TikTok

Senior Privacy Engineer (RED team) - TikTok PDPO

TikTok  •  San Jose, CA (Onsite)  •  3 hours ago
Apply
AI can make mistakes so check important info. Chat history is never stored.

Job Description

About the team:

The Privacy and Data Protection Office (PDPO) leads, supervises, and empowers all of TikTok's privacy work in an accountable and industry-leading way. The team is the in-house expert on the privacy risk landscape and partners across the company to implement the safeguards and technical mitigations that ensure users' privacy is honored across TikTok's products and platforms.

The Global Privacy Red Team within PDPO is looking for a senior red team engineer who can operate independently from day one - driving complex assessments end-to-end, pioneering new techniques to surface privacy risks at scale, push the state of the art in offensive privacy testing and help TikTok continue to raise the bar on user privacy.

What you’ll do:

- Threat model privacy concepts (consent, data sharing, data minimization, purpose limitation, retention, sovereignty, product privacy, etc.) into concrete adversarial scenarios, then design and execute red team engagements against those scenarios

- Conduct deep, hands-on technical assessments and penetration tests of internal and external-facing systems, products, and services, with a focus on bypassing user privacy expectations from the perspective of an external attacker

- Identify exploitable issues across the data lifecycle - how data flows internally between services and how it is shared with external parties - and demonstrate impact end-to-end.

- Research emerging privacy threats and attack techniques; develop new testing methodologies and abuse cases ahead of them landing in production.

- Partner with engineering and product teams to integrate privacy-preserving controls throughout the SDLC, and translate findings into actionable, prioritized remediation guidance.

- Research and analyze emerging threats in privacy, proactively identifying mitigation strategies and testing methodologies to protect user data.

- Help shape the practices, processes, and documentation that define how privacy red teaming is done at TikTok, both internally and with cross-functional working groups.

- Build tooling, scripts, and frameworks to scale privacy-focused assessments and automate recurring checks.

Knowledge, Skills & Abilities:

- Strong fundamentals in computer science, offensive security (especially appsec), security engineering, and privacy engineering.

- Ability to reason about privacy as an attacker: turning abstract concepts (consent, data sharing, minimization, retention) into concrete, testable abuse cases.

- Strong manual secure code review skills, with an eye for privacy-specific bugs in addition to traditional appsec issues.

- Comfortable working across heterogeneous stacks and unfamiliar codebases.

- Ability to operate independently, prioritize across competing engagements, and drive complex assessments to completion.

- Excellent written and verbal communication, with experience working cross-functionally with engineering, legal, and compliance partners.
TikTok

About TikTok

Inspire Creativity and Bring Joy

Industry
Arts & Entertainment
Company Size
10,000+ employees
Headquarters
Los Angeles, California
Year Founded
Unknown
Social Media