Skip to content

Open nowFirst seen 3 hours ago

Security Engineer, Risk Adversary and Intel Discovery - TikTok BRIC

TikTok4,268 open roles

Where
Singapore
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowSecurity Engineer, Risk Adversary and Intel Discovery - TikTok BRICTikTok · Singapore
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on TikTok's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

8.2% of postings close within 7 days. Measured by our own scanner across the market. TikTok postings stay open a median of 7 days.

Share of postings closed within
  1. 1.8%1 day
  2. 3.8%3 days
  3. 8.2%7 days
  4. 15.2%14 days
  5. 34.2%30 days
This job: first seen 3 hours ago

TikTok median: 7 days open

The posting

Business Risk Integrated Control (BRIC) is a global team protecting ByteDance users, platform health, and the authenticity of community and business ecosystems. We build the risk control algorithms, AI technologies, platforms, and infrastructure behind that work, across products including TikTok, CapCut, Lemon8, and Lark.

Our work spans account and content integrity, and safety across advertising and e-commerce. We apply machine learning across areas such as graph learning, anomaly detection, and multimodal models to understand users, content, behavior, and the relationships between them. The challenge is recognizing genuine activity accurately, so the people using our products never notice the systems working.

You will shape the trust, safety, and sustainable growth of ByteDance's global platforms, applying advanced AI to some of the hardest real-world problems in the field.

RAID (Risk Adversary and Intelligence Discovery) focuses on understanding and countering adversarial activities across underground ecosystems. By combining threat intelligence research, adversary analysis, and offensive security assessments, the team helps business teams identify emerging threats, understand attack methods, validate existing defenses, and build comprehensive and measurable risk control capabilities.

Responsibilities - Underground Ecosystem & Threat Intelligence Research: Conduct in-depth research into underground industry chains, adversarial groups, abnormal business activities, and emerging attack trends. Investigate intelligence techniques such as adversary attribution, threat intelligence monitoring, and intelligence-driven risk identification to provide actionable insights and proactive risk warnings. - Adversarial Tool & Attack Analysis: Analyze commonly used illicit tools, cheating software, and attack techniques. Reconstruct attack methods and paths, investigate the underlying technical mechanisms, and identify potential vulnerabilities and gaps in existing risk control strategies. - Adversarial Simulation & Security Assessment: Approach business systems from the perspective of external adversaries and conduct effective adversarial exercises to evaluate the real-world effectiveness of existing risk control strategies. Research emerging offensive and defensive security techniques and recommend improvements to detection and defense mechanisms. - Risk Intelligence Collection & Correlation Analysis: Collect and analyze intelligence from internal and external sources, including OSINT and other relevant intelligence sources. Correlate information across multiple data sources to identify adversarial groups, trace attack origins, and support the investigation and mitigation of business risks. - Underground Ecosystem Mapping & Monitoring: Identify underground industry chains targeting critical business scenarios, monitor key links, and analyze their operational models, monetization mechanisms, scale, and evolution to support targeted risk prevention and disruption. - Security Trend Monitoring & Incident Response: Track domestic and international security developments, conduct technical analysis of security incidents, and support rapid response to emerging threats and attacks. - Risk Defense Optimization: Translate intelligence findings and adversarial assessment results into actionable defense strategies. Collaborate with cross-functional teams to continuously improve risk detection, mitigation, and control capabilities.

Minimum Qualification(s) - Have a solid understanding of underground ecosystems, including adversarial groups, industry chains, attack techniques, and monetization models, with the ability to independently analyze business risks and adversarial behavior. - Be familiar with at least one of the following areas: Android/iOS/Web reverse engineering, mobile application security, abuse and cheating techniques, fake engagement, incentive abuse, or other forms of adversarial attacks. - Understand common web application, mobile application, and system vulnerabilities, including their underlying principles, detection methods, and remediation approaches. Stay informed about emerging offensive and defensive security techniques. - Be familiar with core risk control strategies and mechanisms, with the ability to analyze adversarial behavior and evaluate the effectiveness of existing defenses. - Have proficiency in at least one major programming language, such as Python, Go, Java, C/C++, or JavaScript, and possess foundational data analysis and mining skills. - Demonstrate strong analytical thinking and risk awareness, with the ability to correlate information across multiple data sources, investigate adversarial activities, and independently solve complex problems.

Preferred Qualification(s) - Have experience with threat intelligence collection and analysis, including OSINT and relevant intelligence sources. Be proficient in using domestic and international social platforms or other channels for intelligence gathering and analysis. - Experience building or contributing to enterprise Red Team capabilities, business risk control, threat intelligence, adversarial analysis, or underground ecosystem disruption. - Experience in enterprise Red Team operations, penetration testing, or vulnerability discovery, including contributions as a security researcher or white-hat hacker through a Security Response Center (SRC). - A proven track record of identifying and submitting high-impact vulnerabilities in mobile applications, mini-programs, or web applications. - Strong expertise in threat intelligence analysis, adversary attribution, or technical investigations, with established analytical methodologies. - Access to extensive intelligence sources, particularly international or overseas intelligence channels. - Demonstrated experience identifying and mitigating underground ecosystem risks through the analysis and correlation of internal and external data sources.

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against TikTok's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on TikTok's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    TikTok's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.