Head of Advanced Threat Management
- 🇺🇸 United States
- On-site
- Manager or above
- 4 weeks ago
- Splunk
- Agile
- AI
- Incident Response
- SIEM
- Computer Vision
- Machine Learning
About the Team
The USDS JV Threat Detection and Response team is responsible for protecting TikTok’s people, data, and systems from threats that originate within the organization. We partner across Security, Legal, HR, IT, and Engineering to detect, investigate, and mitigate insider risks ranging from data exfiltration and policy violations to fraud and unauthorized access.
About the Role
As the Head of Advanced Threat Management Operations, you will own end-to-end threat defense operations in the JV Secure Environment, spanning both cyber and physical domains. This is a highly technical, visionary leadership role. You will move the organization away from legacy workflows—such as pulling massive data into a centralized Splunk instance before generating alerts—and instead pioneer an agile, decentralized, and intelligent defense model.
You will lead the team into an AI-enabled future where Agentic AI powers the entire threat management lifecycle: from autonomous detection engineering and real-time case enrichment to automated incident response. Your scope covers product-level application security at internet scale, global logging and data source intake strategy, and a modernized physical threat defense program.
Responsibilities
- Next-Gen Cyber Operations: Drive the strategy for monitoring, detection, and response across our consumer-facing internet products at the application level, moving far beyond standard corporate enterprise security.
- AI & Agentic Automation: Architect and deploy autonomous AI agents to manage detection engineering, execute real-time telemetry enrichment, and orchestrate complex response playbooks.
- Modern Data & Logging Intake: Define the data ingestion and edge-processing strategy tailored for high-volume internet products, optimizing for real-time telemetry without relying on legacy centralized SIEM bottlenecks.
- Major Incident Command: Coordinate with the Head of Cyber Crisis & Critical Incident Manaagement on large-scale, highly complex security incidents across cross-functional engineering and business teams.
- AI-Driven Physical Security: Oversee physical security monitoring operations, shifting the paradigm from manual screen-watching to computer vision and AI-enabled anomaly detection to optimize resource allocation.
Minium Qualifications
- Experience: 10+ years of dedicated experience in cybersecurity, specifically within the tech industry or high-scale internet product environments.
- Technical Background: A proven, rigorous engineering or highly technical cyber background. You must be able to go deep into application code, distributed systems, and modern cloud architecture.
- Incident Mastery: Proven track record of commanding major, high-stakes security incidents with minimal disruption to global product availability.
- Visionary Mindset: A strong refusal to rely on old ways of thinking; an evangelist for autonomous systems, machine learning, and agentic workflows in security.
Head of Advanced Threat Management · TikTok USDS