Likeremote

Subscribe to the latest remote jobs:

  • Likeremote jobs on https://LinkedIn.com/
  • Likeremote jobs on https://telegram.org/
  • Likeremote jobs on Reddit.com
TikTok USDS logo

Solution Architect, Security

TikTok USDS
  • πŸ‡ΊπŸ‡Έ United States
  • On-site
  • Staff / Principal
  • 4 months ago
  • Design Systems
  • IaC
  • Microservices
  • mTLS
  • KMS
  • Vulnerability Management
  • IAM
  • VPC
  • PKI
  • TLS
  • Network Security
  • Zero Trust
  • SOC2
  • ISO 27001
  • PCI DSS
  • CI/CD
  • Devops
  • Terraform
  • Kubernetes
  • TCP
  • DNS
  • Load Balancing
  • OAuth2
  • OIDC
  • SAML
  • FedRAMP
  • CISA
  • Risk Management
  • Incident Response
  • Threat Modeling
  • Sigstore
Not scoredNo CV on file. Upload one and this job gets a score out of 100.Upload CV

About the Team

The Security and Information Technology team is missioned to run and operate security infrastructures, platforms and technologies, as well as to support cross-functional teams to protect our users, products and infrastructures. In this team you'll have a unique opportunity to have first-hand exposure to the strategy of the company in key security initiatives, especially in deploying and maintaining scalable and secure-by-design systems and solutions. Our challenges are not your regular day-to-day technical problems; you'll be part of a team that's developing new solutions to new challenges of a kind not previously addressed by big tech. It's working fast, at scale, and we're making a difference.

About the Role

The Security Solution Architect is a deeply hands-on individual contributor who personally designs end-to-end technical security architectures for assigned products. You read source code and infrastructure-as-code, trace data flows across microservices, reason about networking and trust boundaries at the protocol level, and author detailed, implementable designs yourself— from threat models through reference architectures, data-flow diagrams, and control specifications. You lead through technical depth, defending every decision at the level of cryptographic primitives, identity and key management, network segmentation, and service-to-service trust. Subject-matter experts retain final authority in their domains; your value is the engineering-grade design work that makes their decisions concrete and buildable, rather than handing off a framework and orchestrating meetings.

Responsibilities

  • Author Compliance-by-Design Architectures: Translate abstract national-security, privacy, and policy requirements (e.g., NIST SP 800-53, data residency, access segregation) into concrete, buildable designs you write yourself: trust-boundary and data-flow diagrams, identity and key-management schemes, network segmentation, and service-to-service authentication (mTLS, request signing, token exchange). You specify protocols, message formats, crypto primitives, and failure modes in enough detail that engineering can build directly from your design.
  • Reverse-Engineer Real Systems: Build an accurate model of how each product actually works by reading code, IaC, service manifests, and API contracts—mapping microservice topology, data flows, authn/authz paths, network paths, and trust boundaries—and pinpoint exactly where controls must sit (telemetry, access segregation, data residency, encryption in transit and at rest).
  • Threat Model and Prove Out Designs: Produce rigorous threat models (e.g., STRIDE/attack-tree) tied to the real architecture, enumerating failure modes, attacker capabilities, and the control mitigating each. Where feasible, validate hands-on through prototyping, proofs of concept, or testing actual behavior—so designs are demonstrably correct, not theoretical.
  • Lead Deep Technical Design Reviews: Run reviews where you engage at the implementation level—challenging API contracts, key lifecycles, segmentation, and data handling, not just checking boxes. Produce and maintain reference architectures, design specs, and Architecture Decision Records (ADRs) capturing concrete trade-offs (e.g., mTLS vs. per-message signing, KMS/HSM model, isolation boundary). You are accountable for the technical correctness and completeness of the design.
  • Be the Front Door and Calibrate "Good Enough": Serve as the primary intake point for product teams seeking security architecture support, and partner with downstream security and privacy teams (TDR, Data Security, Infrastructure Security, Vulnerability Management, GRC, Privacy) to right-size controls to the actual threat—negotiating pragmatic, defensible trade-offs rather than gold-plating or under-protecting.
  • Documentation and Audit Readiness: Maintain high-quality architecture documentation, control mappings, and evidence artifacts that are traceable to specific requirements and defensible to regulators in internal and external audits.

Measures of Success (First 6–12 Months)

  • Documented architecture baselines and security architecture maps for priority products, with clear owners and traceability to national-security and privacy requirements.
  • Approved solution designs with clear traceability from requirements through architecture decisions, design specs, and deployed controls.
  • Reduced compliance-related rework and faster alignment on key security decisions, with fewer iterations between security, product, and engineering.

Minimum Qualifications

  • Bachelor's degree in Computer Science, Information Security, or a related field, or equivalent practical experience, with experience working in the technology industry.
  • 8+ years in a hands-on security architecture or security engineering role, with a portfolio of detailed technical designs you personally authored (reference architectures, threat models, design specs, data-flow/sequence diagrams) that shipped to production. Prior software/infrastructure engineering experience is strongly expected. You have written code and/or operated real systems, not only governed them.
  • Deep, demonstrable expertise in at least two of: cloud security (IaaS/PaaS, IAM, VPC design), application/API security, data security and cryptography (PKI, key management, TLS/mTLS, signing, encryption at rest/in transit), or network security (segmentation, zero-trust, service mesh)—designed to the protocol and primitive level.
  • Demonstrable experience translating regulatory or compliance requirements (e.g., SOC 2, ISO 27001, PCI DSS) into technical security controls.
  • Strong understanding of modern development practices (e.g., CI/CD, DevOps) and how to integrate security into them.
  • Demonstrated ability to partner and negotiate with cross-functional business, product, and compliance stakeholders, balancing business needs and regulatory obligations without exposing the business to undue risk.
  • Able to independently read source code, IaC (e.g., Terraform), Kubernetes/container manifests, and API specs to understand microservice architecture, data flows, authn/authz, and trust boundaries—without relying on engineering to walk you through it.
  • Fluency in modern architecture and protocols: distributed/microservice systems, networking (TCP/TLS, DNS, HTTP, load balancing, VPC/segmentation), identity (OAuth2/OIDC, SAML, mTLS, workload identity), and applied cryptography (signing, PKI, key lifecycle, HSM/KMS).

Preferred Qualifications

  • Direct experience designing security solutions to meet U.S. national security-related compliance obligations, such as those governed by NIST SP 800-53, NIST SP 800-171, FedRAMP, CISA directives, or similar frameworks.
  • In-depth knowledge of security controls related to data residency and localization, supply chain risk management (SCRM), and mandatory incident reporting.
  • Proven ability to design and implement comprehensive logging and monitoring solutions that enable effective security operations and incident response.
  • Experience conducting threat modeling, security design reviews, and risk assessments for complex software and infrastructure.
  • Familiarity with enterprise architecture frameworks and their application to security.
  • Designing software/artifact supply-chain integrity controls: code/artifact signing (e.g., GPG/Sigstore), SHA-256 manifests, keyservers, and verification gates in build and distribution pipelines.
  • Exposure to hardware- or platform-rooted security (hardware root of trust, secure boot, TEEs/attestation, HSM-backed keys) is a plus, but not required—this role centers on application, cloud, data, and network architecture.
  • Designing service-to-service trust and tenant/region isolation: mTLS vs. per-message signing trade-offs, certificate and key lifecycle, and network-level isolation boundaries.

Solution Architect, Security Β· TikTok USDS

Auto apply with Likeremote