Manager, Security Posture Validation

TikTok USDS Joint Venture

Washington (District of Columbia)

On-site

USD 168,000 - 394,000

Full time

3 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

TikTok USDS Joint Venture LLC is seeking a Manager of Security Posture Validation to design and deliver an in-house continuous control-validation platform, turning adversary techniques into automated tests and a leadership-facing posture dashboard.

You will lead red team, purple team, and control-validation engineers across cloud, mobile, and web, partnering with Legal, Risk & Compliance, and Engineering to translate findings into pragmatic remediation.

Qualifications

  • 8+ years in offensive security or privacy disciplines (Red Teaming, Pentesting, Vulnerability Research).
  • 3+ years in formal people management or lead role.
  • Proven cross-cloud security experience across AWS/Azure/OCI, mobile and web apps.
  • Experience building tooling or platforms adopted by others.

Responsibilities

  • Lead offensive security and privacy engineers; foster innovation.
  • Build in-house continuous validation platform and dashboard.
  • Coordinate red/purple team exercises; translate results to governance.
  • Interface with executive leadership, Legal, Risk & Compliance.
  • Define SOPs and ROE for modern tech stacks.
  • Develop automated validation pipelines integrated with CI/CD.
  • Collaborate with Blue Teams to remediate findings.
  • Provide leadership metrics via posture dashboards.

Skills

Red Teaming
Cloud Security
Threat Emulation
Tooling Automation
MITRE ATT&CK
Privacy by Design
Python/Golang
Windows/Linux/MacOS

Education

Bachelor’s degree in CS/InfoSec/Engineering

Tools

Burp Suite Pro
Cobalt Strike
Frida
Objection
MobSF
SQLMap
Nessus

Job description

Responsibilities

About the Team
The Validation and Verification (VnV) organization ensures the security and reliability of our products by validating that security controls are implemented correctly, operating effectively, and delivering measurable risk reduction across the enterprise.
VnV operates across a continuous security lifecycle: Prevent → Assure → Test → Fix → Prove, ensuring that security posture is not only designed and tested, but continuously validated in real-world conditions.

About the Role
We are seeking a Manager of Security Posture Validation to build the technology and processes that prove — continuously and at scale — that USDS security controls actually work. This is a builder-leader role: you will own the strategy and delivery of an in-house continuous control-validation capability, turning adversary tradecraft into automated, repeatable tests and translating the results into an authoritative, leadership-facing view of our security posture.
You will lead a specialized team spanning red team, purple team, and control-validation engineering, and drive the success of an internal platform (with an executive-facing dashboard layer) that serves as the single source of truth for control health across cloud infrastructure, web resources, and mobile applications. The mission: replace point-in-time, tool-by-tool testing with a continuously running validation engine that measures control coverage and efficacy over time, quantifies SLAs and remediation velocity, and tells us — with evidence — how good we are and how good we want to be. You will bridge deep technical exploitation (red teaming) and systematic control validation, ensuring USDS maintains a world-class, measurable defense-in-depth posture.

