Team Introduction:
We are the Global E-commerce Security BP team. We partner closely with product, engineering and operations to safeguard Global E-commerce (e.g., TikTok Shop) across regions.Our scope covers application security, data security, privacy compliance and architecture security. We build and operate the SDLC/DevSecOps security program, conduct threat modeling, code reviews, penetration testing, red team exercises and vulnerability management, respond to security incidents rapidly and drive systemic fixes. We value pragmatism, ownership and cross-team collaboration, protecting business growth and user trust on a global scale.
We are looking for talented individuals to join our team. As a graduate, you will get opportunities to pursue bold ideas, tackle complex challenges, and unlock limitless growth.
Successful candidates must be able to commit to an onboarding date by the end of the year. Please state your availability and graduation date clearly in your resume.
Candidates can apply to a maximum of two positions and will be considered for jobs in the order you apply. The application limit is applicable to our Company and its affiliates' jobs globally. Applications will be reviewed on a rolling basis - we encourage you to apply early.
Responsibilities
- Conduct vulnerability discovery and risk management for global e-commerce business-related applications and APP products, and provide security assurance and support for key projects.
- Participate in the construction and optimization of the SDLC security system and processes, proactively mitigate potential security risks during the design and development phase, and systematically address security risks from the architectural level.
- Responsible for building security-related capabilities and processes, including security assessment, code auditing, penetration testing, vulnerability discovery, and attack and defense drills, and working closely with the product development team to improve the business's security level.
- Track domestic and international security trends and vulnerabilities, respond quickly to security incidents propose solutions and technical analysis, and coordinate with multiple departments to handle them.
Minimum Qualifications
- Individuals who are completing or have recently completed a Bachelor's/ Master's degree in Computer Science, Cybersecurity, Software Engineering, or a related discipline.
- Solid understanding of common Web/App/System vulnerabilities and remediation.
- Strong white-box auditing skills; Able to review Python/Go/Node.js/Java; Capable of automating repetitive tasks.
- Fast learning and analytical problem-solving skills; Keeps up with the latest security trends.
- Excellent communication, collaboration and professional ethhics.
Preferred Qualifications
- Experience building or optimizing SDLC/DevSecOps security programs at scale.
- Deep expertise in one or more areas: application security, data security, privacy compliance, architecture security.
- Experience with red exercises, incident response and cross-regional security operations.