Risk Governance & Remediation Lead, Insider Threat

1 Month ago • 5 Years + • Cyber Security • Undisclosed

Job Summary

Job Description

The Risk Governance & Remediation Lead, Insider Threat at ByteDance is responsible for managing and mitigating information security risks within the organization. This involves developing key risk metrics, analyzing internal threat data to identify trends, and creating reports for senior management. The role requires defining and implementing a robust risk governance framework, collaborating with cross-functional teams, and ensuring alignment with organizational risk management and compliance strategies. Responsibilities include developing KPIs and KRIs, monitoring UEBA/DLP platforms, and working with HR and legal on data protection and employee rights. The ideal candidate possesses strong data analysis skills, experience with risk governance frameworks, and excellent communication abilities.
Must have:
  • Develop key risk metrics and KPIs
  • Analyze internal threat data and identify trends
  • Create risk reports for senior management
  • Implement a robust risk governance framework
  • Collaborate with cross-functional teams
  • 5+ years experience, 3+ years team management
  • Strong data analysis and reporting skills
Good to have:
  • Familiarity with GDPR, CCPA, HIPAA
  • Experience with UBA/UEBA solutions (Splunk, Exabeam)
  • Experience with threat modeling methodologies (STRIDE, PASTA)

Job Details

Responsibilities
About the Company Founded in 2012, ByteDance's mission is to inspire creativity and enrich life. With a suite of more than a dozen products, including TikTok as well as platforms specific to the China market, including Toutiao, Douyin, and Xigua, ByteDance has made it easier and more fun for people to connect with, consume, and create content. Why Join Us Creation is the core of ByteDance's purpose. Our products are built to help imaginations thrive. This is doubly true of the teams that make our innovations possible. Together, we inspire creativity and enrich life - a mission we aim towards achieving every day. To us, every challenge, no matter how ambiguous, is an opportunity; to learn, to innovate, and to grow as one team. Status quo? Never. Courage? Always. At ByteDance, we create together and grow together. That's how we drive impact - for ourselves, our company, and the users we serve. Join us. About the Team The Internal Threat Management team is responsible for managing and mitigating information security risks posed within the organisation. To ensure that the company's risk management and governance strategies are up to date and aligned across the organisation, this team is responsible for regular industry benchmarking and working with stakeholders from cross-functional teams to perform regular risk assessments and align risk mitigation strategies. This team is also responsible for managing the optimization, operation, training, and data analysis of the internal threat platform and UEBA (User and Entity Behavior Analytics) and DLP (Data Loss Prevention) platforms within the company. Responsibilities 1. Internal Threat Risk Metrics Creation: - Develop and define key risk metrics to assess the effectiveness of internal threat detection and mitigation strategies (e.g., number of insider threat incidents, false positives/negatives, response time, and incident resolution). - Create and maintain KPI (Key Performance Indicators) and KRI (Key Risk Indicators) specifically focused on internal threat risks, such as data exfiltration, privilege misuse, policy violations, and unauthorized access. - Design and implement frameworks to measure the performance of insider threat programs and related risk management initiatives. 2. Trend Analysis & Risk Monitoring: - Continuously monitor and analyze internal threat data, identifying emerging trends, patterns, and areas of concern related to insider threats (e.g., disgruntled employees, high-risk data access). - Use historical data to forecast future risk trends and provide actionable insights into potential vulnerabilities or growing threats. - Analyze incident trends (e.g., types of insider threats, departments at higher risk, or specific systems targeted) and report findings to key stakeholders. 3. Internal Threat Risk Reporting: - Develop and deliver regular risk reports for senior management, providing insights on the status and effectiveness of internal threat programs, key risk indicators, and threat trends. - Prepare reports and dashboards for internal stakeholders, ensuring that they highlight critical risk areas, emerging threats, and recommended actions for mitigation. - Collaborate with security, compliance, HR, and other teams to gather necessary data for reporting and ensure the reports meet regulatory and organizational requirements. 4. Governance Framework for Internal Threat Management: - Define and implement a robust risk governance framework that supports internal threat management, ensuring it is aligned with the organization’s overall risk management and compliance strategies. - Establish and manage processes for risk assessment, control testing, and risk mitigation related to internal threats, ensuring that these processes are effective and aligned with industry best practices. - Work closely with internal stakeholders to ensure that policies and procedures are properly followed and that risk management processes are integrated across departments. 5. Collaboration & Stakeholder Engagement: - Act as a liaison between internal sub-units, business units, IT, and other security teams to ensure that internal threat governance processes are integrated across the organization. - Engage with senior management to discuss findings from risk metrics, trend analysis, and reporting, and recommend necessary actions to address any identified risk areas. - Work with HR and legal teams to ensure that internal threat risk governance efforts align with employee rights, data protection regulations, and corporate policies.
Qualifications
Minimum Qualifications: - Bachelor's degree or above, with a preference for majors in Information Security, Computer Science, Information Technology, privacy, risk or a related field. Professional certifications such as CISSP, CISM, CRISC, or CGEIT are highly desirable. - Minimum of 5 years of work experience, with at least 3 years of team management experience and a preference for experience in risk management and insider threat program - Strong experience in data analysis and the ability to extract insights from complex risk data to identify patterns and trends. Expertise in developing dashboards and reports that clearly communicate complex risk data to senior management and non-technical stakeholders. - Proficient in risk governance frameworks and best practices for internal threat management, including risk assessments, control testing, and compliance. - Solid understanding of insider threat risks, including data exfiltration, privilege abuse, policy violations, and insider fraud. - Strong communication skills, with the ability to translate complex risk-related information into clear, actionable insights for diverse audiences. - Proven ability to manage and prioritize multiple projects and tasks. Preferred Qualifications - Familiarity with regulatory requirements related to data protection and internal threat management (e.g., GDPR, CCPA, HIPAA). - Experience with designing, implementation and operation of commercial or in-house UBA/UEBA solutions (e.g., Splunk, Exabeam) are highly desirable - Experience with threat modeling methodologies (e.g., STRIDE, PASTA) to analyze and assess security threats within software applications, systems, and networks. ByteDance is committed to creating an inclusive space where employees are valued for their skills, experiences, and unique perspectives. Our platform connects people from across the globe and so does our workplace. At ByteDance, our mission is to inspire creativity and enrich life. To achieve that goal, we are committed to celebrating our diverse voices and to creating an environment that reflects the many communities we reach. We are passionate about this and hope you are too.

