Manager, Cloud & Infrastructure Vulnerability - USDS

TikTok USDS Joint Venture

Washington (District of Columbia)

On-site

USD 132,000 - 337,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

TikTok USDS Joint Venture LLC is seeking a Vulnerability Management expert to lead the identification, prioritization, and remediation of security flaws across cloud environments and office infrastructure.

This role directs a team of security practitioners, deploying agents in OCI, leveraging Wiz and Qualys, and ensuring ISO 27001 compliance while aligning with patching SLAs and executive reporting.

Qualifications

  • 5+ years in Cybersecurity with at least 3+ years leading VM or Security Operations.
  • Hands-on experience securing Oracle Cloud Infrastructure (OCI); OCI IAM and Compute security.
  • Proficiency with Wiz and Qualys VMDR for cloud and endpoints.
  • Strong knowledge of NIST 800-53, ISO 27001, CIS Benchmarks for vulnerability management.
  • Ability to write scripts (Python, Bash, PowerShell) to automate security tasks.

Responsibilities

  • Lead the Vulnerability Management program for cloud and office infrastructure.
  • Coordinate agent deployment, scanning, and asset discovery across OCI and on‑prem networks.
  • Prioritize remediation using risk signals and threat intel.
  • Collaborate with SRE, IT, and Eng to enforce patch SLAs and remediation workflows.
  • Oversee office network security including firewalls and IoT devices.
  • Define and report key risk metrics to executives and auditors.
  • Administer VM tools and integrate findings with Jira and GRC platforms.
  • Drive continuous improvement of the vulnerability lifecycle.

Skills

Cybersecurity
Vulnerability Management
Security Operations
Cloud Security
Scripting (Python/Bash/PowerShell)
OCI Security
Threat Intelligence

Tools

Wiz
Qualys
Terraform
Ansible

Job description

Responsibilities

About the Team


The Validation and Verification (VnV) organization ensures the security and reliability of our products by validating that security controls are implemented correctly, operating effectively, and delivering measurable risk reduction across the enterprise.


VnV operates across a continuous security lifecycle: Prevent → Assure → Test → Fix → Prove, ensuring that security posture is not only designed and tested, but continuously validated in real-world conditions.


About the Role

We are looking for a Vulnerability Management expert to lead the identification, prioritization, and remediation of security flaws across our specialized cloud environments and corporate office infrastructure. This role is at the heart of our defense strategy: you aren't just running scans; you are architecting a risk-based program that secures the very foundation of USDS.


You will lead a team of security practitioners to manage the full vulnerability lifecycle, from agent deployment in OCI to securing the physical and digital footprint of our office environments. By leveraging industry-leading tools like Wiz for cloud-native visibility and Qualys for deep asset assessment, you will ensure that our attack surface is minimized and our compliance with ISO 27001 and other standards is absolute.



  • Program Leadership: Build and scale the Vulnerability Management (VM) function for USDS, covering both Cloud and Office/Corporate Infrastructure.

  • Cloud‑Native Security: Utilize tools like Wiz to perform agentless scanning, analyze the \"Security Graph\" for toxic combinations, and identify misconfigurations within our Oracle Cloud (and other cloud) tenancies.

  • Infrastructure Scanning: Manage the deployment and tuning of Qualys (Vulnerability Management, Detection and Response - VMDR) for corporate endpoints, servers, and office network appliances.

  • Risk‑Based Prioritization: Move beyond \"critical/high\" labels by correlating vulnerability data with threat intelligence and business context to drive the most impactful remediation efforts first.

  • Cross‑Functional Orchestration: Partner with SRE, IT, and Engineering teams to establish patching SLAs, automate remediation workflows, and provide technical guidance on complex \"won't‑fix\" or exception scenarios.

  • Office Infrastructure Security: Oversee the security posture of office networks, including firewalls, Wi‑Fi controllers, and IoT devices, ensuring corporate environments meet USDS‑specific hardening standards.

  • Reporting & Governance: Define and report on key risk metrics (MTTR, scan coverage, patch compliance) for executive leadership and external auditors.

  • Tooling Optimization: Act as the primary administrator for the Vulnerability Management toolset, ensuring 100% asset visibility and integrating findings into Jira and GRC platforms.


Qualifications

Minimum Qualifications


  • Experience: 5+ years in Cybersecurity, with at least 3+ years leading a Vulnerability Management or Security Operations team.

  • Cloud Expertise: Hands‑on experience securing Oracle Cloud Infrastructure (OCI); familiarity with OCI VCNs, IAM, and Compute security. (Experience with AWS/Azure/GCP is also acceptable).

  • Tooling Mastery: Advanced proficiency with Wiz (Cloud Security Posture Management) and Qualys (VMDR/Policy Compliance).

  • Framework Knowledge: Strong understanding of NIST 800‑53, ISO 27001, and CIS Benchmarks as they apply to vulnerability and configuration management.

  • Technical Skills: Ability to write scripts (Python, Bash, or PowerShell) to automate data export/normalization or interact with security tool APIs.


Preferred Qualifications


  • Certifications: OCI Architect/Security Associate, Qualys Certified Specialist, or Wiz specialized training. Industry standards like CISSP, CCSP, or CISM.

  • Infrastructure as Code (IaC): Experience reviewing Terraform or Ansible for security misconfigurations before deployment.

  • Automation: Experience integrating vulnerability data into ITSM tools (ServiceNow, Jira) for automated ticket routing and tracking.

