Detection Analyst, Threat Intelligence - Global Security Organization

Singapore Until 9/4/2026 H-1B sponsor history First posted July 6, 2026 Last posted July 6, 2026
Job description

Description

The mission of TikTok's Global Security Organization is to build and earn trust by reducing risk and securing our businesses and products. Also known as "GSO", this team is the foundation of our efforts to keep TikTok safe, secure, and operating at scale for over 1 billion people around the world. We work to ensure that the TikTok platform is safe and secure, that our users' experience and their data remains safe from external or internal threats, and that we comply with global regulations wherever TikTok operates.

Trust is one of TikTok's biggest initiatives, and security is integral to our success. In whatever ways users interact with us — whether they're watching videos on their For You page, interacting with a Live video, or buying products on TikTok Shop — GSO protects their data and privacy, so they can have a secure and trustworthy experience.

We are looking for a Detection Analyst who enjoys solving security problems through software. In this role, you will build the systems, pipelines, and detection logic that turn threat intelligence into scalable detection capabilities for our partners.
This is a hands-on engineering position for someone who excels in coding and enjoys building production-quality solutions. You will work at the intersection of threat intelligence, data engineering, and detection development to operationalize intelligence into reliable tools, pipelines, and automated detections.

What You’ll Do
- Build Threat-Informed Detections: Design, implement, and maintain detection logic based on threat intelligence, attacker behaviors, fraud patterns, and abuse trends.
- Develop Production-Grade Pipelines & Tooling: Write clean, maintainable code to collect, ingest, normalize, enrich, and serve data used for detections and investigations.
- Turn Intelligence into Engineering Outputs: Translate threat reports, indicators, and behavioral patterns into scalable detection content, enrichment workflows, and monitoring logic.
- Improve Detection Quality: Measure detection performance, tune logic, reduce noise, and improve coverage through data-driven iteration.
- Build Internal Tools: Create services, scripts, workflows, or lightweight applications that help analysts and investigators search, analyze, and act on threat data more efficiently.
- Collaborate Cross-Functionally: Partner with Threat Intelligence, Security Engineering, Product, and business teams to design, validate, and deploy detection capabilities into production.

Requirements

Minimum Qualification(s):
- Strong software engineering fundamentals and hands-on coding ability.
- Proficiency in Python and/or Golang for building data pipelines, automation, APIs, or backend services.
- Demonstrated experience writing maintainable, testable, and production-quality code.
- Experience working with structured and semi-structured data, including logs, event data, and text-based intelligence.
- Familiarity with SQL, data modeling, and designing schemas that support detection and investigation workflows.
- A strong interest or background in detection engineering, threat intelligence, security analytics, fraud, abuse, or cybercrime problems.
- Excellent communication skills, with the ability to explain technical decisions and translate complex security problems into engineering solutions.

Preferred Qualification(s):
- Experience building detection pipelines, alerting workflows, or specialized security tooling.
- Familiarity with threat intelligence concepts, indicators of compromise (IOCs), TTPs, and investigation workflows.
- Experience working with Hive, MongoDB, advanced SQL, and data visualization dashboards.
- Background in distributed systems, workflow orchestration, or large-scale data processing.

About this role

Summary

Build detection systems and pipelines translating threat intelligence into scalable security solutions

Job title

Detection Analyst, Threat Intelligence - Global Security Organization

Experience level

none

Industry

software

Location requirements

Singapore, remote work not specified

Salary

Not specified

Visa sponsorship

H-1B sponsor history

Management role

No

Skills & keywords

Required skills

pythongolangsqldata modelingsecurity analytics

Preferred skills

detection pipelinesalerting workflowsthreat intelligencemongodbdistributed systems

Specializations

threat detectiondata pipelinesthreat intelligencesecurity analyticsdetection engineering
Locations

Structured locations inferred from the posting.

Singapore

Work arrangement unknown Country