TikTok
Posted 3w ago

Security Engineer, Detection & Response - Global Security Organization

TikTok
Singapore
OnsiteFull Time
Responsibilities
  • designing workflows
  • engineering pipelines
  • driving detection
Requirements
  • Bachelor's in Cybersecurity/Information Security/Computer Engineering,5+ years in cybersecurity/DevSecOps,experience with Python/Go,SIEM/EDR and large-scale telemetry pipelines,knowledge of AI agent security risks
Technical tools mentioned
PythonGoSIEMEDRLLMMITRE ATLAS

Job description

The mission of TikTok's Global Security Organization is to build and earn trust by reducing risk and securing our businesses and products. Also known as "GSO", this team is the foundation of our efforts to keep TikTok safe, secure, and operating at scale for over 1 billion people around the world. We work to ensure that the TikTok platform is safe and secure, that our users' experience and their data remains safe from external or internal threats, and that we comply with global regulations wherever TikTok operates.

Trust is one of TikTok's biggest initiatives, and security is integral to our success. In whatever ways users interact with us — whether they're watching videos on their For You page, interacting with a Live video, or buying products on TikTok Shop — GSO protects their data and privacy, so they can have a secure and trustworthy experience.

TikTok’s Global Forensics team is responsible for the company’s technical investigations and digital forensics work.
This role sits at the intersection of applied AI, software engineering, security data engineering, and digital forensics. You will build evidence-aware AI systems that help investigators retrieve, correlate, reason over, package, and explain evidence across complex enterprise telemetry, while preserving auditability, reproducibility, privacy, and human judgment.
You will also partner closely with investigators to convert recurring case patterns into reusable workflows, AI-assisted investigation tools, evaluation datasets, playbooks, and detection/control improvements.

Responsibilities:
- Design and build AI-native forensic investigation workflows for evidence retrieval, enrichment, entity normalization, timeline reconstruction, evidence indexing, evidence packaging, and investigation report generation.
- Build agentic systems that safely interact with internal tools, APIs, logs, and investigation datasets through controlled tool use, permissioning, human-in-the-loop review, and auditable execution traces.
- Develop retrieval, knowledge, and reasoning systems over cases, logs, policies, tickets, reports, and evidence repositories, with grounded citations and structured outputs.
- Create evaluation frameworks for forensic AI workflows, including golden cases, regression tests, grounding checks, hallucination/failure analysis, precision/recall measurement, and investigator feedback loops.
- Engineer data workflows across platform audit logs, identity/cloud logs, endpoint/server telemetry, network logs, DLP, and other investigation data sources.
- Partner with forensic investigators to turn ambiguous investigative questions into reproducible workflows, reusable query packs, dashboards, agent tools, and defensible technical outputs.
- Drive proactive risk discovery by generalizing patterns from real cases, running targeted hunts across multi-source telemetry, validating signals, and converting findings into detection, logging, control, and process improvements.
- Apply AI-assisted engineering responsibly to accelerate prototyping, refactoring, testing, and documentation while maintaining code review, test coverage, change control, privacy safeguards, and evidentiary defensibility.

Minimum Qualifications
- Bachelor's Degree in Cybersecurity, Information Security, or Computer Engineering.
- Minimum 5 years of experience in Cybersecurity or DevSecOps roles.
- Demonstrated capabilities using Python, Go, or other production languages to build custom threat detection rules or threat hunting queries for SIEM/EDR platforms.
- Proven experience designing and building robust data pipelines to process, normalise and correlate large-scale security telemetry from multiple sources.
- Strong knowledge and demonstrated exposure addressing common AI Agent security risks and hardening strategies (e.g., OWASP Top 10 for LLMs, including prompt injection, unauthorised tool execution, and denial of service).

Preferred Qualifications
- Regional or global enterprise scale Security detection operations experience.
- Proven track record of integrating LLM or Agentic AI into cybersecurity workflows.
- Knowledge of Agent Loop architecture.
- Strong familiarity and track record of applying MITRE ATLAS framework to threat modeling and risk assessments for AI systems.

TikTok is the leading destination for short-form mobile video. At TikTok, our mission is to inspire creativity and bring joy. TikTok's global headquarters are in Los Angeles and Singapore, and we also have offices in New York City, London, Dublin, Paris, Berlin, Dubai, Jakarta, Seoul, and Tokyo.



Inspiring creativity is at the core of TikTok's mission. Our innovative product is built to help people authentically express themselves, discover and connect – and our global, diverse teams make that possible. Together, we create value for our communities, inspire creativity and bring joy - a mission we work towards every day.

We strive to do great things with great people. We lead with curiosity, humility, and a desire to make impact in a rapidly growing tech company. Every challenge is an opportunity to learn and innovate as one team. We're resilient and embrace challenges as they come. By constantly iterating and fostering an "Always Day 1" mindset, we achieve meaningful breakthroughs for ourselves, our company, and our users. When we create and grow together, the possibilities are limitless. Join us.

Diversity & Inclusion

TikTok is committed to creating an inclusive space where employees are valued for their skills, experiences, and unique perspectives. Our platform connects people from across the globe and so does our workplace. At TikTok, our mission is to inspire creativity and bring joy. To achieve that goal, we are committed to celebrating our diverse voices and to creating an environment that reflects the many communities we reach. We are passionate about this and hope you are too.

f:

About TikTok

Global short-form video hosting and social media platform.

