logo
Locations
Blog
Jobs
triangle icon

Technology

Security Engineer, Risk Adversary and Intel Discovery - TikTok BRIC

Location:

Singapore

Employment Type:

Regular

Job Code:

A20456

Share this listing:

Responsibilities

Business Risk Integrated Control (BRIC) is a global team protecting ByteDance users, platform health, and the authenticity of community and business ecosystems. We build the risk control algorithms, AI technologies, platforms, and infrastructure behind that work, across products including TikTok, CapCut, Lemon8, and Lark. Our work spans account and content integrity, and safety across advertising and e-commerce. We apply machine learning across areas such as graph learning, anomaly detection, and multimodal models to understand users, content, behavior, and the relationships between them. The challenge is recognizing genuine activity accurately, so the people using our products never notice the systems working. You will shape the trust, safety, and sustainable growth of ByteDance's global platforms, applying advanced AI to some of the hardest real-world problems in the field. RAID (Risk Adversary and Intelligence Discovery) focuses on understanding and countering adversarial activities across underground ecosystems. By combining threat intelligence research, adversary analysis, and offensive security assessments, the team helps business teams identify emerging threats, understand attack methods, validate existing defenses, and build comprehensive and measurable risk control capabilities. Responsibilities - Underground Ecosystem & Threat Intelligence Research: Conduct in-depth research into underground industry chains, adversarial groups, abnormal business activities, and emerging attack trends. Investigate intelligence techniques such as adversary attribution, threat intelligence monitoring, and intelligence-driven risk identification to provide actionable insights and proactive risk warnings. - Adversarial Tool & Attack Analysis: Analyze commonly used illicit tools, cheating software, and attack techniques. Reconstruct attack methods and paths, investigate the underlying technical mechanisms, and identify potential vulnerabilities and gaps in existing risk control strategies. - Adversarial Simulation & Security Assessment: Approach business systems from the perspective of external adversaries and conduct effective adversarial exercises to evaluate the real-world effectiveness of existing risk control strategies. Research emerging offensive and defensive security techniques and recommend improvements to detection and defense mechanisms. - Risk Intelligence Collection & Correlation Analysis: Collect and analyze intelligence from internal and external sources, including OSINT and other relevant intelligence sources. Correlate information across multiple data sources to identify adversarial groups, trace attack origins, and support the investigation and mitigation of business risks. - Underground Ecosystem Mapping & Monitoring: Identify underground industry chains targeting critical business scenarios, monitor key links, and analyze their operational models, monetization mechanisms, scale, and evolution to support targeted risk prevention and disruption. - Security Trend Monitoring & Incident Response: Track domestic and international security developments, conduct technical analysis of security incidents, and support rapid response to emerging threats and attacks. - Risk Defense Optimization: Translate intelligence findings and adversarial assessment results into actionable defense strategies. Collaborate with cross-functional teams to continuously improve risk detection, mitigation, and control capabilities.


Qualifications

Minimum Qualification(s) - Have a solid understanding of underground ecosystems, including adversarial groups, industry chains, attack techniques, and monetization models, with the ability to independently analyze business risks and adversarial behavior. - Be familiar with at least one of the following areas: Android/iOS/Web reverse engineering, mobile application security, abuse and cheating techniques, fake engagement, incentive abuse, or other forms of adversarial attacks. - Understand common web application, mobile application, and system vulnerabilities, including their underlying principles, detection methods, and remediation approaches. Stay informed about emerging offensive and defensive security techniques. - Be familiar with core risk control strategies and mechanisms, with the ability to analyze adversarial behavior and evaluate the effectiveness of existing defenses. - Have proficiency in at least one major programming language, such as Python, Go, Java, C/C++, or JavaScript, and possess foundational data analysis and mining skills. - Demonstrate strong analytical thinking and risk awareness, with the ability to correlate information across multiple data sources, investigate adversarial activities, and independently solve complex problems. Preferred Qualification(s) - Have experience with threat intelligence collection and analysis, including OSINT and relevant intelligence sources. Be proficient in using domestic and international social platforms or other channels for intelligence gathering and analysis. - Experience building or contributing to enterprise Red Team capabilities, business risk control, threat intelligence, adversarial analysis, or underground ecosystem disruption. - Experience in enterprise Red Team operations, penetration testing, or vulnerability discovery, including contributions as a security researcher or white-hat hacker through a Security Response Center (SRC). - A proven track record of identifying and submitting high-impact vulnerabilities in mobile applications, mini-programs, or web applications. - Strong expertise in threat intelligence analysis, adversary attribution, or technical investigations, with established analytical methodologies. - Access to extensive intelligence sources, particularly international or overseas intelligence channels. - Demonstrated experience identifying and mitigating underground ecosystem risks through the analysis and correlation of internal and external data sources.


Job Information

About TikTok

TikTok is the leading destination for short-form mobile video. At TikTok, our mission is to inspire creativity and bring joy. TikTok's global headquarters are in Los Angeles and Singapore, and we also have offices in New York City, London, Dublin, Paris, Berlin, Dubai, Jakarta, Seoul, and Tokyo.​

Why Join Us

Inspiring creativity is at the core of TikTok's mission. Our innovative product is built to help people authentically express themselves, discover and connect – and our global, diverse teams make that possible. Together, we create value for our communities, inspire creativity and bring joy - a mission we work towards every day.​

We strive to do great things with great people. We lead with curiosity, humility, and a desire to make impact in a rapidly growing tech company. Every challenge is an opportunity to learn and innovate as one team. We're resilient and embrace challenges as they come. By constantly iterating and fostering an "Always Day 1" mindset, we achieve meaningful breakthroughs for ourselves, our company, and our users. When we create and grow together, the possibilities are limitless. Join us.​

​

Diversity & Inclusion​

TikTok is committed to creating an inclusive space where employees are valued for their skills, experiences, and unique perspectives. Our platform connects people from across the globe and so does our workplace. At TikTok, our mission is to inspire creativity and bring joy. To achieve that goal, we are committed to celebrating our diverse voices and to creating an environment that reflects the many communities we reach. We are passionate about this and hope you are too.​

Ready for a career

at TikTok?

Discover a career that energizes and excites you every day.

triangle icon

@2026 TikTok