New York, United StatesFull TimeEntry-levelPosted Today
Internal Audit is a global function responsible for providing independent assurance and evaluating the company's risk management, governance and internal control processes to determine if they are designed and operating effectively. The Internal Audit team plans and executes audit projects according to our risk-based audit plan by evaluating operational, compliance, IT, and financial processes and controls. We work with business functions in addressing risks and improving the control environment through timely and comprehensive audit work and tracking of remediation actions until completion.
Position Summary:
We are looking for an experienced Technology Internal Audit Lead to join the Global Technology Audit team. The role will primarily support TikTok and other products operating outside China and will be responsible for leading technology audits and risk reviews. The individual will be part of the Global Technology Audit team and innovative assurance methods to impact and influence positive business outcomes across products such as TikTok, TikTok Shop and Dola.
Responsibilities:
- Technology Audit Delivery: Lead planning and execution of technology audit programs and complex technology control assessments: Products powered by LLMs, Information Security, Infrastructure, Privacy. Assess technical architectures for AI/ML systems, focusing on data flow, model training & fine-tuning processes, model serving infrastructure, and integration with downstream applications.
- Advanced Data Analytics: Leverage data analytics to detect risk signals and unearth insights for AI/ML models. Review controls for data quality, privacy, security, access management, safety testing, hallucination mitigation, evaluation metrics, red-teaming procedures, and output monitoring.
- Technology Risk Assessment: Develop practical, risk-based recommendations that address root causes while considering product, engineering, regulatory, and business requirements. Ability to grasp complex, home grown technology stack, comfortable speaking with engineers and product teams.
- Stakeholder Relationships: Develop and maintain collaborative working relationships with management, understand the business to provide value-added services, and establish credibility as a management consultant and internal controls resource. Partner with engineering and product teams to advise on design and implementation of technology solutions.
- Quality Assurance: Ensure the overall quality and consistency of audit work, adhering to department and professional standards. Continuously seek opportunities for audit process improvement.
Minimum Qualifications:
- 5+ years of relevant experience in Technology Audits, Product Security, Security Engineering or Security Compliance preferably within the technology sector (Social Media, Content Management, FinTech etc.), and/or consulting firms. Proven ability to work in a fast-paced environment with a product centric culture.
- Strong understanding of security fundamentals across various cyber domains: IAM, applied cryptography, key management systems, data security, application security, web security, security protocols, API Design, threat intelligence, network security, hardware security, vulnerability management, etc.
- Proven analytical ability to assess complex technology environments against risk assessment outcomes, industry best practices, internal standards and external regulatory requirements.
- Excellent problem solving, critical thinking, collaboration and communication skills combined with the ability to provide a credible technical challenge to the business.
Preferred Qualifications:
- Deep understanding of LLMs, ML pipelines, model lifecycle management, and data engineering architectures.
- Experience working in a fast-paced, global technology company or rapidly scaling environment across different time zones.
- Solid background and experience working with one or more of the following areas:
- LLMs or ML frameworks (e.g., PyTorch, TensorFlow, HuggingFace)
- Common application and infrastructure security vulnerabilities and mitigations (OWASP Top 10, CWE 25)
- Source code and DevOps management tools (e.g., Github, Bitbucket)
- SaaS and IaaS cloud platforms (e.g., AWS, Azure, GCP)
- Professional certifications such as CISSP, CISM, GIAC, CCNA, CISA, CRISC, or CIA.
- Be able to handle ambiguity and collaborate with a global team.
- Passion for emerging technologies, products and standards.
Position Summary:
We are looking for an experienced Technology Internal Audit Lead to join the Global Technology Audit team. The role will primarily support TikTok and other products operating outside China and will be responsible for leading technology audits and risk reviews. The individual will be part of the Global Technology Audit team and innovative assurance methods to impact and influence positive business outcomes across products such as TikTok, TikTok Shop and Dola.
Responsibilities:
- Technology Audit Delivery: Lead planning and execution of technology audit programs and complex technology control assessments: Products powered by LLMs, Information Security, Infrastructure, Privacy. Assess technical architectures for AI/ML systems, focusing on data flow, model training & fine-tuning processes, model serving infrastructure, and integration with downstream applications.
- Advanced Data Analytics: Leverage data analytics to detect risk signals and unearth insights for AI/ML models. Review controls for data quality, privacy, security, access management, safety testing, hallucination mitigation, evaluation metrics, red-teaming procedures, and output monitoring.
- Technology Risk Assessment: Develop practical, risk-based recommendations that address root causes while considering product, engineering, regulatory, and business requirements. Ability to grasp complex, home grown technology stack, comfortable speaking with engineers and product teams.
- Stakeholder Relationships: Develop and maintain collaborative working relationships with management, understand the business to provide value-added services, and establish credibility as a management consultant and internal controls resource. Partner with engineering and product teams to advise on design and implementation of technology solutions.
- Quality Assurance: Ensure the overall quality and consistency of audit work, adhering to department and professional standards. Continuously seek opportunities for audit process improvement.
Minimum Qualifications:
- 5+ years of relevant experience in Technology Audits, Product Security, Security Engineering or Security Compliance preferably within the technology sector (Social Media, Content Management, FinTech etc.), and/or consulting firms. Proven ability to work in a fast-paced environment with a product centric culture.
- Strong understanding of security fundamentals across various cyber domains: IAM, applied cryptography, key management systems, data security, application security, web security, security protocols, API Design, threat intelligence, network security, hardware security, vulnerability management, etc.
- Proven analytical ability to assess complex technology environments against risk assessment outcomes, industry best practices, internal standards and external regulatory requirements.
- Excellent problem solving, critical thinking, collaboration and communication skills combined with the ability to provide a credible technical challenge to the business.
Preferred Qualifications:
- Deep understanding of LLMs, ML pipelines, model lifecycle management, and data engineering architectures.
- Experience working in a fast-paced, global technology company or rapidly scaling environment across different time zones.
- Solid background and experience working with one or more of the following areas:
- LLMs or ML frameworks (e.g., PyTorch, TensorFlow, HuggingFace)
- Common application and infrastructure security vulnerabilities and mitigations (OWASP Top 10, CWE 25)
- Source code and DevOps management tools (e.g., Github, Bitbucket)
- SaaS and IaaS cloud platforms (e.g., AWS, Azure, GCP)
- Professional certifications such as CISSP, CISM, GIAC, CCNA, CISA, CRISC, or CIA.
- Be able to handle ambiguity and collaborate with a global team.
- Passion for emerging technologies, products and standards.
