Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Compliance Management Specialist - Governance Risk and Compliance

$120.96k - $212.04k

TikTok

Responsibilities The mission of TikTok's Global Security Organization is to build and earn trust by reducing risk and securing our businesses and products. Also known as "GSO", this team is the foundation of our efforts to keep TikTok safe, secure, and operating at scale for over 1 billion people around the world. We work to ensure that the TikTok platform is safe and secure, that our users' experience and their data remains safe from external or internal threats, and that we comply with global regulations wherever TikTok operates. Trust is one of TikTok's biggest initiatives, and security is integral to our success. In whatever ways users interact with us — whether they're watching videos on their For You page, interacting with a Live video, or buying products on TikTok Shop — GSO protects their data and privacy, so they can have a secure and trustworthy experience. The Security Strategy, Risk, and Resilience (SRR) team is responsible for TikTok's Governance, Risk and Compliance function working closely with cross-functional partners to manage security risks, mature security operations, and build organizational resilience. We support our partners in meeting industry cybersecurity compliance standards and government regulations by developing and driving the organization’s cybersecurity strategy, establishing and maintaining a comprehensive business continuity management program, creating and maintaining governing security policies, implementing our security control framework, conducting regular security risk and control assessments, and staying up-to-date on global compliance initiatives and evolving regulatory requirements. The Security Strategy, Risk and Resilience (SRR) Controls Management Specialist is an experienced individual contributor responsible for driving the lifecycle of TikTok's cybersecurity risks and controls. This includes assessing cybersecurity risk, control testing and monitoring, identification and treatment of risks and/or control gaps, and facilitating internal and external audits. In addition, this individual will drive compliance engineering projects to improve our compliance program maturity. You would be a great fit for this role if you: Have a strong security risk, controls, and compliance mindset with experience in evaluating and testing controls against leading security frameworks such as ISO 27001, SOC 2, PCI DSS, and others. Enjoy fostering collaboration with multi-disciplinary, cross-functional partnerships to solve challenging and unique cybersecurity risks with product, engineering and other business teams. Thrive in dynamic, global environments and enjoy engineering an automated solution to a problem. Possess a strong appetite for acquiring new knowledge and skills in cybersecurity and staying up-to-date on emerging trends. Excel at analyzing complex systems and ideas and making these easy to understand. Can provide candid and clear feedback on critical cybersecurity initiatives from policies to application designs and much more! Responsibilities As a SRR Compliance Management Specialist, you will be responsible for: Supporting the scoping and maturity of the cybersecurity compliance program to align with industry best practices and regulatory requirements including but not limited to ISO 27001, PCI DSS, and SOC 2. Identifying and assessing cybersecurity risks, working with risk owners to develop risk treatment plans, monitoring and reporting on cybersecurity risks, and maintaining a cybersecurity risk register. Leading control design walkthroughs and tests of operating effectiveness for product and business line controls against security requirements and compliance obligations. Preparing and supporting control owners and process owners for internal and external audits by conducting thorough examinations of people, processes, technologies and key system configurations and helping identify best-in-class evidence. Influencing and collaborating with key stakeholders to support, track, and report on remediation efforts for identified security control gaps. Maintaining a global security controls library to include periodic updates and validation of security controls and owners. Communicating with technical and non-technical stakeholders on cybersecurity risk and control topics and program-specific reporting. Qualifications Minimum Qualifications: Experience supporting cybersecurity risk controls management programs with in-depth knowledge and experience of cybersecurity frameworks including ISO 27001, PCI-DSS, SOC 2, and other regulatory requirements. Experience collaborating closely with engineers, business teams, and security partners, including incident response, red teams, and architects to seamlessly incorporate cybersecurity controls and risk management processes into their day-to-day operations. Experience with the entire risk and controls monitoring lifecycle, including identifying, assessing, monitoring, and treating risk and control gaps. Excellent communication skills with the ability to document, communicate, and report security assessments as well as the status of the implementation, effectiveness, and remediation of cybersecurity controls with product and business leaders. Strong project management skills with the ability to lead and execute security assessment projects and initiatives on time with multiple stakeholders. Ability to work in D.C. office for 5 days per week and be willing to travel to other offices with the flexibility to conduct virtual meetings, including international locations, as required to support business needs. Preferred Qualifications: Minimum of 5 years in Information Technology (IT) or Information Security (IS) compliance and controls programs in a global organization with in-depth knowledge and experience of cybersecurity frameworks such as ISO 27001, PCI-DSS, SOC 2, and other regulatory requirements. Experience supporting complex audit projects in a cloud-centric environment with a strong aptitude to understand emerging technologies to assure regulatory and compliance requirements are met. Experience engineering governance, risk and compliance solutions to help automate testing and compliance workflows. CISM, CISA, CISSP, CCSP, SecurityX, CySA+, Security+, CRISC, CGEIT, GSEC, QSA, or other relevant certifications. Job Information [For Pay Transparency] Compensation Description (Annually) - Washington, DC The base salary range for this position in the selected city is $ 120960 - $ 212040 annually. Compensation may vary outside of this range depending on a number of factors, including a candidate’s qualifications, skills, competencies and experience, and location. Base pay is one part of the Total Package that is provided to compensate and recognize employees for their work, and this role may be eligible for additional discretionary bonuses/incentives, and restricted stock units. Benefits may vary depending on the nature of employment and the country work location. Employees have day one access to medical, dental, and vision insurance, a 401(k) savings plan with company match, paid parental leave, short-term and long-term disability coverage, life insurance, wellbeing benefits, among others. Employees also receive 10 paid holidays per year, 10 paid sick days per year and 17 days of Paid Personal Time (prorated upon hire with increasing accruals by tenure). The Company reserves the right to modify or change these benefits programs at any time, with or without notice. #J-18808-Ljbffr TikTok

