Senior Container Security Analyst - USDS

TikTok

5

Washington, DC

Why you should apply for a job to TikTok:

  • 5/5 in overall job satisfaction

  • 4/5 in supportive management

  • Ratings are based on anonymous reviews by Fairygodboss members.
  • Employee well-being is supported via hybrid work, short-term counseling through our EAP and a premium subscription to Headspace.

  • We embrace diversity across all dimensions and provide employees with 9 employee resource groups globally, including our WOMEN ERG.

  • Comprehensive parental leave policy as well as fertility treatment through healthcare providers with a $20,000 lifetime maximum.

  • #JL67V

    Position summary

    TikTok is the leading destination for short-form mobile video. Our mission is to inspire creativity and bring joy. TikTok has global offices, including Los Angeles, New York, London, Paris, Berlin, Dubai, Mumbai, Singapore, Jakarta, Seoul, and Tokyo. Why Join Us At TikTok, our people are humble, intelligent, compassionate and creative. We create to inspire - for you, for us, and for more than 1 billion users on our platform. We lead with curiosity and aim for the highest, never shying away from taking calculated risks and embracing ambiguity as it comes. Here, the opportunities are limitless for those who dare to pursue bold ideas that exist just beyond the boundary of possibility. Join us and make impact happen with a career at TikTok. About USDS At TikTok, we're committed to a process of continuous innovation and improvement in our user experience and safety controls. We're proud to be able to serve a global community of more than a billion people who use TikTok to creatively express themselves and be entertained, and we're dedicated to giving them a platform that builds opportunity and fosters connection. We also take our responsibility to safeguard our community seriously, both in how we address potentially harmful content and how we protect against unauthorized access to user data. U.S. Data Security (“USDS”) is a standalone department of TikTok in the U.S. This new security-first division was created to bring heightened focus and governance to our data protection policies and content assurance protocols to keep U.S. users safe. Our focus is on providing oversight and protection of the TikTok platform and user data in the U.S., so millions of Americans can continue turning to TikTok to learn something new, earn a living, express themselves creatively, or be entertained. The teams within USDS that deliver on this commitment daily span Trust & Safety, Security & Privacy, Engineering, User & Product Ops, Corporate Functions and more. The Container Security Analyst is tasked with the day to day activities of vulnerability management in a cloud environment. They schedule, conduct, and regularly review container scans, analyzing key risks and escalating where needed. They should be aware of current policies and procedures and ensure they are being followed properly. The Container Security Analyst should have hands on experience with container scanning tools, image remediation and be able to mentor and advise other team members. Tasks and Responsibilities: - Continuously log and track remediation activities of discovered vulnerabilities throughout the environment - Evaluate vulnerabilities based on prioritization criteria - Investigate persistent vulnerabilities - Coordinate and communicate with cross-functional teams throughout the VM lifecycle - Generate and distribute operational-level reports - Facilitate exception handling and escalation - Support regulatory compliance monitoring and reporting - Review and optimize scan templates to ensure complete coverage of environment - Support treatment and remediation activities with identified points of contact and system owners - Provide risk analysis for identified vulnerabilities and system change requests - Maintain regular communication with Vulnerability Management Lead and organizational management for collaboration, process optimization, tools tuning, and information sharing Minimum Qualifications: - Bachelor’s Degree or industry equivalent work experience in vulnerability management in a security program - Experience in one or more of the following: Amazon Web Services (AWS), Microsoft Azure, Google Cloud Platform (GCP) and Oracle Cloud Infrastructure (OCI) - 4+ years of applicable experience - Hands on operational experience with container scanning tools (e.g. Aquasec, Prisma) including the ability to deploy, configure, and run these tools. - Experience assessing the security of cloud and Kubernetes/Docker environments - Ability to conduct root cause analysis against vulnerabilities and determine feasible technical solutions. - Ability to handle large datasets and perform vulnerability analysis - Ability to work alongside other security functions to determine vulnerability scoring and impact - Ability to examine issues both strategically and analytically. - Ability to work collaboratively in a team environment - Strong analytical and problem-solving skills Preferred Qualifications: - CISSP, CISM, or equivalent certification - Relevant cloud certifications (e.g., AWS, GCP, Azure)  - Experience integrating security tools with the CI/CD pipeline - Familiarity with vulnerability management across SaaS and IaaS cloud platforms (e.g., AWS, Google Cloud, etc.) - Working knowledge/experience with Python, SQL and REST APIs - Ability to handle ambiguity and collaborate with a global team - Ability to coach junior staff and contractors TikTok is committed to creating an inclusive space where employees are valued for their skills, experiences, and unique perspectives. Our platform connects people from across the globe and so does our workplace. At TikTok, our mission is to inspire creativity and bring joy. To achieve that goal, we are committed to celebrating our diverse voices and to creating an environment that reflects the many communities we reach. We are passionate about this and hope you are too. TikTok is committed to providing reasonable accommodations during our recruitment process. If you need assistance or an accommodation, please reach out to us at [email protected]

    Get jobs straight to your inbox

    Anonymous company reviews, virtual recruiting events, and a supportive community for women when you sign up.

    What are TikTok perks and benefits

    Lactation facilities

    Fertility

    Unconscious bias training

    Networking

    Succession planning

    Diversity recruiting

    Diversity performance

    Short term disability

    Paid paternity

    Paid maternity

    Paid adoptive

    About the company

    Industry: Technology: Consumer Internet

    As the leading destination for short-form mobile video, our platform helps people around the world become a part of a global community. In a world that feels more divided than ever, we are here to inspire creativity and bring joy. We do this by embracing change, thriving in ambiguity, and always looking for solutions.

    Why you should apply for a job to TikTok:

  • 5/5 in overall job satisfaction

  • 4/5 in supportive management

  • Ratings are based on anonymous reviews by Fairygodboss members.
  • Employee well-being is supported via hybrid work, short-term counseling through our EAP and a premium subscription to Headspace.

  • We embrace diversity across all dimensions and provide employees with 9 employee resource groups globally, including our WOMEN ERG.

  • Comprehensive parental leave policy as well as fertility treatment through healthcare providers with a $20,000 lifetime maximum.