San Jose
Regular
R&D - Security
Job ID: A93928
Responsibilities
The Security and Information Technology team is missioned to run and operate security infrastructures, platforms and technologies, as well as to support cross-functional teams to protect our users, products and infrastructures. In this team you'll have a unique opportunity to have first-hand exposure to the strategy of the company in key security initiatives, especially in deploying and maintaining scalable and secure-by-design systems and solutions. Our challenges are not your regular day-to-day technical problems; you'll be part of a team that's developing new solutions to new challenges of a kind not previously addressed by big tech. It's working fast, at scale, and we're making a difference. About the Role The Security Solution Architect is a deeply hands-on individual contributor who personally designs end-to-end technical security architectures for assigned products. You read source code and infrastructure-as-code, trace data flows across microservices, reason about networking and trust boundaries at the protocol level, and author detailed, implementable designs yourself— from threat models through reference architectures, data-flow diagrams, and control specifications. You lead through technical depth, defending every decision at the level of cryptographic primitives, identity and key management, network segmentation, and service-to-service trust. Subject-matter experts retain final authority in their domains; your value is the engineering-grade design work that makes their decisions concrete and buildable, rather than handing off a framework and orchestrating meetings. Responsibilities - Author Compliance-by-Design Architectures: Translate abstract national-security, privacy, and policy requirements (e.g., NIST SP 800-53, data residency, access segregation) into concrete, buildable designs you write yourself: trust-boundary and data-flow diagrams, identity and key-management schemes, network segmentation, and service-to-service authentication (mTLS, request signing, token exchange). You specify protocols, message formats, crypto primitives, and failure modes in enough detail that engineering can build directly from your design. - Reverse-Engineer Real Systems: Build an accurate model of how each product actually works by reading code, IaC, service manifests, and API contracts—mapping microservice topology, data flows, authn/authz paths, network paths, and trust boundaries—and pinpoint exactly where controls must sit (telemetry, access segregation, data residency, encryption in transit and at rest). - Threat Model and Prove Out Designs: Produce rigorous threat models (e.g., STRIDE/attack-tree) tied to the real architecture, enumerating failure modes, attacker capabilities, and the control mitigating each. Where feasible, validate hands-on through prototyping, proofs of concept, or testing actual behavior—so designs are demonstrably correct, not theoretical. - Lead Deep Technical Design Reviews: Run reviews where you engage at the implementation level—challenging API contracts, key lifecycles, segmentation, and data handling, not just checking boxes. Produce and maintain reference architectures, design specs, and Architecture Decision Records (ADRs) capturing concrete trade-offs (e.g., mTLS vs. per-message signing, KMS/HSM model, isolation boundary). You are accountable for the technical correctness and completeness of the design. - Be the Front Door and Calibrate "Good Enough": Serve as the primary intake point for product teams seeking security architecture support, and partner with downstream security and privacy teams (TDR, Data Security, Infrastructure Security, Vulnerability Management, GRC, Privacy) to right-size controls to the actual threat—negotiating pragmatic, defensible trade-offs rather than gold-plating or under-protecting. - Documentation and Audit Readiness: Maintain high-quality architecture documentation, control mappings, and evidence artifacts that are traceable to specific requirements and defensible to regulators in internal and external audits. Measures of Success (First 6–12 Months) - Documented architecture baselines and security architecture maps for priority products, with clear owners and traceability to national-security and privacy requirements. - Approved solution designs with clear traceability from requirements through architecture decisions, design specs, and deployed controls. - Reduced compliance-related rework and faster alignment on key security decisions, with fewer iterations between security, product, and engineering.
Qualifications
Minimum Qualifications - Bachelor's degree in Computer Science, Information Security, or a related field, or equivalent practical experience, with experience working in the technology industry. - 8+ years in a hands-on security architecture or security engineering role, with a portfolio of detailed technical designs you personally authored (reference architectures, threat models, design specs, data-flow/sequence diagrams) that shipped to production. Prior software/infrastructure engineering experience is strongly expected. You have written code and/or operated real systems, not only governed them. - Deep, demonstrable expertise in at least two of: cloud security (IaaS/PaaS, IAM, VPC design), application/API security, data security and cryptography (PKI, key management, TLS/mTLS, signing, encryption at rest/in transit), or network security (segmentation, zero-trust, service mesh)—designed to the protocol and primitive level. - Demonstrable experience translating regulatory or compliance requirements (e.g., SOC 2, ISO 27001, PCI DSS) into technical security controls. - Strong understanding of modern development practices (e.g., CI/CD, DevOps) and how to integrate security into them. - Demonstrated ability to partner and negotiate with cross-functional business, product, and compliance stakeholders, balancing business needs and regulatory obligations without exposing the business to undue risk. - Able to independently read source code, IaC (e.g., Terraform), Kubernetes/container manifests, and API specs to understand microservice architecture, data flows, authn/authz, and trust boundaries—without relying on engineering to walk you through it. - Fluency in modern architecture and protocols: distributed/microservice systems, networking (TCP/TLS, DNS, HTTP, load balancing, VPC/segmentation), identity (OAuth2/OIDC, SAML, mTLS, workload identity), and applied cryptography (signing, PKI, key lifecycle, HSM/KMS). Preferred Qualifications - Direct experience designing security solutions to meet U.S. national security-related compliance obligations, such as those governed by NIST SP 800-53, NIST SP 800-171, FedRAMP, CISA directives, or similar frameworks. - In-depth knowledge of security controls related to data residency and localization, supply chain risk management (SCRM), and mandatory incident reporting. - Proven ability to design and implement comprehensive logging and monitoring solutions that enable effective security operations and incident response. - Experience conducting threat modeling, security design reviews, and risk assessments for complex software and infrastructure. - Familiarity with enterprise architecture frameworks and their application to security. - Designing software/artifact supply-chain integrity controls: code/artifact signing (e.g., GPG/Sigstore), SHA-256 manifests, keyservers, and verification gates in build and distribution pipelines. - Exposure to hardware- or platform-rooted security (hardware root of trust, secure boot, TEEs/attestation, HSM-backed keys) is a plus, but not required—this role centers on application, cloud, data, and network architecture. - Designing service-to-service trust and tenant/region isolation: mTLS vs. per-message signing trade-offs, certificate and key lifecycle, and network-level isolation boundaries.
