies
- Short-Term Disability
- Long-Term Disability
- On-Site Gym
- Mental Health Benefits
- Virtual Fitness Classes
Parental Benefits
- Fertility Benefits
- Adoption Assistance Program
- Family Support Resources
Work Flexibility
- Flexible Work Hours
- Hybrid Work Opportunities
Office Life and Perks
- Casual Dress
- Snacks
- Pet-friendly Office
- Happy Hours
- Some Meals Provided
- Company Outings
- On-Site Cafeteria
- Holiday Events
Vacation and Time Off
- Paid Vacation
- Paid Holidays
- Personal/Sick Days
- Leave of Absence
Financial and Retirement
- 401(K) With Company Matching
- Performance Bonus
- Company Equity
Professional Development
- Promote From Within
- Access to Online Courses
- Leadership Training Program
- Associate or Rotational Training Program
- Mentor Program
Diversity and Inclusion
- Diversity, Equity, and Inclusion Program
- Employee Resource Groups (ERG)
Company Videos
Hear directly from employees about what it is like to work at TikTok.