Identity and Access Management Senior Analyst - Global Security Organization
TikTokAbout the role
The mission of TikTok's Global Security Organization is to build and earn trust by reducing risk and securing our businesses and products. Also known as "GSO", this team is the foundation of our efforts to keep TikTok safe, secure, and operating at scale for over 1 billion people around the world. We work to ensure that the TikTok platform is safe and secure, that our users' experience and their data remains safe from external or internal threats, and that we comply with global regulations wherever TikTok operates.
Trust is one of TikTok's biggest initiatives, and security is integral to our success. In whatever ways users interact with us — whether they're watching videos on their For You page, interacting with a Live video, or buying products on TikTok Shop — GSO protects their data and privacy, so they can have a secure and trustworthy experience.
TikTok is seeking a Senior Analyst for Access Operations to be part of the Product Trust and Access Governance team and will be responsible for overseeing operations and management of data access and data transfer requests to validate compliance with relevant company policy, geographical regulation, contractual commitments, and confidentiality requirements.
As a direct report to the Identity and Access Management lead within the Global Security Organization, you are part of a team that manages the security of TikTok data through access management processes and controls across the entire data lifecycle, from creation to destruction.
Further, you will oversee policies and procedures for managing access based and will ingest organizational policies to create enforcement mechanisms. This will entail understanding requirements, designing controls, and ultimately managing the on-going operation of those controls.
RESPONSIBILITIES
- Build and review technical and functional requirements for in-house or external technologies to support access management and assurance needs
- Design and implement access management and validation programs (people, process, and technology) to mitigate security threats and risks related to access that may impact business data through a holistic global program-oriented approach
- Design and implement the access review process, ensuring that access is reviewed regularly, both for appropriateness of access as well as privilege levels for all users
- Guide the team in developing use cases and integrating access management technologies with related cybersecurity technologies (e.g., security incident and event management, data classification, vulnerability management, identity management, authentication requirements)
- Create reporting and response execution for Access Management processes. This includes ensuring metrics coverage, accuracy, and usability to make key decisions and inform executive strategy. The candidate will also be responsible for drafting and executing processes that require expedited and prioritized response, in scenarios that may require collaboration across multiple teams
- Deliver projects in alignment with established guidelines for data security and data regionalization across global regions. The candidate is also expected to stay up-to-date with evolving data protection and regionalization requirements and guidelines (e.g., GDPR, cross-border transfer requirements). Based on the developments, the candidate will collaborate with stakeholders to ensure process implementations comply with relevant regional regulations and policies. The candidate will implement and enforce mechanisms to proactively monitor, respond and report on inappropriate data access events
- Provide input in cross-functional Legal and Engineering engagements where security operations are required to advance Global Security-IAM owned projects. The candidate will be expected to collaborate with engineers to assess new process requests for adherence to data privacy and security requirements, provide guidance and recommendations to ensure technical solutions align with best practices and regulatory standards. The candidate will also be responsible for interacting with engineering and business teams to define access standards and/or necessary modifications to new or existing access policies or roles in support of data security standards and regulations
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s