Vacancy posted 3 days ago
Similar jobs that could be interesting for youBased on the Compliance Management Specialist - Governance Risk and Compliance in Washington DC vacancy
  •  ...nCompany Description ProSidian is a Management And Operations Consulting Services firm...  ...enterprise services/solutions for Risk Management | Compliance | Business Process | IT...  ...public and private, defense and civilian government, and non-profit organizations. Our solution... 
    Suggested
    Full time
    Contract work
    Temporary work
    For contractors
    H1b
    Work at office
    Flexible hours

    ProSidian Consulting, LLC

    Alexandria, VA
    3 days ago
  • $189k - $225k

     ...documentation, and operational execution of the company's security governance, risk, and compliance obligations. This role sits at the intersection of...  ...to work effectively with legal, sourcing, program management, engineering, and security operations stakeholders. Key... 
    Suggested
    Ongoing contract
    Contract work
    For subcontractor
    Work at office
    3 days per week

    GoTo Meeting

    Washington DC
    1 day ago
  •  ...Multifamily Governance and Compliance - Risk Analysis - Lead Associate-Underwriting Experience Required (Flexible Hybrid) 6 days ago Be among...  ...meetings, and resolving conflict. Risk Assessment and Management including conducting impact assessments, remediating risk... 
    Suggested
    Full time
    Work at office
    Remote work
    Flexible hours

    Fannie Mae

    Washington DC
    3 days ago
  •  ...Description ProSidian is a Management And Operations Consulting...  ...enterprise services/solutions for Risk Management | Compliance | Business Process | IT...  ..., defense and civilian government, and non-profit...  ...a HR Policy & Compliance Specialist | Human Capital Programmatic... 
    Suggested
    Full time
    Contract work
    Temporary work
    For contractors
    H1b
    Work at office
    Flexible hours

    ProSidian Consulting, LLC

    Alexandria, VA
    3 days ago
  •  ...Partners GRC, Inc. as a Regulatory Compliance Specialist - Content & Product. In this dynamic...  ...organizational and project management skills. Analytical mindset with the...  ...Inc. helps organizations strengthen governance, manage risk, and build a lasting culture of compliance... 
    Suggested
    Work from home
    Flexible hours

    CFM Partners GRC, Inc.

    Washington DC
    3 days ago
  • $75k - $85k

    Aleto, Inc. is seeking a Compliance Specialist for a Full-Time Remote position focusing on compliance governance and management systems. This role involves oversight of ISO/IEC 27001 and ISO 9001, conducting audits, and maintaining compliance with federal regulations.... 
    Remote job
    Full time

    Aleto, Inc.

