Skip to main contentA logo with &quat;the muse&quat; in dark blue text.

Senior Forensics Investigator - Global Security Organization

2 days ago Singapore

Responsibilities

The mission of TikTok's Global Security Organization is to build and earn trust by reducing risk and securing our businesses and products. Also known as "GSO", this team is the foundation of our efforts to keep TikTok safe, secure, and operating at scale for over 1 billion people around the world. We work to ensure that the TikTok platform is safe and secure, that our users' experience and their data remains safe from external or internal threats, and that we comply with global regulations wherever TikTok operates.

Trust is one of TikTok's biggest initiatives, and security is integral to our success. In whatever ways users interact with us - whether they're watching videos on their For You page, interacting with a Live video, or buying products on TikTok Shop - GSO protects their data and privacy, so they can have a secure and trustworthy experience.

TikTok's Global Digital Forensics team is responsible for the company's technical investigations and digital forensics work. We are seeking a Senior Digital Forensics Investigator. This role focuses on technical threat investigations by correlating and analyzing multi-source logs and data to build reviewable evidence chains and fact-based narratives, producing audit-ready and reproducible investigation conclusions and supporting materials.

Responsibilities
- Lead end-to-end investigations of suspected threat activity covering scoping, planning, triage, evidence collection and preservation, analysis, documentation of findings, and remediation recommendations.

Want more jobs like this?

Get jobs in Singapore delivered to your inbox every week.

Job alert subscription

- Investigate both insider threats with user behavior analysis and external threats with root cause analysis to determine intent, vector, scope, and affected assets.
- Acquire and preserve network, host, mobile, and cloud evidence using forensically sound techniques to support legal or disciplinary processes.
- Perform host-based forensic analysis of Windows, macOS, and Linux devices as well as iOS and Android mobile devices.
- Acquire and analyze cloud artifacts from Azure, AWS, Google Cloud and internal platforms.
- Analyze telemetry across EDR/HIDS, DLP, firewall/proxy/VPN/DNS/flow logs, and internal platform logs to identify staging, access, exfiltration, or misuse patterns.
- Correlate data across sources to build timelines, entity relationships, and causality chains that support findings.
- Produce technical findings that stand up to scrutiny.
- Produce and communicate executive-level findings and recommended actions to non-technical stakeholders such as Legal, Compliance, HR, and senior leadership.
- Drive proactive threat discovery and hunting by mining telemetry to surface suspicious behaviors and emerging patterns.
- Propose and refine detection rules, monitoring use cases, and investigation playbooks based on lessons learned during investigations.
- Maintain forensic lab equipment, imaging tools, and evidence storage procedures.
- Develop and maintain automation and scripts to speed evidence processing, parsing, and reporting.
- Coordinate large-scale or cross-functional forensic efforts and manage external vendors as needed.
- Mentor and train junior analysts and contribute metrics and post-incident reviews to improve response maturity.

Qualifications

Minimum Qualifications:
- Hands-on DF/IR or equivalent investigation experience across endpoints, network, cloud, and internal platform logs.
- Strong log analytics using SIEM or log-query platforms, with ability to query, pivot, and correlate large and noisy datasets.
- Practical experience with EDR/HIDS and endpoint telemetry interpretation.
- Experience identifying and investigating data exfiltration and data misuse across cloud, endpoint, network, and internal systems.
- Ability to acquire and preserve evidence with documented chain-of-custody and forensic controls.
- Ability to produce defensible, reproducible investigations with clear reasoning and evidence traceability.
- Scripting or automation skills such as Python, JQ, or SQL to accelerate investigations.
- Experience leading investigations, coordinating stakeholders, and driving cases to closure.
- Strong analytical skills for data mining and anomaly detection in large datasets.

Preferred Qualifications
- 5+ years in a Digital Forensics or Incident Response role.
- Experience with mobile forensics and cloud platform acquisition and analysis.
- Experience operating in regulated environments and supporting audits or evidence requests.
- Familiarity with AI-assisted investigation tools for triage, log summarization, report drafting, and automation.
- Advanced scripting and query skills for automation and custom parsing.
- Experience coordinating or providing evidence for legal or disciplinary processes, or testifying in legal settings.
- Relevant certifications such as GIME, GCFE, GCFA, EnCE, or similar.

Client-provided location(s): Singapore
Job ID: TikTok-7619354844582775045
Employment Type: OTHER
Posted: 2026-03-20T20:31:37

Perks and Benefits

  • Health and Wellness

    • Health Insurance
    • Dental Insurance
    • Vision Insurance
    • HSA
    • Life Insurance
    • Fitness Subsidies
    • Short-Term Disability
    • Long-Term Disability
    • On-Site Gym
    • Mental Health Benefits
    • Virtual Fitness Classes
  • Parental Benefits

    • Fertility Benefits
    • Adoption Assistance Program
    • Family Support Resources
  • Work Flexibility

    • Flexible Work Hours
    • Hybrid Work Opportunities
  • Office Life and Perks

    • Casual Dress
    • Snacks
    • Pet-friendly Office
    • Happy Hours
    • Some Meals Provided
    • Company Outings
    • On-Site Cafeteria
    • Holiday Events
  • Vacation and Time Off

    • Paid Vacation
    • Paid Holidays
    • Personal/Sick Days
    • Leave of Absence
  • Financial and Retirement

    • 401(K) With Company Matching
    • Performance Bonus
    • Company Equity
  • Professional Development

    • Promote From Within
    • Access to Online Courses
    • Leadership Training Program
    • Associate or Rotational Training Program
    • Mentor Program
  • Diversity and Inclusion

    • Diversity, Equity, and Inclusion Program
    • Employee Resource Groups (ERG)

Company Videos

Hear directly from employees about what it is like to work at TikTok.