Similar Jobs

Warner Bros Discovery - Sr. Cybersecurity Engineer

Warner Bros Discovery

Georgia, United States (Hybrid)
1 Month ago
The Walt Disney Company - Senior Systems Engineer (Project Hire)

The Walt Disney Company

Bay Lake, Florida, United States (On-Site)
2 Months ago
ByteDance - Insider Threat Program Manager, Information Security

ByteDance

Singapore (On-Site)
2 Months ago
Morning Star - Manager of Software Engineering, Credit Technology

Morning Star

Mumbai, Maharashtra, India (Hybrid)
3 Months ago
Fubo - Software Engineer, Data - Ad Engineering

Fubo

Bengaluru, Karnataka, India (Hybrid)
4 Months ago
Trend Micro - (Sr.) Cloud Developer (Vision One)

Trend Micro

Taipei City, Taiwan (On-Site)
4 Months ago
Luxoft - Security FW (PSP) / Memory Firmware (ABL FW) Developer

Luxoft

Bengaluru, Karnataka, India (On-Site)
2 Months ago
Applike - IT Security Manager (f/m/d)

Applike

Hamburg, Hamburg, Germany (Hybrid)
1 Month ago
Google - Google Security Manager, Data Centers

Google

Midlothian, Texas, United States (On-Site)
1 Month ago

Get notifed when new similar jobs are uploaded

Similar Skill Jobs

Trackman - DevOps Engineer

Trackman

Denmark (On-Site)
5 Months ago
Experian - Senior iOS Engineer

Experian

Hyderabad, Telangana, India (Hybrid)
4 Months ago
PwC - CD&E-Quality Assurance SOC Analyst-Senior Associate-Bangalore

PwC

Bengaluru, Karnataka, India (On-Site)
3 Months ago
The Walt Disney Company - Lead Software Engineer

The Walt Disney Company

Glendale, California, United States (On-Site)
1 Month ago
Intel Corporation - Network Security Engineer (DevSecOps)

