Third Party Security Engineer

2 weeks ago


Singapore TikTok Full time

Responsibilities
TikTok is the leading destination for short-form mobile video. At TikTok, our mission is to inspire creativity and bring joy. TikTok's global headquarters are in Los Angeles and Singapore, and its offices include New York, London, Dublin, Paris, Berlin, Dubai, Jakarta, Seoul, and Tokyo.

Why Join Us
Creation is the core of TikTok's purpose. Our platform is built to help imaginations thrive. This is doubly true of the teams that make TikTok possible.
Together, we inspire creativity and bring joy - a mission we all believe in and aim towards achieving every day.
To us, every challenge, no matter how difficult, is an opportunity; to learn, to innovate, and to grow as one team. Status quo? Never. Courage? Always.
At TikTok, we create together and grow together. That's how we drive impact - for ourselves, our company, and the communities we serve.
Join us.

The Global Security Organization provides industry-leading cyber-security and business protection services to TikTok globally. Our organization employs four principles that guide our strategic and tactical operations. Firstly, we Champion Transparency & Trust by leading the charge in organizational transparency, prioritizing customer trust, and placing user needs first. Secondly, we aim to maintain Best in Class Global Security by proactively identifying and reducing risks while enabling innovative product development. We constantly work towards a sustainable world-class security capability. Thirdly, we strive to be a Business Catalyst & Enabler by embodying the DNA of technical innovation and ensuring our Global Security operations are fast and agile. Finally, we Drive Empowered & Risk-Informed Decision Making by providing our leaders with the necessary information to make agile decisions based on risk. In order to enhance collaboration and cross-functional partnerships, our organization follows a hybrid work schedule that requires employees to work in the office for 2 to 3 days a week, as directed by their manager. We regularly review our hybrid work model, and the specific requirements may change at any time.

As a direct report to the Global Third Party Security Management (TPSM) Lead, you will join a team that is responsible for reducing the security risk related to ByteDance's use of third parties. In support of that responsibility, you will conduct and partner with Third Party Security Risk Analysts to provide technical security and engineering consultation on security assessments. These consultations are often in support of complex third party arrangements, strategic initiatives and data sharing integrations.
- Provide security engineering consultation to several teams to help identify potential security flaws in high risk third party engagements or assist with remediation efforts, including retesting
- Conduct security assessments of Bytedance's third parties. This includes:

- The planning of third party security assessments, namely, coordinating internal and external stakeholders, evaluating security and developing a security assessment plan
- The execution of third party security assessments, namely, the review of security documentation and the performance of technical assessment procedures
- Proficient in implementing a security engineering centric approach to enhance infrastructure, SaaS and platform security which may include conducting technical security reviews
- Capable of formulating comprehensive security strategies in ambiguous situations
- Lead conversations that delve into technical domains
- Assist in developing innovative solutions to help evaluate complex business, technology, and risk issues in a fast paced environment
- Advocate GSO capabilities to business stakeholders by demonstrating value and fostering awareness

**Qualifications**:
**Minimum Qualifications**:

- Strong knowledge of security architecture, threat modeling, and secure design
- Familiarity with operating systems security, including hardening, patch and vulnerability management, access management, and monitoring
- Knowledge of controls frameworks and industry standard frameworks (FAIR, COBIT, NIST CSF, SOC, ISO, etc.)
- Experienced in conducting security assessments and formulating effective remediation plans

**Preferred Qualifications**:

- Background in Computer Science, Computer Engineering, Information Systems or other STEM disciplines.
- Accustomed to working in a startup-like environment. Adaptable to changing or emerging priorities
- A highly motivated individual, with strong communication and relationship-building skills, and demonstrate a record of ongoing accomplishment and commitment to excellence

TikTok is committed to creating an inclusive space where employees are valued for their skills, experiences, and unique perspectives. Our platform connects people from across the globe and so does our workplace. At TikTok, our mission is to inspire creativity and bring joy. To achieve that goal, we are committed to celebrating our diverse voi



  • Singapore TikTok Full time

    Responsibilities TikTok is the leading destination for short-form mobile video. Our mission is to inspire creativity and bring joy. TikTok has global offices including Los Angeles, New York, London, Paris, Berlin, Dubai, Singapore, Jakarta, Seoul and Tokyo. Why Join Us At TikTok, our people are humble, intelligent, compassionate and creative. We create to...


  • Singapore AIA Full time

    At AIA we've started an exciting movement to create a healthier, more sustainable future for everyone. If you believe in developing a better tomorrow, read on. About the Role This position is responsible for overseeing the Third-Party Security Risk Management domain, providing consultation, professional advice on information security and key technology risk...


  • Singapore AIA Full time

    At AIA we’ve started an exciting movement to create a healthier, more sustainable future for everyone. - As pioneering innovators for over 100 years, we’re now transforming our organisation to be faster, simpler and more connected. Because we want to be even better equipped to develop digital solutions and experiences that help more people live...

  • Third Party

    3 days ago


    Singapore Commerzbank Aktiengesellschaft Full time $80,000 - $120,000 per year

    Job purpose:We are seeking a detail-oriented and proactive Third-Party Risk Management (TPRM) Specialist to oversee and manage the organization's third-party risk framework and outsourcing arrangements in the region.This role involves assessing and monitoring third-party relationships to ensure regulatory compliance, mitigate risks, and safeguard the...


  • Singapore AIA Full time

    A leading financial services firm in Singapore is seeking a Third-Party Security Risk Management professional. You will oversee vendor evaluations and risk assessments, ensuring compliance with security policies. The ideal candidate has over 8 years of experience in IT and risk management, holds relevant security certifications, and possesses strong...


  • Singapore The Edge Asia Full time

    Our client is looking for a highly motivated and experienced Vendor Manager to join their team. In this role, you will be responsible for managing and supporting the third-party risk management processes and compliance with governance standards, in addition to collaborating with various teams across the organization. EA License Number: 16S8131 Recruiter...


  • Singapore Airwallex Full time

    About Airwallex Airwallex is the only unified payments and financial platform for global businesses. Powered by our unique combination of proprietary infrastructure and software, we empower over 150,000 businesses worldwide – including Brex, Rippling, Navan, Qantas, SHEIN and many more – with fully integrated solutions to manage everything from business...


  • Singapore The Edge Partnership Full time

    **Key Responsibilities**: - Support business functions with risk assessments - Validating third-party risks - Ensure compliance of the TPRM Framework - Prepare reports of third-party risk oversight activities and escalating any identified issues - Provide support to TPRM committing **Requirements**: - Degree in Economics, Business Administration, Supply...


  • Singapore UBS Full time

    Singapore - Outsourcing / Offshoring, Process, project and program management - Group Functions **Job Reference #** - 266829BR **City** - Singapore **Job Type** - Full Time **Your role** - The Third Party Risk Management (TPRM) function is responsible for providing oversight of the third party risk (inc. outsourcing) within Singapore. - The...


  • Singapore KS Talent Solutions Full time

    **Key Responsibilities**: - Provide leadership, strategic direction, and oversight to ensure successful execution of the TPRM program, promoting a consistent risk-based approach. - Create, manage, enhance, and implement TPRM Policy, procedures, and program governance, ensuring effective risk management of Vendor/Third Parties in accordance with global risk...