Skip to content

Regulatory Intelligence & Implementation Specialist - Global Security Organization

TikTok

New York, United States of America

Applying for this one?

We write the CV against this exact posting — its wording, its requirements — not a template with your name in it.

Get my CV for this job

$25, one-time. No subscription.

The mission of TikTok's Global Security Organization is to build and earn trust by reducing risk and securing our businesses and products. Also known as "GSO", this team is the foundation of our efforts to keep TikTok safe, secure, and operating at scale for over 1 billion people around the world. We work to ensure that the TikTok platform is safe and secure, that our users' experience and their data remains safe from external or internal threats, and that we comply with global regulations wherever TikTok operates.

Trust is one of TikTok's biggest initiatives, and security is integral to our success. In whatever ways users interact with us — whether they're watching videos on their For You page, interacting with a Live video, or buying products on TikTok Shop — GSO protects their data and privacy, so they can have a secure and trustworthy experience.

The GSO provides industry-leading security and privacy services to company, guided by four principles: trust and transparency, business enablement, risk-informed decision-making, and proactive risk reduction. We strive to build sustainable, world-class security capabilities.

The Security Solutions & Delivery (SSD) team turns security requirements into practical, auditable outcomes that help the business move faster and reduce risk. We support business revenue through Customer Assurance, sustain critical third-party integrations through Partner Compliance, translate evolving regulatory requirements into action through Regulatory Intelligence, and directly take ownership of fixing systemic identified risks through Security Remediation. In addition, Our Organizational Excellence pillar supports the broader Global Security Organization with the finance, coordination, and the operational foundations it needs to run effectively. The impact of this work is clear and immediate: faster deals, stronger partner continuity, addressing high priorities, and greater trust with customers and partners.

We are seeking a Regulatory Intelligence & Implementation Senior Specialist to drive the translation of complex US, EU, and global regulatory requirements into operational security controls. You will inherit and expand upon an established program portfolio that includes USDS joint venture compliance, data sovereignty, and cross-functional security initiatives. This role sits at the intersection of regulatory compliance, security operations, and strategic program management. You will be the person who ensures that when new regulations emerge our security organization is not only aware but has a clear, operational plan to comply.

Key Responsibilities - Track and analyze emerging US, EU, and global regulatory developments (GDPR, US requirements, data sovereignty) to anticipate security obligations before they land - Translate legal and regulatory requirements into concrete security control implications for the global security organization - Build and maintain a regulatory roadmap that maps compliance deadlines to security implementation efforts - Leverage industry frameworks (ISO, NIST, SOC 2) to bridge regulatory requirements and internal controls - Lead gap assessments comparing current controls against new and evolving regulatory requirements and requests - Partner with European Privacy teams to operationalize GDPR, and other EU requirements across security processes - Serve as the primary Global Security liaison to USDS ,own the relationship and ensure alignment on joint venture compliance obligations - Ensure USDS-negotiated security commitments are reflected in internal controls, processes, and documentation - Build scalable security processes that adapt to multiple regulatory frameworks without bespoke solutions for every new request - Maintain a notification decision tree and escalation paths, know who needs to be notified, when, what evidence is required, and when service timelines slip - Maintain a formal legal review checkpoint for regulatory interpretations before security teams act on them - Establish regulatory compliance metrics that give regular, measurable visibility into posture and progress - Maintain a regular reporting cadence to leadership and relevant committees through dashboards and reports - Develop playbooks and SOPs that enable the broader security team to implement regulatory requirements consistently

Minimum Qualifications: - Demonstrated expertise in translating regulatory requirements into operational security controls — not just compliance reporting, but actual implementation - Strong working knowledge of US and EU regulatory frameworks relevant to technology companies: GDPR, DSA, OSA, CCPA, and data sovereignty requirements - Experience working with or interfacing to government oversight entities, auditors, or regulatory bodies - Proven track record of cross-functional program management, driving initiatives that span Legal, Privacy, Engineering, and Product teams - Experience establishing metrics, reporting cadences, and strategic visibility mechanisms for compliance programs - Excellent ability to brief senior leadership on regulatory matters

Preferred Qualifications - Bachelor's degree in Law, Public Policy, Information Security, Computer Science, or related field, or equivalent practical experience - 5+ years of experience in regulatory compliance, security governance, or privacy programs — preferably in a technology company operating under complex regulatory oversight - Direct experience with US or similar government-negotiated data security arrangements - Experience managing large-scale compliance training programs (1,000+ learners) - Familiarity with IAM governance programs, including User Access Reviews and access management strategy - Industry certifications such as CIPP/E, CIPM, CISSP, or CISA (e.g., company-wide offsites, training drives)

Seen 7 hours ago · TikTok postings close after a median of 0 days.

Original posting on TikTok's site ↗

Posting text belongs to the employer. Removal requests: contact us.

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

One job at a time

One posting. One CV. $25.

Pick the job you actually want and we write for it.

Get my CV for this job