The posting
Threat Management, Incident Response, and Investigations protects our global businesses, products, employees, and users across the full security lifecycle. We detect and respond to cyber threats, vulnerabilities, and security risks across the lifecycle, and investigate issues end to end.
Our global team provides prompt security response worldwide, leveraging AI to identify and respond to security issues quickly. You will work on high-stakes problems, from detection and automation to live intelligence-driven incident response and investigation, and see your work protect the company and its users worldwide.
The mission of TikTok's Global Security Organization is to build and earn trust by reducing risk and securing our businesses and products. Also known as "GSO", this team is the foundation of our efforts to keep TikTok safe, secure, and operating at scale for over 1 billion people around the world. We work to ensure that the TikTok platform is safe and secure, that our users' experience and their data remains safe from external or internal threats, and that we comply with global regulations wherever TikTok operates.
Trust is one of TikTok's biggest initiatives, and security is integral to our success. In whatever ways users interact with us — whether they're watching videos on their For You page, interacting with a Live video, or buying products on TikTok Shop — GSO protects their data and privacy, so they can have a secure and trustworthy experience.
TikTok's Detection Engineering team is responsible for identifying anomalous behaviors across the enterprise at scale. We are seeking a Detection Engineer. This role focuses on mining abnormal patterns from massive volumes of logs including host, network, endpoint, authentication and business application data, to detect potential unintended activities within the internal environment. This covers both external intrusion attempts, and emerging AI-specific security risks, and requires strong data analysis and algorithmic skill sets.
TikTok's Global Detection Engineering team identifies anomalous behaviors at enterprise scale. We are seeking a Detection Engineer to mine abnormal patterns from massive host, network, endpoint, authentication and business application logs. This role detects external intrusions and emerging AI security risks, requiring strong data analysis and algorithmic skills.
Responsibilities - End-to-End Detection Engineering: Own detection rules, behavioral models, and pipelines end-to-end — from log ingestion through alerting — across petabyte-scale security telemetry. - Streaming & ML-Based Anomaly Detection: Build streaming detection pipelines that combine statistical methods and unsupervised learning to baseline normal behavior and surface unknown threats. - AI Agent Security Detection: Design detection capabilities for internal agent systems based on the MITRE ATLAS framework, covering invocation, tool execution, privilege escalation, and data access. - Detect emerging attack patterns: agent abuse, unauthorized tool calls, agent escape, multi-agent collusion. - Monitor agent-LLM-tool-data interactions to catch instruction manipulation and data exfiltration. - Retrospective Threat Hunting: Run hunting pipelines against cold storage and historical logs to support post-incident analysis and detection gap validation. - Continuous Optimization: Improve signal-to-noise ratio, cut down alert fatigue, and work with AI security teams to shape logging standards for LLM and agent systems.
Minimum Qualifications - 5+ years of hands-on experience in information security, cybersecurity engineering, or a related technical field. - Proven experience processing and correlating large-scale multi-source security telemetry - Solid foundation in data analysis, statistics and applied machine learning for anomaly detection - Hands-on experience building detection rules or threat hunting queries for SIEM/EDR platforms - Strong knowledge of common AI Agent security risks and hardening strategies (e.g., OWASP Top 10 for LLMs, including prompt injection, unauthorized tool execution, and denial of service).
Preferred Qualifications - Deep familiarity with the MITRE ATLAS framework, with a proven track record of applying it to threat modeling and risk assessment for AI systems. - LLM/Agent detection experience, Agent Loop architecture knowledge - Global enterprise-scale detection operations experience



