Skip to main contentA logo with &quat;the muse&quat; in dark blue text.
TikTok

Governance, Risk, & Compliance (GRC) ISO/PCI Compliance Assurance Specialist

San Jose, CA

Responsibilities

TikTok is the leading destination for short-form mobile video. Our mission is to inspire creativity and bring joy. TikTok has global offices including Los Angeles, New York, London, Paris, Berlin, Dubai, Singapore, Jakarta, Seoul and Tokyo.

Why Join Us
Creation is the core of TikTok's purpose. Our platform is built to help imaginations thrive. This is doubly true of the teams that make TikTok possible.
Together, we inspire creativity and bring joy - a mission we all believe in and aim towards achieving every day.
To us, every challenge, no matter how difficult, is an opportunity; to learn, to innovate, and to grow as one team. Status quo? Never. Courage? Always.
At TikTok, we create together and grow together. That's how we drive impact - for ourselves, our company, and the communities we serve.

Want more jobs like this?

Get jobs in San Jose, CA delivered to your inbox every week.

By signing up, you agree to our Terms of Service & Privacy Policy.

Join us.

The Global Security Organization provides industry-leading cybersecurity and business protection services to TikTok globally. Our organization employs four principles that guide our strategic and tactical operations. Firstly, we Champion Transparency & Trust by leading the charge in organizational transparency, prioritizing customer trust, and placing user needs first. Secondly, we aim to maintain Best in Class Global Security by proactively identifying and reducing risks while enabling innovative product development. We constantly work towards a sustainable world-class security capability. Thirdly, we strive to be a Business Catalyst & Enabler by embodying the DNA of technical innovation and ensuring our Global Security operations are fast and agile. Finally, we Drive Empowered & Risk-Informed Decision Making by providing our leaders with the necessary information to make agile decisions based on risk. In order to enhance collaboration and cross-functional partnerships, our organization follows a hybrid work schedule that requires employees to work in the office for 3 days a week, as directed by their manager. We regularly review our hybrid work model, and the specific requirements may change at any time.

The Security Governance, Risk, and Compliance team is responsible for working closely with cross-functional partners to manage security risks to ensure we meet all industry cybersecurity compliance standards and government regulations through developing governing policies, implementing the security control framework, conducting security risk and control assessments, and staying up-to-date on global compliance initiatives.

The ISO/PCI Compliance Assurance Specialist will be a key member of the Governance, Risk, & Compliance (GRC) team, responsible for managing external audits for ISO 27001, SOC 2 Type II and PCI-DSS. This role involves leading a program which includes performing comprehensive scoping, control assessments, and audit facilitation to ensure the organization's adherence to cybersecurity frameworks and regulatory requirements. You would be a great fit for this role if you are enthusiastic about:
1. Maturing an industry-leading cybersecurity compliance management program for individual product lines and business initiatives, which includes monitoring of controls, remediation of gaps, and comprehensive reporting
2. Interpreting and assessing controls using compliance frameworks with a focus on payment card compliance and security (PCI-DSS)
3. Collaborating with exceptional compliance team members in effectively identifying, assessing, and managing cybersecurity risk and controls frameworks
4. Providing industry leading guidance and education on security risk, controls, and compliance best practices to product teams, engineering, and other key stakeholders
5. Coordinating with external auditors, process/control owners, and other key stakeholders to streamline the audit process for gained efficiencies and reporting over the audit life cycle

Responsibilities
As the Compliance Assurance Specialist, you will be responsible for:
- Leading the scoping and implementation of the cybersecurity compliance management program for individual product lines and business initiatives, ensuring readiness and alignment with industry best practices and regulatory requirements (ISO 27001, PCI-DSS, SOC 2 etc.)
- Conducting thorough examinations of processes, systems, policies, procedures, network diagrams, and system configurations
- Owning the end-to-end product specific controls management life cycle including identifying, assessing, monitoring, and remediating controls
- Performing control design and operating effectiveness reviews to identify changes impacting security operations and supporting continuous control monitoring and maturity
- Monitoring business activities by collaborating with cross-functional team leaders to ensure the organization maintains compliance with external certifications
- Communicating with technical and non-technical stakeholders on cybersecurity risk and controls management topics, providing program-specific reporting