  • Team Leadership & Development: Lead, mentor, and grow a specialized team of offensive security and privacy engineers. Foster a culture of continuous research, innovation, and ethical hacking.
  • Build the Validation Platform: Own the vision, roadmap, and delivery of an in-house continuous control-validation capability (an attack-and-breach-simulation engine plus an authoritative posture dashboard). Replace commercial point-solutions with proprietary tooling that exercises controls with real adversary techniques and produces status, coverage, and efficacy signal over time.
  • Operationalize Red & Purple Team: Run adversary-emulation and purple-team exercises as a primary input to the platform — converting validated attack paths and TTPs into automated, repeatable validation content, and partnering with detection and IR teams to prove and close coverage gaps across OCI, AWS, and Azure.
  • Stakeholder Management: Act as the primary interface for Executive leadership, Legal, Risk & Compliance, and Engineering. Translate complex technical vulnerabilities into actionable business risks.
  • Methodology & Governance: Define and maintain Standard Operating Procedures (SOPs) and Rules of Engagement (ROE) for testing modern tech stacks (Kubernetes, Serverless, Mobile).
  • Build Automation & Continuous Controls Monitoring: Design automated, CI/CD-integrated and on-demand validation pipelines so control testing is continuous and self-service. Onboard controls (e.g., HIDS, WAF, and beyond) into continuous attack-and-breach simulation, produce documented coverage and efficacy mappings, and expand validation across assurance domains including content assurance, data lineage, and privacy controls. Remain hands-on, guiding complex exploitation, reverse engineering, and custom tooling.
  • Remediation Advocacy: Collaborate with Blue Teams and Control Owners to track findings through to completion, providing pragmatic, risk-appropriate recommendations to correct flaws and misconfigurations.
  • Posture Dashboards & Metrics: Turn validation results into an authoritative, leadership-accessible view of security posture — SLA/SLI compliance, trends, remediation velocity, and per-control coverage and efficacy — so leadership always knows how good we are and how good we want to be, and discrepancies are detected and remediated quickly.
Qualifications
Minimum Qualifications
  • Experience: 8+ years in offensive security or privacy disciplines (Red Teaming, Pentesting, Vulnerability Research), with at least 3+ years in a formal people management or lead role.
  • Technical Breadth: Proven expertise across Cloud (AWS/Azure/OCI), Mobile (iOS/Android), and Web Application security ecosystems.
  • Control Validation & Platform Building: Strong working knowledge of security standards (ISO 27001, NIST 800-53, PCI-DSS) and a proven track record of building tooling, automation, or platforms that others adopt — not just running assessments. Familiarity with adversary emulation / breach-and-attack-simulation and MITRE ATT&CK coverage mapping.
  • Privacy Knowledge: Understanding of privacy-enhancing technologies (PETs) and the ability to apply offensive mindsets to identify data leakage or privacy-control bypasses.
  • Coding/Scripting: Proficiency in at least two languages (e.g., Python, Golang, C++, Bash, or Java) for exploit development and tool automation.
  • OS Mastery: Advanced knowledge of Windows, *nix, and MacOS environments, including troubleshooting and administration.
  • Bachelor’s degree in Computer Science, Information Security, Computer Engineering, or a related technical field.
Preferred Qualifications
  • Advanced Certifications: A combination of security and privacy certifications (e.g., OSCP/OSEP/GXPN and CIPP/CIPT/CIPM).
  • Tooling Expertise: Mastery of industry-standard tools such as Burp Suite Pro, Cobalt Strike, Frida, Objection, MobSF, SQLMap, and Nessus.
  • Community Impact: Contributions to the security/privacy community (CVEs, bug bounty recognition, whitepapers, or speaking at conferences like DEF CON or Black Hat).
  • Regulatory Expertise: Experience navigating security testing within highly regulated or national security-focused divisions (USDS/FedRAMP).
About USDS

TikTok USDS Joint Venture LLC is dedicated to the safety and security of millions of Americans who create, discover, and connect with what they love on the apps we operate. The Joint Venture has been established in compliance with the Executive Order signed by President Trump on September 25, 2025. Our foundation is a comprehensive data privacy and cybersecurity program we operate under defined safeguards to protect national security and secure U.S. user data, apps and the algorithm. We safeguard the U.S. content ecosystem, holding decision-making authority for trust and safety policies and moderation. USDS Joint Venture helps ensure Americans can continue to express their creativity, discover new hobbies and interests, and build thriving communities and businesses on a global scale.

On-site presence across teams allows the company to operate with greater speed, alignment, and agility — especially in areas like real-time decision-making, team development, and integrated execution. As such, the company is shifting from a hybrid work model to a fully in-person schedule up to 5 days a week.

Why Join Us

Inspiring creativity is at the core of TikTok’s mission. Our innovative product is built to help people authentically express themselves, discover and connect – and our global, diverse teams make that possible. Together, we create value for our communities, inspire creativity and bring joy - a mission we work towards every day. We strive to do great things with great people. We lead with curiosity, humility, and a desire to make impact in a rapidly growing tech company. Every challenge is an opportunity to learn and innovate as one team. We’re resilient and embrace challenges as they come. By constantly iterating and fostering an "Always Day 1" mindset, we achieve meaningful breakthroughs for ourselves, our company, and our users. When we create and grow together, the possibilities are limitless. Join us.