Intel Corporation

Folsom, California, United States (On-Site)
2 Months ago
Rockstar Games - NOC Engineer

Rockstar Games

India (On-Site)
1 Month ago
Blue Yonder - Support Engineer I

Blue Yonder

Monterrey, Nuevo Leon, Mexico (Remote)
3 Months ago
NICE - Senior Cloud SRE

NICE

Pune, Maharashtra, India (Hybrid)
3 Months ago
Take-Two Interactive - NOC Engineer - Systems Infrastructure

Take-Two Interactive

Barcelona, Catalonia, Spain (On-Site)
3 Months ago
Next Level Business Services - Sr. Performance Test Engineer

Next Level Business Services

El Segundo, California, United States (On-Site)
3 Months ago

Get notifed when new similar jobs are uploaded

Jobs in Singapore

Interactive Brokers - Associate - Client Services

Interactive Brokers

Singapore (Hybrid)
3 Months ago
Garena - Intern, IP Collaboration & Partnerships

Garena

Singapore (On-Site)
2 Months ago
Netflix - Regional Sales Enablement Senior Associate, APAC

Netflix

Singapore, Singapore (On-Site)
1 Month ago
ByteDance - Tech Expert - Machine Learning Infrastructure

ByteDance

Singapore (On-Site)
2 Months ago
The Walt Disney Company - Strategy & Business Development Manager DTCR APAC

The Walt Disney Company

Singapore, Singapore (On-Site)
1 Month ago
Garena - Engineer/Senior Engineer, Database

Garena

Singapore (On-Site)
3 Months ago
The Walt Disney Company - Director, Integrated Marketing SEA

The Walt Disney Company

Singapore, Singapore (On-Site)
2 Months ago
ByteDance - Backend Software Engineer (SRE) Intern - 2025 Start

ByteDance

Singapore (On-Site)
1 Month ago
ByteDance - Senior Software Engineer, Vulnerability Scanning

ByteDance

Singapore (On-Site)
1 Month ago
Razer - Solutions Architect

Razer

Singapore (On-Site)
4 Months ago

Get notifed when new similar jobs are uploaded

Cyber Security Jobs

ByteDance - Privacy and Security Manager - Information System - San Jose

ByteDance

San Jose, California, United States (On-Site)
3 Months ago
Palo Alto Networks - Presales Manager - Network Security (Domain Consulting)

Palo Alto Networks

Geneva, Geneva, Switzerland (Remote)
2 Months ago
Infoblox - Technical Writer II

Infoblox

Bengaluru, Karnataka, India (On-Site)
3 Months ago
Granicus - Senior Security Analyst

Granicus

Bengaluru, Karnataka, India (Hybrid)
3 Months ago
PwC - IN_Associate_Java_Application Technology__Advisory_Jaipur

PwC

Jaipur, Rajasthan, India (On-Site)
4 Months ago
PwC - CD-Cyber Security-GRC Tech-Servicenow Now GRC Developer-Senior Associate-Bangalore

PwC

Bengaluru, Karnataka, India (On-Site)
4 Months ago
Fanatics - Offensive Security Engineer III

Fanatics

Hyderabad, Telangana, India (Hybrid)
3 Months ago
Penumbra - Sr Manager Cybersecurity

Penumbra

Alameda, California, United States (On-Site)
3 Months ago
Duolingo - Senior Security Engineer

Duolingo

Pittsburgh, Pennsylvania, United States (On-Site)
3 Months ago
Palo Alto Networks - Solutions Consultant - SLED

Palo Alto Networks

Sacramento, California, United States (On_site)
2 Months ago

Get notifed when new similar jobs are uploaded

About The Company

Where imagination meets innovation, delivering limitless gaming experiences.

Los Angeles, California, United States (Hybrid)

San Jose, California, United States (On-Site)

Gurugram, Haryana, India (On-Site)

San Jose, California, United States (On-Site)

Seattle, Washington, United States (On-Site)

View All Jobs

Get notified when new jobs are added by ByteDance

Level Up Your Career in Game Development!

Transform Your Passion into Profession with Our Comprehensive Courses for Aspiring Game Developers.

Job Common Plug