Responsibilities
- Lead the end-to-end Third-Party Risk Management lifecycle (intake, due diligence, contracting, ongoing monitoring, and exit) for relevant third-parties, aligning to enterprise risk, national security compliance, security, privacy, and resilience requirements.
- Design and maintain the TPRM operating model, including roles and responsibilities, RACI, and handoffs across cross-functional business teams, Procurement, Legal, and Security & Privacy.
- Implement and continuously refine automation- and AI-enabled workflows (e.g., dynamic questionnaires, evidence collection, control testing, and issue tracking) to scale assessments, reduce manual effort, and show measurable efficiencies.
- Develop and manage continuous control monitoring and data-driven vendor risk scoring, leveraging internal and external data sources (e.g., security ratings, vulnerability and incident data, SOC 2 reports) to produce actionable risk indicators, including supply chain and concentration risk.
- Translate regulatory requirements and industry frameworks (e.g., NIST CSF, NIST 800-53, ISO 27001, SOC 2, SIG/CAIQ) into practical third-party control requirements, playbooks, and testing procedures.
- Prepare and present clear metrics, dashboards, and narratives on third-party risk posture, key issues, and remediation progress to senior leadership, governance forums, and audit stakeholders.
- Drive remediation and risk decisions with influence, partnering with senior leaders to resolve material third-party issues, shape risk acceptance decisions, and ensure timely closure of gaps.
Qualifications
- Minimum Qualifications: Bachelor’s degree or equivalent practical experience and 5+ years of applicable experience in information security, risk management, privacy, or compliance, with significant experience focused on Third-Party Risk Management, vendor risk, or supply chain security in a program leadership role.
- Proven experience designing, implementing, and operating TPRM processes across the third-party lifecycle (intake, due diligence, contracting, ongoing monitoring, and termination) in a highly regulated or high-risk environment, including hands-on experience evaluating technical and procedural controls at third parties, interpreting SOC 2 and similar assurance reports, and reviewing supporting evidence with infrastructure, application, and security engineering teams.
- Strong working knowledge of information security and privacy control frameworks as applied to third parties (e.g., NIST CSF, NIST 800-53, ISO 27001, SOC 2, SIG/CAIQ, vendor due diligence standards).
- Experience designing or using vendor risk scoring models, key risk indicators, and dashboards to monitor third-party risk posture and drive measurable outcomes, plus ability to design and improve process automation using modern GRC/TPRM tooling (e.g., Archer, ServiceNow, OneTrust, ProcessUnity or similar), including leveraging rules, integrations, and AI-enabled capabilities to streamline assessments and monitoring.
- Proven ability to build cross-functional relationships with technology and engineering teams to enable technical workflows and advancements to the program, with success leading cross-functional initiatives and influencing stakeholders across Procurement, Legal, Privacy, Security, Engineering, Finance, and business teams without direct authority.
- Excellent communication skills, with the ability to translate complex technical and regulatory concepts into clear, business-focused narratives for diverse audiences.
- Familiarity with US-centric regulatory expectations related to third-party risk, data protection, and security (e.g., federal and state privacy and cybersecurity requirements, industry supervisory guidance).
Preferred Qualifications:
- Experience building, scaling, or modernizing Third-Party Risk Management programs in highly regulated or US-critical sectors (e.g., financial services, telecommunications, cloud, or public sector), including close partnership with Privacy and Legal teams to align TPRM controls with data protection requirements.
- Experience designing continuous control monitoring, automation, and data pipelines for third-party risk (e.g., integrating external security ratings, SIG/CAIQ responses, SOC 2 outputs, vulnerability and incident data), including experimentation with AI/ML or advanced analytics to identify anomalies and prioritize remediation.
- Relevant professional certifications such as CTPRP, CTPRA, CISA, CISSP, CISM, CRISC, or similar.
About USDS
- TikTok USDS Joint Venture LLC is dedicated to the safety and security of millions of Americans who create, discover, and connect with what they love on the apps we operate. The Joint Venture has been established in compliance with the Executive Order signed by President Trump on September 25, 2025.
- Our foundation is a comprehensive data privacy and cybersecurity program we operate under defined safeguards to protect national security and secure U.S. user data, apps and the algorithm. We safeguard the U.S. content ecosystem, holding decision-making authority for trust and safety policies and moderation.
- On-site presence across teams allows the company to operate with greater speed, alignment, and agility — especially in areas like real-time decision-making, team development, and integrated execution. As such, the company is shifting from a hybrid work model to a fully in-person schedule up to 5 days a week.
Why Join Us
- Inspiring creativity is at the core of TikTok's mission. Our product helps people express themselves, discover, and connect. Our diverse teams make that possible, and we strive to create value for communities while inspiring creativity and joy.
- We aim to do great things with great people, leading with curiosity, humility, and a desire to make an impact in a fast-growing tech company. We embrace challenges, iterate, and maintain an "Always Day 1" mindset to achieve meaningful breakthroughs.
Diversity & Inclusion
TikTok is committed to creating an inclusive space where employees are valued for their skills, experiences, and unique perspectives. Our platform connects people from across the globe and so does our workplace. We are passionate about diversity and building an environment that reflects the communities we reach.
USDS Reasonable Accommodation
USDS provides reasonable accommodations in our recruitment processes for candidates with disabilities, pregnancy, sincerely held religious beliefs, or other protected reasons. If you need assistance or a reasonable accommodation, please reach out at
Job Information
Compensation (Annual): The base salary range for this position in Washington, DC is $132,480 - $336,960. Compensation may vary based on qualifications, skills, competencies, experience, and location. Base pay is one part of the total package and may include discretionary bonuses/incentives and stock units. Benefits include medical, dental, vision, 401(k) with company match, paid parental leave, disability coverage, life insurance, wellbeing benefits, and paid time off. The company reserves the right to modify benefits programs at any time.
#J-18808-Ljbffr