Skip to content

Open nowPosted 10 days ago

Senior Tech Lead Manager, Vulnerability Management - Global Security Organization

MyCareersFuture94,028 open roles

Pay
SGD 12,500 – SGD 25,000 a Monthly
Where
Central, Singapore
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowSenior Tech Lead Manager, Vulnerability Management - Global Security OrganizationMyCareersFuture · Central, Singapore
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on MyCareersFuture's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

7.7% of postings close within 7 days. Measured by our own scanner across the market.

Share of postings closed within
  1. 1.6%1 day
  2. 3.3%3 days
  3. 7.7%7 days
  4. 14.0%14 days
  5. 33.7%30 days
This job: posted 10 days ago

The posting

The mission of TikTok's Global Security Organization is to build and earn trust by reducing risk and securing our businesses and products. Also known as "GSO", this team is the foundation of our efforts to keep TikTok safe, secure, and operating at scale for over 1 billion people around the world. We work to ensure that the TikTok platform is safe and secure, that our users' experience and their data remains safe from external or internal threats, and that we comply with global regulations wherever TikTok operates.

Trust is one of TikTok's biggest initiatives, and security is integral to our success. In whatever ways users interact with us — whether they're watching videos on their For You page, interacting with a Live video, or buying products on TikTok Shop — GSO protects their data and privacy, so they can have a secure and trustworthy experience.

Your role, as the Senior Tech Lead Manager of the vulnerability management team, will be to manage product security incidents, develop internal security initiatives, gather intelligence, investigate, and validate reported vulnerabilities. We're heavily involved in the vulnerability space to improve TikTok's security every day.

Responsibilities:

  • Take the initiative to explore and define security problems in TikTok infrastructure and products; identify the gaps between existing systems and security goals.
  • Define the scalable and robust security components and infrastructures evolution strategy and roadmap; lead the execution based on the company's business, industry trends and technology stack.
  • Lead highly motivated software engineers; interpret architectural design and goals into executable engineering plans addressing full stack security, privacy and compliance requirements; and eventually build and deliver software, which is secure-by-design.
  • Establish risk-based scoring by correlating scanning data with threat intelligence, real-world exploitability (CVSS, OWASP Top 10), and business asset criticality.
  • Collaborate with cross-function teams in TikTok, promoting/onboarding security services/products in TikTok infrastructure.
  • Track cutting-edge security technologies and bring them to TikTok in an effective way.
  • Leverage AI and Agents in the full lifecycle of vulnerability and attack surface management to improve the efficiency

Minimum Qualifications

  • BA/BS degree or above with 7+ years of project delivery or technical leadership background, plus strong organisational and interpersonal skills, will enable you to succeed in TikTok’s fast paced environment.
  • Possess an understanding of security fundamentals, especially in vulnerability management (VM), attack surface management (ASM).
  • AI and Development Experience: Practical experience in utilizing Artificial Intelligence (AI) technologies or participating in AI-related development, especially applied to security workflows or automation.
  • Security Vulnerability Analysis: Proven experience in identifying and understanding security weaknesses, including how they can be exploited, with a thorough understanding of common vulnerabilities like the OWASP Top 10. This involves analyzing potential attack methods from code and concepts, pinpointing affected systems or applications, and clearly documenting the risks and exposures.
  • Leading Security Remediation: Capability to act as the primary point of contact for resolving critical security vulnerabilities, including coordinating action plans and verifying their effectiveness.
  • Collaboration with Security Researchers: Demonstrated ability to work effectively and technically with external security experts, fostering open and productive discussions about security.
  • Programming Skills: Proficiency in programming languages such as Python, Go, and JavaScript.

Preferred qualifications

  • Secure Software Development: Familiarity with best practices for integrating security throughout the software development process.
  • Security Incident Handling: Experience with managing and responding to cybersecurity incidents, ensuring a structured approach to addressing security breaches.
  • An understanding of Agile is desirable but not essential, more important than your specific skillset is your ‘can do’ attitude and willingness not to be constrained by your job description.
  • Effective communication skills to handle comms to teams, management and cross functional stakeholders at all levels, and a proven track record of getting things done/shipping projects.
  • Proficiency in *nix Based Systems: A strong practical understanding of *nix based systems and the tools that can be used to secure such systems.
  • Experience working in a dynamic, fast-moving environment where self-motivated, autonomy and self-decision making is needed (to an extent) and juggle between multiple projects/tasks.
  • Comprehensive Cybersecurity Understanding: A strong and broad grasp of various cybersecurity safeguards, covering physical, technical, and procedural controls.
From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against MyCareersFuture's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on MyCareersFuture's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    MyCareersFuture's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.