Third Party Risk Management Lead - USDS

TikTok USDS Joint Venture

Washington (District of Columbia)

On-site

USD 132,480 - 336,960

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Medical, dental, and vision insurance
401(k) with company match
Paid parental leave
Disability coverage
Paid time off

Job summary

TikTok USDS Joint Venture in Washington, DC, is looking for a skilled professional to lead the Third-Party Risk Management (TPRM) lifecycle. This role involves evaluating vendor risks, ensuring compliance with national security standards, and implementing automation in risk processes.

The ideal candidate has extensive experience in risk management, handles TPRM processes, and is adept at building relationships across teams. Join us to support the safeguarding of user data and compliance efforts within a dynamic tech environment.

Qualifications

  • 5+ years of experience in information security, risk management, privacy, or compliance.
  • Hands-on experience evaluating technical and procedural controls at third parties.
  • Proven ability to build cross-functional relationships with technology and engineering teams.

Responsibilities

  • Lead the Third-Party Risk Management lifecycle including due diligence and ongoing monitoring.
  • Implement and refine automation and AI-enabled workflows.
  • Prepare and present metrics and dashboards on third-party risk posture.

Skills

Information security
Risk management
Compliance
Third-Party Risk Management
Vendor risk
Supply chain security
Technical controls evaluation
GRC/TPRM tooling
Stakeholder influence
Communication skills

Education

Bachelor's degree or equivalent

Tools

Archer
ServiceNow
OneTrust
ProcessUnity

Job description

Responsibilities

  • Lead the end-to-end Third-Party Risk Management lifecycle (intake, due diligence, contracting, ongoing monitoring, and exit) for relevant third-parties, aligning to enterprise risk, national security compliance, security, privacy, and resilience requirements.
  • Design and maintain the TPRM operating model, including roles and responsibilities, RACI, and handoffs across cross-functional business teams, Procurement, Legal, and Security & Privacy.
  • Implement and continuously refine automation- and AI-enabled workflows (e.g., dynamic questionnaires, evidence collection, control testing, and issue tracking) to scale assessments, reduce manual effort, and show measurable efficiencies.
  • Develop and manage continuous control monitoring and data-driven vendor risk scoring, leveraging internal and external data sources (e.g., security ratings, vulnerability and incident data, SOC 2 reports) to produce actionable risk indicators, including supply chain and concentration risk.
  • Translate regulatory requirements and industry frameworks (e.g., NIST CSF, NIST 800-53, ISO 27001, SOC 2, SIG/CAIQ) into practical third-party control requirements, playbooks, and testing procedures.
  • Prepare and present clear metrics, dashboards, and narratives on third-party risk posture, key issues, and remediation progress to senior leadership, governance forums, and audit stakeholders.
  • Drive remediation and risk decisions with influence, partnering with senior leaders to resolve material third-party issues, shape risk acceptance decisions, and ensure timely closure of gaps.

Qualifications

  • Minimum Qualifications: Bachelor’s degree or equivalent practical experience and 5+ years of applicable experience in information security, risk management, privacy, or compliance, with significant experience focused on Third-Party Risk Management, vendor risk, or supply chain security in a program leadership role.
  • Proven experience designing, implementing, and operating TPRM processes across the third-party lifecycle (intake, due diligence, contracting, ongoing monitoring, and termination) in a highly regulated or high-risk environment, including hands-on experience evaluating technical and procedural controls at third parties, interpreting SOC 2 and similar assurance reports, and reviewing supporting evidence with infrastructure, application, and security engineering teams.
  • Strong working knowledge of information security and privacy control frameworks as applied to third parties (e.g., NIST CSF, NIST 800-53, ISO 27001, SOC 2, SIG/CAIQ, vendor due diligence standards).
  • Experience designing or using vendor risk scoring models, key risk indicators, and dashboards to monitor third-party risk posture and drive measurable outcomes, plus ability to design and improve process automation using modern GRC/TPRM tooling (e.g., Archer, ServiceNow, OneTrust, ProcessUnity or similar), including leveraging rules, integrations, and AI-enabled capabilities to streamline assessments and monitoring.
  • Proven ability to build cross-functional relationships with technology and engineering teams to enable technical workflows and advancements to the program, with success leading cross-functional initiatives and influencing stakeholders across Procurement, Legal, Privacy, Security, Engineering, Finance, and business teams without direct authority.
  • Excellent communication skills, with the ability to translate complex technical and regulatory concepts into clear, business-focused narratives for diverse audiences.
  • Familiarity with US-centric regulatory expectations related to third-party risk, data protection, and security (e.g., federal and state privacy and cybersecurity requirements, industry supervisory guidance).

