Offensive Privacy Testing Lead

2 months ago


New York, New York, United States TikTok Full time
TikTok is the leading destination for short-form mobile video.
Our mission is to inspire creativity and bring joy.
U.
S.
Data Security (USDS) is a subsidiary of TikTok in the U.
S.

This new, security-first division was created to bring heightened focus and governance to our data protection policies and content assurance protocols to keep U.

S.
users safe.
Our focus is on providing oversight and protection of the TikTok platform and U.
S.

user data, so millions of Americans can continue turning to TikTok to learn something new, earn a living, express themselves creatively, or be entertained.

The teams within USDS that deliver on this commitment daily span across Trust & Safety, Security & Privacy, Engineering, User & Product Ops, Corporate Functions and more.

Creation is the core of TikTok's purpose.
Our platform is built to help imaginations thrive.
This is doubly true of the teams that make TikTok possible.

Together, we inspire creativity and bring joy - a mission we all believe in and aim towards achieving every day.

To us, every challenge, no matter how difficult, is an opportunity; to learn, to innovate, and to grow as one team.

Status quo? Never.
Courage? Always.
At TikTok, we create together and grow together.
That's how we drive impact - for ourselves, our company, and the communities we serve.
Join us.

Our Privacy Testing function provides services to TikTok's US market using four principles that guide our strategic and tactical operations.

First, we champion trust and transparency, leading the charge in organizational transparency and execution of security and privacy capabilities that drive customer trust.

Second, we are a business catalyst and enabler, embodying the DNA of technical innovation.
Third, we drive risk-informed and empowered decision-making, giving our business leaders the information needed to make key decisions.

Finally, we proactively identify and reduce risk while enabling innovative product development to consistently build sustainable world-class and trusted security capabilities.

As an Offensive Privacy Testing Lead, you will spearhead collaboration, creation and execution of comprehensive privacy testing programs, to identify and mitigate privacy risks within our organization's infrastructure, applications, products and services.

You will manage a small team, conduct hands on technical testing and collaborate closely with cross-functional teams, including USDS stakeholders, global stakeholders, engineering and product teams, to enhance our privacy practices and ensure the protection of user data.

In order to enhance collaboration and cross-functional partnerships, among other things, at this time, our organization follows a hybrid work schedule that requires employees to work in the office 3 days a week, or as directed by their manager/department.

We regularly review our hybrid work model, and the specific requirements may change at any time.

Responsibilities:

  • Lead and execute indepth offensive privacy testing utilizing an inhouse control framework and riskbased threat modeling.
  • Collaborate and manage a team of testers and act as the primary interface for various stakeholders like legal, risk and compliance, privacy incident response, trust and safety etc.
  • Identify, exploit, and report privacy vulnerabilities across various platforms, including infrastructure, web, iOS, and Android.
  • Collaborate with engineering, product, and vulnerability management teams to assist vulnerability management teams in the remediation of identified privacy weaknesses.
  • Develop and maintain effective communication channels to report findings and recommend solutions to technical and nontechnical stakeholders.
  • Continuously improve testing methodologies and team processes to enhance privacy protections.
  • Advocate for privacy best practices and help establish longterm security and privacy strategies.
  • Interface directly with executive leadership and technical staff to lead Privacy Testing engagements
  • Plan, coordinate, authorize, and execute framework base and risk prioritized testing engagements; both short and long duration
  • Develop comprehensive, accurate reports targeting both technical and executive audiences
  • Communicate findings and strategy effectively to client stakeholders, including technical staff, executive leadership, and legal counsel
  • Define and maintain a set of Standard Operating Procedures (SOP), Rules of Engagement (ROE), Methodologies and checklist for various Privacy Testing domains
  • Utilize attacker tools, tactics, and procedures to perform analysis and identify vulnerabilities
  • Build, develop, and maintain a technical team to provide Offensive Privacy Testing services to the organization
  • Procure, develop, maintain and refine an inventory of security tools needed for various operationsQualificationsMinimum
Qualifications:

  • Bachelor's degree in Information Security, Computer Science, IT, or a related field.
  • Experience in offensive privacy and security disciplines such as red teaming, penetration testing, vulnerability research, or security/privacy research.
  • Relevant industry certifications (e.
g.
, CIPP, CIPT, CIPM) - Hands on technical experience in web, mobile and infrastructure penetration testing with tools like Burp Suite Pro, SQLMap, Frida, Objection, Android Studio, XCode, MobSF, Drozer- Experience with conducting reverse engineering on mobile applications, including applications with anti-emulator and obfuscation protections- Familiarity and experience working with frameworks like MITRE ATT&CK/D3FEND, NIST, CCPA, COPPA, OECS, ISO etc.

