Skip to main contentA logo with &quat;the muse&quat; in dark blue text.

Security Engineer, Detection & Response - Global Security Organization

2 days ago Singapore

Responsibilities

The mission of TikTok's Global Security Organization is to build and earn trust by reducing risk and securing our businesses and products. Also known as "GSO", this team is the foundation of our efforts to keep TikTok safe, secure, and operating at scale for over 1 billion people around the world. We work to ensure that the TikTok platform is safe and secure, that our users' experience and their data remains safe from external or internal threats, and that we comply with global regulations wherever TikTok operates.

Trust is one of TikTok's biggest initiatives, and security is integral to our success. In whatever ways users interact with us - whether they're watching videos on their For You page, interacting with a Live video, or buying products on TikTok Shop - GSO protects their data and privacy, so they can have a secure and trustworthy experience.

TikTok's Global Forensics team is responsible for the company's technical investigations and digital forensics work.
This role sits at the intersection of applied AI, software engineering, security data engineering, and digital forensics. You will build evidence-aware AI systems that help investigators retrieve, correlate, reason over, package, and explain evidence across complex enterprise telemetry, while preserving auditability, reproducibility, privacy, and human judgment.

Want more jobs like this?

Get Software Engineering jobs in Singapore delivered to your inbox every week.

Job alert subscription

You will also partner closely with investigators to convert recurring case patterns into reusable workflows, AI-assisted investigation tools, evaluation datasets, playbooks, and detection/control improvements.

Responsibilities:
- Design and build AI-native forensic investigation workflows for evidence retrieval, enrichment, entity normalization, timeline reconstruction, evidence indexing, evidence packaging, and investigation report generation.
- Build agentic systems that safely interact with internal tools, APIs, logs, and investigation datasets through controlled tool use, permissioning, human-in-the-loop review, and auditable execution traces.
- Develop retrieval, knowledge, and reasoning systems over cases, logs, policies, tickets, reports, and evidence repositories, with grounded citations and structured outputs.
- Create evaluation frameworks for forensic AI workflows, including golden cases, regression tests, grounding checks, hallucination/failure analysis, precision/recall measurement, and investigator feedback loops.
- Engineer data workflows across platform audit logs, identity/cloud logs, endpoint/server telemetry, network logs, DLP, and other investigation data sources.
- Partner with forensic investigators to turn ambiguous investigative questions into reproducible workflows, reusable query packs, dashboards, agent tools, and defensible technical outputs.
- Drive proactive risk discovery by generalizing patterns from real cases, running targeted hunts across multi-source telemetry, validating signals, and converting findings into detection, logging, control, and process improvements.
- Apply AI-assisted engineering responsibly to accelerate prototyping, refactoring, testing, and documentation while maintaining code review, test coverage, change control, privacy safeguards, and evidentiary defensibility.

Qualifications

Minimum Qualifications
- Bachelor's Degree in Cybersecurity, Information Security, or Computer Engineering.
- Minimum 5 years of experience in Cybersecurity or DevSecOps roles.
- Demonstrated capabilities using Python, Go, or other production languages to build custom threat detection rules or threat hunting queries for SIEM/EDR platforms.
- Proven experience designing and building robust data pipelines to process, normalise and correlate large-scale security telemetry from multiple sources.
- Strong knowledge and demonstrated exposure addressing common AI Agent security risks and hardening strategies (e.g., OWASP Top 10 for LLMs, including prompt injection, unauthorised tool execution, and denial of service).

Preferred Qualifications
- Regional or global enterprise scale Security detection operations experience.
- Proven track record of integrating LLM or Agentic AI into cybersecurity workflows.
- Knowledge of Agent Loop architecture.
- Strong familiarity and track record of applying MITRE ATLAS framework to threat modeling and risk assessments for AI systems.

Client-provided location(s): Singapore
Job ID: TikTok-7667924371042814213
Employment Type: OTHER
Posted: 2026-07-29T20:18:47

Perks and Benefits

  • Health and Wellness

    • Health Insurance
    • Dental Insurance
    • Vision Insurance
    • HSA
    • Life Insurance
    • Fitness Subsidies
    • Short-Term Disability
    • Long-Term Disability
    • On-Site Gym
    • Mental Health Benefits
    • Virtual Fitness Classes
  • Parental Benefits

    • Fertility Benefits
    • Adoption Assistance Program
    • Family Support Resources
  • Work Flexibility

    • Flexible Work Hours
    • Hybrid Work Opportunities
  • Office Life and Perks

    • Casual Dress
    • Snacks
    • Pet-friendly Office
    • Happy Hours
    • Some Meals Provided
    • Company Outings
    • On-Site Cafeteria
    • Holiday Events
  • Vacation and Time Off

    • Paid Vacation
    • Paid Holidays
    • Personal/Sick Days
    • Leave of Absence
  • Financial and Retirement

    • 401(K) With Company Matching
    • Performance Bonus
    • Company Equity
  • Professional Development

    • Promote From Within
    • Access to Online Courses
    • Leadership Training Program
    • Associate or Rotational Training Program
    • Mentor Program
  • Diversity and Inclusion

    • Diversity, Equity, and Inclusion Program
    • Employee Resource Groups (ERG)

Company Videos

Hear directly from employees about what it is like to work at TikTok.