Insider Threat Program Manager Lead, Information Security

4 Months ago • 5-7 Years • Program Management

Job Summary

Job Description

The Insider Threat Program Manager Lead at ByteDance will develop and maintain the organization's insider risk security governance framework, aligning with industry best practices and regulatory requirements. Responsibilities include communicating this framework to stakeholders, conducting regular security risk assessments, monitoring security controls, and reporting to senior management. Collaboration with IT and business units to integrate insider threat measures into projects and processes is crucial. The role requires analyzing large datasets, identifying emerging risks, and translating business needs into actionable rules. A strong understanding of DLP, UEBA, and security platforms is essential.
Must have:
  • Develop and maintain insider risk governance framework
  • Conduct regular security risk assessments
  • Communicate risk posture to all stakeholders
  • Collaborate with IT and business units
  • Analyze large datasets, identify emerging risks
  • Minimum 5 years experience, 2 years leadership
Good to have:
  • Experience with UBA/UEBA solutions (e.g., Splunk, Exabeam)
  • Experience with threat modeling methodologies (e.g., STRIDE, PASTA)

Job Details

Responsibilities
About the Company Founded in 2012, ByteDance's mission is to inspire creativity and enrich life. With a suite of more than a dozen products, including TikTok as well as platforms specific to the China market, including Toutiao, Douyin, and Xigua, ByteDance has made it easier and more fun for people to connect with, consume, and create content. Why Join Us Creation is the core of ByteDance's purpose. Our products are built to help imaginations thrive. This is doubly true of the teams that make our innovations possible. Together, we inspire creativity and enrich life - a mission we aim towards achieving every day. To us, every challenge, no matter how ambiguous, is an opportunity; to learn, to innovate, and to grow as one team. Status quo? Never. Courage? Always. At ByteDance, we create together and grow together. That's how we drive impact - for ourselves, our company, and the users we serve. Join us. About the Team The Internal Security Risk Management & Governance team is responsible for managing and mitigating information security risks posed within the organisation. To ensure that the company's risk management and governance strategies are up to date and aligned across the organisation, this team is responsible for working with stakeholders from cross-functional teams to perform regular risk assessments, designing and implementing risk mitigation controls. This team is also responsible for managing the optimization, operation, training, and data analysis of the internal threat platform and UEBA (User and Entity Behavior Analytics) and DLP (Data Loss Prevention) platforms within the company. Responsibilities - Develop and maintain the organization's insider risk security governance framework, including risk scenario mapping to controls, policies, procedures, and standards that align with industry best practices and regulatory requirements. Such framework must be sufficiently detailed to allow ease of execution with clarity in roles and responsibility amongst stakeholders. - Communicate the insider threat governance framework to key stakeholders and build effective collaboration models with stakeholders with clear roles and responsibilities, transparent tracking of metrics and seamless management reporting. - Conduct regular security risk assessments to identify risk trends, vulnerabilities and alert patterns, and work with relevant departments to develop mitigation and remediation strategies. - Monitor and report on the effectiveness of security controls and the status of security risks to senior management. Communicate risk assessment and trend analysis findings, risks and gaps to both technical and non-technical program stakeholders. - Coordinate with IT and business units to ensure insider threat security measures are integrated into technology projects and business processes. - Identify and garner the support of internal and external stakeholders to collaborate on driving change, including risk remediation and leading parties involved to meet risk remediation objectives. - Translate business and technology requirements into relevant insider threat rules for operational teams to implement - Stay abreast of the latest security trends, threats, and technologies to continuously improve the organization's insider threat security posture. - Conduct analysis of large complex datasets involving insider risks, track metrics and identify gaps and vulnerabilities - Understanding emerging insider risks to build and improve proactive threat detection.
Qualifications
Minimum Qualifications 1. Bachelor's degree or above, with a preference for majors in Information Security, Computer Science, Information Technology, privacy, risk or a related field. Professional certifications such as CISSP, CISM, CRISC, or CGEIT are highly desirable. 2. Minimum of 5 years of work experience, with a preference for experience in DLP (Data Loss Prevention), UEBA (User and Entity Behavior Analytics), or security platforms-related work. 3. Minimum 2 years of leadership experience in managing high-performing GRC/Information Security team. 4. Experience with security risk assessment methodologies and tools. 5. Skilled in creating and maintaining risk registers, developing risk treatment plans, and effectively communicating risk posture to stakeholders at all levels of the organization. 6. Self-driven and results-oriented, enjoys challenging tasks, demonstrates enthusiasm for work, and can handle job pressures. 7. Excellent communication and interpersonal skills, with the ability to engage and influence stakeholders at all levels. Proven ability to manage and prioritize multiple projects and tasks. Preferred Qualifications - Hands on in-house experience with designing, implementation and operation of commercial or in-house UBA/UEBA solutions (e.g., Splunk, Exabeam) are highly desirable - Experience with threat modeling methodologies (e.g., STRIDE, PASTA) to analyze and assess security threats within software applications, systems, and networks. ByteDance is committed to creating an inclusive space where employees are valued for their skills, experiences, and unique perspectives. Our platform connects people from across the globe and so does our workplace. At ByteDance, our mission is to inspire creativity and enrich life. To achieve that goal, we are committed to celebrating our diverse voices and to creating an environment that reflects the many communities we reach. We are passionate about this and hope you are too.

