Skip to main contentA logo with &quat;the muse&quat; in dark blue text.
TikTok

Vulnerability Management and Bug Bounty Senior Analyst

Washington, DC

Responsibilities

TikTok is the leading destination for short-form mobile video. Our mission is to inspire creativity and bring joy. TikTok has global offices including Los Angeles, New York, London, Paris, Berlin, Dubai, Singapore, Jakarta, Seoul and Tokyo.

Why Join Us
Creation is the core of TikTok's purpose. Our platform is built to help imaginations thrive. This is doubly true of the teams that make TikTok possible.
Together, we inspire creativity and bring joy - a mission we all believe in and aim towards achieving every day.
To us, every challenge, no matter how difficult, is an opportunity; to learn, to innovate, and to grow as one team. Status quo? Never. Courage? Always.
At TikTok, we create together and grow together. That's how we drive impact - for ourselves, our company, and the communities we serve.

Want more jobs like this?

Get jobs in Washington, DC delivered to your inbox every week.

By signing up, you agree to our Terms of Service & Privacy Policy.

Join us.

The Global Security Organization provides industry-leading cyber-security and business protection services to TikTok globally. Our organization employs four principles that guide our strategic and tactical operations. Firstly, we Champion Transparency & Trust by leading the charge in organizational transparency, prioritizing customer trust, and placing user needs first. Secondly, we aim to maintain Best in Class Global Security by proactively identifying and reducing risks while enabling innovative product development. We constantly work towards a sustainable world-class security capability. Thirdly, we strive to be a Business Catalyst & Enabler by embodying the DNA of technical innovation and ensuring our Global Security operations are fast and agile. Finally, we Drive Empowered & Risk-Informed Decision Making by providing our leaders with the necessary information to make agile decisions based on risk.

The Vulnerability Management and Bug Bounty Senior Analyst is tasked with the day to day activities of the Vulnerability Management Team. They manage and continuously improve the external bug bounty program. They should be aware of current policies and procedures and ensure they are being followed properly. The senior analyst should have hands on experience with vulnerability management tools and be able to mentor and advise other team members.

Tasks and Responsibilites:
- Develop and implement a comprehensive vulnerability management strategy for web and mobile applications.
- Manage and continuously improve the external bug bounty program, including setting program scope, rules of engagement, and incentives for researchers to participate.
- Triage reported vulnerabilities from the bug bounty program, prioritize them based on risk and impact assessments, and coordinate with internal development teams for timely resolution.
- Regularly evaluate the performance and results of the bug bounty program, identify areas for improvement, and implement enhancements to mature the program over time.
- Collaborate with external bug bounty platforms or vendors to ensure the program's effectiveness and efficiency.
- Actively engage with external security researchers, fostering a collaborative relationship to encourage their participation in the bug bounty program and to facilitate effective communication throughout the vulnerability disclosure process.
- Conduct manual verification of security issues identified through automated scans, manual tests or reported by external researchers to validate their severity and impact.
- Collaborate with cross-functional teams to prioritize and address identified vulnerabilities based on risk and impact assessments.
- Track and report on the status of vulnerability remediation efforts, including providing regular updates to stakeholders.
- Stay informed about emerging security threats, industry best practices, and relevant regulations to continuously improve the effectiveness of our vulnerability management program.
- Mentor and provide guidance to junior team members on vulnerability management processes and techniques.
- Evaluate vulnerabilities based on prioritization criteria
- Investigate persistent vulnerabilities
- Coordinate and communicate with cross-functional teams throughout the VM lifecycle
- Facilitate exception handling and escalation
- Support regulatory compliance monitoring and reporting
- Review and optimize scan templates to ensure complete coverage of environment
- Support treatment and remediation activities with identified points of contact and system owners
- Provide risk analysis for identified vulnerabilities and system change requests
- Develop processes and document procedures for use by other team members and to enhance efficiencies
- Maintain regular communication with Vulnerability Management Lead and organizational management for collaboration, process optimization, tools tuning, and information sharing

Qualifications

Minimum Qualifications:
- Hands-on experience with vulnerability assessment tools, penetration testing methodologies, and secure coding practices.
- Experience managing external bug bounty programs and working with security researchers.
- Strong understanding of web and mobile application security vulnerabilities, such as OWASP Top 10.
- Excellent communication skills, with the ability to effectively collaborate with both technical and non-technical stakeholders.
- Ability to conduct root cause analysis against vulnerabilities and determine feasible technical solutions.
- Ability to work alongside other security functions to determine vulnerability scoring and impact
- Strong analytical and problem-solving skills and Project management experience

Preferred Qualifications:
- Bachelor's Degree or industry equivalent work experience in vulnerability management or application security testing
- 5 years of experience in vulnerability management, penetration testing, or related fields
- CISSP, CEH, OSCP, or equivalent certification
- Familiarity with vulnerability management across SaaS and IaaS cloud platforms (e.g., AWS, Google Cloud, etc.)
- Working knowledge/experience with Python, SQL and REST APIs
- Ability to handle ambiguity and collaborate with a global team
- Ability to coach junior staff and contractors

TikTok is committed to creating an inclusive space where employees are valued for their skills, experiences, and unique perspectives. Our platform connects people from across the globe and so does our workplace. At TikTok, our mission is to inspire creativity and bring joy. To achieve that goal, we are committed to celebrating our diverse voices and to creating an environment that reflects the many communities we reach. We are passionate about this and hope you are too.

TikTok is committed to providing reasonable accommodations in our recruitment processes for candidates with disabilities, pregnancy, sincerely held religious beliefs or other reasons protected by applicable laws. If you need assistance or a reasonable accommodation, please reach out to us at https://shorturl.at/cdpT2

Client-provided location(s): Washington, DC, USA
Job ID: TikTok-7340836770987329801
Employment Type: Other

Perks and Benefits

  • Health and Wellness

    • Health Insurance
    • Dental Insurance
    • Vision Insurance
    • HSA
    • Life Insurance
    • Fitness Subsidies
    • Short-Term Disability
    • Long-Term Disability
    • On-Site Gym
    • Mental Health Benefits
    • Virtual Fitness Classes
  • Parental Benefits

    • Fertility Benefits
    • Adoption Assistance Program
    • Family Support Resources
  • Work Flexibility

    • Flexible Work Hours
    • Hybrid Work Opportunities
  • Office Life and Perks

    • Casual Dress
    • Snacks
    • Pet-friendly Office
    • Happy Hours
    • Some Meals Provided
    • Company Outings
    • On-Site Cafeteria
    • Holiday Events
  • Vacation and Time Off

    • Paid Vacation
    • Paid Holidays
    • Personal/Sick Days
    • Leave of Absence
  • Financial and Retirement

    • 401(K) With Company Matching
    • Performance Bonus
    • Company Equity
  • Professional Development

    • Promote From Within
    • Access to Online Courses
    • Leadership Training Program
    • Associate or Rotational Training Program
    • Mentor Program
  • Diversity and Inclusion

    • Diversity, Equity, and Inclusion Program
    • Employee Resource Groups (ERG)

Company Videos

Hear directly from employees about what it is like to work at TikTok.