Compliance Analytics & Reporting Analyst - USDS
- ๐บ๐ธ United States
- On-site
- Manager or above
- 3 months ago
- Risk Management
- Regulatory Compliance
- Python
- CISA
- CISM
- CRISC
- GCIH
- GCIA
- ISO 27001
- NIST
- RMF
- SOC2
- Change Management
About the Team
The USDS Security - Governance, Risk & Compliance team is responsible for managing USDS security compliance in accordance with US compliance requirements and objectives, and providing industry leading governance, risk, and compliance services.
The core service offerings include: Compliance & Security Risk Management, Controls & Compliance Framework, Security Compliance Policies, Charters, & Protocols, Vendor Program & Third-Party Risk Management, National Security Reporting and Enablement, and Security & Compliance Behavior & Culture.
About the Role
TikTok USDS JV is seeking a Compliance Analytics & Reporting Analyst to be part of the US Security & Privacy, Governance, Risk and Compliance team. This role will be responsible for driving the data-backed coordination, execution, and automation of regulatory reporting associated with TikTok's regulatory compliance requirements.
This is a truly cross-functional role requiring a proactive self-starter who can bridge the gap between technical data environments and regulatory reporting. Beyond translating GRC metrics into executive-ready reports, the ideal candidate will actively seek out opportunities to optimize our operations. They will build automated workflows, design data pipelines, and eliminate manual overhead, helping to improve a structured, transparent, and industry-leading compliance framework.
Responsibilities
- Design, build, and maintain data pipelines, dashboards, and automated workflows to streamline compliance tracking and eliminate manual reporting overhead.
- Serve as the liaison, partnering with the business, security, and privacy teams and assisting them to implement regulatory compliance requirements and establish mechanisms to track compliance and potential violations
- Develop, track, and visualize key performance indicators (KPIs) and key risk indicators (KRIs) that accurately reflect organizational compliance posture and may impact organizational compliance and regulatory requirements
- Oversee data management, change documentation in collaboration with the Compliance Assurance Team and implementation tracking in response to actual or perceived compliance incidents or changing compliance requirements
- Identify systemic operational bottlenecks across GRC streams and independently build scalability solutions that decouple workflow volume from headcount growth.
- Manage the compliance lifecycle: assess current US Compliance posture, identify compliance gaps and develop corrective action plans to remediate gaps, drive remediation efforts with control owners, and report progress to stakeholders
- Consistently deliver high-quality services and deliverables
Minimum Qualifications
- Excellent analytical, written reporting, and problem-solving skills, communication skills (verbal and written), ability to influence and ability to manage a project end-to-end.
- Hands-on experience building basic automations, data workflows, or scripting solutions (e.g., Python, low-code automation tools, or advanced spreadsheet models) from scratch.
- Experience reporting risk (KRIs/KPIs) within a global enterprise, developing a culture of risk informed decision making
- Experience conducting risk assessments and tracking treatment plans and working within compliance programs; experience with U.S. compliance frameworks.
- Experience contributing to complex compliance reporting structures (e.g., CFIUS, FTC orders, or other applicable U.S. Compliance regulatory reporting); Ability to navigate between U.S. compliance content and technical details
- Highly motivated to contribute and grow within a complex area of importance to the organization; demonstrates excellent organizational direction, time management, problem-solving, prioritization, goal setting, leadership, motivation, negotiation, and interpersonal relations
- 3+ years applicable experience, working knowledge of international compliance standards and requirements
Preferred Qualifications
- Experience navigating fast-paced, complex, or high-growth technology environments.
- One of the following certifications, or equivalent certifications: CISA, CDPSE, CISM, CRISC, GCIH, GCIA, CRCM or CCEP (or industry-specific) compliance certification
- Working knowledge of risk and control frameworks (e.g., ISO 27001, NIST CSF, NIST RMF, SOC 2).
- Experience executing data governance, data protection, change management processes
Compliance Analytics & Reporting Analyst - USDS ยท TikTok USDS