  • Proven handson experience with programming and scripting languages (e.
g.
, C/C++, C#, Python, Golang, JS).

Preferred Qualification:

  • Experience in conducting hands on technical offensive security testing on various platforms.
  • Effective communicator with experience of working in a fast paced environment, where prioritization is key to success.
  • Contributions to the privacy community such as research, public CVEs, bugbounty recognitions, opensource projects, blogs, publications, speaking at conferences etc.
  • Industry certifications such as CPT, CRTO, OSCP, OSEP, OSWA, OSWE, OWSE, OSED, GPEN, GXPN, GWAPT, GMOB, BSCPTikTok is committed to creating an inclusive space where employees are valued for their skills, experiences, and unique perspectives.
Our platform connects people from across the globe and so does our workplace.
At TikTok, our mission is to inspire creativity and bring joy.

To achieve that goal, we are committed to celebrating our diverse voices and to creating an environment that reflects the many communities we reach.

We are passionate about this and hope you are too.

TikTok is committed to providing reasonable accommodations in our recruitment processes for candidates with disabilities, pregnancy, sincerely held religious beliefs or other reasons protected by applicable laws.

If you need assistance or a reasonable accommodation, please reach out to us at https:
//shorturl.
at/ktJP6This role requires the ability to work with and support systems designed to protect sensitive data and information.
As such, this role will be subject to strict national security-related screening.
RegularExperienced.

Estimated Salary:
$20 to $28 per hour based on qualifications.

  • New York, New York, United States Michael Page Full time

    Contract Role located in New York, New York (Hudson Yards).6-Month Contract with Opportunity to Covert to Full-Time. About Our Client Our client, headquartered in Hudson Yards in New York City, is a leading global asset management firm renowned for its extensive expertise and innovative solutions in investment management. As one of the world's largest...


  • New York, New York, United States Motion Recruitment Full time

    Our client is looking for full-time Privacy Compliance Officer. This role will be onsite in New York, NYThe successful candidate will be involved in global privacy initiatives, interacting on a regular basis with Legal & Compliance, Information Security, Technology, Business, and Internal Audit groups as well as with senior leadership teams. Candidates must...


  • New York, New York, United States Bully Pulpit International Full time

    Job OverviewLocation: Flexible options available including remote work.Bully Pulpit International is a results-driven agency comprised of strategists, data analysts, and creative professionals. With a diverse team of over 250 members across multiple countries and offices, we specialize in strategic communications, public affairs, research, and digital...

  • Privacy Counsel

    1 month ago


    New York, New York, United States Take-Two Interactive Full time

    Who We Are: Headquartered in New York City, Take-Two Interactive Software, Inc. is a leading developer, publisher, and marketer of interactive entertainment for consumers around the globe. The Company develops and publishes products principally through Rockstar Games, 2K, Private Division, and Zynga. Our products are currently designed for console gaming...


  • New York, New York, United States Forhyre Full time

    Exciting Role: Automation Testing Lead at ForhyreWe are seeking a talented Automation Testing Lead to enhance our quality assurance efforts. If you have a strong passion for automated testing and a proven track record in creating and executing automation frameworks, this position is ideal for you. As the Automation Testing Lead at Forhyre, you will be...

  • Privacy Counsel

    11 hours ago


    New York, New York, United States Ramp Full time

    About the RoleAs the founding member of Ramp's Privacy team, you will play a pivotal role in developing, executing, and scaling our global privacy strategy. Your expertise will be instrumental in driving initiatives to identify and address domestic and international data protection requirements, defining technical and policy solutions, and supporting...


  • New York, New York, United States American Express Full time

    You Lead the Way. We've Got Your Back.With the right backing, people and businesses have the power to progress in incredible ways. When you join Team Amex, you become part of a global and diverse community of colleagues with an unwavering commitment to back our customers, communities and each other. Here, you'll learn and grow as we help you create a career...


  • New York, New York, United States Pfizer Full time

    ROLE SUMMARYThe Privacy Counsel will enable the development and execution of innovative data-driven business initiatives while ensuring compliance with global data privacy, cyber and data protection laws. The successful candidate will: 1) provide expert legal counseling to ensure privacy and data protection compliance, and 2) provide leadership and subject...


