Manager, Security Posture Validation
TikTok USDS Joint Venture - Washington, DC
Hiring: Manager, Security Posture Validation Company: TikTok USDS Joint Venture Location: Washington, DC Job Posted Time: 2026-09-16 18:25:01 Employment Type: Hybrid Target Skills & Keywords : AWS, Android, Azure, Bash, C++, CI/CD, FedRAMP, Go, Java, Kubernetes, OCI, Python, Serverless, Stakeholder Management, WAF, iOS, macOS About the job Experience: •8+ years in offensive security or privacy disciplines (Red Teaming, Pentesting, Vulnerability Research), with at least 3+ years in a formal people management or lead role. Required Skills: •The Validation and Verification (VnV) organization ensures the security and reliability of our products by validating that security controls are implemented correctly, operating effectively, and delivering measurable risk reduction across the enterprise. •VnV operates across a continuous security lifecycle: Prevent → Assure → Test → Fix → Prove, ensuring that security posture is not only designed and tested, but continuously validated in real-world conditions. •Team Leadership & Development: Lead, mentor, and grow a specialized team of offensive security and privacy engineers. Foster a culture of continuous research, innovation, and ethical hacking. •Operationalize Red & Purple Team: Run adversary-emulation and purple-team exercises as a primary input to the platform — converting validated attack paths and TTPs into automated, repeatable validation content, and partnering with detection and IR teams to prove and close coverage gaps across OCI, AWS, and Azure. •Stakeholder Management: Act as the primary interface for Executive leadership, Legal, Risk & Compliance, and Engineering. Translate complex technical vulnerabilities into actionable business risks. •Methodology & Governance: Define and maintain Standard Operating Procedures (SOPs) and Rules of Engagement (ROE) for testing modern tech stacks (Kubernetes, Serverless, Mobile). •Remediation Advocacy: Collaborate with Blue Teams and Control Owners to track findings through to completion, providing pragmatic, risk-appropriate recommendations to correct flaws and misconfigurations. •Posture Dashboards & Metrics: Turn validation results into an authoritative, leadership-accessible view of security posture — SLA/SLI compliance, trends, remediation velocity, and per-control coverage and efficacy — so leadership always knows how good we are and how good we want to be, and discrepancies are detected and remediated quickly. Qualifications: •Technical Breadth: Proven expertise across Cloud (AWS/Azure/OCI), Mobile (iOS/Android), and Web Application security ecosystems. •Control Validation & Platform Building: Strong working knowledge of security standards (ISO 27001, NIST 800-53, PCI-DSS) and a proven track record of building tooling, automation, or platforms that others adopt — not just running assessments. Familiarity with adversary emulation / breach-and-attack-simulation and MITRE ATT&CK coverage mapping. •Privacy Knowledge: Understanding of privacy-enhancing technologies (PETs) and the ability to apply offensive mindsets to identify data leakage or privacy-control bypasses. •Coding/Scripting: Proficiency in at least two languages (e.g., Python, Golang, C++, Bash, or Java) for exploit development and tool automation. •OS Mastery: Advanced knowledge of Windows, *nix, and MacOS environments, including troubleshooting and administration. •Bachelor’s degree in Computer Science, Information Security, Computer Engineering, or a related technical field. •Advanced Certifications: A combination of security and privacy certifications (e.g., OSCP/OSEP/GXPN and CIPP/CIPT/CIPM). •Tooling Expertise: Mastery of industry-standard tools such as Burp Suite Pro, Cobalt Strike, Frida, Objection, MobSF, SQLMap, and Nessus. •Community Impact: Contributions to the security/privacy community (CVEs, bug bounty recognition, whitepapers, or speaking at conferences like DEF CON or Black Hat). •Regulatory Expertise: Experience navigating security testing within highly regulated or national security-focused divisions (USDS/FedRAMP). Interested candidates, please apply directly through the job posting on company's career page or try via AI auto apply on this platform. Don't miss this opportunity to join a forward-thinking team!