Diversity & Inclusion

TikTok is committed to creating an inclusive space where employees are valued for their skills, experiences, and unique perspectives. Our platform connects people from across the globe and so does our workplace. At TikTok, our mission is to inspire creativity and bring joy. To achieve that goal, we are committed to celebrating our diverse voices and to creating an environment that reflects the many communities we reach. We are passionate about this and hope you are too.

USDS Reasonable Accommodation

USDS is committed to providing reasonable accommodations in our recruitment processes for candidates with disabilities, pregnancy, sincerely held religious beliefs or other reasons protected by applicable laws. If you need assistance or a reasonable accommodation, please reach out to us at https://tinyurl.com/USDS-RA

Job Information

【For Pay Transparency】 Compensation Description (Annually) - Washington, DC
The base salary range for this position in the selected city is $ 168336 - $ 394200 annually.
Compensation may vary outside of this range depending on a number of factors, including a candidate’s qualifications, skills, competencies and experience, and location. Base pay is one part of the Total Package that is provided to compensate and recognize employees for their work, and this role may be eligible for additional discretionary bonuses/incentives, and restricted stock units.
Benefits may vary depending on the nature of employment and the country work location. Employees have day one access to medical, dental, and vision insurance, a 401(k) savings plan with company match, paid parental leave, short-term and long-term disability coverage, life insurance, wellbeing benefits, among others. Employees also receive 10 paid holidays per year, 10 paid sick days per year and 17 days of Paid Personal Time (prorated upon hire with increasing accruals by tenure).
The Company reserves the right to modify or change these benefits programs at any time, with or without notice.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Manager, Security & Privacy Testing - USDS
Manager, Security & Privacy Testing - USDS

TikTok USDS Joint Venture • Washington

On-site
USD 168,000 - 395,000
Medical, dental, and vision insurance
401(k) savings plan with company match
Paid parental leave
+1
Manager, Cloud & Infrastructure Vulnerability - USDS
Manager, Cloud & Infrastructure Vulnerability - USDS

TikTok USDS Joint Venture • Washington

On-site
USD 132,000 - 337,000
Senior Security Automation Specialist - USDS
Senior Security Automation Specialist - USDS

TikTok USDS Joint Venture • Washington

On-site
USD 132,000 - 243,000
Medical, dental, and vision insurance
401(k) with company match
Paid parental leave
+6
Head of Cyber Crisis & Critical Incident Management - USDS
Head of Cyber Crisis & Critical Incident Management - USDS

TikTok USDS Joint Venture • Washington

On-site
USD 206,000 - 397,000
Medical insurance
401(k) match
Paid parental leave
+3
Senior Technical Program Manager, Operational Excellence - USDS
Senior Technical Program Manager, Operational Excellence - USDS

TikTok USDS Joint Venture • Washington

On-site
USD 119,000 - 282,000
Health insurance
401(k) with company match
Paid parental leave
+4
Senior Digital Workplace Technician - USDS
Senior Digital Workplace Technician - USDS

TikTok USDS Joint Venture • Washington

On-site
USD 99,000 - 163,000
Senior Manager, Application Vulnerability Validation & Verification - USDS
Senior Manager, Application Vulnerability Validation & Verification - USDS

TikTok USDS Joint Venture • San Jose (CA)

On-site
USD 199,000 - 442,000
Health insurance
401(k) matching
Paid parental leave
+1
Senior Incident Response Analyst
Senior Incident Response Analyst

TikTok USDS Joint Venture • Washington

On-site
USD 132,000 - 337,000
Head of Insider Risk - USDS
Head of Insider Risk - USDS

TikTok USDS Joint Venture • Washington

On-site
USD 205,000 - 398,000
Engineering Manager, Employee Experience - USDS
Engineering Manager, Employee Experience - USDS

TikTok USDS Joint Venture • San Jose (CA)

On-site
USD 209,000 - 616,000
Medical, dental, vision insurance
401(k) with company match
Paid parental leave