About this roleThe mission of TikTok's Global Security Organization is to build and earn trust by reducing risk and securing our businesses and products. Also known as "GSO", this team is the foundation of our efforts to keep TikTok safe, secure, and operating at scale for over 1 billion people around the world. We work to ensure that the TikTok platform is safe and secure, that our users' experience and their data remains safe from external or internal threats, and that we comply with global regulations wherever TikTok operates.
Trust is one of TikTok's biggest initiatives, and security is integral to our success. In whatever ways users interact with us — whether they're watching videos on their For You page, interacting with a Live video, or buying products on TikTok Shop — GSO protects their data and privacy, so they can have a secure and trustworthy experience.
TikTok’s Insider Risk team is seeking a technical security analyst to help lead high-impact internal investigations globally. In this position, you will investigate threats related to, but not limited to, exfiltration, data misuse, policy violations, dual employment, and reputational risk stemming from TikTok personnel or operations.
This role demands strong technical acumen, investigative instincts, and the ability to navigate sensitive matters across multiple jurisdictions. You will work independently but collaboratively, serving as the key technical point of contact for insider risk cases. Candidates must have experience in security analysis or engineering and have operated within a large-scale tech, platform, or media environment.
Key Responsibilities:
- Lead technical insider risk investigations from intake to closure involving sensitive matters such as: Data exfiltration or misuse, Unauthorized platform access or privilege abuse, Dual employment and conflict of interest concerns, Misconduct with potential public or regulatory exposure and Tampering with intellectual property
- Analyze telemetry data and indicators across regional infrastructure: DLP alerts, endpoint logs, VPN activity, service logs, and our internal collaboration platform.
- Conduct interviews with employees and stakeholders across the AMS and other regions, exercising sound judgment and cultural sensitivity.
- Write thorough, region-specific investigation reports, ensuring alignment with global protocols while reflecting local legal and business context.
- Collaborate with Legal, HR, Engineering, PR, and Policy teams across the Americas to coordinate investigative outcomes and support remediation or disciplinary action.
- Monitor and assess external threats and public disclosures originating from internal actions that may affect TikTok’s brand globally.
- Identify and address regional detection gaps, contribute to threat modeling, and help shape alerting logic in partnership with detection, analysis, and engineering teams.
- Maintain complete discretion and proper handling of sensitive employee, operational, and company data in accordance with regional privacy laws.