Similar Jobs

GoMotive - Senior Sales Strategy & Operations Manager (AM Focused)

GoMotive

United States (Remote)
1 Month ago
KPIT - CTO_ML/DL Data scientist

KPIT

Pune, Maharashtra, India (On-Site)
8 Months ago
GameJobs - Strategic Financial Analyst - Infrastructure

GameJobs

San Mateo, California, United States (On-Site)
2 Months ago
Qualcomm - Staff Camera SW Customer Engineer

Qualcomm

Shanghai, China (On-Site)
4 Weeks ago
WebMD - Senior Program Manager (Salesforce CPQ & Go-to-Market Operations)

WebMD

Yardley, Pennsylvania, United States (Hybrid)
1 Month ago
Playstation - Senior Technical Program Manager (Software/Firmware)

Playstation

San Mateo, California, United States (On-Site)
2 Months ago
Enphase Energy - Program Manager SW

Enphase Energy

Bengaluru, Karnataka, India (On-Site)
5 Months ago
Marvell - Global Compensation Program Manager

Marvell

Santa Clara, California, United States (On-Site)
1 Month ago
Rippling - Senior Program Manager, Talent Management

Rippling

San Francisco, California, United States (On-Site)
1 Month ago

Get notifed when new similar jobs are uploaded

Similar Skill Jobs

Rippling - Account Manager - Strategic, Growth & Retention (Partner Referred Business)

Rippling

San Francisco, California, United States (Hybrid)
3 Weeks ago
Accenture - Quality Engineer (Tester)

Accenture

Bengaluru, Karnataka, India (On-Site)
2 Months ago
Apple - Software Development Engineer in Test, Release Validation Automation

Apple

San Diego, California, United States (On-Site)
1 Month ago
Apple - Sr. Software Engineering Manager - Test

Apple

Cupertino, California, United States (On-Site)
2 Months ago
Blazesoft - SEO Manager

Blazesoft

Vaughan, Ontario, Canada (On-Site)
1 Month ago
Unity - Senior Client Partner, Ad Monetization

Unity

San Francisco, California, United States (On-Site)
4 Days ago
bytedance - Network Automation Engineer

bytedance

Seattle, Washington, United States (On-Site)
3 Months ago
Synechron - Lead AI/ML Engineer

Synechron

Bengaluru, Karnataka, India (On-Site)
1 Month ago
Springer Group - UI Designer

Springer Group

Pune, Maharashtra, India (On-Site)
1 Month ago

Get notifed when new similar jobs are uploaded

Jobs in Singapore

bytedance - LLM Global Data - LLM Coding Trainer Intern - 2025 Start

bytedance

Singapore (On-Site)
6 Months ago
Tencent - Research and Development Intern

Tencent

Singapore (On-Site)
11 Months ago
Thales - Regional Manager, Business Security & Governance

Thales

Singapore, Singapore (On-Site)
2 Months ago
bytedance - Site Reliability Engineer - Privacy & Security - Singapore

bytedance

Singapore (On-Site)
8 Months ago
CME Group - APAC Commercials Manager

CME Group

Singapore (On-Site)
2 Weeks ago
bytedance - Software Engineer, LLM Storage System Intern

bytedance

Singapore (On-Site)
1 Month ago
appier - Director, Organizational & Talent Development

appier

Singapore (On-Site)
1 Month ago
Sony Music Career - Business Development Manager/Sr. Manager South East Asia (Talent Pooling)

Sony Music Career

Singapore (On-Site)
1 Month ago

Get notifed when new similar jobs are uploaded

Program Management Jobs

ness digital  - Data Solutions Program Manager

ness digital

Prague, Czechia (On-Site)
3 Months ago
zoox - Senior Program Manager, Contingent Workforce Systems

zoox

Foster City, California, United States (Hybrid)
3 Weeks ago
Qualcomm - Program Manager, IoT Chipset

Qualcomm

San Diego, California, United States (On-Site)
2 Weeks ago
Tesla - Technical Program Management Internship

Tesla

Brandenburg, Germany (On-Site)
4 Months ago
Coherent corp. - Principal Program Manager

Coherent corp.

Murrieta, California, United States (On-Site)
3 Weeks ago
Adyen - Supportability Program Manager

Adyen

Bengaluru, Karnataka, India (On-Site)
1 Month ago
CAE - Program Manager

CAE

Binghamton, New York, United States (On-Site)
3 Weeks ago
Qualcomm - Sr Program Manager- APSS Linux Android, CPU SS & Multimedia Technologies

Qualcomm

Hyderabad, Telangana, India (On-Site)
1 Month ago
WebMD - Wellness Program Manager

WebMD

Newark, New Jersey, United States (Hybrid)
2 Months ago
NVIDIA - Senior Software Program Manager

NVIDIA

Taipei City, Taiwan (Hybrid)
2 Months ago

Get notifed when new similar jobs are uploaded

About The Company

Founded in 2012, ByteDance's mission is to inspire creativity and enrich life. With a suite of more than a dozen products, including TikTok as well as platforms specific to the China market, including Toutiao, Douyin, and Xigua, ByteDance has made it easier and more fun for people to connect with, consume, and create content.

San Jose, California, United States (On-Site)

San Jose, California, United States (On-Site)

Seattle, Washington, United States (On-Site)

Seattle, Washington, United States (On-Site)

San Jose, California, United States (On-Site)

View All Jobs

Get notified when new jobs are added by bytedance

Level Up Your Career in Game Development!

Transform Your Passion into Profession with Our Comprehensive Courses for Aspiring Game Developers.

Job Common Plug