AI Governance and Compliance Specialist - Global Security Organization

San Jose, California, US Until 8/22/2026 4+ years exp H-1B sponsor history First posted May 19, 2026 Last posted May 19, 2026
Job description

Description

The mission of TikTok's Global Security Organization is to build and earn trust by reducing risk and securing our businesses and products. Also known as "GSO", this team is the foundation of our efforts to keep TikTok safe, secure, and operating at scale for over 1 billion people around the world. We work to ensure that the TikTok platform is safe and secure, that our users' experience and their data remains safe from external or internal threats, and that we comply with global regulations wherever TikTok operates.

Trust is one of TikTok's biggest initiatives, and security is integral to our success. In whatever ways users interact with us — whether they're watching videos on their For You page, interacting with a Live video, or buying products on TikTok Shop — GSO protects their data and privacy, so they can have a secure and trustworthy experience.

The GSO provides industry-leading security and privacy services to company, guided by four principles: trust and transparency, business enablement, risk-informed decision-making, and proactive risk reduction. We strive to build sustainable, world-class security capabilities.

TikTok is seeking an AI Governance and Compliance Specialist to drive the technical assurance and compliance operations of our content recommendation and AI systems, ensuring they operate transparantly, fairly, and in compliance with evolving regulatory frameworks such as the AI Governance Act, DSA, GDPR, ISO, OSA, etc. This role sits at the intersection of engineering, policy, and governance — translating regulatory obligations into concrete compliance frameworks, algorithmic controls, risk assessments, and providing expert input into regulatory engagement.

Responsibilities
Regulatory Readiness & Operational Controls
- Regulatory Mapping: Interpret global AI and platform safety laws (e.g., EU DSA, EU AI Act, US state laws like CA SB 1047 / Colorado AI Act) and translate requirements into actionable technical guardrails for recommendation and Algorithmic systems.
- Recommender Compliance: Execute compliance strategy for Recommender specific mandates, including options for non-profiling recommendation feeds, ad/content parameter disclosures, and systemic risk mitigation for content curation.
- Model Risk Tiering & Auditability: Evaluate recommendation architectures, input data, and optimization objectives to assign appropriate regulatory risk classifications. Build automated tracking systems that log model lineage, training parameters, and evaluation results to ensure end-to-end traceability for compliance audits.

Technical Assurance and Model Auditing
- Systemic Risk Mitigation Pipelines: Design operational guardrails to prevent feed algorithms from amplifying illegal content, severe disinformation, hate speech, or content linked to mental health harms and minor safety
- Algorithmic Bias & Fairness Testing: Conduct quantitative pre-release and post-release audits evaluating candidate generation (retrieval) and ranking stages for popularity bias, demographic disparity, and filter-bubble formation.
- ML-SDLC Governance Gates: Ensure compliance sign-off gates into the Machine Learning Software Development Lifecycle (ML-SDLC), ensuring no high-risk recommendation model ships to production without documented clearance.
- Third-Party Audit Package Preparation: Assemble end-to-end evidence packages, data samples, and code/architecture explanations for external statutory auditors and regulatory bodies.

Audit Readiness & External Engagement
- Regulatory Liaison: Act as the primary technical point of contact during independent third-party audits, regulatory inquiries, or statutory compliance filings.
- Auditing Rigor: Exceptional attention to detail in constructing audit trails, technical documentation, and regulatory evidence packages.
- Engineering & Legal Bridge: Serve as the translator between Machine Learning Engineers/Data Scientists and Legal/Policy teams to align model architecture choices with legal defensibility.
- Global Process Enablement: Establish standardized playbooks and repeatable compliance protocols for recommendation engine risk assessments, ensuring consistent regulatory adherence across diverse geographic markets and product verticals.

Requirements

Minimum Qualifications:
- Proven track record in successfully developing, implementing, and managing comprehensive compliance programs at scale with experience engaging directly with regulators, external auditors, or supervisory bodies on algorithmic or AI compliance matters.
- Deep understanding of recommendation systems, ranking algorithms, recommendation architectures, and content distribution pipelines at scale.
- Proficiency in Python, SQL, and data analysis; experience with ML frameworks (e.g., PyTorch, TensorFlow) and experimentation platforms.
- Exceptional analytical, critical thinking, and problem-solving skills, coupled with the ability to translate complex legal and technical concepts into clear, actionable advice for diverse technical and non-technical audiences.
- Demonstrated ability to work independently, effectively manage multiple competing priorities, and thrive in a fast-paced, dynamic, and often ambiguous environment.

Preferred Qualifications
- Bachelor’s degree in Computer Science, Data Science, Information Policy, Law & Technology, or a related quantitative/policy discipline.
- 4+ years of professional experience in AI/ML governance, tech compliance, algorithmic auditing, or responsible AI engineering.
- Solid understanding and practical experience in Global regulations (e.g., DSA, OSA, GDPR, AI Governance Act), including practical experience in their application.
- Strong foundational understanding of leading cybersecurity frameworks (e.g., NIST, ISO 27001) and robust control environments.
- Audit and risk experience conducting algorithmic impact assessments (AIAs), data protection impact assessments (DPIAs), or systemic risk evaluations.
- Familiarity with the unique challenges and opportunities related to algorithmic governance, fairness, and transparency in large-scale online platforms.
- Industry experience in technology or social media.
- Relevant professional certifications such as AIGP, CISA, CISM, CRISC, CISSP, or CIPP/E.

About this role

Summary

Manage AI compliance, design system safeguards, conduct audits, and liaise with regulators.

Job title

AI Governance and Compliance Specialist - Global Security Organization

Experience level

4+ years

Minimum experience

4+ years exp

Industry

software

Location requirements

San Jose, California, USA; remote work not specified.

Salary

Not specified

Visa sponsorship

H-1B sponsor history

Management role

No

Skills & keywords

Required skills

PythonSQLML frameworksregulatory knowledgeaudit documentation

Preferred skills

law & technologymachine learning governancealgorithmic auditingcybersecurity frameworksprofessional certifications

Specializations

regulatory mappingrecommendation systemsmodel risk assessmentalgorithmic biascompliance
Locations

Structured locations inferred from the posting.

San Jose, CA, USA

Work arrangement unknown City