    Washington DC
    17 hours ago
  • GoTo Meeting is seeking a GRC Analyst, Federal & Customer Programs, to manage security governance, risk, and compliance obligations. Responsibilities include analyzing contracts, mapping obligations to compliance frameworks, and producing compliance matrices. The ideal... 

    GoTo Meeting

    Washington DC
    1 day ago
  • $88k - $140k

    Affirm is seeking a Compliance Analyst II in Washington, D.C. to support its compliance governance program. The Analyst will review and challenge responses to consumer...  ...are 3 to 5+ years in compliance or risk management within financial services, strong analytical... 
    Remote job

    Affirm

    Washington DC
    3 days ago
  • Governance, Risk, & Compliance (GRC) Analyst Washington, DC Remote Full-Time About This Role As a GRC Analyst, you will help organizations navigate...  ...complex landscape of cybersecurity compliance and risk management. You will work directly with clients to assess their security... 
    Full time
    Remote work

    Districttechgroup

    Washington DC
    3 days ago
  • $130k - $180k

     ...Virtru is building a cutting‑edge security compliance program aligned with FedRAMP, SOC2, PCI,...  ...frameworks. As a GRC Analyst you’ll help manage these initiatives using tools such as...  ...infrastructure, endpoints, and SaaS services. Conduct risk assessments across business units and... 
    Local area
    Flexible hours

    Neier Inc.

    Washington DC
    1 day ago
  • $130k - $180k

     ...’ll help build a cutting edge security compliance program aligned with FedRAMP, SOC 2, PCI...  ...-related inquiries. You will lead and manage the organization's efforts to achieve and...  ...compliance program. As a Security Governance Risk & Compliance (GRC) Analyst, your responsibilities... 
    Remote job
    Local area
    Flexible hours
    Shift work

    Virtru

    Washington DC
    more than 2 months ago
  •  ...Job Description Healthcare Compliance Consultant (Full-Time) - Alexandria...  ..., VA (Hybrid) Strategic Management is seeking a highly motivated...  ...systems and in the Federal government, including its CEO, Richard Kusserow...  ...compliance and compliance risk areas. Responsibilities... 
    Full time
    Interim role
    Work at office

    Strategic Management

    Alexandria, VA
    11 days ago
  •  ...The Governance, Risk, and Compliance (GRC) Analyst supporting federal and customer programs is responsible for evaluating, documenting, and operationalizing...  ..., and identifying gaps. The role also supports risk management processes, policy and governance activities, and audit... 
    Contract work

    Nexus IT Group

    Washington DC
    3 days ago
  •  ...Security is offering an exciting internship opportunity for a Governance, Risk, and Compliance (GRC) Analyst. This role is perfect for students or...  ...-on experience in cybersecurity, compliance, and risk management. The internship provides the potential to convert into a... 
    Full time
    Internship

    Ruleset Security

    Arlington, VA
    17 hours ago
  • $111k - $159k

    Google is seeking a Compliance Analyst for their Governance, Risk, and Compliance team in Washington, D.C. This role involves managing compliance processes, applying innovative AI solutions, and ensuring adherence to financial regulations. The ideal candidate will have... 

    Google

    Washington DC
    3 days ago
  •  ...Security is offering an exciting internship opportunity for a Governance, Risk, and Compliance (GRC) Analyst. This role is perfect for students or...  ...‑on experience in cybersecurity, compliance, and risk management. The internship provides the potential to convert into a... 
    Remote job
    Full time
    Internship

    Ruleset Security

    Arlington, VA
    17 hours ago
  •  ...Inc. is looking for a GRC Analyst to enhance their security compliance program. You will lead compliance efforts for CMMC, manage complex control frameworks, and design automation solutions to streamline risk assessments. The ideal candidate has over 5 years of experience... 
    Flexible hours

    Neier Inc.

    Washington DC
    1 day ago
  •  ...Compliance Data Analyst ProSidian is a Management And Operations Consulting Services firm that focuses on providing...  ...enterprise services/solutions for Risk Management | Compliance | Business...  ...098098] candidates with relevant Government And Public Services Sector... 
    Contract work
    H1b
    Work at office

    ProSidian Consulting

    Alexandria, VA
    17 hours ago
  •  ...seeking a Cybersecurity Analyst in Alexandria, VA, focused on governance, risk, and compliance (GRC) activities. The ideal candidate should have a...  ...cybersecurity certifications. You will lead compliance efforts, manage security controls, and provide risk analysis reporting to... 

