Product Security Validation Architect - Global Security Organisation
Responsibilities
Team Introduction:
The mission of TikTok's Global Security Organization is to build and earn trust by reducing risk and securing our businesses and products. Also known as "GSO", this team is the foundation of our efforts to keep TikTok safe, secure, and operating at scale for over 1 billion people around the world. We work to ensure that the TikTok platform is safe and secure, that our users' experience and their data remains safe from external or internal threats, and that we comply with global regulations wherever TikTok operates.
Trust is one of TikTok's biggest initiatives, and security is integral to our success. In whatever ways users interact with us - whether they're watching videos on their For You page, interacting with a Live video, or buying products on TikTok Shop - GSO protects their data and privacy, so they can have a secure and trustworthy experience.
Security Tools Operations and Validation team's responsibilities include designing and implementing IT security solutions that address the organization's needs, assessing risks and vulnerabilities, and developing strategies to mitigate them, validation of security technical controls.
The role will be responsible for architecture design and optimization, red team validation, metric operation for TikTok Product Security This role will use the solid experience in cybersecurity and architecture to implement the deep cyber defense technology for TikTok. Pushing remediation of current GAPs in Secure SDLC is another important function. This role will lead the team to push cross functional teams fixing issues of Secure SDLC. This role will lead cross functional teams to implement best practice of Secure SDLC in the company. This role will be responsible for TikTok's maturity in Secure SDLC domain.
Responsibilities:
- Define and validate product security technical controls, design the automation validation architecture
- Work with XFN teams to implement Security by Design and shift-left technical security controls. Define and enforce secure architecture standards and patterns to prevent common security issues, pushing implementation in product and developers
- Accountable for end-to-end solutions to complex SDLC issues, lead the effort of technical coordination and evaluation of remediation.
Qualifications
Minimum Qualifications:
- A bachelor's (master's preferred) degree in computer science, information technology, cybersecurity, or a related field is usually required.
- Strong understanding of Secure SDLC with best practice in industry
- Strong experience in Cybersecurity technologies, including penetration tests, security assessment, familiarity with SAST, DAST, SCA security tools etc
Want more jobs like this?
Get jobs in Singapore delivered to your inbox every week.

- Deep understanding of security architecture, having successful experience of implementing end to end security architecture.
- Solid knowledge about modern internet company security architecture and development stack
- Having experience to threat modeling of complicated business
- Excellent team-working skills are needed. Previous successful working experience through different time zones is a plus.
Preferred Qualifications:
- Rich experience in pentesting, red team operation, application security, vulnerability exploit etc
- Experience in mobile, web application development will be a big pluseatures or tools.
Perks and Benefits
Health and Wellness
- Health Insurance
- Dental Insurance
- Vision Insurance
- HSA
- Life Insurance
- Fitness Subsidies
- Short-Term Disability
- Long-Term Disability
- On-Site Gym
- Mental Health Benefits
- Virtual Fitness Classes
Parental Benefits
- Fertility Benefits
- Adoption Assistance Program
- Family Support Resources
Work Flexibility
- Flexible Work Hours
- Hybrid Work Opportunities
Office Life and Perks
- Casual Dress
- Snacks
- Pet-friendly Office
- Happy Hours
- Some Meals Provided
- Company Outings
- On-Site Cafeteria
- Holiday Events
Vacation and Time Off
- Paid Vacation
- Paid Holidays
- Personal/Sick Days
- Leave of Absence
Financial and Retirement
- 401(K) With Company Matching
- Performance Bonus
- Company Equity
Professional Development
- Promote From Within
- Access to Online Courses
- Leadership Training Program
- Associate or Rotational Training Program
- Mentor Program
Diversity and Inclusion
- Diversity, Equity, and Inclusion Program
- Employee Resource Groups (ERG)
Company Videos
Hear directly from employees about what it is like to work at TikTok.