IT Security Tools Operations Engineer

TikTok Inc

  • San Jose, CA
  • 12 days ago

    Highlights

    Strong understanding of Windows, Linux, endpoint, network, and application security, with the ability to troubleshoot issues across agents, servers, networks, APIs, integrations, and backend infrastructure; perform root cause analysis; and coordinate remediation with infrastructure, endpoint, network, SOC, and vendor teams. Hands-on experience with enterprise security technologies such as EDR/AV, SIEM, IDS/IPS, VPN, SWG, CASB, firewalls, vulnerability scanners, or endpoint management platforms, including agent/client rollout, policy configuration, health monitoring, version upgrades, and issue remediation.

    Numbers & Facts

    LocationSan Jose, CA

    Description

    IT Security team is responsible for global enterprise IT cyber security, server security, endpoint security, application security construction, and protection. We work to improve overall IT security capabilities and security posture by providing security processes, security assessments, security operations, and security vulnerability management services. The team also supports IT teams and business departments across the organization in meeting their security requirements.

    Responsibilities

    • Security Tools Administration: Manage the day-to-day operations, configuration, and administration of enterprise IT security tools (including firewalls, IDS/IPS, EDR, SWG, VPN, DLP, Mail Gateways, and other security-related technologies).
    • Performance & Health Monitoring: Proactively monitor the performance, health, and availability of security infrastructure; identify, troubleshoot, and resolve technical issues or anomalies to ensure continuous functionality.
    • Lifecycle & Patch Management: Perform regular maintenance activities, including updates, patches, upgrades, and configuration fine-tuning to ensure systems remain secure and up to date.
    • Policy & Rule Optimization: Collaborate with IT and cross-functional security teams to define, implement, and optimize security tool configurations, policies, and rules to align with organizational security requirements and industry best practices.
    • Compliance & Auditing: Conduct routine audits and compliance assessments of security tools to verify alignment with regulatory standards and internal security policies.
    • Evaluation & Deployment: Participate in the evaluation, proof-of-concept (PoC) testing, selection, and implementation of new security tools and technologies to continuously enhance the overall security posture.
    • Incident Response & Log Analysis: Review security logs and reports to identify patterns or anomalies that may indicate potential security breaches; respond to and resolve security incidents in a timely manner.
    • Documentation & SOPs: Assist in developing and maintaining comprehensive security documentation, including standard operating procedures (SOPs), user guides, and knowledge base articles to facilitate effective tool utilization and support.
    • Training & Support: Provide technical support and training to end-users and other IT teams on the proper usage and maintenance of security tools.
    • Cross-Functional Collaboration: Partner with vendors, internal stakeholders, and cross-functional teams to ensure security policies and procedures are followed and technical issues are resolved efficiently.
    • Operational Flexibility: Support operational needs, which may require flexible working hours, shift schedules, or weekend/holiday coverage, while maintaining a standard 5-day in-office work week. Minimum Qualification(s)
    • Bachelor's degree in Computer Science, Cyber Security, Information Technology, Engineering, or a related technical field.
    • 4+ years of hands-on experience in enterprise security engineering, IT security operations, endpoint security engineering, network security engineering, or security tools administration.
    • Experience owning production security platforms, including deployment, configuration, service health and capacity/performance monitoring, operational support, change management, upgrades, patching, optimization, incident troubleshooting, and maintaining service availability.
    • Hands-on experience with enterprise security technologies such as EDR/AV, SIEM, IDS/IPS, VPN, SWG, CASB, firewalls, vulnerability scanners, or endpoint management platforms, including agent/client rollout, policy configuration, health monitoring, version upgrades, and issue remediation.
    • Programming or scripting ability, such as Python, Bash, PowerShell, or API-based automation, with experience automating repetitive security operations or security tool administration tasks.
    • Strong understanding of Windows, Linux, endpoint, network, and application security, with the ability to troubleshoot issues across agents, servers, networks, APIs, integrations, and backend infrastructure; perform root cause analysis; and coordinate remediation with infrastructure, endpoint, network, SOC, and vendor teams.

    Preferred Qualification(s)

    • Experience with security tool integrations and telemetry/log forwarding to SIEM, SOC, or incident response teams, including log source onboarding, connector configuration, parser/field mapping, and data pipeline validation.
    • Experience with vulnerability validation, security control testing, or technical security assessments, with the ability to validate findings, understand attacker techniques, and translate results into security tool configuration or control improvements.
    • Hands-on experience with tools such as CrowdStrike, Microsoft Defender for Endpoint, SentinelOne, Carbon Black, Trend Micro, McAfee ePO, Symantec Endpoint Protection, Intune, Jamf, SCCM, Palo Alto, Fortinet, Check Point, Zscaler, Netskope, Splunk, Microsoft Sentinel, QRadar, Tenable, Qualys, or Rapid7.
    • Experience designing or automating security tool health checks, endpoint compliance reporting, patch tracking, failed installation remediation, log pipeline validation, policy deployment, or security operations reporting.
    • Relevant professional certifications such as CISSP, CISM, CISA, Security+, GCIH, GCIA, GCED, OSCP, or equivalent.

    Similar Jobs

    See more jobs