Search jobs > New York, NY > Senior security risk

Governance, Risk, & Compliance (GRC) Security Risk Senior Analyst - Global Security Organization

TikTok
New York, NY
Full-time

Responsibilities

TikTok is the leading destination for short-form mobile video. At TikTok, our mission is to inspire creativity and bring joy.

TikTok's global headquarters are in Los Angeles and Singapore, and its offices include New York, London, Dublin, Paris, Berlin, Dubai, Jakarta, Seoul, and Tokyo.

Why Join Us

Creation is the core of TikTok's purpose. Our platform is built to help imaginations thrive. This is doubly true of the teams that make TikTok possible.

Together, we inspire creativity and bring joy - a mission we all believe in and aim towards achieving every day.

To us, every challenge, no matter how difficult, is an opportunity; to learn, to innovate, and to grow as one team. Status quo? Never. Courage? Always.

At TikTok, we create together and grow together. That's how we drive impact - for ourselves, our company, and the communities we serve.

Join us.

The Global Security Organization provides industry-leading cybersecurity and business protection services to TikTok globally.

Our organization employs four principles that guide our strategic and tactical operations. Firstly, we Champion Transparency & Trust by leading the charge in organizational transparency, prioritizing customer trust, and placing user needs first.

Secondly, we aim to maintain Best in Class Global Security by proactively identifying and reducing risks while enabling innovative product development.

We constantly work towards a sustainable world-class security capability. Thirdly, we strive to be a Business Catalyst & Enabler by embodying the DNA of technical innovation and ensuring our Global Security operations are fast and agile.

Finally, we Drive Empowered & Risk-Informed Decision Making by providing our leaders with the necessary information to make agile decisions based on risk.

In order to enhance collaboration and cross-functional partnerships, our organization follows a hybrid work schedule that requires employees to work in the office for 3 days a week, as directed by their manager.

We regularly review our hybrid work model, and the specific requirements may change at any time.

The Security Governance, Risk, and Compliance team is responsible for working closely with cross-functional partners to manage security risks to ensure we meet all industry cybersecurity compliance standards and government regulations through developing governing policies, implementing the security control framework, conducting security risk and control assessments, and staying up-to-date on global compliance initiatives.

The Governance, Risk, & Compliance (GRC) Security Risk Management Senior Analyst involves performing comprehensive cybersecurity risk assessments to identify, assess, treat, and monitor cybersecurity risks throughout our products and enterprise.

You will be responsible for working closely with cross-functional partners to evaluate risks and develop innovative mitigation strategies, provide ongoing compliance risk mitigation support, and lead various risk management projects.

You would be a great fit for this role if you are enthusiastic about :

1. Maturing an industry-leading security risk management program alongside a team of outstanding individuals

2. Thriving in fast-paced environments and pivoting priorities while demonstrating the ability to quickly adapt in the face of constantly evolving cybersecurity challenges

3. Learning quickly and often with a strong appetite for acquiring new knowledge in the realm of cybersecurity and staying up-to-date on current emerging trends

4. Fostering collaboration and cross-functional partnerships to help spread awareness and drive the implementation of a strong security risk management program in order to mitigate risks faced by our organization

Responsibilities

As a Governance, Risk, & Compliance (GRC) Risk Management Senior Analyst, you will be responsible for :

  • Planning, developing, implementing, maintaining, and managing Cybersecurity Risk Management framework based on industry best practices (including ISO 31000, ISO 27005, and NIST 800-39)
  • Implementing and supporting scalable processes and procedures for the security risk lifecycle management including risk assessments, treatment, and monitoring
  • Collaborating with risk owners to ensure risk mitigation plans are developed and completed, tracking and reporting on the progress of the remediation plans on a regular basis
  • Continuously monitoring the Risk Register by assessing and re-assessing likelihood, impact, and the risk rating of all items in the Risk Register on a regular basis to maintain up-to-date status
  • Maintaining exception and acceptance processes to calculate residual business risk after weighing application security gaps, compensating controls, and inherent risk scores against established security risk appetite and tolerance criteria per business line
  • Mentor, coach, and train security staff and security risk analysts

Qualifications

Minimum Qualifications :

