×
Register Here to Apply for Jobs or Post Jobs. X

GRC Cybersecurity Controls Analyst

Job in Washington, District of Columbia, 20022, USA
Listing for: TikTok USDS Joint Venture
Full Time position
Listed on 2026-09-16
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security & Data Protection
Salary/Wage Range or Industry Benchmark: 88920 - 176400 USD Yearly USD 88920.00 176400.00 YEAR
Job Description & How to Apply Below

Responsibilities

About the Team

Tik Tok is seeking a GRC Cybersecurity Controls Analyst to join the Tik Tok USDS Joint Venture (JV) GRC Controls & Certifications team. This role will support the operation, testing, and continuous improvement of the controls framework and will help drive audit readiness across key security, compliance, privacy, and regulatory obligations. The candidate will work closely with control owners, product teams, security teams, privacy, legal, internal audit, external auditors, and GRC leadership to evaluate control design, implementation, and operating effectiveness.

About the Role

The role will support control testing, evidence review, audit response coordination, control narrative development, and issue identification across frameworks and obligations such as ISO 27001, SOC 2, NIST CSF, PCI, control validation, and other certification or assessment activities. The candidate will also help mature the team’s approach to GRC automation and engineering. This includes improving how controls are mapped, tested, monitored, and reported through tooling, dashboards, structured data, workflow automation, evidence recommendations, and scalable testing.

The ideal candidate is comfortable working at the intersection of GRC, security controls, audit readiness, and process automation.

Key responsibilities include:
  • Support the maintenance and continuous improvement of the controls framework, including control descriptions, mappings, owners, evidence expectations, testing procedures, and control narratives.
  • Perform control testing and validation activities, including design, implementation, and operating effectiveness testing.
  • Review evidence submitted by control owners and product teams to determine whether it sufficiently demonstrates control performance and meets audit or assessment expectations.
  • Coordinate with control owners, evidence owners, product teams, and GRC stakeholders to resolve evidence gaps, clarify control intent, and improve testing quality.
  • Support internal and external audits, certifications, and assessments, including ISO 27001, SOC 2, PCI, NIST CSF, and other GRC obligations.
  • Support GRC automation initiatives by helping define requirements for workflow automation, control monitoring, and scalable control testing processes.
  • Work with technical and engineering teams to understand security tools, data sources, system-generated evidence, and opportunities to automate or improve control validation.
  • Contribute to a culture of high-quality documentation, defensible controls testing, and continuous improvement across the Controls & Certifications function.
Minium Qualifications
  • Bachelor’s degree in Information Security, Cybersecurity, Information Technology, Risk Management, Compliance, Engineering, Data Analytics, or a related discipline, or equivalent practical experience.
  • 3+ years of experience in GRC, IT risk, security controls, audit readiness, control testing, compliance, security assurance, or a related field. Experience performing or supporting control testing, including evaluating control design, implementation, and operating effectiveness.
  • Experience gathering, reviewing, and assessing technical control evidence from stakeholders, systems, tools, dashboards, or documentation repositories. Working knowledge of security and compliance frameworks such as ISO 27001, NIST CSF, SOC 2, PCI-DSS, or similar control frameworks.
  • Familiarity with security domains such as Identity and Access Management, Vulnerability Management, Incident Management, Asset Management, Logging and Monitoring, Data Security, SDLC, Third-Party Risk Management, Business Continuity / Disaster Recovery, or Privacy.
  • Strong writing and documentation skills, with the ability to create clear control…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary