Compliance Management Specialist - Governance Risk and Compliance
$120.96k - $212.04kTik Tok
Overview The mission of TikTok's Global Security Organization is to build and earn trust by reducing risk and securing our businesses and products. Also known as "GSO", this team is the foundation of our efforts to keep TikTok safe, secure, and operating at scale for over 1 billion people around the world. We work to ensure that the TikTok platform is safe and secure, that our users' experience and their data remains safe from external or internal threats, and that we comply with global regulations wherever TikTok operates. Trust is one of TikTok's biggest initiatives, and security is integral to our success. In whatever ways users interact with us — whether they're watching videos on their For You page, interacting with a Live video, or buying products on TikTok Shop — GSO protects their data and privacy, so they can have a secure and trustworthy experience. The Security Strategy, Risk, and Resilience (SRR) team is responsible for TikTok's Governance, Risk and Compliance function working closely with cross-functional partners to manage security risks, mature security operations, and build organizational resilience. We support our partners in meeting industry cybersecurity compliance standards and government regulations by developing and driving the organization’s cybersecurity strategy, establishing and maintaining a comprehensive business continuity management program, creating and maintaining governing security policies, implementing our security control framework, conducting regular security risk and control assessments, and staying up-to-date on global compliance initiatives and evolving regulatory requirements. The Security Strategy, Risk and Resilience (SRR) Controls Management Specialist is an experienced individual contributor responsible for driving the lifecycle of TikTok's cybersecurity risks and controls. This includes assessing cybersecurity risk, control testing and monitoring, identification and treatment of risks and/or control gaps, and facilitating internal and external audits. In addition, this individual will drive compliance engineering projects to improve our compliance program maturity. You would be a great fit for this role if you: Have a strong security risk, controls, and compliance mindset with experience in evaluating and testing controls against leading security frameworks such as ISO 27001, SOC 2, PCI DSS, and others Enjoy fostering collaboration with multi-disciplinary, cross-functional partnerships to solve challenging and unique cybersecurity risks with product, engineering and other business teams Thrive in dynamic, global environments and enjoy engineering an automated solution to a problem Possess a strong appetite for acquiring new knowledge and skills in cybersecurity and staying up-to-date on emerging trends Excel at analyzing complex systems and ideas and making these easy to understand Can provide candid and clear feedback on critical cybersecurity initiatives from policies to application designs and much more! Responsibilities Supporting the scoping and maturity of the cybersecurity compliance program to align with industry best practices and regulatory requirements including but not limited to ISO 27001, PCI DSS, and SOC 2 Identifying and assessing cybersecurity risks, working with risk owners to develop risk treatment plans, monitoring and reporting on cybersecurity risks, and maintaining a cybersecurity risk register Leading control design walkthroughs and tests of operating effectiveness for product and business line controls against security requirements and compliance obligations Preparing and supporting control owners and process owners for internal and external audits by conducting thorough examinations of people, processes, technologies and key system configurations and helping identify best-in-class evidence Influencing and collaborating with key stakeholders to support, track, and report on remediation efforts for identified security control gaps Maintaining a global security controls library to include periodic updates and validation of security controls and owners Communicating with technical and non-technical stakeholders on cybersecurity risk and control topics and program-specific reporting Qualifications Minimum Qualifications Experience supporting cybersecurity risk controls management programs with in-depth knowledge and experience of cybersecurity frameworks including ISO 27001, PCI-DSS, SOC 2, and other regulatory requirements Experience collaborating closely with engineers, business teams, and security partners, including incident response, red teams, and architects to seamlessly incorporate cybersecurity controls and risk management processes into their day-to-day operations Experience with the entire risk and controls monitoring lifecycle, including identifying, assessing, monitoring, and treating risk and control gaps Excellent communication skills with the ability to document, communicate, and report security assessments as well as the status of the implementation, effectiveness, and remediation of cybersecurity controls with product and business leaders Strong project management skills with the ability to lead and execute security assessment projects and initiatives on time with multiple stakeholders Ability to work in D.C. office for 5 days per week and be willing to travel to other offices with the flexibility to conduct virtual meetings, including international locations, as required to support business needs Preferred Qualifications Minimum of 5 years in Information