← Back to all jobs

Software Engineer, Insider Risk - Global Security Organization

TikTok · California · Posted 2026-09-02

Apply on the company site →

Job description

The mission of TikTok's Global Security Organization is to build and earn trust by reducing risk and securing our businesses and products. Also known as "GSO", this team is the foundation of our efforts to keep TikTok safe, secure, and operating at scale for over 1 billion people around the world. We work to ensure that the TikTok platform is safe and secure, that our users' experience and their data remains safe from external or internal threats, and that we comply with global regulations wherever TikTok operates. Trust is one of TikTok's biggest initiatives, and security is integral to our success. In whatever ways users interact with us — whether they're watching videos on their For You page, interacting with a Live video, or buying products on TikTok Shop — GSO protects their data and privacy, so they can have a secure and trustworthy experience. The GSO provides industry-leading security and privacy services guided by four principles: trust and transparency, business enablement, risk-informed decision-making, and proactive risk reduction. We strive to build sustainable, world-class security capabilities. This is a Software Engineer role within Global Security's Insider Risk team. In this role, you are responsible for executing on the overall strategy for insider risk, from detection and triage to containment and remediation of Insider Risk incidents. There are two major deliverables for the team, automation development and detection engineering. Automation development focuses on ideating and creating tooling solutions and automated workflows to support investigation analysts and remediate crucial Insider Risk issues. Detection engineering focuses on the creation and maintenance of proactive logic to proactively identify inside risks with high fidelity and at scale to prevent harm to users and to the company. This role will work cross functionally with various business organizations to detect, mitigate, and remediate instances of Insider Risk through: - Review critical services involved in Insider risk security incidents and work with RD teams to scope technical remediations and security posture improvements (e.g. re-architecting a manual operations workflow to remove the viewability of an API secret token) - Help stakeholders identify relevant strategies for mitigating insider threats for users and the business. - Maintain and support compliant data flows and automation access to allow for interoperability across various business regions. - Directly contribute to technical projects via committing code, root cause analyses, code reviews, and architecture design. - Work with cross functional teams globally to ensure alignment, collect feedback on automations, and deploy solutions to get cross functional adoption. Minimum Qualification(s) - Proficiency in at least one of the following: Python, Golang, Typescript - Demonstrated experience with SQL - Familiarity with application security principles - Strong technical documentation and reporting skills - Ability to handle confidential information with discretion Preferred Qualification(s) - Bachelor's degree or industry equivalent work experience in Computer Science or Computer Engineering - 3+ years of industry experience as an engineer - Experience performing security production-readiness reviews and securing the software development lifecycle (SDLC) - Knowledge of online deceptive and manipulative behavior. Knowledge of the signals of specific threat actors, their cross-platform tactics, and how they evolve or change over time. - Working knowledge of cloud platforms (i.e. OCI, GCP, AWS, etc) - Demonstrates excellent organizational, time management, and problem-solving skills - Works well within time/budget constraints to solve problems or meet objectives - Ability to communicate technical concepts to a broad range of technical and non-technical staff