TikTok
Overview
Responsibilities and qualifications for the Privacy Risk Assessor role within the USDS Privacy and Integrated Security team at TikTok. Responsibilities
Perform privacy threshold analyses and impact assessments to drive risk identification and reduction associated with product and feature launches and third party engagements. Support the development, implementation, and documentation of the privacy impact assessment program and corresponding processes in adherence with security principles and industry frameworks. Draft operating procedures and document the engagement model with internal partners to drive effective collaboration. Support the management and communication of privacy risk findings and mitigation strategies with partner teams and leadership and align with security risk findings and analysis. Perform risk monitoring, manage the risk remediation process, ensuring risk treatment plans are executed effectively. Support risk reporting and socialization to inform stakeholders and risk owners. Drive automation and efficiency initiatives to facilitate integration with other internal risk assessment programs and support timely due diligence for business partners. Engage in special projects and additional responsibilities as the team expands and capabilities are enhanced. Qualifications
Minimum Qualifications: Bachelor’s degree in Information Security, IT Management, Accounting, or a related field. Candidates with significant relevant experience in security, privacy and data protection fields will be considered in lieu of a formal degree. Hands-on experience conducting control validation, risk assessments and tracking remediation plans. 5+ years of relevant technical experience in risk management, product compliance management, privacy compliance. Knowledge of global and US privacy regulations (GDPR, COPPA, CCPA, etc.). Excellent knowledge of industry standards frameworks (NIST Privacy Framework, ISO/IEC 27701, NIST RMF, ISO 31000, COBIT, IAPP guidelines, etc.). Demonstrated analytical, problem solving, teamwork and collaboration skills in leading or contributing to multi-functional teams. Preferred Qualifications: CISSP, CIPP, CIPT, CIPM, CISA, or CRISC certification is a plus. Cyber security, information security, or privacy engineering experience in an R&D setting. If you do not have privacy risk management experience but have strong cyber security and risk management experience, we encourage you to apply. Security or privacy engineering experience is highly desired to elevate technical knowledge to the enterprise level. About USDS
TikTok is the leading destination for short-form mobile video. Our mission is to inspire creativity and bring joy. U.S. Data Security (USDS) is a subsidiary of TikTok in the U.S. This security-first division focuses on data protection policies and content assurance protocols to keep U.S. users safe. USDS teams span Trust & Safety, Security & Privacy, Engineering, User & Product Ops, Corporate Functions, and more. Data Security Statement
This role requires the ability to work with and support systems designed to protect sensitive data and information. As such, this role will be subject to strict national security-related screening. Why Join Us
Inspiring creativity is core to TikTok's mission. Our innovative product helps people express themselves, discover, and connect. Our global, diverse teams make that possible. We strive to do great things with great people and foster an "Always Day 1" mindset to achieve meaningful breakthroughs for our users, company, and ourselves. USDS Reasonable Accommodation
USDS provides reasonable accommodations in our recruitment processes for candidates with disabilities or other protected reasons. If you need assistance, please reach out to us at https://tinyurl.com/USDS-RA. Job Information
For Pay Transparency: Compensation Description (Annually) - Washington, DC. The base salary range for this position in the selected city is 89,920 - 162,400 USD annually. Compensation may vary outside this range based on qualifications, skills, competencies, experience, and location. Base pay is one part of the Total Package and may include bonuses, incentives, and restricted stock units. Benefits include medical, dental, vision, 401(k) with company match, paid parental leave, disability coverage, life insurance, wellbeing benefits, and paid time off. The Company reserves the right to modify benefits programs at any time. Seniority level: Associate • Employment type: Full-time • Job function: Other • Industries: Technology, Information and Internet
#J-18808-Ljbffr
Responsibilities and qualifications for the Privacy Risk Assessor role within the USDS Privacy and Integrated Security team at TikTok. Responsibilities
Perform privacy threshold analyses and impact assessments to drive risk identification and reduction associated with product and feature launches and third party engagements. Support the development, implementation, and documentation of the privacy impact assessment program and corresponding processes in adherence with security principles and industry frameworks. Draft operating procedures and document the engagement model with internal partners to drive effective collaboration. Support the management and communication of privacy risk findings and mitigation strategies with partner teams and leadership and align with security risk findings and analysis. Perform risk monitoring, manage the risk remediation process, ensuring risk treatment plans are executed effectively. Support risk reporting and socialization to inform stakeholders and risk owners. Drive automation and efficiency initiatives to facilitate integration with other internal risk assessment programs and support timely due diligence for business partners. Engage in special projects and additional responsibilities as the team expands and capabilities are enhanced. Qualifications
Minimum Qualifications: Bachelor’s degree in Information Security, IT Management, Accounting, or a related field. Candidates with significant relevant experience in security, privacy and data protection fields will be considered in lieu of a formal degree. Hands-on experience conducting control validation, risk assessments and tracking remediation plans. 5+ years of relevant technical experience in risk management, product compliance management, privacy compliance. Knowledge of global and US privacy regulations (GDPR, COPPA, CCPA, etc.). Excellent knowledge of industry standards frameworks (NIST Privacy Framework, ISO/IEC 27701, NIST RMF, ISO 31000, COBIT, IAPP guidelines, etc.). Demonstrated analytical, problem solving, teamwork and collaboration skills in leading or contributing to multi-functional teams. Preferred Qualifications: CISSP, CIPP, CIPT, CIPM, CISA, or CRISC certification is a plus. Cyber security, information security, or privacy engineering experience in an R&D setting. If you do not have privacy risk management experience but have strong cyber security and risk management experience, we encourage you to apply. Security or privacy engineering experience is highly desired to elevate technical knowledge to the enterprise level. About USDS
TikTok is the leading destination for short-form mobile video. Our mission is to inspire creativity and bring joy. U.S. Data Security (USDS) is a subsidiary of TikTok in the U.S. This security-first division focuses on data protection policies and content assurance protocols to keep U.S. users safe. USDS teams span Trust & Safety, Security & Privacy, Engineering, User & Product Ops, Corporate Functions, and more. Data Security Statement
This role requires the ability to work with and support systems designed to protect sensitive data and information. As such, this role will be subject to strict national security-related screening. Why Join Us
Inspiring creativity is core to TikTok's mission. Our innovative product helps people express themselves, discover, and connect. Our global, diverse teams make that possible. We strive to do great things with great people and foster an "Always Day 1" mindset to achieve meaningful breakthroughs for our users, company, and ourselves. USDS Reasonable Accommodation
USDS provides reasonable accommodations in our recruitment processes for candidates with disabilities or other protected reasons. If you need assistance, please reach out to us at https://tinyurl.com/USDS-RA. Job Information
For Pay Transparency: Compensation Description (Annually) - Washington, DC. The base salary range for this position in the selected city is 89,920 - 162,400 USD annually. Compensation may vary outside this range based on qualifications, skills, competencies, experience, and location. Base pay is one part of the Total Package and may include bonuses, incentives, and restricted stock units. Benefits include medical, dental, vision, 401(k) with company match, paid parental leave, disability coverage, life insurance, wellbeing benefits, and paid time off. The Company reserves the right to modify benefits programs at any time. Seniority level: Associate • Employment type: Full-time • Job function: Other • Industries: Technology, Information and Internet
#J-18808-Ljbffr