  • Experience collaborating closely with security partners, including incident response, red teams, architects, and engineers to seamlessly incorporate cybersecurity controls and risk management processes into their day-to-day operations
  • Team player and motivated self-starter who is resourceful and has the ability to work collaboratively with multiple stakeholders across different products, business lines, and regions
  • Excellent verbal communication skills with the ability to translate complex technical concepts into business language
  • Strong project management skills with the ability to lead and execute security risk and control projects and initiatives on time with multiple stakeholders
  • Ability to work at the San Jose office for 3 days per week and be willing to travel to other offices, including international locations, as required to support business needs

Preferred Qualifications

  • Minimum of 5 years of experience in planning, designing, implementing and managing cyber security risk management frameworks such as ISO 31000, ISO 27005, and NIST 800-39.
  • Minimum of 5 years of cybersecurity experience related to working on projects and teams related to security risk management, audit, compliance, information security, or other related fields
  • Familiarity with Governance, Risk, and Compliance (GRC) technologies such as RSA Archer or ServiceNow
  • CISM, CISA, CISSP, CCSP, CASP, Security+, CRISC, CGEIT, GSEC, or other relevant certifications

TikTok is committed to creating an inclusive space where employees are valued for their skills, experiences, and unique perspectives.

Our platform connects people from across the globe and so does our workplace. At TikTok, our mission is to inspire creativity and bring joy.

To achieve that goal, we are committed to celebrating our diverse voices and to creating an environment that reflects the many communities we reach.

We are passionate about this and hope you are too.

TikTok is committed to providing reasonable accommodations in our recruitment processes for candidates with disabilities, pregnancy, sincerely held religious beliefs or other reasons protected by applicable laws.

If you need assistance or a reasonable accommodation, please reach out to us at https : / / shorturl.at / cdpT2

18 days ago
Related jobs
Promoted
VirtualVocations
Queens, New York

A company is looking for a Governance, Risk & Compliance Manager to enhance and mature security programs. ...

Pelham Berkeley Search
New York, New York

Assess and evaluate Information Risks by conducting annual risk assessment, vulnerability Assessments and special risk assessments for new information risk related processes and trend analysis of key information risk measurements. Information Security Risk Governance Analyst. Develop and manage info...

Promoted
VirtualVocations
Queens, New York

A company is looking for a Director of Information Security Governance. ...

Promoted
Oscar Health
New York, New York

The Senior Specialist, Risk Adjustment for Medicare Advantage (MA) and Affordable Care Act (ACA) lines of business will work with management to meet communicated single and departmental goals, deadlines set forth by Centers for Medicare & Medicaid Services (CMS) and Health and Human Services (HH...

S&P Global
New York, New York

Technology Risk professional with in-depth knowledge of IT risk, Cybersecurity, Network risk, operational risk, 3rd party risk and other risks. A Key leader in development and execution of Technology Risk & Data Governance that provides strategic leadership to foster a culture of security and compli...

Veterans Sourcing
New York, New York

Develop, implement, and maintain Financial and Balance Sheet Risk Management framework to include the identification, assessment, measurement, simulation and management of funding and liquidity risk, investment risk, market and interest rate risk, capital risk, GAAP accounting risk, and earnings and...

JPMorgan Chase Bank, N.A.
New York, US

Act as a point of escalation for analysts on the team Required qualifications, capabilities, and skills * 3+ years of experience in cybersecurity operations, including threat detection, incident response, and vulnerability management * Demonstrated experience in network traf...

Capital One
New York, New York

We are hiring! The Enterprise Services Business Risk Office provides risk management support to several lines of business including: Brand, Enterprise Supplier Management, Enterprise Products & Experience (EPX), Software, External Affairs, eData, Global Workplace Solutions, Emerging Payments, Ventur...

S&P Global
New York, New York

The role of every member of the triCalculate Valuation and Risk Analytics team is multi-faceted and includes communicating regularly with our clients, business partners and relaying external information to other stakeholders within OSTTRA; delivering OSTTRA’s triCalculate services to its subscribers...

Bank of America
New York, New York

Key responsibilities include monitoring and adhering to market risk management policies, procedures, and standards, and implementing new/complex product approval processes, analysis of model risk, analysis and reporting of market risk, distributing the market risk reports, and interfacing with the t...