Security Analyst, Insider Risk - Global Security Organisation
TikTok
Singapore
Full time
4 days ago
The Global Security Organization provides industry-leading cybersecurity and business protection services to TikTok globally. Our organization employs four principles that guide our strategic and tactical operations. Firstly, we Champion Transparency & Trust by leading the charge in organizational transparency, prioritizing customer trust, and placing user needs first. Secondly, we aim to maintain Best in Class Global Security by proactively identifying and reducing risks while enabling innovative product development. We constantly work towards a sustainable world-class security capability. Thirdly, we strive to be a Business Catalyst & Enabler by embodying the DNA of technical innovation and ensuring our Global Security operations are fast and agile. Finally, we Drive Empowered & Risk-Informed Decision Making by providing our leaders with the necessary information to make agile decisions based on risk. In order to enhance collaboration and cross-functional partnerships, our organization follows a hybrid work schedule that requires employees to work in the office for 3 days a week, as directed by their manager. We regularly review our hybrid work model, and the specific requirements may change at any time.
As part of the Threat and Incident Management team, you will support TikTok's inside threat operation. You will utilize analytical methods to understand insider risk patterns and establish models for forecasting insider risk scenarios. The candidate will also collaborate with stakeholders from data engineers to executives, prioritizing data sources for onboarding into risk models and gathering requirements for dashboards to provide a holistic view on operations.
Responsibilities
- Analyze large and complex datasets to identify potential threats and develop detection logic to mitigate risks.
- Triage, investigate, and escalate security incidents from various sources including SIEM, DLP, UEBA, and endpoint tools.
- Respond to security incidents in real-time and participate in root cause analysis, escalation, and incident recovery efforts.
- Coordinate with system owners, data teams, and business units to enhance detection logic, data, reduce false positives, and refine workflows.
- Create and maintain dashboards to support threat hunting, investigations, and operational reporting.
- Communicate findings, risk posture, and recommended remediation steps clearly to both technical and non-technical stakeholders.
- Partner with cross-functional teams to identify process improvements and implement scalable security solutions.
- Contribute to continuous improvement efforts in detection coverage, response readiness, and insider threat frameworks.