Tech Lead Privacy Engineer- Red Team
Responsibilities
About the Team
PDPO(Privacy and Data Protection Office) is the organization to lead, supervise, and empower all TikTok's privacy work in an accountable and industry leading way. This team is the expert in the landscape of privacy risks and passionate about consulting across the company on implementing the proper safeguards and technical mitigations to ensure that our users' privacy is honored across the TikTok's products and platforms.
Our mission is to protect personal data and privacy for billions of users on TikTok platform, let users explore, create and connect with each other with trust. On the path of constructing and consolidating a reliable and resilient tool, framework, architecture and relative workflow, you will face challenges of ensuring high quality and stability with global multi-datacenter deployment, high-concurrency micro service, and you will face global cooperation.
Responsibilities
1. Privacy and security assessment on TikTok's data protection system to find both privacy and security issues that can affect user's data
2. Build data protection system threat model to summarise the overall data leakage risks and help engineering teams to strengthen the protection system
3. Advanced privacy and security topics research
Qualifications
Minimum Qualifications
1. Experience with web system penetration testing, vulnerability research and data privacy understanding, the ability to complete vulnerability finding and verification independently
2. Understanding of common web application framework architecture, cloud service architecture and data storage system architecture, have practical penetration experience on actual web system or data protection system
3. Experience with common testing frameworks and tools to perform security testing (e.g. Burp Suite, sqlmap, any kind of SAST or DAST tools)
4. Coding experience in one of the programming languages for more than 5 years : Golang, python, Java, C/C++
5. 5+ years work experience in web security or data security
6. B.S. or M.S. in Computer Science or relevant certification
Preferred Qualifications
1. Public research or paper in privacy or security communities and conferences;
2. Public CVEs owners, bug bounty hall of fame nomination
3. Top winners of famous CTF competition
Job Information
[For Pay Transparency] Compensation Description (annually)
The base salary range for this position in the selected city is $208800 - $438000 annually.
Compensation may vary outside of this range depending on a number of factors, including a candidate's qualifications, skills, competencies and experience, and location. Base pay is one part of the Total Package that is provided to compensate and recognize employees for their work, and this role may be eligible for additional discretionary bonuses/incentives, and restricted stock units.
Benefits may vary depending on the nature of employment and the country work location. Employees have day one access to medical, dental, and vision insurance, a 401(k) savings plan with company match, paid parental leave, short-term and long-term disability coverage, life insurance, wellbeing benefits, among others. Employees also receive 10 paid holidays per year, 10 paid sick days per year and 17 days of Paid Personal Time (prorated upon hire with increasing accruals by tenure).
The Company reserves the right to modify or change these benefits programs at any time, with or without notice.
For Los Angeles County (unincorporated) Candidates:
Qualified applicants with arrest or conviction records will be considered for employment in accordance with all federal, state, and local laws including the Los Angeles County Fair Chance Ordinance for Employers and the California Fair Chance Act. Our company believes that criminal history may have a direct, adverse and negative relationship on the following job duties, potentially resulting in the withdrawal of the conditional offer of employment:
1. Interacting and occasionally having unsupervised contact with internal/external clients and/or colleagues;
2. Appropriately handling and managing confidential information including proprietary and trade secret information and access to information technology systems; and
3. Exercising sound judgment.
Want more jobs like this?
Get jobs in San Jose, CA delivered to your inbox every week.

Perks and Benefits
Health and Wellness
- Health Insurance
- Dental Insurance
- Vision Insurance
- HSA
- Life Insurance
- Fitness Subsidies
- Short-Term Disability
- Long-Term Disability
- On-Site Gym
- Mental Health Benefits
- Virtual Fitness Classes
Parental Benefits
- Fertility Benefits
- Adoption Assistance Program
- Family Support Resources
Work Flexibility
- Flexible Work Hours
- Hybrid Work Opportunities
Office Life and Perks
- Casual Dress
- Snacks
- Pet-friendly Office
- Happy Hours
- Some Meals Provided
- Company Outings
- On-Site Cafeteria
- Holiday Events
Vacation and Time Off
- Paid Vacation
- Paid Holidays
- Personal/Sick Days
- Leave of Absence
Financial and Retirement
- 401(K) With Company Matching
- Performance Bonus
- Company Equity
Professional Development
- Promote From Within
- Access to Online Courses
- Leadership Training Program
- Associate or Rotational Training Program
- Mentor Program
Diversity and Inclusion
- Diversity, Equity, and Inclusion Program
- Employee Resource Groups (ERG)
Company Videos
Hear directly from employees about what it is like to work at TikTok.