TikTok USDS is looking to enhance its security and defense platforms, tools, and services to support security controls across its cloud environments.
Requirements
- Hands-on expertise with AWS, Azure, GCP, and/or OCI services (EC2, VPC, S3, IAM, Azure VNets, OCI Compute, etc.).
- Proficient in Windows Server 2019/2022 and Linux (Debian, Ubuntu) infrastructure
- Working understanding of Active Directory and PKI
- Familiarity with source code management tools (e.g., Github, Bitbucket) along with Experience with container platforms (Docker, Kubernetes).
- Experience with deploying, managing and operating tools in the following areas: Data loss prevention, Privileged access management, Federated authentication and authorization, Physical Security, Forensics investigation, Governance, Risk and Compliance (GRC)
- CISSP, SSCP, CAP, CCSP, CISM, CSX-P or applicable experience in the Information Security field
- AWS Certified Solutions Architect, Microsoft Certified: Azure Administrator, or OCI Architect Associate.
Responsibilities
- Build technical and functional requirements to configure and deploy tools that support the Security & Privacy mission
- Develop standard operating procedures and trainings for each technology
- Architect and continuously improve security technology stack, infrastructure process and procedures, support model and cross-function interactions
- Manage end-to-end patching processes for servers and cloud workloads to maintain secure and up-to-date systems.
- Coordinate change management activities with cross-functional teams to ensure secure, compliant, and well-communicated implementation of system modifications.
- Review and investigate operational alerts generated from security tools and escalate as appropriate
- Review and assess utilization of security tooling
Other
- 5+ years applicable experience deploying and maintaining infrastructure
- Bachelor's degree or higher in a relevant field (not explicitly mentioned but implied)
- Ability to work in the office 3 days a week, or as directed by their manager/department
- Must be able to interact and occasionally have unsupervised contact with internal/external clients and/or colleagues
- Must be able to appropriately handle and manage confidential information including proprietary and trade secret information and access to information technology systems