Technology Internal Audit Lead
Responsibilities
Internal Audit is a global function responsible for providing independent assurance and evaluating the company's risk management, governance and internal control processes to determine if they are designed and operating effectively. The Internal Audit team plans and executes audit projects according to our risk-based audit plan by evaluating operational, compliance, IT, and financial processes and controls. We work with business functions in addressing risks and improving the control environment through timely and comprehensive audit work and tracking of remediation actions until completion.
Position Summary:
We are looking for an experienced Technology Internal Audit Lead to join the Global Technology Audit team. The role will primarily support TikTok and other products operating outside China and will be responsible for leading technology audits and risk reviews. The individual will be part of the Global Technology Audit team and innovative assurance methods to impact and influence positive business outcomes across products such as TikTok, TikTok Shop and Dola.
Responsibilities:
- Technology Audit Delivery: Lead planning and execution of technology audit programs and complex technology control assessments: Products powered by LLMs, Information Security, Infrastructure, Privacy. Assess technical architectures for AI/ML systems, focusing on data flow, model training & fine-tuning processes, model serving infrastructure, and integration with downstream applications.
- Advanced Data Analytics: Leverage data analytics to detect risk signals and unearth insights for AI/ML models. Review controls for data quality, privacy, security, access management, safety testing, hallucination mitigation, evaluation metrics, red-teaming procedures, and output monitoring.
- Technology Risk Assessment: Develop practical, risk-based recommendations that address root causes while considering product, engineering, regulatory, and business requirements. Ability to grasp complex, home grown technology stack, comfortable speaking with engineers and product teams.
- Stakeholder Relationships: Develop and maintain collaborative working relationships with management, understand the business to provide value-added services, and establish credibility as a management consultant and internal controls resource. Partner with engineering and product teams to advise on design and implementation of technology solutions.
- Quality Assurance: Ensure the overall quality and consistency of audit work, adhering to department and professional standards. Continuously seek opportunities for audit process improvement.
Qualifications
Minimum Qualifications:
- 5+ years of relevant experience in Technology Audits, Product Security, Security Engineering or Security Compliance preferably within the technology sector (Social Media, Content Management, FinTech etc.), and/or consulting firms. Proven ability to work in a fast-paced environment with a product centric culture.
- Strong understanding of security fundamentals across various cyber domains: IAM, applied cryptography, key management systems, data security, application security, web security, security protocols, API Design, threat intelligence, network security, hardware security, vulnerability management, etc.
- Proven analytical ability to assess complex technology environments against risk assessment outcomes, industry best practices, internal standards and external regulatory requirements.
- Excellent problem solving, critical thinking, collaboration and communication skills combined with the ability to provide a credible technical challenge to the business.
Want more jobs like this?
Get jobs in New York, NY delivered to your inbox every week.

Preferred Qualifications:
- Deep understanding of LLMs, ML pipelines, model lifecycle management, and data engineering architectures.
- Experience working in a fast-paced, global technology company or rapidly scaling environment across different time zones.
- Solid background and experience working with one or more of the following areas:
- LLMs or ML frameworks (e.g., PyTorch, TensorFlow, HuggingFace)
- Common application and infrastructure security vulnerabilities and mitigations (OWASP Top 10, CWE 25)
- Source code and DevOps management tools (e.g., Github, Bitbucket)
- SaaS and IaaS cloud platforms (e.g., AWS, Azure, GCP)
- Professional certifications such as CISSP, CISM, GIAC, CCNA, CISA, CRISC, or CIA.
- Be able to handle ambiguity and collaborate with a global team.
- Passion for emerging technologies, products and standards.
Job Information
[For Pay Transparency] Compensation Description (annually)
The base salary range for this position in the selected city is $108000 - $208800 annually.
Compensation may vary outside of this range depending on a number of factors, including a candidate's qualifications, skills, competencies and experience, and location. Base pay is one part of the Total Package that is provided to compensate and recognize employees for their work, and this role may be eligible for additional discretionary bonuses/incentives, and restricted stock units.
Benefits may vary depending on the nature of employment and the country work location. Employees have day one access to medical, dental, and vision insurance, a 401(k) savings plan with company match, paid parental leave, short-term and long-term disability coverage, life insurance, wellbeing benefits, among others. Employees also receive 10 paid holidays per year, 10 paid sick days per year and 17 days of Paid Personal Time (prorated upon hire with increasing accruals by tenure).
The Company reserves the right to modify or change these benefits programs at any time, with or without notice.
For Los Angeles County (unincorporated) Candidates:
Qualified applicants with arrest or conviction records will be considered for employment in accordance with all federal, state, and local laws including the Los Angeles County Fair Chance Ordinance for Employers and the California Fair Chance Act. Our company believes that criminal history may have a direct, adverse and negative relationship on the following job duties, potentially resulting in the withdrawal of the conditional offer of employment:
1. Interacting and occasionally having unsupervised contact with internal/external clients and/or colleagues;
2. Appropriately handling and managing confidential information including proprietary and trade secret information and access to information technology systems; and
3. Exercising sound judgment.
Perks and Benefits
Health and Wellness
- Health Insurance
- Dental Insurance
- Vision Insurance
- HSA
- Life Insurance
- Fitness Subsidies
- Short-Term Disability
- Long-Term Disability
- On-Site Gym
- Mental Health Benefits
- Virtual Fitness Classes
Parental Benefits
- Fertility Benefits
- Adoption Assistance Program
- Family Support Resources
Work Flexibility
- Flexible Work Hours
- Hybrid Work Opportunities
Office Life and Perks
- Casual Dress
- Snacks
- Pet-friendly Office
- Happy Hours
- Some Meals Provided
- Company Outings
- On-Site Cafeteria
- Holiday Events
Vacation and Time Off
- Paid Vacation
- Paid Holidays
- Personal/Sick Days
- Leave of Absence
Financial and Retirement
- 401(K) With Company Matching
- Performance Bonus
- Company Equity
Professional Development
- Promote From Within
- Access to Online Courses
- Leadership Training Program
- Associate or Rotational Training Program
- Mentor Program
Diversity and Inclusion
- Diversity, Equity, and Inclusion Program
- Employee Resource Groups (ERG)
Company Videos
Hear directly from employees about what it is like to work at TikTok.