IT Security Compliance Engineer (Multiple Positions)

San Jose

ByteDance

ByteDance is a technology company operating a range of content platforms that inform, educate, entertain and inspire people across languages, cultures and geographies.

View all jobs at ByteDance

Apply now Apply later

Responsibilities

About ByteDance
Founded in 2012, ByteDance's mission is to inspire creativity and enrich life. With a suite of more than a dozen products, including TikTok, Lemon8, CapCut and Pico as well as platforms specific to the China market, including Toutiao, Douyin, and Xigua, ByteDance has made it easier and more fun for people to connect with, consume, and create content.

Why Join Us
Inspiring creativity is at the core of ByteDance's mission. Our innovative products are built to help people authentically express themselves, discover and connect – and our global, diverse teams make that possible. Together, we create value for our communities, inspire creativity and enrich life - a mission we work towards every day.
As ByteDancers, we strive to do great things with great people. We lead with curiosity, humility, and a desire to make impact in a rapidly growing tech company. By constantly iterating and fostering an "Always Day 1" mindset, we achieve meaningful breakthroughs for ourselves, our Company, and our users. When we create and grow together, the possibilities are limitless.
Join us.

About the Team
Our team plays a crucial role in ensuring the company’s success. We seek people who are willing to learn and put in the effort to solve problems. Our challenges are not your regular day-to-day problems - you’ll be part of a team that’s developing new solutions to new challenges. It’s working fast, at scale, and we’re making a difference. We are looking for talents to join us on this exciting journey!


Responsibilities
Develop and implement a comprehensive security compliance program in office security scope, ensuring alignment with regulatory requirements, industry standards, and internal policies.
Conduct regular compliance assessments and audits to identify gaps and areas for improvement.
Drive the development and implementation of security policies, standards, and procedures while working closely with stakeholders to ensure their adoption and compliance.
Conduct IT security compliance related project implementation.
Develop and deliver security awareness and training programs to educate employees on IT security best practices, policies, and procedures to foster a strong security culture within the organization.
Collaborate with cross-functional teams to integrate security controls into the development and implementation of new systems, applications, and processes.
Monitor and track security regulations and vulnerability information, ensuring timely reporting, investigation, and resolution.
Stay up to date with evolving security regulations and standards, communicating changes and updates to relevant stakeholders and ensuring compliance with new requirements.
Serve as the primary point of contact for internal/external auditors and regulatory bodies during security assessments and audits.

Qualifications

Qualifications
Must have a Master’s degree or foreign equivalent degree in Computer Science, Engineering (any), Information Systems, Management and Systems, Information Security, Cybersecurity, or a related field, and 1 year of related work experience; OR a Bachelor's degree or foreign equivalent degree in Computer Science, Engineering (any), Information Systems, Management and Systems, Information Security, Cybersecurity, or a related field, and 3 years of related work experience.

Of the required experience, must have 1 year of experience in each of the following:
Supporting internal security audits and ISO27001/SOC2 audit activities;
Compiling tailored security policies, standards, and guidance to improve security standards;
Performing security reviews including Firewall rules review, service account provision, and quarterly access review of sensitive groups to comply with compliance requirements;
Working on compliance readiness by leveraging information security controls, security frameworks, or standards, including ISO 27001, NIST CSF, PCI-DSS, or HIPAA;
Maintaining security rules and configuration per user feedback; and
Assessing current and emerging threats, cyberattacks, and zero-day vulnerabilities and recommending security controls and corrective actions to mitigate vulnerability risk.

Type: Full time, 40 hours/week
Location: San Jose, CA
Salary Range: $132579 - $196000 per year

To Apply, click the apply button below. Contact lpresumes@bytedance.com if you have difficulty submitting resume through the website.

ByteDance is committed to creating an inclusive space where employees are valued for their skills, experiences, and unique perspectives. Our platform connects people from across the globe and so does our workplace. At ByteDance, our mission is to inspire creativity and enrich life. To achieve that goal, we are committed to celebrating our diverse voices and to creating an environment that reflects the many communities we reach. We are passionate about this and hope you are too.

ByteDance is committed to providing reasonable accommodations in our recruitment processes for candidates with disabilities, pregnancy, sincerely held religious beliefs or other reasons protected by applicable laws. If you need assistance or a reasonable accommodation, please reach out to us at https://tinyurl.com/RA-request

#LI-DNI
#IND-DNI

Job Information

【For Pay Transparency】Compensation Description (Annually)

The base salary range for this position in the selected city is $132579 - $196000 annually.​

Compensation may vary outside of this range depending on a number of factors, including a candidate’s qualifications, skills, competencies and experience, and location. Base pay is one part of the Total Package that is provided to compensate and recognize employees for their work, and this role may be eligible for additional discretionary bonuses/incentives, and restricted stock units.​

Benefits may vary depending on the nature of employment and the country work location. Employees have day one access to medical, dental, and vision insurance, a 401(k) savings plan with company match, paid parental leave, short-term and long-term disability coverage, life insurance, wellbeing benefits, among others. Employees also receive 10 paid holidays per year, 10 paid sick days per year and 17 days of Paid Personal Time (prorated upon hire with increasing accruals by tenure).​

The Company reserves the right to modify or change these benefits programs at any time, with or without notice.​

For Los Angeles County (unincorporated) Candidates:​

Qualified applicants with arrest or conviction records will be considered for employment in accordance with all federal, state, and local laws including the Los Angeles County Fair Chance Ordinance for Employers and the California Fair Chance Act. Our company believes that criminal history may have a direct, adverse and negative relationship on the following job duties, potentially resulting in the withdrawal of the conditional offer of employment:​

1. Interacting and occasionally having unsupervised contact with internal/external clients and/or colleagues;​

2. Appropriately handling and managing confidential information including proprietary and trade secret information and access to information technology systems; and​

3. Exercising sound judgment.​

Apply now Apply later
Job stats:  0  0  0

Tags: Audits Compliance Computer Science Firewalls HIPAA ISO 27001 NIST Security assessment SOC 2 Vulnerabilities Zero-day

Perks/benefits: 401(k) matching Career development Equity / stock options Health care Insurance Medical leave Parental leave

Region: North America
Country: United States

More jobs like this

Explore more career opportunities

Find even more open roles below ordered by popularity of job title or skills/products/technologies used.