Regulatory Intelligence & Implementation Specialist - Global Security Organization
Indexed description
Responsibilities
The mission of TikTok's Global Security Organization is to build and earn trust by reducing risk and securing our businesses and products. Also known as "GSO", this team is the foundation of our efforts to keep TikTok safe, secure, and operating at scale for over 1 billion people around the world. We work to ensure that the TikTok platform is safe and secure, that our users' experience and their data remains safe from external or internal threats, and that we comply with global regulations wherever TikTok operates.
Trust is one of TikTok's biggest initiatives, and security is integral to our success. In whatever ways users interact with us - whether they're watching videos on their For You page, interacting with a Live video, or buying products on TikTok Shop - GSO protects their data and privacy, so they can have a secure and trustworthy experience.
The GSO provides industry-leading security and privacy services to company, guided by four principles: trust and transparency, business enablement, risk-informed decision-making, and proactive risk reduction. We strive to build sustainable, world-class security capabilities.
The Security Solutions & Delivery (SSD) team turns security requirements into practical, auditable outcomes that help the business move faster and reduce risk. We support business revenue through Customer Assurance, sustain critical third-party integrations through Partner Compliance, translate evolving regulatory requirements into action through Regulatory Intelligence, and directly take ownership of fixing systemic identified risks through Security Remediation. In addition, Our Organizational Excellence pillar supports the broader Global Security Organization with the finance, coordination, and the operational foundations it needs to run effectively. The impact of this work is clear and immediate: faster deals, stronger partner continuity, addressing high priorities, and greater trust with customers and partners.
We are seeking a Regulatory Intelligence & Implementation Lead to drive the translation of complex US, EU, and global regulatory requirements into operational security controls. This is a backfill role following the transition of the previous lead, who built a strong foundation in USDS liaison, regulatory intelligence, and cross-functional execution. You will inherit and expand upon an established program portfolio that includes USDS joint venture compliance, regulatory intelligence tracking, and cross-functional security initiatives.
This role sits at the intersection of regulatory compliance, security operations, and strategic program management. You will be the person who ensures that when new regulations emerge - whether it's an EU Digital Services Act amendment, a US data sovereignty directive, or a regional data protection law - our security organization is not only aware but has a clear, operational plan to comply. You will own the end-to-end process: from horizon scanning and regulatory analysis, through gap assessment and control design, to facilitation, validation, and readiness.
Responsibilities
- Track and analyze emerging US, EU, and global regulatory developments (GDPR, US requirements, data sovereignty) to anticipate security obligations before they land
- Translate legal and regulatory requirements into concrete security control implications for the global security organization
- Build and maintain a regulatory roadmap that maps compliance deadlines to security implementation efforts
- Leverage industry frameworks (ISO, NIST, SOC 2) to bridge regulatory requirements and internal controls
- Lead gap assessments comparing current controls against new and evolving regulatory requirements and requests
- Partner with European Privacy teams to operationalize GDPR, and other EU requirements across security processes
- Serve as the primary Global Security liaison to USDS ,own the relationship and ensure alignment on joint venture compliance obligations
- Ensure USDS-negotiated security commitments are reflected in internal controls, processes, and documentation
- Build scalable security processes that adapt to multiple regulatory frameworks without bespoke solutions for every new request
- Maintain a notification decision tree and escalation paths, know who needs to be notified, when, what evidence is required, and when service timelines slip
- Maintain a formal legal review checkpoint for regulatory interpretations before security teams act on them
- Establish regulatory compliance metrics that give regular, measurable visibility into posture and progress
- Maintain a regular reporting cadence to leadership and relevant committees through dashboards and reports
- Develop playbooks and SOPs that enable the broader security team to implement regulatory requirements consistently
Qualifications
Minimum Qualifications:
- Demonstrated expertise in translating regulatory requirements into operational security controls - not just compliance reporting, but actual implementation
- Strong working knowledge of US and EU regulatory frameworks relevant to technology companies: GDPR, DSA, OSA, CCPA, and data sovereignty requirements
- Experience working with or interfacing to government oversight entities, auditors, or regulatory bodies
- Proven track record of cross-functional program management, driving initiatives that span Legal, Privacy, Engineering, and Product teams
- Experience establishing metrics, reporting cadences, and strategic visibility mechanisms for compliance programs
- Excellent ability to brief senior leadership on regulatory matters
Preferred Qualifications
- Bachelor's degree in Law, Public Policy, Information Security, Computer Science, or related field, or equivalent practical experience
- 5+ years of experience in regulatory compliance, security governance, or privacy programs - preferably in a technology company operating under complex regulatory oversight
- Direct experience with US or similar government-negotiated data security arrangements
- Experience managing large-scale compliance training programs (1,000+ learners)
- Familiarity with IAM governance programs, including User Access Reviews and access management strategy
- Industry certifications such as CIPP/E, CIPM, CISSP, or CISA
(e.g., company-wide offsites, training drives)
Job Information
[For Pay Transparency] Compensation Description (annually)
The base salary range for this position in the selected city is $111600 - $162000 annually.
Compensation may vary outside of this range depending on a number of factors, including a candidate's qualifications, skills, competencies and experience, and location. Base pay is one part of the Total Package that is provided to compensate and recognize employees for their work, and this role may be eligible for additional discretionary bonuses/incentives, and restricted stock units.
Benefits may vary depending on the nature of employment and the country work location. Employees have day one access to medical, dental, and vision insurance, a 401(k) savings plan with company match, paid parental leave, short-term and long-term disability coverage, life insurance, wellbeing benefits, among others. Employees also receive 10 paid holidays per year, 10 paid sick days per year and 17 days of Paid Personal Time (prorated upon hire with increasing accruals by tenure).
The Company reserves the right to modify or change these benefits programs at any time, with or without notice.
For Los Angeles County (unincorporated) Candidates:
Qualified applicants with arrest or conviction records will be considered for employment in accordance with all federal, state, and local laws including the Los Angeles County Fair Chance Ordinance for Employers and the California Fair Chance Act. Our company believes that criminal history may have a direct, adverse and negative relationship on the following job duties, potentially resulting in the withdrawal of the conditional offer of employment:
1. Interacting and occasionally having unsupervised contact with internal/external clients and/or colleagues;
2. Appropriately handling and managing confidential information including proprietary and trade secret information and access to information technology systems; and
3. Exercising sound judgment.
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search