Job Information
【For Pay Transparency】Compensation Description (Annually)
The base salary range for this position in the selected city is $199800 - $441600 annually.
Compensation may vary outside of this range depending on a number of factors, including a candidate’s qualifications, skills, competencies and experience, and location. Base pay is one part of the Total Package that is provided to compensate and recognize employees for their work, and this role may be eligible for additional discretionary bonuses/incentives, and restricted stock units.
Benefits may vary depending on the nature of employment and the country work location. Employees have day one access to medical, dental, and vision insurance, a 401(k) savings plan with company match, paid parental leave, short-term and long-term disability coverage, life insurance, wellbeing benefits, among others. Employees also receive 10 paid holidays per year, 10 paid sick days per year and 17 days of Paid Personal Time (prorated upon hire with increasing accruals by tenure).
The Company reserves the right to modify or change these benefits programs at any time, with or without notice.
For Los Angeles County (unincorporated) Candidates:
Qualified applicants with arrest or conviction records will be considered for employment in accordance with all federal, state, and local laws including the Los Angeles County Fair Chance Ordinance for Employers and the California Fair Chance Act. Our company believes that criminal history may have a direct, adverse and negative relationship on the following job duties, potentially resulting in the withdrawal of the conditional offer of employment:
1. Interacting and occasionally having unsupervised contact with internal/external clients and/or colleagues;
2. Appropriately handling and managing confidential information including proprietary and trade secret information and access to information technology systems; and
3. Exercising sound judgment.
About USDS
TikTok USDS Joint Venture LLC is dedicated to the safety and security of millions of Americans who create, discover, and connect with what they love on the apps we operate. The Joint Venture has been established in compliance with the Executive Order signed by President Trump on September 25, 2025. Our foundation is a comprehensive data privacy and cybersecurity program we operate under defined safeguards to protect national security and secure U.S. user data, apps and the algorithm. We safeguard the U.S. content ecosystem, holding decision-making authority for trust and safety policies and moderation. USDS Joint Venture helps ensure Americans can continue to express their creativity, discover new hobbies and interests, and build thriving communities and businesses on a global scale.
On-site presence across teams allows the company to operate with greater speed, alignment, and agility — especially in areas like real-time decision-making, team development, and integrated execution. As such, the company is shifting from a hybrid work model to a fully in-person schedule up to 5 days a week.
Why Join Us
Inspiring creativity is at the core of TikTok's mission. Our innovative product is built to help people authentically express themselves, discover and connect – and our global, diverse teams make that possible. Together, we create value for our communities, inspire creativity and bring joy - a mission we work towards every day.
We strive to do great things with great people. We lead with curiosity, humility, and a desire to make impact in a rapidly growing tech company. Every challenge is an opportunity to learn and innovate as one team. We're resilient and embrace challenges as they come. By constantly iterating and fostering an "Always Day 1" mindset, we achieve meaningful breakthroughs for ourselves, our company, and our users. When we create and grow together, the possibilities are limitless. Join us.
Diversity & Inclusion
TikTok is committed to creating an inclusive space where employees are valued for their skills, experiences, and unique perspectives. Our platform connects people from across the globe and so does our workplace. At TikTok, our mission is to inspire creativity and bring joy. To achieve that goal, we are committed to celebrating our diverse voices and to creating an environment that reflects the many communities we reach. We are passionate about this and hope you are too.
USDS Reasonable Accommodation
USDS is committed to providing reasonable accommodations in our recruitment processes for candidates with disabilities, pregnancy, sincerely held religious beliefs or other reasons protected by applicable laws. If you need assistance or a reasonable accommodation, please reach out to us at https://tinyurl.com/USDS-RA