Preferred Qualifications:

  • Experience building, scaling, or modernizing Third-Party Risk Management programs in highly regulated or US-critical sectors (e.g., financial services, telecommunications, cloud, or public sector), including close partnership with Privacy and Legal teams to align TPRM controls with data protection requirements.
  • Experience designing continuous control monitoring, automation, and data pipelines for third-party risk (e.g., integrating external security ratings, SIG/CAIQ responses, SOC 2 outputs, vulnerability and incident data), including experimentation with AI/ML or advanced analytics to identify anomalies and prioritize remediation.
  • Relevant professional certifications such as CTPRP, CTPRA, CISA, CISSP, CISM, CRISC, or similar.

About USDS

  • TikTok USDS Joint Venture LLC is dedicated to the safety and security of millions of Americans who create, discover, and connect with what they love on the apps we operate. The Joint Venture has been established in compliance with the Executive Order signed by President Trump on September 25, 2025.
  • Our foundation is a comprehensive data privacy and cybersecurity program we operate under defined safeguards to protect national security and secure U.S. user data, apps and the algorithm. We safeguard the U.S. content ecosystem, holding decision-making authority for trust and safety policies and moderation.
  • On-site presence across teams allows the company to operate with greater speed, alignment, and agility — especially in areas like real-time decision-making, team development, and integrated execution. As such, the company is shifting from a hybrid work model to a fully in-person schedule up to 5 days a week.

Why Join Us

  • Inspiring creativity is at the core of TikTok's mission. Our product helps people express themselves, discover, and connect. Our diverse teams make that possible, and we strive to create value for communities while inspiring creativity and joy.
  • We aim to do great things with great people, leading with curiosity, humility, and a desire to make an impact in a fast-growing tech company. We embrace challenges, iterate, and maintain an "Always Day 1" mindset to achieve meaningful breakthroughs.

Diversity & Inclusion

TikTok is committed to creating an inclusive space where employees are valued for their skills, experiences, and unique perspectives. Our platform connects people from across the globe and so does our workplace. We are passionate about diversity and building an environment that reflects the communities we reach.

USDS Reasonable Accommodation

USDS provides reasonable accommodations in our recruitment processes for candidates with disabilities, pregnancy, sincerely held religious beliefs, or other protected reasons. If you need assistance or a reasonable accommodation, please reach out at https://tinyurl.com/USDS-RA

Job Information

Compensation (Annual): The base salary range for this position in Washington, DC is $132,480 - $336,960. Compensation may vary based on qualifications, skills, competencies, experience, and location. Base pay is one part of the total package and may include discretionary bonuses/incentives and stock units. Benefits include medical, dental, vision, 401(k) with company match, paid parental leave, disability coverage, life insurance, wellbeing benefits, and paid time off. The company reserves the right to modify benefits programs at any time.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Third Party Risk Management Analyst - USDS
Third Party Risk Management Analyst - USDS

TikTok • New York (NY)

Hybrid
USD 98,000 - 147,000
Medical, dental, and vision insurance
401(k) savings plan with company match
Paid parental leave
+4
Manager, Security Posture Validation
Manager, Security Posture Validation

TikTok USDS Joint Venture • Washington

On-site
USD 168,000 - 394,000
Senior Security Automation Specialist - USDS
Senior Security Automation Specialist - USDS

TikTok USDS Joint Venture • Washington

On-site
USD 132,000 - 243,000
Medical, dental, and vision insurance
401(k) with company match
Paid parental leave
+6
Head of Cyber Crisis & Critical Incident Management - USDS
Head of Cyber Crisis & Critical Incident Management - USDS

TikTok USDS Joint Venture • Washington

On-site
USD 206,000 - 397,000
Medical insurance
401(k) match
Paid parental leave
+3
Manager, Security & Privacy Testing - USDS
Manager, Security & Privacy Testing - USDS

TikTok USDS Joint Venture • Washington

On-site
USD 168,000 - 395,000
Medical, dental, and vision insurance
401(k) savings plan with company match
Paid parental leave
+1
Senior Technical Program Manager, Operational Excellence - USDS
Senior Technical Program Manager, Operational Excellence - USDS

TikTok USDS Joint Venture • Washington

On-site
USD 119,000 - 282,000
Health insurance
401(k) with company match
Paid parental leave
+4
Procurement Generalist - USDS
Procurement Generalist - USDS

TikTok USDS Joint Venture • Los Angeles (CA)

On-site
USD 84,000 - 144,000
Product Manager, Risk Solutions - USDS
Product Manager, Risk Solutions - USDS

TikTok USDS Joint Venture • Seattle (WA)

On-site
USD 157,000 - 296,000
Procurement Category Manager - USDS
Procurement Category Manager - USDS

TikTok USDS Joint Venture • Los Angeles (CA)

On-site
USD 84,000 - 181,000
Medical, Dental, Vision
401(k) matching
Parental leave
+4
Product Manager, Risk Solutions - USDS
Product Manager, Risk Solutions - USDS

TikTok USDS Joint Venture • San Jose (CA)

On-site
USD 149,000 - 312,000