As part of the Threat and Incident Management team, you will support TikTok's inside threat operation. You will utilize analytical methods to understand insider risk patterns and establish models for forecasting insider risk scenarios. The candidate will also collaborate with stakeholders from data engineers to executives, prioritizing data sources for onboarding into risk models and gathering requirements for dashboards to provide a holistic view on operations.
Responsibilities
- Analyze large and complex datasets to identify potential threats and develop detection logic to mitigate risks.
- Triage, investigate, and escalate security incidents from various sources including SIEM, DLP, UEBA, and endpoint tools.
- Respond to security incidents in real-time and participate in root cause analysis, escalation, and incident recovery efforts.
- Coordinate with system owners, data teams, and business units to enhance detection logic, data, reduce false positives, and refine workflows.
- Create and maintain dashboards to support threat hunting, investigations, and operational reporting.
- Communicate findings, risk posture, and recommended remediation steps clearly to both technical and non-technical stakeholders.
- Partner with cross-functional teams to identify process improvements and implement scalable security solutions.
- Contribute to continuous improvement efforts in detection coverage, response readiness, and insider threat frameworks.
Report job