Year founded
2016
Employees
10000
Organization type
Private
Latest investment
Raised $9.40B Private Equity (2020) — led by SoftBank, KKR, General Atlantic
Subsidiaries
Headquarters
US

Similar jobs

Security Engineer roles
2d
Save
Mark Applied
Hide
Senior Security Engineer, Enterprise SaaS Security
Singapore, Central Region, Singapore
OnsiteFull Time
Google
GoogleNASDAQ: GOOGL: Provides online search, advertising, cloud computing, and consumer electronics.
5+ YOE1+ MgmtBachelor's degree or equivalent; 5 years in security assessments, design reviews, threat modeling, security engineering, computer/network security, protocols, and coding; 1 year leading technical teams or risk analysis.
Python, Go, SQL, JavaScript, SAML, SCIM, OIDC, SaaS Security Posture Management (SSPM), AI/ML
2d
Save
Mark Applied
Hide
Junior Security Engineer
Singapore, Singapore, Singapore
HybridFull Time
Pave Bank
Pave Bank: Programmable commercial bank for global businesses and digital assets.
Familiarity with attacker tools, OWASP Top 10, and secure development practices; programming experience in Go, Python, or TypeScript; strong communication, self-motivation, and continuous learning.
OWASP Top 10, Go, Python, TypeScript
3d
Save
Mark Applied
Hide
SA, Security Engineer – Project Advisory, Information Security Services, Technology and Operations
Singapore, East Region, Singapore
OnsiteFull Time
DBS
DBSSingapore Exchange: D05: Provides diverse banking, wealth management, and financial services.
Experience in security reviews, architecture assessments, or IT security audits; broad IT and information security knowledge; risk assessment skills; and knowledge of enterprise controls and regulatory requirements.
Microsoft 365, APIs, IoT, PCI DSS
1w
Save
Mark Applied
Hide
Sr. Security Engineer, Security Search and Observability, Field Innovation, Security Search and Observability (SSO)
Singapore, Central Region, Singapore
OnsiteFull Time
Amazon
AmazonNASDAQ: AMZN: Global online retail and cloud computing technology provider.
5+ YOERequires 5+ years troubleshooting systems, analyzing logs, automating tasks, identifying security risks, and developing mitigations; experience with vulnerabilities and at least two listed programming languages.
Scala, Java, Python, C/C++, Go, AWS Security Hub, AWS CloudTrail, AWS GuardDuty
1w
Save
Mark Applied
Hide
Security Engineer (Infrastructure Security SDLC) Graduate (Security BP) - 2027 Start
Singapore, Singapore, Singapore
OnsiteFull Time
ByteDance
ByteDance: Developing AI-driven content platforms and mobile applications.
Bachelor's or master's degree in computer science, cybersecurity, software engineering, or related field; vulnerability research experience; programming experience; knowledge of common vulnerability classes.
C/C++, Go, Python, Rust, Java, AWS, Azure, GCP, Kubernetes, Large Language Models (LLMs), AI, GitHub
2w
Save
Mark Applied
Hide
Security Engineer
Singapore
OnsiteFull Time
Fujitsu
FujitsuTokyo Stock Exchange: 6702: Global provider of IT services and computing hardware products.
Requires CyberArk CDE-PAM or Privilege Cloud certification, hands-on CyberArk deployment, Venafi and MFA experience, Windows/Linux, directory services, networking, scripting, IAM, and security practices.
CyberArk, Enterprise Password Vault (EPV), Central Policy Manager (CPM), Privileged Session Manager (PSM), Password Vault Web Access (PVWA), Privileged Threat Analytics (PTA), Privilege Cloud Connector, CyberArk Adaptive Multi-Factor Authentication (MFA), CyberArk Vendor Privileged Access Manager (Vendor PAM), RSA, SecurEnvoy, Cisco Duo, Venafi TLS Protect, Active Directory, LDAP, Entra ID, Splunk, QRadar, ServiceNow, Microsoft CA, DigiCert, Entrust, GlobalSign, Windows Server, Linux, RHEL, Conjur, SIEM, ITSM, IAM, PKI, VPN
2w
Save
Mark Applied
Hide
Staff Engineer, Security Platform Development
Hong Kong or Singapore
OnsiteFull Time
OKX
OKX: Global cryptocurrency exchange and Web3 digital wallet developer.
Deep security and CS fundamentals, expert Java/JVM, production experience with RASP/SAST/DAST/IAST/SCA, familiarity with ASM/ByteBuddy, proficiency in Python or Go, LLM/AI experience, strong communication and product instincts.
Java, JVM, ASM, ByteBuddy, Python, Go, SonarQube, Coverity, RASP, SAST, DAST, IAST, SCA, CI/CD, LLMs
3w
Save
Mark Applied
Hide
IT Compliance Security Engineer
Singapore
OnsiteFull Time
Thales
ThalesEuronext Paris: HO: Designs and manufactures electronic systems for aerospace and defense.
3+ YOE3+ years IT security or audit experience, bachelor in IT or equivalent, ability to conduct internal/external audits, perform risk assessments, and manage physical and logical security.