The posting
The Privacy and Data Protection Office (PDPO) leads and supports TikTok's global privacy efforts, making sure privacy is protected across our products, platforms, and technologies. As a technical privacy center of excellence, we partner closely with engineering, product, legal, and compliance teams to identify privacy risks and design effective technical safeguards throughout the software development lifecycle.
At TikTok's scale, protecting user data means going beyond compliance to find complex privacy vulnerabilities and emerging risks across highly distributed products and systems. We combine privacy engineering, security engineering, penetration testing, red teaming, and secure code review to surface those risks, develop mitigations, and build scalable automated assessment capabilities that protect privacy without slowing product innovation.
You will work at the intersection of privacy, security, and engineering, on real-world privacy challenges at global scale, influencing how privacy is built into products from the ground up.
About the Role: We are seeking a Privacy Program Manager to join our PDPO team as an audit expert and liaison, primarily supporting our product team. In this role, you will translate complex audit requirements into actionable processes. You will ensure our product teams consistently achieve regulatory compliance and remain fully audit-ready.
Key Responsibilities: - Audit Readiness: Guide cross-functional teams through the audit preparation lifecycle. Proactively evaluate current processes against regulatory frameworks, implement necessary compliance controls, and ensure teams are fully equipped for successful internal and external audits. - Audit & Compliance: Facilitate external audits by attending control design walkthroughs and tests of operating effectiveness. Support the maintenance and enhancement of the control framework to align with current regulations and industry standards. - Project Management: Lead projects from conception to execution. Develop comprehensive project plans and collaborate with a wide range of technical and non-technical stakeholders to ensure timely completion. - Program Development: Create and maintain essential program documentation, including process flows, policies, frameworks, and management reports. - Training & Enablement: Develop and deliver internal training materials on privacy controls, certifications, and best practices to enhance organizational awareness and compliance. - Continuous Improvement: Stay current with the latest privacy trends, digital regulations, and industry best practices to continuously strengthen the program.
Minimum Qualifications - Bachelor’s degree in Information Technology, Cybersecurity, Law, Business, or a related field. Proven experience in conducting audits or facilitating external audits. - Proven hands-on experience conducting audits or assessments, evaluating control design, and managing or supporting external audit engagements from kickoff to completion. - 3+ years of governance risk and compliance (GRC) or related privacy, compliance, and security experience - Strong project management skills, with the ability to manage multiple projects simultaneously, with the ability to translate legal and regulatory requirements into actionable plans. - Experience collaborating closely with engineers, business teams, and security partners, including incident response, red teams, and architects to seamlessly incorporate cybersecurity controls and risk management processes into their day-to-day operations. - Familiarity with regulations such as GDPR, DSA, and DMA
Preferred Qualifications: - A highly motivated individual, with strong communication and relationship-building skills, and demonstrate a record of ongoing accomplishment and commitment to excellence. - Accustomed to working in a fast-paced, startup-like environment. Adaptable to changing or emerging priorities. - Prior experience working with regulatory authorities or law enforcement agencies is a plus.