  • Communication: Proven ability to explain the \"so what?\" of a vulnerability to non-technical stakeholders and business owners.


About USDS

TikTok USDS Joint Venture LLC is dedicated to the safety and security of millions of Americans who create, discover, and connect with what they love on the apps we operate. The Joint Venture has been established in compliance with the Executive Order signed by President Trump on September 25, 2025. Our foundation is a comprehensive data privacy and cybersecurity program we operate under defined safeguards to protect national security and secure U.S. user data, apps and the algorithm. We safeguard the U.S. content ecosystem, holding decision‑making authority for trust and safety policies and moderation. USDS Joint Venture helps ensure Americans can continue to express their creativity, discover new hobbies and interests, and build thriving communities and businesses on a global scale.


On‑site presence across teams allows the company to operate with greater speed, alignment, and agility — especially in areas like real‑time decision‑making, team development, and integrated execution. As such, the company is shifting from a hybrid work model to a fully in‑person schedule up to 5 days a week.


Why Join Us

Inspiring creativity is at the core of TikTok's mission. Our innovative product is built to help people authentically express themselves, discover and connect – and our global, diverse teams make that possible. Together, we create value for our communities, inspire creativity and bring joy - a mission we work towards every day.


We strive to do great things with great people. We lead with curiosity, humility, and a desire to make impact in a rapidly growing tech company. Every challenge is an opportunity to learn and innovate as one team. We're resilient and embrace challenges as they come. By constantly iterating and fostering an \"Always Day 1\" mindset, we achieve meaningful breakthroughs for ourselves, our company, and our users. When we create and grow together, the possibilities are limitless. Join us.


Diversity & Inclusion

TikTok is committed to creating an inclusive space where employees are valued for their skills, experiences, and unique perspectives. Our platform connects people from across the globe and so does our workplace. At TikTok, our mission is to inspire creativity and bring joy. To achieve that goal, we are committed to celebrating our diverse voices and to creating an environment that reflects the many communities we reach. We are passionate about this and hope you are too.


USDS Reasonable Accommodation

USDS is committed to providing reasonable accommodations in our recruitment processes for candidates with disabilities, pregnancy, sincerely held religious beliefs or other reasons protected by applicable laws. If you need assistance or a reasonable accommodation, please reach out to us at https://tinyurl.com/USDS-RA


Job Information

【For Pay Transparency】 Compensation Description (Annually) - Washington, DC


The base salary range for this position in the selected city is $132480 - $336960 annually.


Compensation may vary outside of this range depending on a number of factors, including a candidate’s qualifications, skills, competencies and experience, and location. Base pay is one part of the Total Package that is provided to compensate and recognize employees for their work, and this role may be eligible for additional discretionary bonuses/incentives, and restricted stock units.


Benefits may vary depending on the nature of employment and the country work location. Employees have day one access to medical, dental, and vision insurance, a 401(k) savings plan with company match, paid parental leave, short‑term and long‑term disability coverage, life insurance, wellbeing benefits, among others. Employees also receive 10 paid holidays per year, 10 paid sick days per year and 17 days of Paid Personal Time (prorated upon hire with increasing accruals by tenure).


The Company reserves the right to modify or change these benefits programs at any time, with or without notice.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Manager, Security Posture Validation
Manager, Security Posture Validation

TikTok USDS Joint Venture • Washington

On-site
USD 168,000 - 394,000
Senior Digital Workplace Technician - USDS
Senior Digital Workplace Technician - USDS

TikTok USDS Joint Venture • Washington

On-site
USD 99,000 - 163,000
Manager, Security & Privacy Testing - USDS
Manager, Security & Privacy Testing - USDS

TikTok USDS Joint Venture • Washington

On-site
USD 168,000 - 395,000
Medical, dental, and vision insurance
401(k) savings plan with company match
Paid parental leave
+1
Senior Incident Response Analyst
Senior Incident Response Analyst

TikTok USDS Joint Venture • Washington

On-site
USD 132,000 - 337,000
Head of Cyber Crisis & Critical Incident Management - USDS
Head of Cyber Crisis & Critical Incident Management - USDS

TikTok USDS Joint Venture • Washington

On-site
USD 206,000 - 397,000
Medical insurance
401(k) match
Paid parental leave
+3
Senior Security Automation Specialist - USDS
Senior Security Automation Specialist - USDS

TikTok USDS Joint Venture • Washington

On-site
USD 132,000 - 243,000
Medical, dental, and vision insurance
401(k) with company match
Paid parental leave
+6
Senior Technical Program Manager, Operational Excellence - USDS
Senior Technical Program Manager, Operational Excellence - USDS

TikTok USDS Joint Venture • Washington

On-site
USD 119,000 - 282,000
Health insurance
401(k) with company match
Paid parental leave
+4
Data Scientist, CapCut - USDS
Data Scientist, CapCut - USDS

TikTok USDS Joint Venture • San Jose (CA)

On-site
USD 144,000 - 329,000
Head of Insider Risk - USDS
Head of Insider Risk - USDS

TikTok USDS Joint Venture • Washington

On-site
USD 205,000 - 398,000
Software Engineer, Corporate Information Systems - USDS
Software Engineer, Corporate Information Systems - USDS

TikTok USDS Joint Venture • San Jose (CA)

On-site
USD 137,000 - 360,000
Medical insurance
Dental insurance
Vision insurance
+8