    Medium

    Alexandria, VA
    2 days ago
  •  ...Hansen, Todd, Figel & Frederick, P.L.L.C. is seeking a highly skilled and detail-oriented Governance, Risk, and Compliance (GRC) Officer to oversee and enhance our firm's risk management, compliance, and governance practices. This individual will be responsible for... 
    Shift work

    Kellogg Hansen

    Washington DC
    17 hours ago
  • $120k - $180k

     ...Job Description Job Description Compliance and Data Governance Specialist - Department of State The...  ...predictive analytics to assess sponsor risk and detect anomalies Establish secure...  ..., data governance, and records management responsibilities Collaborate with... 
    Full time
    For contractors
    Work at office
    Remote work
    Work from home
    Flexible hours
    Night shift

    Censeo Consulting Group

    Washington DC
    4 days ago
  • $84k - $100k

     ...energy. We make software that manages energy resources in homes and...  ...Manage 3rd party/vendor risk management assessments Assist...  ...functions by managing security and compliance-related tasks such as...  ...dedicated to improving Uplight's governance, risk, compliance (GRC),... 
    Local area
    Flexible hours
    Shift work

    upLIGHT

    Washington DC
    4 days ago
  • $88k - $124k

    IG Compliance & Security Analyst Cooley is seeking an IG Compliance &...  ...Analyst to join the Information Governance & Data Privacy team....  ...tasks to ensure the readiness of managers and their teams for audit testing...  ...Conduct/support periodic risk assessments and develop appropriate... 
    Full time
    Temporary work
    Work experience placement
    Flexible hours
    Weekend work

    Cooley LLP

    Washington DC
    4 days ago
  • A growing fintech company in Washington, D.C. is seeking a Regulatory Compliance Specialist to ensure compliance with card network rules, consumer protection laws, and complaint management. This role is ideal for someone early in their compliance career, with foundational... 
    Flexible hours

    Rain

    Washington DC
    4 days ago
  •  ...seeking a professional for Program and Grant Management Support Services to assist the Near...  .... This role involves supporting U.S. Government representatives in the award process, communicating...  ...with grantees, and ensuring compliance with grant regulations. The ideal... 
    Work at office

    Delaware Nation Industries

    Washington DC
    2 days ago
  • A leading management solutions company is seeking a full-time Records Management Specialist in Washington, DC. This role involves overseeing and ensuring compliance with regulations, developing procedures, conducting audits, and providing guidance on records management... 
    Full time
    Relocation

    ARMADA, Ltd.

    Washington DC
    1 day ago
  • $70.6k - $141.2k

    Oracle Health Government Services is currently looking for a talented Compliance and Risk Specialist to bolster our dedicated team. You will play a crucial role in enhancing...  ...will include developing business processes, managing internal audits of operational controls,... 
    Temporary work
    Flexible hours

    Broughton Group

    Arlington, VA
    1 day ago
  •  ...providers with expert financial, engineering, management, operational, regulatory, and strategic...  ...to solve complex challenges, mitigate risk, and help clients navigate the intricate...  ...and timely advice on state and federal compliance requirements across the full spectrum of... 
    Work at office
    Remote work
    Shift work

    Utilicom

    Greenbelt, MD
    17 hours ago
  • Eastaway Property Management, LLC is seeking an Occupancy & Compliance Specialist in Washington, DC. This role is pivotal in ensuring affordable housing property operates within legal and regulatory guidelines while managing tenant arrears through effective communication... 

    Eastaway Property Management, LLC

    Washington DC
    4 days ago
  • $64k - $80k

     ...detail-oriented and proactive Privacy Compliance Specialist to join our team. In this role, you will...  ...comply with privacy laws and regulations, manage data protection initiatives, and ensure...  ...regulations. Monitor and track privacy risks, incidents, and compliance metrics;... 
    Full time
    Temporary work
    Work at office
    Remote work
    Monday to Friday
    Flexible hours

    RVO Health

    Washington DC
    4 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Compliance Management Specialist - Governance Risk and Compliance. Be the first to apply!