Overview
Cybersecurity Risk Quantification Analyst - USDS
The USDS Security, Risk & Compliance team manages security compliance in accordance with US requirements and provides governance, risk, and compliance services. Core offerings include : Compliance & Security Risk Management, Controls & Compliance Framework, Security Compliance Policies, Charters & Protocols, Vendor Program & Third-Party Risk Management, GRC Platform, and Security & Compliance Behavior & Culture.
Responsibilities
- Partner with Risk Owners to manage Security and Compliance related risks in the risk register throughout the risk lifecycle in accordance with leading industry frameworks.
- Lead the development and implementation of risk quantification improvements to scale current risk program operations.
- Identify risk using data, perform quantitative risk assessments, drive mitigation through risk treatment plans and by building KRIs to monitor risk.
- Develop business risk thresholds to drive risk management efforts.
- Deliver executive leadership risk reporting providing data-driven insights on top security and compliance risks measured against thresholds to drive decision-making.
- Scale the existing exception process and drive remediation efforts.
Qualifications
Minimum Qualifications
5+ years of applicable experience in relevant GRC functions (Security Risk Management) and implementing industry frameworks and technical programs including : Risk Quantification, FAIR model, ISO 31000.Strong organizational skills, effective time management, problem-solving abilities in ambiguous environments, and exceptional teamwork and collaboration skills, particularly in leading or contributing to global and multi-functional teams.Experience writing risk scenarios, managing identified risks in the register throughout all steps of the risk lifecycle, and driving follow-up with Risk Owners / Liaisons.Technical experience driving risk quantification enhancements supported by operational data (incidents, threat intel, findings) and KRIs within a global enterprise, developing a culture of risk-informed decision making.Strong technical knowledge of the tech stack, architecture, and technical security domains (e.g., SDLC, Identity and Access Management, Supply Chain) with the ability to clearly explain complex technical concepts to a non-technical audience.Preferred Qualifications
Excellent knowledge of industry standard frameworks and experience implementing programs aligned to FAIR, ISO 31000, ISO 27005, and NIST 800-39.Programming skills to develop tools and automate processes for risk monitoring and analysis based on operational data and KRIs / KPIs.Proficiency with modern GRC tooling (Archer, ServiceNow).Start-up experience.Relevant certifications (e.g., CISM, CISA, CISSP, CCSP, CASP, ISO27001 Lead Implementer / Audit, Security+, CRISC, CGEIT, GSEC).About USDS
USDS is a security-focused division of TikTok in the U.S. dedicated to governance and protection of TikTok platform and U.S. user data. Our teams span Trust & Safety, Security & Privacy, Engineering, User & Product Ops, and Corporate Functions.
Data Security Statement
This role requires working with systems designed to protect sensitive data and will be subject to strict national security-related screening.
Why Join Us
TikTok's mission is to inspire creativity and bring joy. We value curiosity, humility, collaboration, and a fast-paced, always-day-one mindset. We strive to achieve meaningful breakthroughs by growing together as a global team.
Diversity & Inclusion
TikTok is committed to an inclusive environment where employees are valued for their skills, experiences, and unique perspectives. We celebrate diverse voices and aim to reflect the communities we reach.
USDS Reasonable Accommodation
USDS provides reasonable accommodations in our recruitment processes for candidates with disabilities or other protected reasons. If you need assistance, please reach out to us at the provided accommodation contact.
Job Information
The base salary range and benefits, location applicability, and additional compensation details are provided as part of the formal job posting and may vary by city and candidate qualifications.
Location : New York, United States
Seniority level
Mid-Senior levelEmployment type
Full-timeJob function
Information TechnologyIndustries
Technology, Information and InternetJ-18808-Ljbffr