Technology (IT) or Information Security (IS) compliance and controls programs in a global organization with in-depth knowledge and experience of cybersecurity frameworks such as ISO 27001, PCI-DSS, SOC 2, and other regulatory requirements Experience supporting complex audit projects in a cloud-centric environment with a strong aptitude to understand emerging technologies to assure regulatory and compliance requirements are met Experience engineering governance, risk and compliance solutions to help automate testing and compliance workflows CISM, CISA, CISSP, CCSP, SecurityX, CySA+, Security+, CRISC, CGEIT, GSEC, QSA, or other relevant certifications TikTok Accommodation TikTok is committed to providing reasonable accommodations in our recruitment processes for candidates with disabilities, pregnancy, sincerely held religious beliefs or other reasons protected by applicable laws. If you need assistance or a reasonable accommodation, please reach out to us at Job Information 【For Pay Transparency】 Compensation Description (Annually) - Washington, DC The base salary range for this position in the selected city is $ 120960 - $ 212040 annually. Compensation may vary outside of this range depending on a number of factors, including a candidate’s qualifications, skills, competencies and experience, and location. Base pay is one part of the Total Package that is provided to compensate and recognize employees for their work, and this role may be eligible for additional discretionary bonuses/incentives, and restricted stock units. Benefits may vary depending on the nature of employment and the country work location. Employees have day one access to medical, dental, and vision insurance, a 401(k) savings plan with company match, paid parental leave, short-term and long-term disability coverage, life insurance, wellbeing benefits, among others. Employees also receive 10 paid holidays per year, 10 paid sick days per year and 17 days of Paid Personal Time (prorated upon hire with increasing accruals by tenure). The Company reserves the right to modify or change these benefits programs at any time, with or without notice. #J-18808-Ljbffr
$189k - $225k
...documentation, and operational execution of the company's security governance, risk, and compliance obligations. This role sits at the intersection of... ...to work effectively with legal, sourcing, program management, engineering, and security operations stakeholders. Key...SuggestedOngoing contractContract workFor subcontractorWork at office3 days per week$136k - $253k
...mission-critical decisions across government and highly regulated... ...seeking a Lead Governance & Compliance Analyst to join our Operations... ...products such as Legal Research and Risk & Fraud. This role is... ...activities, including POA&M management, vulnerability reporting,...SuggestedContract workWork at officeLocal areaFlexible hours2 days per week3 days per week- ...Lead Contract Governance & Compliance Consultant Anywhere Type: Consulting Category: Regulatory... ...minimal direction, can identify risks and gaps proactively, and effectively... ...provisions related to compliance, risk management, data handling, and vendor oversight....SuggestedHourly payContract workFor contractorsLocal areaRemote work
- ...nCompany Description ProSidian is a Management And Operations Consulting Services firm... ...enterprise services/solutions for Risk Management | Compliance | Business Process | IT... ...public and private, defense and civilian government, and non-profit organizations. Our solution...SuggestedFull timeContract workTemporary workFor contractorsH1bWork at officeFlexible hours
- ...Partners GRC, Inc. as a Regulatory Compliance Specialist - Content & Product. In this dynamic... ...organizational and project management skills. Analytical mindset with the... ...Inc. helps organizations strengthen governance, manage risk, and build a lasting culture of compliance...SuggestedWork from homeFlexible hours
- ...Description ProSidian is a Management and Operations Consulting... ...enterprise services/solutions for Risk Management, Compliance, Business Process, IT... ..., defense and civilian government, and non-profit organizations... ...a Regulatory Compliance Specialist | Compliance / Risk /...Contract workFor contractorsWork at officeLocal areaRemote work
- ...Governance, Risk, & Compliance (GRC) Analyst Washington, DC Remote Full-Time About This Role As a GRC Analyst, you will help organizations navigate... ...complex landscape of cybersecurity compliance and risk management. You will work directly with clients to assess their security...Full timeRemote work
$130k - $180k
...Virtru is building a cutting‑edge security compliance program aligned with FedRAMP, SOC2, PCI,... ...frameworks. As a GRC Analyst you’ll help manage these initiatives using tools such as... ...infrastructure, endpoints, and SaaS services. Conduct risk assessments across business units and...Local areaFlexible hours- ...Description ProSidian is a Management And Operations Consulting... ...enterprise services/solutions for Risk Management | Compliance | Business Process | IT... ..., defense and civilian government, and non-profit... ...a HR Policy & Compliance Specialist | Human Capital Programmatic...Full timeContract workTemporary workFor contractorsH1bWork at officeFlexible hours
- BAE Systems in Washington DC is seeking a skilled Risk Management Specialist to conduct risk assessments and internal control testing related to foreign ownership, control, or influence (FOCI) management strategies. You will utilize ServiceNow and monitor performance reports...