  • New York, New York, United States Fidelity Information Services Full time

    JOB DESCRIPTIONPosition Type :Full timeType Of Hire :Experienced (relevant combination of work and education)Education Desired :Bachelor's degree in Computer Science or related fieldTravel Percentage :0%Location: BangaloreAre you driven, inquisitive, and innovative? At FIS, you will have the chance to tackle some of the most significant and pertinent...


  • New York, New York, United States WithSecure Full time

    About the RoleWe are seeking a highly skilled and experienced Senior Cybersecurity Consultant to join our team at WithSecure. As a key member of our team, you will be responsible for leading penetration tests and security assessments, as well as representing the company in key client relationships.Key ResponsibilitiesLead penetration tests and security...


  • New York, New York, United States Office of the Special Narcotics Prosecutor Full time

    The Office of the Special Narcotics Prosecutor (SNP) is offering a remarkable opportunity for qualified candidates to join our Detective Investigations Unit as a Lead Rackets Investigator. In this pivotal role, the Lead Rackets Investigator will oversee the efforts of Rackets Investigators in gathering and validating information essential for criminal...

  • Test Lead

    4 days ago


    New York, New York, United States Insight Global Full time

    Job Summary:Insight Global is seeking a highly experienced Quality Assurance Lead to join our Direct-to-Consumer team. As a key member of our team, you will be responsible for leading the end-to-end test delivery for our Peacock International Program.Key Responsibilities:Lead a team of 5-8 QA Engineers and Specialists in coordinating end-to-end QA testing...

  • Application Lead

    3 months ago


    New York, New York, United States QData Full time

    Primary Skills 7+ years of experience as Application Lead using stack of various .NET Framework and programming languages like C# C++ VB.NET.Experience Identifying and remediating application vulnerabilities. Cybersecurity and privacy principles and organizational requirements (relevant to confidentiality integrity availability authentication...


  • New York, New York, United States Deutsche Bank Full time

    Job ID:R Full/Part-Time: Full-time Regular/Temporary: Regular Location: New York Position Overview Job Title Anti Financial Crime (AFC) Compliance Testing Lead Corporate Title Assistant Vice President Location New York, NY Overview At Deutsche Bank, our Anti Financial Crime (AFC) division plays a pivotal role in safeguarding our operations and the global...

  • Application Lead-zOS

    3 months ago


    New York, New York, United States QData Full time

    Primary Skills Candidates should have overall 10+ years of IT experience. Should have experience as Application Lead using COBOL JCL PL/1 Assembler MQ CICS DB2 IMS-DB SQL.Experience in the following Identifying and remediating application vulnerabilities. Cybersecurity and privacy principles and organizational requirements (relevant to confidentiality...


  • New York, New York, United States Ordergroove Full time

    Job OverviewCompany Background:Ordergroove operates in a vibrant and rapidly evolving sector where innovation and growth are at the forefront. We are on the lookout for intelligent and skilled individuals who are passionate about creating impactful solutions in the realm of Relationship Commerce. If you thrive on solving complex challenges and delivering...


  • New York, New York, United States WithSecure Full time

    Salary Range: $134,000 - $158,000 At WithSecure™, we provide research-driven cyber defense solutions to protect organizations, communities, and individuals from real-world threats while enhancing their resilience. Our team comprises a diverse group of technical and creative professionals who are dedicated to innovating the cybersecurity landscape. They...


  • New York, New York, United States 00002 Citibank, N.A. Full time

    Position: Finance Controls Testing Team LeaderCompany: Citibank, N.A.The Finance Controls Testing Team Leader is responsible for overseeing the evaluation of controls implemented by Citibank's Global Functions divisions. This pivotal role reports directly to the Director of Finance Controls Testing and encompasses comprehensive controls evaluation,...

  • Senior Account Manager

    10 hours ago


    New York, New York, United States BigID Full time

    About BigIDBigID is a leading technology company specializing in data security, compliance, privacy, and governance solutions. Our mission is to empower organizations to unlock the full potential of their data while ensuring its security and integrity.Job SummaryWe are seeking a highly skilled Senior Customer Success Manager to join our team. As a key member...


  • New York, New York, United States QData Full time

    Primary Skills Candidates should have overall 10 years of IT experience. Should have experience as Application Lead using Java/J2EE technology under these platforms WebLogic WebSphere JBOSS Tomcat JRE. Frameworks Spring STRUTS UI framework Angular JavaScript.Experience Identifying and remediating application vulnerabilities. Cybersecurity and privacy...