Technology Internal Audit Lead
TikTok - San Jose, CA
Hiring: Technology Internal Audit Lead Company: TikTok Location: San Jose, CA Job Posted Time: 2026-09-03 10:14:19 Target Skills & Keywords : API Design, AWS, Azure, Bitbucket, Fine-tuning, GCP, GitHub, Hugging Face, IAM, IaaS, LLM, OWASP, PyTorch, SaaS, TensorFlow About the job Experience: •5+ years of relevant experience in Technology Audits, Product Security, Security Engineering or Security Compliance preferably within the technology sector (Social Media, Content Management, FinTech etc.), and/or consulting firms. Proven ability to work in a fast-paced environment with a product centric culture. Required Skills: •Advanced Data Analytics: Leverage data analytics to detect risk signals and unearth insights for AI/ML models. Review controls for data quality, privacy, security, access management, safety testing, hallucination mitigation, evaluation metrics, red-teaming procedures, and output monitoring. •Technology Risk Assessment: Develop practical, risk-based recommendations that address root causes while considering product, engineering, regulatory, and business requirements. Ability to grasp complex, home grown technology stack, comfortable speaking with engineers and product teams. •Stakeholder Relationships: Develop and maintain collaborative working relationships with management, understand the business to provide value-added services, and establish credibility as a management consultant and internal controls resource. Partner with engineering and product teams to advise on design and implementation of technology solutions. •Quality Assurance: Ensure the overall quality and consistency of audit work, adhering to department and professional standards. Continuously seek opportunities for audit process improvement. Qualifications: •In-depth knowledge of security fundamentals across various cyber domains: IAM, applied cryptography, key management systems, data security, application security, web security, security protocols, API Design, threat intelligence, network security, hardware security, vulnerability management, etc. •Proven analytical ability to assess complex technology environments against risk assessment outcomes, industry best practices, internal standards and external regulatory requirements. •Excellent problem solving, critical thinking, collaboration and communication skills combined with the ability to provide a credible technical challenge to the business. •Comprehensive expertise in LLMs, ML pipelines, model lifecycle management, and data engineering architectures. •LLMs or ML frameworks (e.g., PyTorch, TensorFlow, HuggingFace) •Common application and infrastructure security vulnerabilities and mitigations (OWASP Top 10, CWE 25) •Source code and DevOps management tools (e.g., Github, Bitbucket) •SaaS and IaaS cloud platforms (e.g., AWS, Azure, GCP) •Professional certifications such as CISSP, CISM, GIAC, CCNA, CISA, CRISC, or CIA. •Be able to handle ambiguity and collaborate with a global team. Interested candidates, please apply directly through the job posting on company's career page or try via AI auto apply on this platform. Don't miss this opportunity to join a forward-thinking team!