$130k - $180k
...’ll help build a cutting edge security compliance program aligned with FedRAMP, SOC 2, PCI... ...-related inquiries. You will lead and manage the organization's efforts to achieve and... ...compliance program. As a Security Governance Risk & Compliance (GRC) Analyst, your responsibilities...Remote jobLocal areaFlexible hoursShift work- ...The Governance, Risk, and Compliance (GRC) Analyst supporting federal and customer programs is responsible for evaluating, documenting, and operationalizing... ..., and identifying gaps. The role also supports risk management processes, policy and governance activities, and audit...Contract work
- ...Security is offering an exciting internship opportunity for a Governance, Risk, and Compliance (GRC) Analyst. This role is perfect for students or... ...‑on experience in cybersecurity, compliance, and risk management. The internship provides the potential to convert into a...Full timeInternshipRemote work
- ...Security is offering an exciting internship opportunity for a Governance, Risk, and Compliance (GRC) Analyst. This role is perfect for students or... ...-on experience in cybersecurity, compliance, and risk management. The internship provides the potential to convert into a...Full timeInternship
- ...Inc. is looking for a GRC Analyst to enhance their security compliance program. You will lead compliance efforts for CMMC, manage complex control frameworks, and design automation solutions to streamline risk assessments. The ideal candidate has over 5 years of experience...Flexible hours
$95k - $105k
...Analyst, IT Artificial Intelligence (AI) Compliance United States (Remote) Trending Job... ...organization’s Artificial Intelligence (AI) governance and compliance program. Works closely with Information Security, Legal, Risk Management, and business stakeholders to help ensure...Full timeWork experience placementRemote workWork from home- ...Job Description Healthcare Compliance Consultant (Full-Time) - Alexandria... ..., VA (Hybrid) Strategic Management is seeking a highly motivated... ...systems and in the Federal government, including its CEO, Richard Kusserow... ...compliance and compliance risk areas. Responsibilities...Full timeInterim roleWork at office
- ...seeking a Cybersecurity Analyst in Alexandria, VA, focused on governance, risk, and compliance (GRC) activities. The ideal candidate should have a... ...cybersecurity certifications. You will lead compliance efforts, manage security controls, and provide risk analysis reporting to...
$90k - $115k
...Koitecc Solutions is seeking an IT Risk and Compliance Analyst to evaluate and monitor compliance with information security standards. This... ...have at least 3 years of experience in IT security or risk management and be knowledgeable about regulations like HIPAA and GDPR....$64k - $80k
...detail-oriented and proactive Privacy Compliance Specialist to join our team. In this role, you will... ...comply with privacy laws and regulations, manage data protection initiatives, and ensure... ...regulations. Monitor and track privacy risks, incidents, and compliance metrics;...Full timeTemporary workWork at officeRemote workMonday to FridayFlexible hours- Armada LTD is seeking a Security Specialist II - Risk Assessment Specialist to manage FCC position descriptions and conduct risk assessments. This role requires at least four years of personnel security experience and proficiency with MS Office, particularly Word and Excel...
- ...Authority, Inc. is seeking a Corporate Governance Specialist for its Washington, DC office. In this role, you will provide legal and compliance support to enhance governance and election... ...research, drafting documents, and managing governance databases. A Bachelor's degree...Work at office
- ...A growing fintech company in Washington, D.C. is seeking a Regulatory Compliance Specialist to ensure compliance with card network rules, consumer protection laws, and complaint management. This role is ideal for someone early in their compliance career, with foundational...Flexible hours
- ...Mesa Airlines Safety Management System Administrator Provide day to day administration of... ...changes. Has overall responsibility to ensure compliance to company general procedures manual,... ...with analysis of data to determine risk levels Detail oriented with gathering...Work experience placementShift work
- ...MacMore LLC. is seeking a Grant Management Specialist based at the Institute of Museum and Library Services in Washington, DC. This role involves a variety of administrative tasks, including application data validation, budget checks, and preparations for peer reviews....
$84k - $100k
...energy. We make software that manages energy resources in homes and... ...Manage 3rd party/vendor risk management assessments Assist... ...functions by managing security and compliance-related tasks such as... ...dedicated to improving Uplight's governance, risk, compliance (GRC),...Local areaFlexible hoursShift work- ...FINRA is searching for a Corporate Governance Specialist based in Washington, DC. The specialist will provide legal research and operational... ...processes. This role involves conducting legal research, managing compliance reviews, and maintaining critical databases. The ideal...3 days per week
- A property management company is seeking a Property Compliance Specialist in Washington, D.C. to ensure compliance in affordable housing. This role involves maintaining tenant files, determining eligibility for admissions, and monitoring compliance with regulations. Ideal...
- Wellspring Philanthropic Fund is seeking a Grants Management Associate in Washington, D.C. This pivotal role involves managing the grants lifecycle, ensuring compliance, and fostering relationships with grantee partners. The ideal candidate should possess a college degree...Work at office
- People, Technology & Processes, LLC is seeking an Asset Management Specialist I based in Arlington, Virginia. The role involves conducting inventories of government-owned equipment, maintaining asset records, and supporting audit processes. Candidates should possess strong...
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Compliance Management Specialist - Governance Risk and Compliance. Be the first to apply!
- governance risk & compliance analyst Washington DC
- regulatory officer Washington DC
- regulatory affairs specialist Washington DC
- information security compliance analyst Washington DC
- regulatory compliance specialist Washington DC
- compliance coordinator Washington DC
- compliance consultant Washington DC
- junior compliance officer Washington DC
- senior compliance analyst Washington DC
- regulatory affairs consultant Washington DC


