> Markdown version of [/jobs/ext/733702-senior-security-analyst-tier-3-insider-risk-global-security-organization](https://www.wearedevelopers.com/jobs/ext/733702-senior-security-analyst-tier-3-insider-risk-global-security-organization). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Security Analyst (Tier 3, Insider Risk) - Global Security Organization - **Company:** Tiktok Inc. - **Location:** San Jose, CA, United States - **Experience:** Expert - **Salary:** $134,400.0 - $235,600.0 - **Contract:** Permanent contract - **Skills:** Amazon Web Services, Data Analysis, Audit Trail, Microsoft Azure, Cloud Computing, Collaborative Software, Cyber Security, Digital Forensics, Identity and Access Management, Virtual Private Networks (VPN), Python (Programming Language), Role-Based Access Control, Cloud Services, Software Engineering, Google Cloud, Okta, Git, Information Technology, 3-tier Architectures - **Published:** June 29, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=c8a992f1b73df57d ## About the Role Do you have experience in Tooling?, Do you have a Bachelor's degree?, This role demands strong technical acumen, investigative instincts, and the ability to navigate sensitive matters across multiple jurisdictions. You will work independently but collaboratively, serving as the key technical point of contact for insider risk cases. Candidates must have experience in security analysis or engineering and have operated within a large-scale tech, platform, or media environment., * Strong technical proficiency in: Log data analysis (Audit logs for various services, process logs, etc), Security principles (CIA, defense in depth, principle of least privilege, etc.), IAM/SSO (Okta, AD, etc.), Cloud services (GCP, AWS, Azure, Ali Cloud, etc.), Endpoint detection and response (EDR), Network logs, Email logs, Collaboration platform logs (Slack, Microsoft Teams, etc.) * Strong understanding of developer workflows and tools (e.g. Git, python, etc...) and how they are used day to day by engineers. * Experience independently leading complex security investigations from detection through remediation * Experience performing endpoint, cloud, and identity-based investigations across enterprise environments * Experience mentoring analysts and serving as a technical escalation point for investigative teams * Ability to communicate technical findings to both technical and non-technical stakeholders * Strong experience producing investigation reports suitable for internal counsel, executives, and auditors., * 5+ years of experience in Insider Risk, Insider Threat, Security Engineering, Digital Forensics, Incident Response, or related disciplines * Bachelor's degree or above in Cybersecurity, Computer Science, Software Engineering. * Demonstrated experience conducting investigative interviews and subject questioning. * Experience developing detections, investigative playbooks, workflows, or automation to improve insider risk operations * Familiarity with GDPR or equivalent privacy frameworks relevant to internal investigations. * Prior involvement in investigations that resulted in external visibility, public scrutiny, or regulatory engagement. * Familiarity with insider threat frameworks and risk modeling., Qualified applicants with arrest or conviction records will be considered for employment in accordance with all federal, state, and local laws including the Los Angeles County Fair Chance Ordinance for Employers and the California Fair Chance Act. Our company believes that criminal history may have a direct, adverse and negative relationship on the following job duties, potentially resulting in the withdrawal of the conditional offer of employment ## Description * Lead technical insider risk investigations from intake to closure involving sensitive matters such as: Data exfiltration or misuse, Unauthorized platform access or privilege abuse, Dual employment and conflict of interest concerns, Misconduct with potential public or regulatory exposure and Tampering with intellectual property * Analyze telemetry data and indicators across regional infrastructure: DLP alerts, endpoint logs, VPN activity, service logs, and our internal collaboration platform. * Conduct interviews with employees and stakeholders across the AMS and other regions, exercising sound judgment and cultural sensitivity. * Write thorough, region-specific investigation reports, ensuring alignment with global protocols while reflecting local legal and business context. * Collaborate with Legal, HR, Engineering, PR, and Policy teams across the Americas to coordinate investigative outcomes and support remediation or disciplinary action. * Monitor and assess external threats and public disclosures originating from internal actions that may affect TikTok's brand globally. * Identify and address regional detection gaps, contribute to threat modeling, and help shape alerting logic in partnership with detection, analysis, and engineering teams. * Maintain complete discretion and proper handling of sensitive employee, operational, and company data in accordance with regional privacy laws. ## Related Videos - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) - [Resilient by Design: Building Robust Architectures in High-Stakes Financial Systems](https://www.wearedevelopers.com/videos/2106-resilient-by-design-building-robust-architectures-in-high-stakes-financial-systems) - [How a Small Team Shrank a Microsoft Monorepo by 94%](https://www.wearedevelopers.com/videos/1236-how-a-small-team-shrank-a-microsoft-monorepo-by-94) - [Automated Security for the Entire SDLC](https://www.wearedevelopers.com/videos/100323-automated-security-for-the-entire-sdlc) - [No Keys for the Robot: GitOps as the Control Plane for Autonomous Agents](https://www.wearedevelopers.com/videos/100095-no-keys-for-the-robot-gitops-as-the-control-plane-for-autonomous-agents) - [Git for Code Reviews](https://www.wearedevelopers.com/videos/429-git-for-code-reviews) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers)