Manager, Security Posture Validation

TikTok USDS Joint Venture

Washington (District of Columbia)

On-site

USD 180,000 - 240,000

Full time

4 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

TikTok USDS Joint Venture seeks a Manager of Security Posture Validation to lead a specialized team and deliver an in-house continuous control-validation platform. You will drive adversary emulation, pipeline automation, and leadership-facing posture metrics across cloud, web, and mobile environments.

This builder-leader role requires deep security expertise, cross-team collaboration with executives, and a track record of turning complex vulnerabilities into actionable risk insights for ongoing

Qualifications

  • 8+ years in offensive security or privacy disciplines.
  • 3+ years in people leadership or management.
  • Experience across AWS/Azure/OCI, iOS/Android, and web security.
  • Knowledge of standards ISO 27001, NIST 800-53, PCI-DSS.

Responsibilities

  • Lead a team of offensive security and privacy engineers.
  • Own the in-house validation platform and dashboard.
  • Run adversary-emulation and purple-team exercises.
  • Interface with executives, Legal, Risk, and Eng.
  • Define SOPs and ROE for modern tech stacks.
  • Build CI/CD validated control pipelines and onboarding.
  • Collaborate with Blue Teams to remediate findings.
  • Turn results into leadership-facing posture metrics.

Skills

Offensive security
Privacy engineering
Cloud security
Red Teaming
MITRE ATT&CK
Automation tooling
Leadership
Scripting (Python)

Education

Bachelor's degree in CS/InfoSec

Tools

Burp Suite Pro
Cobalt Strike
Frida
Nessus
MobSF
SQLMap

Job description

Responsibilities

About the Team

The Validation and Verification (VnV) organization ensures the security and reliability of our products by validating that security controls are implemented correctly, operating effectively, and delivering measurable risk reduction across the enterprise.

VnV operates across a continuous security lifecycle: Prevent → Assure → Test → Fix → Prove, ensuring that security posture is not only designed and tested, but continuously validated in real-world conditions.

About the Role

We are seeking a Manager of Security Posture Validation to build the technology and processes that prove — continuously and at scale — that USDS security controls actually work. This is a builder-leader role: you will own the strategy and delivery of an in-house continuous control-validation capability, turning adversary tradecraft into automated, repeatable tests and translating the results into an authoritative, leadership-facing view of our security posture.

You will lead a specialized team spanning red team, purple team, and control-validation engineering, and drive the success of an internal platform (with an executive‑facing dashboard layer) that serves as the single source of truth for control health across cloud infrastructure, web resources, and mobile applications. The mission: replace point-in-time, tool-by-tool testing with a continuously running validation engine that measures control coverage and efficacy over time, quantifies SLAs and remediation velocity, and tells us — with evidence — how good we are and how good we want to be. You will bridge deep technical exploitation (red teaming) and systematic control validation, ensuring USDS maintains a world‑class, measurable defense‑in‑depth posture.

  • Team Leadership & Development: Lead, mentor, and grow a specialized team of offensive security and privacy engineers. Foster a culture of continuous research, innovation, and ethical hacking.
  • Build the Validation Platform: Own the vision, roadmap, and delivery of an in-house continuous control-validation capability (an attack-and-breach-simulation engine plus an authoritative posture dashboard). Replace commercial point‑solutions with proprietary tooling that exercises controls with real adversary techniques and produces status, coverage, and efficacy signal over time.
  • Operationalize Red & Purple Team: Run adversary‑emulation and purple‑team exercises as a primary input to the platform — converting validated attack paths and TTPs into automated, repeatable validation content, and partnering with detection and IR teams to prove and close coverage gaps across OCI, AWS, and Azure.
  • Stakeholder Management: Act as the primary interface for Executive leadership, Legal, Risk & Compliance, and Engineering. Translate complex technical vulnerabilities into actionable business risks.
  • Methodology & Governance: Define and maintain Standard Operating Procedures (SOPs) and Rules of Engagement (ROE) for testing modern tech stacks (Kubernetes, Serverless, Mobile).
  • Build Automation & Continuous Controls Monitoring: Design automated, CI/CD-integrated and on-demand validation pipelines so control testing is continuous and self-service. Onboard controls (e.g., HIDS, WAF, and beyond) into continuous attack-and-breach simulation, produce documented coverage and efficacy mappings, and expand validation across assurance domains including content assurance, data lineage, and privacy controls. Remain hands‑on, guiding complex exploitation, reverse engineering, and custom tooling.
  • Remediation Advocacy: Collaborate with Blue Teams and Control Owners to track findings through to completion, providing pragmatic, risk‑appropriate recommendations to correct flaws and misconfigurations.
  • Posture Dashboards & Metrics: Turn validation results into an authoritative, leadership-accessible view of security posture — SLA/SLI compliance, trends, remediation velocity, and per‑control coverage and efficacy — so leadership always knows how good we are and how good we want to be, and discrepancies are detected and remediated quickly.
Qualifications
Minimum Qualifications
  • Experience: 8+ years in offensive security or privacy disciplines (Red Teaming, Pentesting, Vulnerability Research), with at least 3+ years in a formal people management or lead role.
  • Technical Breadth: Proven expertise across Cloud (AWS/Azure/OCI), Mobile (iOS/Android), and Web Application security ecosystems.
  • Control Validation & Platform Building: Strong working knowledge of security standards (ISO 27001, NIST 800-53, PCI-DSS) and a proven track record of building tooling, automation, or platforms that others adopt — not just running assessments. Familiarity with adversary emulation / breach-and-attack-simulation and MITRE ATT&CK coverage mapping.
  • Privacy Knowledge: Understanding of privacy‑enhancing technologies (PETs) and the ability to apply offensive mindsets to identify data leakage or privacy‑control bypasses.
  • Coding/Scripting: Proficiency in at least two languages (e.g., Python, Golang, C++, Bash, or Java) for exploit development and tool automation.
  • OS Mastery: Advanced knowledge of Windows, *nix, and MacOS environments, including troubleshooting and administration.
  • Bachelor’s degree in Computer Science, Information Security, Computer Engineering, or a related technical field.
Preferred Qualifications
  • Advanced Certifications: A combination of security and privacy certifications (e.g., OSCP/OSEP/GXPN and CIPP/CIPT/CIPM).
  • Tooling Expertise: Mastery of industry‑standard tools such as Burp Suite Pro, Cobalt Strike, Frida, Objection, MobSF, SQLMap, and Nessus.
  • Community Impact: Contributions to the security/privacy community (CVEs, bug bounty recognition, whitepapers, or speaking at conferences like DEF CON or Black Hat).
  • Reg
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Security Validation Engineer (Red Team)
Security Validation Engineer (Red Team)

Athena • Palo Alto (CA)

On-site
USD 140,000 - 190,000
Senior System Security Specialist
Senior System Security Specialist

Compunnel, Inc. • Baltimore (MD)

On-site
USD 120,000 - 150,000
Cloud Security Engineering Manager
Cloud Security Engineering Manager

CIBR Warriors • United States

On-site
USD 140,000 - 210,000
Security Controls Engineer
Security Controls Engineer

AVG • Tempe (AZ)

On-site
USD 110,000 - 160,000
Principal Application & AI Security Engineer
Principal Application & AI Security Engineer

DNV • Houston (TX)

Hybrid
USD 180,000 - 230,000
Generous paid time off
Medical and Dental benefits
401(k) with company match
+1
Sr. Security Engineer
Sr. Security Engineer

California Water Service • San Jose (CA)

On-site
USD 180,000 - 240,000
Sr. CyberSecurity Engineer
Sr. CyberSecurity Engineer

Think Consulting • Columbus (OH)

On-site
USD 140,000 - 190,000
Remote Senior Cybersecurity Engineer - Build & Own Controls
Remote Senior Cybersecurity Engineer - Build & Own Controls

Think Consulting • Columbus (OH)

On-site
USD 140,000 - 190,000
Principal Application & AI Security Engineer
Principal Application & AI Security Engineer

DNV • Oakland (CA)

Hybrid
USD 175,000 - 225,000
Generous paid time off
Medical and Dental benefits
401(k) with company match
+2
Principal Offensive Security Engineer
Principal Offensive Security Engineer

Postman • San Francisco (CA)

On-site
USD 150,000 - 200,000