> Markdown version of [/jobs/ext/3218676-grc-cybersecurity-controls-analyst](https://www.wearedevelopers.com/jobs/ext/3218676-grc-cybersecurity-controls-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # GRC Cybersecurity Controls Analyst - **Company:** Tiktok Usds - **Location:** New York, NY, United States - **Experience:** Experienced - **Salary:** $98,800.0 - $196,000.0 - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), Cyber Security, Data Security, Disaster Recovery, Identity and Access Management, PCI Data Security Standards, Systems Development Life Cycle, SQL Databases, Software Vulnerability Management, Workflow Management Systems, Data Logging, Scripting, Information Technology, Data Analytics - **Published:** September 7, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=e09601ccd18c7eee ## About the Role Minium Qualifications - Bachelor's degree in Information Security, Cybersecurity, Information Technology, Risk Management, Compliance, Engineering, Data Analytics, or a related discipline, or equivalent practical experience. - 3+ years of experience in GRC, IT risk, security controls, audit readiness, control testing, compliance, security assurance, or a related field. Experience performing or supporting control testing, including evaluating control design, implementation, and operating effectiveness. - Experience gathering, reviewing, and assessing technical control evidence from stakeholders, systems, tools, dashboards, or documentation repositories. Working knowledge of security and compliance frameworks such as ISO 27001, NIST CSF, SOC 2, PCI-DSS, or similar control frameworks. - Familiarity with security domains such as Identity and Access Management, Vulnerability Management, Incident Management, Asset Management, Logging and Monitoring, Data Security, SDLC, Third-Party Risk Management, Business Continuity / Disaster Recovery, or Privacy. - Strong writing and documentation skills, with the ability to create clear control narratives, evidence and testing summaries, and status updates. Strong analytical skills and ability to assess whether evidence meets the intent of a control, requirement, or audit request. - Experience working with control owners, technical teams, auditors, legal, privacy, compliance, or cross-functional stakeholders. Ability to manage multiple workstreams, follow up on open items, identify blockers, and communicate risks clearly. Demonstrated teamwork and collaboration skills, especially in fast-moving, cross-functional environments. Preferred Qualifications - Professional certification such as CISA, CISSP, CISM, CRISC, CDPSE, ISO 27001 Lead Auditor / Lead Implementer, or equivalent. - Experience supporting external audits, security certifications, or regulatory assessments such as SOC 2, ISO 27001, PCI, NIST CSF, or national security / data protection obligations. - Experience with GRC automation, control monitoring, evidence automation, dashboarding, workflow design, or data-driven control testing. Experience working with engineering, security, infrastructure, product, or data teams to translate technical processes into control evidence and audit-ready narratives. - Familiarity with automation, scripting, SQL, APIs, or data workflows used to improve GRC operations. - Experience maintaining or improving a control library, control framework, control mapping, or integrated compliance framework. Experience identifying evidence quality issues, control design gaps, operating effectiveness concerns, or audit readiness risks. ## Description About the Team TikTok is seeking a GRC Cybersecurity Controls Analyst to join the TikTok USDS Joint Venture (JV) GRC Controls & Certifications team. This role will support the operation, testing, and continuous improvement of the controls framework and will help drive audit readiness across key security, compliance, privacy, and regulatory obligations. The candidate will work closely with control owners, product teams, security teams, privacy, legal, internal audit, external auditors, and GRC leadership to evaluate control design, implementation, and operating effectiveness. About the Role The role will support control testing, evidence review, audit response coordination, control narrative development, and issue identification across frameworks and obligations such as ISO 27001, SOC 2, NIST CSF, PCI, control validation, and other certification or assessment activities. The candidate will also help mature the team's approach to GRC automation and engineering. This includes improving how controls are mapped, tested, monitored, and reported through tooling, dashboards, structured data, workflow automation, evidence recommendations, and scalable testing. The ideal candidate is comfortable working at the intersection of GRC, security controls, audit readiness, and process automation. Key responsibilities include: - Support the maintenance and continuous improvement of the controls framework, including control descriptions, mappings, owners, evidence expectations, testing procedures, and control narratives. - Perform control testing and validation activities, including design, implementation, and operating effectiveness testing. - Review evidence submitted by control owners and product teams to determine whether it sufficiently demonstrates control performance and meets audit or assessment expectations. - Coordinate with control owners, evidence owners, product teams, and GRC stakeholders to resolve evidence gaps, clarify control intent, and improve testing quality. - Support internal and external audits, certifications, and assessments, including ISO 27001, SOC 2, PCI, NIST CSF, and other GRC obligations. - Support GRC automation initiatives by helping define requirements for workflow automation, control monitoring, and scalable control testing processes. - Work with technical and engineering teams to understand security tools, data sources, system-generated evidence, and opportunities to automate or improve control validation. - Contribute to a culture of high-quality documentation, defensible controls testing, and continuous improvement across the Controls & Certifications function. ## Related Videos - [Crypto-secure Data Management with In-Database Blockchain](https://www.wearedevelopers.com/videos/632-crypto-secure-data-management-with-in-database-blockchain) - [Automated Security for the Entire SDLC](https://www.wearedevelopers.com/videos/100323-automated-security-for-the-entire-sdlc) - [JavaScript? No. Java Scripts! - Scripting with Java](https://www.wearedevelopers.com/videos/2094-javascript-no-java-scripts-scripting-with-java) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Build Delightful Mobile Experiences with Kotlin, Realm, and Atlas Device Sync](https://www.wearedevelopers.com/videos/694-build-delightful-mobile-experiences-with-kotlin-realm-and-atlas-device-sync) - [How to govern Vibe Coding for the Enterprise](https://www.wearedevelopers.com/videos/100290-how-to-govern-vibe-coding-for-the-enterprise) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [The Geometry of Incidents: Connecting User Impact to Architecture](https://www.wearedevelopers.com/magazine/764-the-geometry-of-incidents-connecting-user-impact-to-architecture)