Security Remediation Manager - Global Security Organization
关于这个机会
The mission of TikTok's Global Security Organization is to build and earn trust by reducing risk and securing our businesses and products. Also known as "GSO", this team is the foundation of our efforts to keep TikTok safe, secure, and operating at scale for over 1 billion people around the world. We work to ensure that the TikTok platform is safe and secure, that our users' experience and their data remains safe from external or internal threats, and that we comply with global regulations wherever TikTok operates. Trust is one of TikTok's biggest initiatives, and security is integral to our success. In whatever ways users interact with us — whether they're watching videos on their For You page, interacting with a Live video, or buying products on TikTok Shop — GSO protects their data and privacy, so they can have a secure and trustworthy experience. The Security Posture Management (SPM) program is responsible for providing a centralized view of security incident-driven issues across the organization and driving consistent, risk-based remediation across teams. As a Remediation Manager, you will own the end-to-end lifecycle of security issues from intake and prioritization through remediation and closure. You will partner with security domain teams, engineering teams, infrastructure teams, and business stakeholders to ensure high-priority security risks are clearly owned and remediated within defined timelines. This role requires a strong combination of security knowledge, program management, data-driven decision-making, and cross-functional influence. Responsibilities - Manage security issues identified across multiple sources, including security incidents, vulnerability management, penetration testing, risk assessments, insider risk, and other security programs. - Establish, customize, and maintain centralized issue tracking and remediation management systems, and continuously enhance automated posture management processes — including findings intake, remediation ticketing, ownership assignment, action planning, severity calibration, escalation, and closure — to streamline operations across Incident Response, Vulnerability Management, and other security domains. - Partner with security domain teams to conduct root-cause analyses, identify systemic control gaps, and co-design sustainable remediation solutions that translate security findings into executable projects and initiatives. - Drive end-to-end remediation of high-priority security issues with security domain teams, security BP, engineering, infrastructure, IT, and other stakeholder teams. - Define clear remediation strategies, action plans, milestones, accountable owners, and target completion dates based on risk and business impact. - Proactively identify and resolve remediation blockers, cross-team dependencies, ownership gaps, and competing priorities. - Escalate overdue, blocked, or high-risk issues through appropriate governance and leadership channels when necessary. - Validate remediation implementation and supporting evidence, partnering with security SMEs to confirm that identified risks have been effectively addressed and closure criteria are met. - Develop security posture dashboards and reporting to provide clear visibility into remediation roadmaps, progress, key milestones, and overall risk reduction.
任职要求
Minimum Qualification(s) - Experience managing security findings or remediation programs across multiple technical teams. - Strong understanding of common security risks across areas such as cloud, infrastructure, identity, endpoints, applications, and vulnerabilities. - Demonstrated ability to drive complex cross-functional initiatives without direct authority. - Strong analytical and problem-solving skills with the ability to prioritize issues based on risk and business impact. - Experience developing security metrics, dashboards, or executive-level reporting. - Excellent written and verbal communication skills, including the ability to communicate technical security risks to both technical and non-technical stakeholders. Preferred Qualification(s) - 5+ years of experience in cybersecurity, security program management, vulnerability management, security operations, risk management, or related fields. - Experience building or operating centralized security issue management or security posture management programs. - Experience with security domains such as incident response, vulnerability management, threat intelligence, etc. - Experience with managing cross-functional remediation programs across multiple regions. - Understanding of security frameworks such as NIST CSF, CIS Controls, ISO 27001, or related standards. - Experience with root-cause analysis and identifying systemic security control gaps. - Experience using automation, data analytics, or AI to improve security operations and remediation workflows.
内推申请说明
本站为独立内推协助平台。申请会交由管理员核实岗位与内推渠道,不等于已在公司官网投递;薪资、岗位状态和实际招聘流程以官方信息为准。