Qualifications

Minimum Qualifications:
- In-depth knowledge and experience leading external and internal audits relating to cybersecurity frameworks such as ISO 27001, PCI-DSS, SOC 2, NIST CSF, and other regulatory requirements
- Experience in leading readiness and controls maturity assessments as it relates to new products or services to adhere to pertinent frameworks such as ISO 27001, PCI-DSS, SOC 2, etc..
- Experience collaborating with engineering, business, and security partners, including incident response, red teams, architects, and other product teams
- Excellent written communication skills for documenting, communicating, and reporting security assessments
- Strong project management skills with the ability to lead security assessment projects on time with multiple stakeholders
- Ability to work at the San Jose office for 3 days per week and travel to other offices as required

Preferred Qualifications
- Experience leading strategic initiatives and driving Information Technology (IT) and Information Security (IS) compliance and certification process end-to-end
- Has technical expertise to provide recommendations for control gaps to security partners that include architects, engineers, and product teams
- Familiarity with Governance, Risk, and Compliance (GRC) technologies such as RSA Archer or ServiceNow
- QSA, CISM, CISA, CISSP, CCSP, CASP, Security+, CRISC, CGEIT, GSEC, or other relevant certifications

TikTok is committed to creating an inclusive space where employees are valued for their skills, experiences, and unique perspectives. Our platform connects people from across the globe and so does our workplace. At TikTok, our mission is to inspire creativity and bring joy. To achieve that goal, we are committed to celebrating our diverse voices and to creating an environment that reflects the many communities we reach. We are passionate about this and hope you are too.

TikTok is committed to providing reasonable accommodations in our recruitment processes for candidates with disabilities, pregnancy, sincerely held religious beliefs or other reasons protected by applicable laws. If you need assistance or a reasonable accommodation, please reach out to us at https://shorturl.at/cdpT2

Job Information

[For Pay Transparency] Compensation Description (annually)

The base salary range for this position in the selected city is $118800 - $196000 annually.

Compensation may vary outside of this range depending on a number of factors, including a candidate's qualifications, skills, competencies and experience, and location. Base pay is one part of the Total Package that is provided to compensate and recognize employees for their work, and this role may be eligible for additional discretionary bonuses/incentives, and restricted stock units.

Our company benefits are designed to convey company culture and values, to create an efficient and inspiring work environment, and to support our employees to give their best in both work and life. We offer the following benefits to eligible employees:

We cover 100% premium coverage for employee medical insurance, approximately 75% premium coverage for dependents and offer a Health Savings Account(HSA) with a company match. As well as Dental, Vision, Short/Long term Disability, Basic Life, Voluntary Life and AD&D insurance plans. In addition to Flexible Spending Account(FSA) Options like Health Care, Limited Purpose and Dependent Care.

Our time off and leave plans are: 10 paid holidays per year plus 17 days of Paid Personal Time Off (PPTO) (prorated upon hire and increased by tenure) and 10 paid sick days per year as well as 12 weeks of paid Parental leave and 8 weeks of paid Supplemental Disability.

We also provide generous benefits like mental and emotional health benefits through our EAP and Lyra. A 401K company match, gym and cellphone service reimbursements. The Company reserves the right to modify or change these benefits programs at any time, with or without notice.

Client-provided location(s): San Jose, CA, USA
Job ID: TikTok-7340828829399795995
Employment Type: Other

Perks and Benefits

  • Health and Wellness

    • Health Insurance
    • Dental Insurance
    • Vision Insurance
    • HSA
    • Life Insurance
    • Fitness Subsidies
    • Short-Term Disability
    • Long-Term Disability
    • On-Site Gym
    • Mental Health Benefits
    • Virtual Fitness Classes
  • Parental Benefits

    • Fertility Benefits
    • Adoption Assistance Program
    • Family Support Resources
  • Work Flexibility

    • Flexible Work Hours
    • Hybrid Work Opportunities
  • Office Life and Perks

    • Casual Dress
    • Snacks
    • Pet-friendly Office
    • Happy Hours
    • Some Meals Provided
    • Company Outings
    • On-Site Cafeteria
    • Holiday Events
  • Vacation and Time Off

    • Paid Vacation
    • Paid Holidays
    • Personal/Sick Days
    • Leave of Absence
  • Financial and Retirement

    • 401(K) With Company Matching
    • Performance Bonus
    • Company Equity
  • Professional Development

    • Promote From Within
    • Access to Online Courses
    • Leadership Training Program
    • Associate or Rotational Training Program
    • Mentor Program
  • Diversity and Inclusion

    • Diversity, Equity, and Inclusion Program
    • Employee Resource Groups (ERG)

Company Videos

Hear directly from employees about what it is like to work at TikTok.